CyberWire Daily - Clear your calendar, it’s Patch Tuesday.

Episode Date: September 9, 2026

Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47... million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sextortion. Andy Hornegold, Chief Security Technologist from Intruder, discusses what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Putting AI at the head of the class.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Andy Hornegold, Chief Security Technologist from Intruder, discussing what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Selected Reading Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days (Hackread) Ivanti Patches Critical Flaws Across Enterprise Security Products (SecurityWeek) Chrome 153 Patches Seventh Zero-Day of 2026 (SecurityWeek) Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (SecurityWeek) ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws (SecurityWeek) CISA, NSA and FBI Warn Chinese AI Firms Are Targeting U.S. AI Models at Industrial Scale (HSToday) Europe's push for space sovereignty. (N2K Networks) History for European spaceflight: Isar Aerospace reaches orbit and deploys payloads on second flight (Isar Aerospace) ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 (Talos Intelligence) LG TVs caught spying even when offline or on standby (The Verge) 'White hat' hackers take $47 million bounty after $320 million crypto theft (The Record) Man gets 15 years for extorting women with AI-generated porn videos (Bleeping Computer) Alpha School’s AI teaching model is expanding. Does it work? (Scientific American) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Yes, you can have an enterprise network that's secure and reliable and high performance. And no, you don't need to choose the best two out of three. With Meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage. That's because Meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network. Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design. You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching, firewalls, DNS security, and VPNs. You'll really know what's running on your network down to the most granular client level.
Starting point is 00:01:03 Step off the hardware box upgrade treadmill and switch to, to meter for a predictable fee and free up your team to spend time on all the other things that keep your business running. Try it out for yourself and book a demo online at meter.com slash cyberwire. That's METER.com slash cyberwire. Patch Tuesday is a doozy. The feds-worn China-based AI companies are distilling USAI models. A new click-fix campaign goes straight for the browser. Smart TVs get nosy. Packers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sex distortion.
Starting point is 00:02:02 Our guest is Andy Horngold, Chief Security Technologist from Intruder, discussing what makes up a reliable AI pen test. And putting AI at the head of the class. It's Wednesday, September 9th, 2026. I'm Dave Bittner, and this is your. Cyberwire Intel Briefing. Thanks for joining us here today. It's great to have you with us. Microsoft's September Patch Tuesday is its largest on record,
Starting point is 00:02:56 with the company reporting fixes for 966 vulnerabilities. Independent tallies very slightly, but all point to an unusually heavy month. 105 vulnerabilities are rated critical. 258 involve remote code execution, and 438 involve privilege escalation. Two Windows Zero Days were already being exploited. One affects the Windows Update stack and can allow a local attacker to gain system privileges. Another, a buffer overflow in Windows ALPC, can let an attacker escape a low-pledge
Starting point is 00:03:35 app container and reach system. Neither provides an initial remote foothold. Both are useful for escalating privileges after a system. has already been compromised. Microsoft also patched critical vulnerabilities across core networking services, including DNS, DHCP, NetLogon, Messaging Q, and NFS. CrowdStrike identified at least 17 remote code execution flaws reachable over the network without authentication. Office received 22 critical fixes, including vulnerabilities that could potentially execute code
Starting point is 00:04:11 when a malicious file is merely previewed. Hyper V flaws could enable attacks from a compromised guest virtual machine against its host. The broader September patch cycle is similarly busy. Adobe fixed more than 170 vulnerabilities, including an actively exploited, unauthenticated Commerce and Magento RCE Zero Day. Google patched 230 Chrome vulnerabilities, including the browser's seventh exploited zero day of 2026. Evante addressed six critical RCE vulnerabilities in neurons for ITSM,
Starting point is 00:04:50 while Schneider Electric, Siemens, Aviva, and Rockwell Automation issued updates covering industrial systems. SISA, the NSA, and FBI are warning that China-based AI companies have been systematically extracting capabilities from leading U.S. AI models through large-scale knowledge distillation campaigns. The agencies say DeepSeek, Moonshot AI, Alibaba, Minimax, Stepfund, and ZAI have extracted billions of tokens through millions of requests involving models including Claude, GPT, Gemini, and Grok since at least late 2024.
Starting point is 00:05:34 Knowledge distillation is a legitimate technique for training smaller models using outputs for more capable ones, but the advisory says these campaigns violate U.S. providers' terms of service and accelerate Chinese AI development. The agencies assess the activity is occurring likely with Chinese government awareness. The advisory urges U.S. AI companies to improve detection of suspicious accounts and usage patterns, alter responses to suspected distillation attempts to reduce their value, and share intelligence across model providers, cloud platforms, and API aggregators. Maria Vermazis is host of the T-minus Space Cyber Podcast. She joins us each Wednesday with the latest news from space.
Starting point is 00:06:24 Today, it's about European sovereignty. Thank you, Dave. This past Saturday on September 5th, I saw Aerospace of Germany made history with the first launched to orbit from the European continent. Isar's spectrum rocket launched from Andoia spaceport in Norway and successfully deployed six satellites to low Earth orbit. Now, Isar is a commercial space company with a large backing from the European Space Agency, and their successful launch from Norway means Europe will now have launch options much closer to home beyond the Issa spaceport in Kuru, French Guiana. With the proven ability to launch to orbit from European soil with homegrown European
Starting point is 00:07:09 rocketry, the push now is to scale up and increase launch cadence to meet growing demand from European customers. Along those lines, Isar says four additional spectrum rockets are already in production and that the company plans to manufacture up to 40 spectrum launch vehicles a year when their new production facility is complete. In all, Isar's successful orbital, launch is a major step forward for European space sovereignty, especially as Europe continues to build out its high priority, secure satellite communications constellation, the iris squared. For the CyberWire Daily, I'm Maria Vermazes from T-minus Space Cyber Briefing. Back to you, Dave. Be sure to check out the T-minus Space Cyber podcast wherever you get your favorite shows.
Starting point is 00:07:58 Cisco Talos is tracking a cryptocurrency theft campaign that puts a twist on ClickFix social engineering. Instead of persuading victims to execute commands on their computers, attackers convince them to inject malicious JavaScript directly into their browsers. The lure is a fake vulnerability report promising bigger payouts from cryptocurrency exchanges. Victims are instructed either to paste JavaScript into Chrome or, you know, install it through the legitimate tamper monkey extension, which gives the malware persistence. The attackers have promoted the supposed exploit through telegram, dark web forums, and paste sites. The injected code uses Google's visualization API to retrieve obfuscated JavaScript stored
Starting point is 00:08:48 in publicly accessible Google Sheets, making command and control traffic look like legitimate browser activity. Once running, the script acts as a web skill. Gimmer, replacing cryptocurrency deposit addresses in website responses and the clipboard with attacker-controlled wallets while displaying fake bonus information. TALOS identified 49 Bitcoin addresses associated with the campaign and traced roughly $10,000 to known victim payments, though the actual hall may be higher. An investigation by Gamer's Nexus, Level 1 techs, and independent security resources,
Starting point is 00:09:28 researchers found LG smart TVs extensively collecting information about owners and their homes. Tests found the TV's scanning local networks for nearby devices, gathering location and Wi-Fi data, and sending information to LG ad solutions. Researchers also found the TVs could record microphone audio while in standby, storing recordings offline until Internet access returned. LG's automatic content recognition technology, additionally samples audio and video to identify content viewed through smart TV apps and connected devices, including HDI inputs. A $320 million cryptocurrency theft from Liquid Network ended with the attackers returning most of the money and keeping about $47 million as a self-appointed bug bounty. Liquid said purported white-hat hackers withdrew 4,000 Bitcoin from one of its wallets Sunday,
Starting point is 00:10:33 prompting operator Blockstream to pause deposits and withdrawals. The attackers then opened negotiations through messages embedded in blockchain transactions, claiming they were white hats and demanding that Blockstream patch an alleged vulnerability before they returned the funds. After roughly 12 hours of public and private exchanges, The hackers returned about 266.5 million on Monday and retained 598.5 Bitcoin as their reward. Blockstream said updated software had been deployed as it prepared to restart the system. The vulnerability's source remains debated, although side-swap and several blockchain security experts have pointed to a flaw in elements,
Starting point is 00:11:20 the software underlying Blockstream's liquid side chain. An Ohio man has been sentenced to 15 years in federal prison for a cyber-stalking and sex-stortion campaign that used artificial intelligence to create sexually explicit material depicting his victims. Prosecutors say 37-year-old James Stroller II used more than 100 AI models across more than two dozen platforms to generate explicit images and videos. Between December 2024 and June 2025, he harassed at least six adult women, sending both authentic and AI-generated nude images, threatening victims with sexual violence,
Starting point is 00:12:06 and sharing fabricated explicit material with their coworkers. He also threatened victims' mothers in an effort to obtain nude photographs. Investigators found more than 700 images Straller had posted to a child's sexual abuse website, along with thousands of potentially abusive or violent files on his phone. Straller pleaded guilty in April and became the first person convicted under the 2025 Take It Down Act, which prohibits publishing intimate images and AI-generated explicit forgeries without consent. Coming up after the break, my conversation with Andy Horngold from Intruder.
Starting point is 00:12:56 we're discussing what makes up a reliable AI pen test and putting AI at the head of the class. Stick around. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is an opportunity for something to go wrong. And most security programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast-moving companies like Ramp, Hursor, and Harvey to ensure they're always audit-ready.
Starting point is 00:13:49 And now Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools, and your whole environment. The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you, and cutting vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at vanta.com slash cyber. That's V-A-N-T-A dot com slash cyber.
Starting point is 00:14:41 Andy Horngold is chief security technologist from Intruder. We recently sat down to discuss what makes up a reliable AI pen test. Pen testing's come on leaps and bounds probably in the last, I'd say, 24 months. I think everybody's come on leaps and bounds in the last eight, 12 months, right? The whole world seems to have shifted. But I think professional services and human-led pen testing has probably been under more pressure as of late from product-led approaches to delivering security validation and security
Starting point is 00:15:15 assurance. Obviously, pen testing, human-led pen testing has pretty much been point in time for a very long time. And anybody who is a pen tester who works in security will tell you that continuous is definitely the way to go. But historically, it's been difficult to try and turn a human-led approach into a continuous offering, just because human time is expensive. You're capped by people being on a holiday and their availability. But with the advent of AI, being able to reason across applications, being able to hold entire code bases and infrastructure configurations and cloud configurations in its context window in one go, being able to reason across it. There certainly shifted things. And finally, I think after probably a couple of decades
Starting point is 00:16:00 of people saying that continuous is definitely the right approach, it feels like it's finally within grasp of having true security validation on continuously. So the people who are tasked with pen testing, what are some of the specific things they need to be mindful of these days in this new environment? I think in the new environment you're able to do things significantly quicker than you were previously. Like I remember doing pen tests back in the day where you were asked to do source code reviews or at least code-assisted pen tests. And you'd have to use one of the SAST scanners, the static code analysis tools that was out there and was available. was always a headache. I don't think anybody, like, when I ran a pen testing team over a context, nobody enjoyed doing that security, like code review side of things. I think there's
Starting point is 00:16:52 very few people in the world who do enjoy reading other people's code. But, you know, that's part of what we need to do when it comes to informed pen testing. But now with the, you know, with AI that's available, pen testers are able to do that more quickly. So they're able to, they're able to reason across code. They're able to interrogate it. They're able to find answers to questions within a code base that historically would have taken them time to query across. I think the professional services industry is having a bit of a shake-up at the moment, and I put pen testing under professional services. So I think there is some difficulty. The reason is just because AI pen testing, I think, is going to take up some of that market space. That's not to say I think AI pen-testing is
Starting point is 00:17:38 going to hoover up every part of pen testing. I think there's still expertise-led, experience-led components of pen testing that's really important, right? Like when you're dealing with safety systems, ICS, OT, weird and wonderful networks, I think that's still going to be human-led pen testing. But right now, I think we're going to start to see that human come out of that loop for the day-to-day, probably more mundane business-as-usual style pen-testing. And I think that's definitely going to impact the way people are operating within the professional services space. I know you've advocated for the importance of benchmarks provided by an independent party here. Can you explain that to us? Why is that important for AI pen testing?
Starting point is 00:18:24 Sure thing. I think coming from pen testing and red teaming myself, if you're a consumer, if you're somebody who's going out to buy a pen test, you want to make sure that you have some level of assurance of the quality of that pen test, of that red team, whatever it may be. You need to know that I'm going to have somebody on my side who is able to do what I need them to, right? They're not just going to be some, for lack of a better phrase, cowboy who's going to come on and potentially not do what they've told me they can do or they should be doing.
Starting point is 00:19:00 And we've done that historically, right, using benchmarks and using qualifications. So you'll often hear people say I have OSWE, like off-sec qualifications, and as a consumer you can say, okay, the pen testing firm that I'm buying from has a certain level of certification. That's not necessarily going to say that the individual pen tester that is assigned to your gig is necessarily going to have all of those qualifications, but you know you're getting it from a legitimate firm. Now, when it comes to the AI side of things, we don't really have any of that kind of, understanding of what is the level of quality that each of these models with their harnesses, these AI pen testers, are actually capable of delivering? Are they able to deliver at kind of a
Starting point is 00:19:47 certified level, at a high level, like a highly experienced pen tester would be able to deliver? Or are they just going to be able to do the basic checks that we expect of, you know, junior pen testers, graduates who are just coming out of university? And that's really important. It's really important to be able to say with confidence that the pen test I've just received has some level of quality to it. So that's why I think over the last few months we've been investigating, like, what does certification look like for this new wave of AI pen testers? What does it take for somebody to accept that the AI pen test that they've just had run for them is of quality? No, don't get me wrong, the findings that we're seeing within AI pen testing are
Starting point is 00:20:34 eye-wateringly good. They are finding things that experienced pen testers haven't been able to find for kind of the last five, six years. They're chaining together really complicated attack paths and building this understanding of risk through applications and infrastructure that have kind of laid dormant for years. So that kind of gives you some confidence that the quality is there, but how do we benchmark it? And we're seeing kind of a combination of things happen to give people that kind of trust. We're seeing benchmarks from private organizations saying, hey, this model performs slightly better at this benchmark than this other model does.
Starting point is 00:21:17 We're seeing private companies kind of compare themselves against each other, but all of those are led predominantly by the marketing approach, right? You're going to see some favoritism in there. Now, in the UK and actually US, Australia as well, One of the certification approaches we've had historically has been called Crest, the Council for Registered Ethical Security Testers, and they've put pencesters through exams, through assault courses, to be able to say whether they reach a certain bar.
Starting point is 00:21:48 My opinion is that I think we need something independent, third party, that can deliver the same kind of certification and benchmarking for AI pen testers at large. There's an increasing number of AI pen testing firms springing up. So how do we have a third-party independent organization that's able to give us that certification rather than just hearing the noise that comes with a huge, multi, hundreds of thousands of dollars marketing campaign?
Starting point is 00:22:21 In your opinion, what are the types of things that organizations should be asking of the folks that they're engaging with to do their pen testing. I mean, if we're talking specifically around the kind of the AI pen testing approach, I think there's a bunch of different questions you can ask. One of which is kind of like, what is the history, what is the heritage, if you will, of the organization that is providing this pen test? Like, is it run by people who have security experience who have been in the trenches,
Starting point is 00:22:58 who have delivered pen tests in the past, who have run red teams? Have they got a security team who have experience and expertise? So they already qualified. And now they're applying those qualifications and that knowledge to building this new technology. I think that's super important. As you start to see smaller businesses spring up out of nowhere and start to say they're delivering AI pen testing, being able to make sure that there is a culture of quality that has come from years of security testing, in my opinion, is super important. I don't know, Dave, if you've been involved on the pen testing procurement side of things and like the kinds of questions you've asked people in the past,
Starting point is 00:23:38 but have you thought about kind of the, I suppose, the heritage and the culture of the company that you're acquiring a pen test from? I have never had the privilege, no, Andy. That might be a good thing. I can't say I stay up at night wishing that I was involved with that. But I'm glad there are people out there who know the right questions to ask, such as yourself. Thank you. Yeah, I think that's one of the big questions I would ask. There's obviously all of the technical questions.
Starting point is 00:24:09 We're starting to see as well, right? We're starting to see people ask, you know, what are the models that you're using under the hood? Like, what's the methodology that you're following? And how can you guarantee the agents of following that methodology? These are all kind of fun questions to answer, and they're difficult to answer for pen testing, AI pen testing firms in particular because AI agents and models are nondeterministic. So when you try and steer these agents to follow a strict methodology,
Starting point is 00:24:37 they tend to get tunnel vision and they will only follow that methodology. And as a result, within like open benchmarks or in your testing Eval suite, you start to see the quality of that pen test deteriorate. It finds less vulnerabilities. than if you just let the agent reason over the entire code base and follow its own nose. It's kind of funny because it follows what a human pen tester would do as well, right? Like, we've had methodologies for a long time.
Starting point is 00:25:04 We've had methodologies because we want to make sure that the human pen tester is doing everything that they should be doing during engagement. But a good pen tester, a good red teamer, initially will follow their nose. They'll understand the application. They'll understand the environment that they're operating in, work out how it's all bolted together and what the workflows and user journeys are. And then they'll start to find vulnerabilities naturally.
Starting point is 00:25:30 And then towards the end of that assessment, that's when they'll refer to the methodology and they'll start to say, okay, you know, I followed my nose. I found some cool vulnerabilities and cool risk within this app, within this environment. But now I just need to make sure I'm dotting the eyes and crossing the T's, and I'll do that by referring back to the methodology. An agent does the same thing, right? It goes through that code base. It reasons through it.
Starting point is 00:25:52 And it will find interesting vans. But at the end of the day, you don't need to rely just on that agent to deliver that methodology or deliver that AI-driven pen test, right? The AI can do that cool reasoning. But then you can layer on top of it heuristic tools and deterministic tools, like, you know, checking for TLS ciphers, for example. You don't need an agent to do that. You could run an agent if you want to go really deep on pen testing.
Starting point is 00:26:19 like OpenSSL, for example. But just to check whether a TLSCyfer or weak TLSCyfer is in use, you can use testsessl.SH, just a tool that you can run and you'll be able to get the output. So using a combination of both the agent and then those deterministic tools as well gives you a pretty decent coverage of standard methodologies. So that's where that question of like,
Starting point is 00:26:43 how are you ensuring coverage of my application is really important too? That's Andy Horngold from Intruder. And finally, an elite private school called Alpha School is betting that the future of education looks a little like a self-driving car. Feed an AI enough examples of wrong turns, unexpected obstacles and student misconceptions, and eventually it learns to navigate. At Alpha, students spend about two hours each morning. with adaptive AI tutors, followed by workshops in coding, entrepreneurship, and other life skills.
Starting point is 00:27:41 The private school company, where tuition can reach $75,000 a year, plans to expand to roughly 50 U.S. campuses this fall. There's evidence behind parts of the concept. Research has found adaptive AI tutoring can improve learning, including a Harvard study where students using an AI tutor
Starting point is 00:28:01 achieved more than twice the median learning gains of students using classroom active learning strategies. But researchers caution that effective tutoring isn't necessarily effective schooling. Critics worry about replacing trained teachers, weakening teacher-student relationships, and producing knowledge that works inside the software but doesn't travel well outside it. The AI tutor may know the route, whether it should drive the whole school bus, remains another question. And that's the Cyberwire. For links to all of today's stories,
Starting point is 00:28:49 check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app.
Starting point is 00:29:06 Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazis. Our executive producer is Jennifer Ibin.
Starting point is 00:29:23 Peter Kilby is our publisher. And I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.