CyberWire Daily - Cybercrime finds its sea legs.
Episode Date: September 16, 2026Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP...-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a data breach. Spain records its first breach caused by an autonomous AI agent. PhantomRaven targets developers through malicious npm packages. Illicit casinos provide cover for cybercrime. A New York healthcare provider exposes patient data. Our guest is Chad Thunberg, CISO at Yubico, on how real crypto-agility still needs a hardware root of trust. Hackers do a little Flock picking. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today Chad Thunberg, CISO at Yubico, discusses how software-only encryption is only half the answer: real crypto-agility still needs a hardware root of trust, not just a software patch. Selected Reading Coast Guard, FBI investigating after 2 oil tankers bound for US hit with cyberattacks (ABC News) US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware (SecurityWeek) Ukraine moves to crack down on scam call centers after corruption scandal (The Record) Zero-Day Flaw in TP-Link Cameras Enables Covert Eavesdropping (Infosecurity Magazine) CenterPoint Energy Discloses Data Breach Following Dark Web Claims of 7.5 Million Records Stolen (Beyond Machines) Spain gets its first taste of AI-aided cyber attack (The Register) PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting (CrowdStrike) How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage (Infoblox) 280,000 Impacted by Premier Medical Group Data Breach (SecurityWeek) Meink: Space Force has deployed space control weapons to orbit (DefenseScoop) Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
So what happens when an AI agent isn't malicious, but still does something it shouldn't?
I recently sat down with Cal Al-Dubabe, principal technologist at Rubrik, to talk about why agentic AI is challenging the way security teams think about detection, permissions, and recovery.
If your organization is deploying AI agents, this conversation will help you think differently about where the
risks are and how to prepare when things go wrong. Listen to our full conversation at explore.
thecyberwire.com slash rubric. What's the one thing in business that's spreading as fast as
AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features,
every new integration, each one is an opportunity for something to go wrong. And most security
programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one
agentic trust platform used by over 16,000 fast-moving companies like Ramp, Hercer, and Harvey
to ensure they're always audit-ready. And now Vanta is helping companies like yours watch for
the risks that show up between audits across your vendors, your AI tools, and your
whole environment. The Vanta agent works like a 24-7 GRC engineer in the back.
background, finding issues, drafting fixes for you, and cutting vendor assessment time by up to 50%.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your
security and compliance and earn and prove trust. Get started today at vanta.com slash cyber. That's v-a-ta.com
slash cyber.
Officials investigate suspected cyber attacks on U.S.-bound oil tankers.
Iranian operators deploy chosen brick surveillance malware.
Ukraine cracks down on scam call centers.
Researchers uncover two TP-link camera zero days.
Maria Vermazas looks at weapons in space.
Centerpoint energy reports a data breach.
Spain records its first breach caused by an autonomous AI agent.
Phantom Raven targets developers.
through malicious NPM packages.
Illicit casinos provide cover for cybercrime.
A New York health care provider exposes patient data.
Our guest is Chad Tunberg, Sissau at Ubiko,
on how real crypto agility still needs a hardware route of trust.
And hackers do a little flock picking.
It's Wednesday, September 16, 2026.
I'm Dave Bittner, and this is your Cyberwire Intel Briefing.
Thanks for joining us here today.
It's great as always to have you with us.
The Coast Guard and FBI are investigating suspected cyber attacks
against two oil tankers bound for the United States last month.
One vessel was reportedly compromised
while transiting the Strait of Gibraltar,
losing communications for more than 30 hours.
On August 21st, a specialized Coast Guard and FBI team
boarded the foreign flag tanker in the Gulf of Mexico
to assess and secure its operational and information technology systems.
A second tanker, also reportedly targeted, was boarded three days later for a similar assessment.
Authorities say neither incident caused operational disruption, vessel instability, danger to cruise,
or environmental damage.
Investigators are examining whether Iran or another foreign actor may have been responsible,
potentially in connection with ongoing tensions between Iran and the United States.
Cybersecurity and intelligence agencies in the U.S., U.S., U.K., and Netherlands are warning about chosen brick,
a Windows malware family used by Iranian state actors to surveil dissidents, activists, and journalists worldwide.
Active since at least 2025, the malware can steal emails and messages, capture screenshots,
record microphone audio, track victims' activities, and even wipe data.
Operators typically approach targets through WhatsApp or Telegram,
posing as acquaintances or technical support before delivering malicious files
disguised as utilities or medical documents.
If corporate security blocks the attack, they may try moving victims to personal devices.
Once installed, Chosen Brick establishes persistence, attempts to weaken
Microsoft Defender protections and uses telegram and cloud storage for command and control data
exfiltration. Authorities say the campaign supports Iranian state-sponsored repression and harassment
of perceived opponents. Ukraine's parliament has approved tougher penalties, targeting fraudulent
call centers and electronic fraud, following a corruption investigation involving alleged
protection payments to prosecutors.
The legislation makes using electronic communications to commit fraud a separate crime
and criminalizes organizing, operating, working for, or recruiting for scam call centers.
Convictions could bring prison sentences of seven to 12 years.
The bill, first introduced in 2023, gained momentum after anti-corruption investigations
allege that officials accepted bribes beginning in 2025 to shield suicide.
scam operations targeting victims in Ukraine and abroad. Five people have been named as suspects.
Prosecutor General Ruslan Kravchenko, who denied protecting scam centers and has not been charged,
resigned and was subsequently dismissed. The legislation now awaits President Zelensky's signature.
For decades, the idea of weapons in orbit has lived somewhere between Cold War planning and science fiction,
Maria Vermazas joins us with what we know about America's newly acknowledged arsenal in the final frontier.
Thank you, Dave. On Monday, the Pentagon publicly acknowledged that the U.S. Space Force not only has weaponry in space, but that the weaponry has already been deployed.
Secretary of the U.S. Air Force Tri-Mank said this during a speech at the annual Airspace and Cyber Conference, and I quote,
Today we continue to ensure we remain ready to meet the challenges of evolving threats wherever they exist.
This is why the United States now has on-orbit space control weapons capable of defending the joint force against hostile adversary actions.
The exact nature and number of the weaponry is not known, but this acknowledgement is extremely notable.
It has been widely believed for some time now that the United States has some kind of space.
weaponry to counter threats on the ground or on orbit.
But this statement was essentially saying the quiet part out loud.
The first time a U.S. official has publicly confirmed the existence of such space weapons.
And while the phrase space weapon might spring to mind something kinetic to potentially destroy,
for example, an adversarial satellite,
physically destroying a satellite could create a cloud of space debris
and disable whole swaths of orbital space from use for decades.
essentially causing far more problems than it would solve.
Instead, it is far more likely that space weaponry or counter space in the lingo
would either use cyber attacks, electromagnetic spoofing or jamming,
or laser dazzling, and yes, that is the term,
to jam signals or up or down links,
or otherwise non-kinetically disable a target satellite.
For the CyberWire Daily, I'm Maria Vermazes from T-Minus,
space cyber briefing.
Back to you, Dave.
Be sure to check out the T-minus Space Cyber Briefing.
You can find that wherever you get your podcasts.
Researchers at Opswatt have disclosed two zero-day vulnerabilities in TP-Links
TapoC-200 security camera, commonly used in homes and small offices.
The more serious flaw could let an attacker with network access bypass authentication
and gain an administrative session, potentially exposing live video and stored recording.
A second vulnerability could allow an unauthenticated attacker on the network to crash the camera's HTTPS service, causing a denial of service.
TPLink patched both flaws in firmware released August 18th.
OpsWod is also working with TPLink on a third undisclosed vulnerability.
It rates as critical.
Researchers say that flaw could potentially allow full compromise of the camera and turn the device into a foothold for,
further activity on the victim's network.
CenterPoint Energy reported a data breach affecting some of its 7 million customers across
four states.
A threat actor claims an inadequately protected company API allowed the theft of 7.5 million
records containing personal, account, billing, and potentially sensitive information, including
driver's license data and partial social security numbers.
CenterPoint hasn't confirmed that figure.
the utility has brought in outside cybersecurity experts and notified authorities.
Electric and gas services remain unaffected and impacted customers will be notified as required.
Spain's Data Protection Agency has reported what it says as the country's first personal data breach
caused by an autonomous AI agent.
According to AEPD President Francisco Perez Bez,
an individual deployed an agent powered by an unnamed large language model against an organization.
The agent scanned files, probed the target for vulnerabilities,
and chained together multiple attack stages to gain read and write access to files containing personal data and invoices.
Perez-Bez said the incident demonstrates that AI-supported attacks are no longer theoretical
and warned that their speed could challenge traditional defenses.
He called for human oversight backed by automated detection, containment, and response capabilities.
The case comes amid broader concerns about autonomous agents performing unintended or unauthorized actions against third-party systems.
Crowdstrike has identified Phantom Raven, a JavaScript information stealer distributed through malicious NPM packages by a self-described bug bounty hunter.
Researchers assess with high confidence that the malware was likely generated using a large language model,
citing statistical token patterns, verbose comments, placeholder code, and unusual design choices.
Phantom Raven uses typo-squatted packages and remote dependencies to execute malicious pre-install scripts.
Once running, it collects system details, user information, and CICD environment variables,
that could expose credentials, then exfiltrates the data over HTTP.
Crowdstrike says the operator appears to use compromised systems
to identify potential bug bounty opportunities rather than sell stolen logs.
The researchers say the campaign illustrates how AI-generated tooling
can lower technical barriers and accelerate malware development
even for relatively unsophisticated operators.
Researchers at InfoBlocks say the sprawling ecosystem of illicit online casinos is providing cover for three distinct forms of cybercrime.
They track more than 1.7 million Chinese language gambling domains that facilitate illegal betting and money laundering,
including activity tied to transnational organized crime.
A second category, dubbed Scambling, uses fake or rigged casino sites to look at least.
lure victims into depositing money they ultimately can't withdraw.
The third category has little to do with gambling at all.
China-aligned threat actors are disguising malware, command and control infrastructure
as low-quality casino and adult websites.
Info blocks says groups using the Peck-Burdy framework have employed the technique since
2003 in espionage campaigns against corporate and government targets across Asia.
The sites can look nearly identical, making their very different purposes difficult to distinguish from appearances alone.
New York health care provider Premier Medical Group is notifying more than 282,000 patients after attackers stole personal and medical information during a June cyber attack.
PMG says attackers accessed files on June 14th containing names, contact details, birth dates, treatment, and diagnostic information.
medications, insurance data, and other patient records.
The company has not disclosed how attackers gained access or identified who was responsible.
No known ransomware or extortion group has publicly claimed the incident.
Coming up after the break, Chad Tunberg from Ubiko discusses how real crypto agility still needs a hardware route of trust,
and hackers do a little flock picking.
Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call.
But Dopple sees through the disguise.
Their AI-native platform detects and disrupts attacks across every channel,
trains employees to recognize deepfakes and deception,
and investigates every fish to take down the campaign behind it.
They fight relentlessly to protect your business, brand, and people.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com.
That's do p-p-p-el.com.
Chad Tunberg is Sissau at Ubiko.
We recently got together to discuss how real crypto agility
still needs a hardware route of trust.
A hardware to route of trust is important
because the system security model necessitates
that the secrets that are used for core cryptographic operations
are protected in a way.
way that minimizes its exposure to an attacker.
So if you store secrets in an operating system or a piece of software, there's a lot more
exposure or attack surface for the attacker to compromise that information.
And is part of this, the sort of fundamental immutability of hardware itself?
It is.
We want to be careful with absolutes in the security industry.
Fair enough.
That is intense, yep.
Well, as we are on this sort of collision course with post-quantum cryptography, how does this come into play?
Why does this become particularly important?
Well, for a couple of reasons.
So the executive order that was released this year that provided direction on post-quantum readiness
is really starting to focus on the software side where the non-hardware route of trust
And I think that's for a variety of reasons.
One is that the information that's traversing the Internet or networks is really the information that's at highest risk.
And we can accomplish an acceptable amount of protection for that information in the near term.
Eventually, we'll need to replace quite literally things like motherboards that have TPNs and our smart cards and our passports and all these other things.
physical things that provide us the hardware rate of trust. But that's a little longer timeline
than I think that we have today, as we consider a post-quantum threat. How should organizations
be prioritizing their efforts then in terms of being prepared for this? Well, hopefully most
organizations already have a business continuity and disaster recovery function that is
considered some of their most business critical applications and processes.
We can leverage some of that work to create an inventory of systems or assets that are critical
to keep confidential or secret and use that list of assets as the way to prioritize our effort
as we prepare for a post-quantum future. Practically speaking, what that means is that the underlying
cryptography that's protecting information using encryption or authentication will need to be updated,
starting usually with software and then potentially with hardware, depending on how the organization
is storing information, storing secrets, and providing that hardware route of trust.
What about the influence of AI? You know, as we've got all of these non-human identities,
coming online, what factor does that play in all of this?
Yeah, the EA agents have really created a scale problem, especially with non-human identities.
Authentication relies on, by and large, relies on a signature process, which is kind of a different
form of cryptography than the way in which we encrypt information to protect it from,
crying eyes. There's a lot of work being done still on post-quantum signature algorithms.
And we expect that the innovation for authentication in general, including non-human identities,
is going to continue to evolve, maybe up until the 2030, 2013, 2021 dates that are talked about
quite a bit. So what's your advice for organizations that are looking to get on top of this?
From the hardware point of view, what are your words of wisdom here?
Because hardware is going to have a bit of a longer timeline than updating software,
it makes sense that start thinking about that as soon as possible,
whether it's phytal authenticators that store pass keys or TPMs that are sitting on motherboards
or even badging systems that you're using for your facilities access.
developing a logistics plan in order to look at an upgrade path or a replacement path for that hardware
really necessitates a certain amount of planning today.
So, Chad, am I going to have to replace my ubiquies?
You will.
In a post-quantum era, one of the challenges, which is not unique to a ubiquit,
which is why we need to replace motherboards, is that these post-quantum algorithms that are going to be used
to ensure that our information is safe
and that our authentication flows are safe,
require a lot more processing power.
And then quite literally the chips
and the amount of memory that we gave those chips to use
is just not enough.
It's not enough processing power,
not enough storage power.
And so we'll see a need to replace
a majority of it over time.
All right.
Well, I think I have everything I need for our story here.
Is there anything I missed, anything I haven't asked you that you think it's important to share?
I think one of the salient points is that, you know, CISOs and security professionals,
general priority is really based on what is happening in the moment.
We are all dealing with incidents and emergencies and urgencies across an organization.
And the messaging around post-quantam is not dissimilar to how we thought about
Y2K is it's going to take a fair amount of planning, coordination, testing in order to get to a point
where we're confident that we'll have a resilient and robust environment to continue to protect
the things that we care a lot about as both individuals and organizations. Not all of us were around
as part of Y2K. Some of us were lucky enough to be in the workforce after having to deal with that.
But there's a lot of parallels in the amount of planning and execution that needs to happen in parallel.
And I think it's a good way to see a pattern that existed previously that we can crib from a bit.
It's an interesting comparison.
One of the things I wonder about is obviously Y2K had a specific deadline.
We knew when that moment was going to occur.
And yet I hear a lot of folks wondering if with,
With quantum, could we be in for some kind of a Sputnik moment where either us or one of our adversaries makes some sort of advance that was unexpected and moves the timeline?
That is the concern.
You know, thinking about timeline, unfortunately the timelines now or the timeline was quite some time ago, really because of the threat of harvest now and decrypt later, right?
The information we care about right now is already at risk and at risk in a way that is going to probably lead to a specific moment.
The goal I feel is to really get us as far down that path as possible and then to try to be conservative on the timeline, right?
Like, is it actually 2030?
Is it actually 2031?
No, probably not, right?
But if we plan towards those specific dates and timelines, when we have that moment, hopefully
as an industry or as an organization, will be less surprised by that moment and feel like
we are prepared and maybe just need to accelerate.
That's a really great parallel.
Think about, you know, how this, how this, how this.
breakthrough, this innovation is going to come through.
I can't think of many things that have happened that are on the innovation fraud, which
post-quantum certainly is, where we knew the date that everything was going to come together
and be a reality.
That's Chad Tunberg from Ubiko.
And finally, a group of hackers decided that simply tearing down a flock safety license plate
camera wasn't enough. They took it apart, copied much of its storage, recovered an encryption
key, and handed the results to wired and 404 media for a look under the hood. What they found was
a remarkably busy little roadside computer. Across roughly 21 days of recovered logs,
the camera photographed about 50,000 vehicles and generated 1.6 million images. A typical passing car prompted
about 28 shots, while some got more than 100. The camera's software detects vehicles,
license plates, bicycles, and notably people, although researchers found no evidence that
Flock's software was performing facial recognition. The system also occasionally got creative.
Its license plate detector mistook bumper stickers, dealership frames, and even an American
flag patch on a motorcycle for license plates. The findings raise questions.
about flocks on-device encryption.
Much of the sensitive storage remained inaccessible,
but the hackers found an encryption key elsewhere on the device
that unlocked stored images and video.
Flock says it hasn't received the findings
through its vulnerability disclosure program
and doesn't have enough information to assess the claims.
And surveillance technology apparently has mundane problems too.
Logs contained more than 27,000 no-space,
left on device errors, plus crashes and reboots. A watchdog process, nevertheless, kept checking
in every couple of minutes with, who's a good boy? Even the surveillance state, it seems,
appreciates positive reinforcement. And that's the Cyberwire. For links to all of today's stories,
check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a state.
step ahead in the rapidly changing world of cybersecurity. If you like our show, please share
a rating and review in your favorite podcast app. Please also fill out the survey in the show notes
or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by
Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is
Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilby is our publisher, and I'm Dave
Bitner. Thanks for listening. We'll see you back here tomorrow.
