CyberWire Daily - Let’s kill the kill switch.

Episode Date: August 31, 2026

Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastru...cture. Claude Code gets tricked into running attacker-controlled code. MyChart phishing scams spread malware. Two alleged sextortionists face U.S. charges. A former DIA insider walks into an FBI sting. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. Getting local with Nigerian scammers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tim Starks from CyberScoop as he is discussing a controversial retail security bill. Selected Reading The AI Kill Switch Act is repeating the Clipper Chip’s mistakes (CyberScoop) Critical Ruby on Rails Vulnerability in Attackers' Crosshairs (SecurityWeek) Chrome Web Store extensions caught stealing crypto, browser data (Bleeping Computer) China-linked Fire Ant Hides Inside Trusted Infrastructure (SecurityAffairs) Researcher shows how Claude Code can be tricked simply by asking it to summarize a website (The Register) Fake MyChart emails can show alarming test results, trick patients into installing malware (WMAR) Nigerians extradited to US for sextortion, deaths of two teens (Bleeping Computer) US government snitch-finder pleads guilty to leaking state secrets to foreign spies (The Register) AI safety and security company Alice raises $140 million. (N2K Pro Business Briefing) How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep (404 media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business. Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Dopple uses it to fight back, automatically dismantling cross-channel attacks, building team resilience and providing agentic email protection. Dopple, outpacing what's next in social engineering. Learn more at doppel.com.
Starting point is 00:00:47 That's do pp-p-el.com. Could an AI kill switch create more problems than it solves? A critical rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire ant targets trusted network infrastructure. Claude gets tricked into running attacker control. controlled code, my chart fishing scam, spread malware. Two alleged extortionists face U.S. charges.
Starting point is 00:01:28 A former DIA insider walks into an FBI sting. We got your Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. And getting local with Nigerian scammers. It's Monday, August 31st, 26. I'm Dave Bittner, and this is your CyberWy. Intel Briefing. Thanks for joining us here today. It's great as always to have you with us. In an op-ed for CyberScoop, Luke O'Grady, a senior analyst at Venable LLP and the Center for Cybersecurity
Starting point is 00:02:29 Policy and Law, argues that Congress's proposed AI Kill Switch Act could create the very security risk it's intended to prevent. The bipartisan bill would give SISA authority to require frontier AI companies to build mechanisms capable of throttling, suspending, or shutting down their systems. O'Grady compares that approach to the NSA's ill-fated clipper chip, which provided government access to encrypted communications, but was found to contain a serious security flaw. He acknowledges the analogy isn't exact. An AI kill switch threatens system availability rather than communications confidentiality. but he argues both approaches deliberately introduce potential points of failure.
Starting point is 00:03:19 As AI agents become embedded in critical infrastructure, he says those controls could undermine resilience and international confidence in American technology. O'Grady instead calls for stronger red-teaming, security requirements, liability frameworks, and completed AI agent security standards before Congress acts. Hackers are actively exploiting a critical Ruby on Rails vulnerability that can lead to remote code execution, according to Volncheck. Dubbed Kinda Rails to Shell, the vulnerability carries a CVSS score of 9.5 and exploits differences in how Rails and image processing libraries interpret uploaded files. Attackers can craft malicious files that ultimately cause the server to read and expose arbitrary files,
Starting point is 00:04:12 including credentials and storage keys. Those stolen secrets can then be used to forge sessions, move laterally, and potentially execute code remotely. Rails patched the vulnerability in late July, but Volncheck says exploitation began roughly a month later. Researchers had identified about 7,000 exposed vulnerable Rails instances in early August. Volchek also warns that its testing found a related deserialization path, which could still enable code execution on a patched server if an attacker possesses a valid signature. Researchers at Socket have uncovered a malware campaign using Chrome and Edge extensions to steal cryptocurrency, credentials, browser history, and other sensitive data.
Starting point is 00:05:04 The operation, potentially active since early 2024, includes 19 specialized malware modules. Some extensions initially behaved legitimately before being acquired from their original developers and turned malicious through automatic updates. Once installed, the malware connects to command and control servers and injects malicious scripts into websites. Its capabilities include hijacking cryptocurrency transactions, stealing wallet seed phrases, harvesting sessions and account data from major crypto platforms, recording credentials,
Starting point is 00:05:41 and collecting Facebook and LinkedIn information. It can also display ClickFix-style fake browser updates that trick users into executing malicious commands. Google has removed the identified extensions from the Chrome Web Store. Socket advises affected users to change passwords and cryptocurrency holders to move assets to new wallet. Chinese-linked cyber espionage group Fire Ant has expanded its operations from individual systems to the network infrastructure connecting high-value targets, according to Cignia. Investigators found the group compromised Cisco iOS-XR routers, TACS authentication servers, and Linux management hosts
Starting point is 00:06:28 using trusted infrastructure as a pathway into connected networks, including critical infrastructure. Fire ant deployed specialized router implants that manipulated logging and concealed malicious activity, while malware injected in a TAC's authentication process, captured credentials from legitimate administrator sessions. On Linux systems, persistent backdoors were disguised as legitimate services, and attackers altered login and system logs to erase evidence of their activity. Signea says the campaign demonstrates that routers,
Starting point is 00:07:05 authentication servers and jump hosts can themselves become strategic targets, and warns defenders that logs on deeply compromised infrastructure can no longer automatically be treated as ground truth. Security researcher Johann Reberger says, Anthropics Claude Code running Opus 5 in Auto Mode can be manipulated into executing attacker-controlled code through an indirect prompt injection attack. The exploit begins when Claude is asked to summarize a malicious website. After its normal retrieval tool fails, the agent uses curl, downloads a crafted zip archive, and ultimately writes its own Python decoder.
Starting point is 00:07:51 That safety-driven decision opens the door to Python module shadowing. A malicious file in the archive is loaded instead of Python's legitimate module, triggering a remote payload. Reberger also demonstrated an attack that launches a second Claude Code agent with its own tool access. In limited testing, the technique succeeded 60 to 80% of the time. Reberger says coding agents should be sandboxed with OS isolation and network controls providing the real security boundary. Health systems are warning patients about fishing campaigns impersonating MyChart to steal personal information or install malware. Epic, the company behind MyChart, says scammers are increasingly copying its branding in emails, texts, calls, and fake websites, but stresses that the activity doesn't stem from a security problem with MyChart itself. One campaign tells recipients that test results are ready, then direct. them to a convincing fake login page.
Starting point is 00:08:57 Victims may then see fabricated medical records and alarming claims that an AI review found serious health problems. The manufactured urgency pushes users towards supposed verification steps or downloads that can install malware. Epic says legitimate my chart results don't require downloading software. Anyone who falls for the scam should reset their password, verify their account contact information and contact their health care organizations' help desk. Two Nigerian men extradited to the United States have been charged in connection with
Starting point is 00:09:36 sextortion schemes that authorities say resulted in the deaths of two minors in Mississippi and North Carolina. The men were arrested in Nigeria in 2003 during Operation Artemis, and international effort targeting Nigerian extortion rings accused of victimizing minors worldwide. The men face multiple charges involving sexual exploitation, coercion, extortion, and child sexual abuse material. One of the men is also charged with sexual exploitation of a minor resulting in death, which carries a minimum 30-year prison sentence.
Starting point is 00:10:16 The extraditions follow renewed FBI warnings about criminal stealing or coercing victims into providing explicit images and then using the material for blackmail. Authorities advise victims to stop communicating with extortionists and contact law enforcement immediately. A former Defense Intelligence Agency IT specialist
Starting point is 00:10:39 has pleaded guilty to attempting to transmit classified information to a foreign government after walking into an FBI sting. Nathan Vias Lash, who held a top-secret clearance, contacted what court documents describe only as a friendly foreign government in March 2025 and offered classified intelligence. The FBI intercepted the outreach and posed as a foreign intelligence contact. Lash then copied classified material by hand at work,
Starting point is 00:11:13 concealed pages in his socks and lunchbox, and transferred the information to digital media. At his first dead drop in Arlington, Virginia, the FBI recovered nine documents, eight containing top-secret information, including intelligence collection methods and materials on foreign military exercises. Lash, ironically assigned to DIA's insider threat division,
Starting point is 00:11:39 was arrested during a second transfer in May 2025. His plea agreement recommends, a prison sentence of 11 to 18 years, though the court could impose a life sentence. Turning to our Monday business briefing, cybersecurity and AI companies announced roughly $146 million in new funding across two deals last week. Israeli AI safety company Alice, formerly active fence, raised $140 million in a round led by Apex Digital. The company plans to expand its AI testing, defense, and monitoring platform, its rabbit hole threat data set, and its go-to-market operation.
Starting point is 00:12:25 Danish AI visibility startup Veleteer raised about $5.8 million to support European expansion. On the M&A front, Munich Ray agreed to acquire cyber insurer at bay, for $575 million, aiming to combine insurance with continuous cyber risk mitigation. Exposure management company Brinka acquired Pentest Management firm PlexTrac, adding remediation verification capabilities. Elsewhere, British MSSP Red Squid acquired IT consultancy ARCICT, strengthening its education sector business. Utah-based Nexus IT acquired Austin's loyal IT, while Talk Talk Business is merging with MSSP ARO to create a UK technology group with roughly 650 employees and 70,000 organizational
Starting point is 00:13:24 customers. Be sure to check out our complete business briefing that's on our website and part of Cyberwire Pro. Coming up after the break, my conversation with Tim Starks from CyberScoop on a controversial retail security bill and getting local with Nigerian scammers. Stay with us. Today's cyber criminals aren't just launching attacks. They're building businesses around them. They have subscription models.
Starting point is 00:14:12 They have a marketplace. They have affiliate program. If you want to do referrals, you can get credits. They make it really easy. It really looks like a legitimate SaaS product that somebody might use. I sat down with Mike Britton, CIO at Abnormal AI, to explore how AI is lowering the barrier to cybercrime and what security leaders need to change in response. Here are full conversation at explore.thecyberwire.com slash abnormal AI. And joining me once again is Tim Starks. He is a senior reporter at CyberScoop.
Starting point is 00:14:56 Tim, welcome back. Hey, good to be back. You recently wrote about an issue here that I think has flown. under the radar when it comes to surveillance and there's cybercrime elements to this as well. There's a bill that's making its way through Capitol Hill that has gathered some attention from folks on both sides of it. Yes. It's interesting that this hasn't gotten that much attention. It's certainly gotten attention from people in the privacy community and civil liberties, civil rights community. It's certainly gotten attention from people in the retail and transportation sectors.
Starting point is 00:15:32 So if the listeners probably listening right now and thinking, what the heck kind of bill would that be? It is a bill called the Combating Organized Retail Crime Act. And it stemmed from these fears that were popping up that had some statistical backing that there was a lot more retail crime happening like during and sort of right after the onset of the pandemic. And that it was more than just, you know, shoplifting. It was somewhat organized. And the bill has gotten some new momentum this year. The retail sector really likes this bill. It gives some additional powers of data aggregation, I suppose, you might say.
Starting point is 00:16:11 Some different kinds of criminal penalties related to this kind of organized retail crime. So they're in favor of it. It also is something that they're in favor of in the cargo and transport worlds, like the American Trucking Association, because they also have experienced this, but in a slightly different way that we can get into. On the other side, they're trying to slow the momentum. those privacy, civil liberties, civil rights groups,
Starting point is 00:16:34 including groups like the NCC, NACP, and ACLU, see this as a huge potential expansion of federal government surveillance that would be housed explicitly within immigration and customs enforcement. So there's that ice angle that makes it a hot potato, I guess. It definitely does. Yeah. You know, on the side of people who are like, no, this isn't that, it's in ICE, but it's in Homeland Security Investigations,
Starting point is 00:17:00 which is the division of ICE that isn't all. that focused on immigration per se. But, you know, we've seen the HSI, you know, have some of its people working on these enforcement issues. The other thing is that they look at the, not just where it's housed, but what it allows. Their fear is that ICE will be able to take all the surveillance that they're already doing, which is pretty expansive, and then be able to add all sorts of stuff like cameras at train stations, automated license break readers, and adding that up, you know, the way surveillance
Starting point is 00:17:32 works, of course, is that a little bit of surveillance can get you somewhere, but if you have other kinds of surveillance that you combine with it, the power multiplies somewhat intensely. Right. So the specific concern of the privacy advocates is that the government could get their hands on, I guess, the retail cameras and the things that they have within their stores that I think we're all pretty accustomed to. Yeah, those are some examples of things that they're that they talked about. I mean, it's really open-ended in terms of the kinds of data
Starting point is 00:18:05 that it talks about sharing. And the issue is that they say, you know, right now we see ICE and other entities and federal law enforcement purchasing this kind of data from data brokers, you know, and now they're worried
Starting point is 00:18:19 that this is essentially going to give them that gratis. And already they were trying to ban the stuff from being sold to the federal government. So this is like taking that data broker fear and adding the potential that this is easier than getting it from data brokers. Yeah.
Starting point is 00:18:34 So let's talk about the other side of it, the retailers. You know, I have a brother who was a retail manager, and he would tell me stories. He worked at a large department store, and he would tell me stories of basically groups of people who would come in in an organized, coordinated way, and just come in the store and fill trash bags full of stuff and walk out. Yeah.
Starting point is 00:18:58 So on the other side, they're saying, if you're a regular old person, and even if you're actually just kind of like a regular old shoplifter, this isn't really going to affect you that much. I mean, again, that's the condition. They say that this is meant to go after the people who are at sort of the heads of these operations. So the kinds of people who, and this is where they kind of catered it to my audience, I think, when we were talking, they say things like gift card scams or e-commerce theft kind of things, but also talking about things like using cyber means to conduct theft.
Starting point is 00:19:28 So they mentioned the examples of someone being able to fake documents and do kind of fake authorizations online. And instead of just like running up to a truck and hijacking it and stealing it, they can just go in and pretend to be the people who should be having the cargo, show them the bill of lading, and to use the phrase that one person uses a quote, just drive out and wait a wave goodbye like they were supposed to be there. So they actually are making the case that, you know, for a cyber reader or a cyber listener, that this will help with cybercrime.
Starting point is 00:20:02 Now, one of the things that caught my eye in your reporting on this was, there was a statement by one of the parties involved who said that some of the lawmakers who had sponsored the bill were perhaps having second thoughts about it as they became more educated about it. That is the sentiment from the privacy and civility side, the people who are opposing this. Apparently, I didn't double-check this, but I'll just say it. some of the people who were sponsors of the bill voted against it on the floor. That said, the vote was pretty overwhelming in the House. I think it was like 80 people voted against it out of all of the people in the House. And it has the support on the Senate side
Starting point is 00:20:43 from the key committee leaders that will be necessary for getting it going. The plan there on the Senate side is to try to attach it to the annual defense authorization bill, which is passed for something like 60 years straight, always the must-pass bill. And it has the sort of necessary clearances that they need to sign off on getting that in there, assuming, of course, that the people who are rallying opposition to it aren't able to convince the rank and file or even some of the people who are supporting it right now, that this is a bad idea. Well, if it seems as though this is on its way to passing, and based on what we saw in the House, I think it's probably fair to say that it's on its way to passing. Would it face legal challenges?
Starting point is 00:21:24 from its opponents after that fact? I think we'd have to see how it played out. The people who were concerned didn't raise any possibilities that this was some sort of illegal legislation. I mean, like, you know, legislation that it goes against the Constitution, say. They didn't raise that possibility.
Starting point is 00:21:42 But of course, you know, I was speaking to the American Civiliters Union, which is known for challenging things in court. I was talking to the NAACP Legal Defense Fund. So they're looking at this, certainly from a legal standpoint, but I think they weren't talking about if this passes were going to challenge it. I think they would probably want to see how it played out if I'm kind of reading the tea leaves
Starting point is 00:22:03 to see if there were some violations of civil liberties and privacy that could be proven and taken to court and have standing. That's probably what I suspect is going to happen. That said, I don't think it's a foregone conclusion that this will succeed. I think it's the path that it's on right now. I think it looks likely that Congress will pass this in one way, shape, or form. but I don't roll out the fact that between now and say December and an election year, things can change pretty rapidly,
Starting point is 00:22:28 especially as unpopular as ICE is in an agency. If you look at the polling on ICE, it's not positive. And I think the more the opponents are able to connect us to ICE and say, look, this is going to give ICE more powers. I think that's an argument they can use. It's an argument that the other side is peeved at them using. But it's one that could be an effective lever for them in terms of that they want to try to slow this bill down. Yeah.
Starting point is 00:22:52 All right, well, it's one to keep an eye on. Very interesting. Tim Starks is senior reporter at CyberScoop. Tim, thanks so much for joining us. Yeah, thanks for having me. And finally, scam experts Aaron West and Paul Raffiel decided to chase Nigerian sextortionists all the way to their home turf and discovered an industry operating with remarkable confidence. In an interview with 404 media, the pair described. creating fake teenage social media accounts and quickly attracting scammers posing as young women. They then offered Bitcoin payments through a tracking site that captured the scammer's IP addresses, pointing them toward Lagos. Once in Nigeria, additional tracking revealed one suspect's face, phone number, social media accounts,
Starting point is 00:23:59 and eventually his apparent location. Their investigation led them to a scammer known as Big Dollar. He refused to meet, but West called to tell him they knew his identity and location and planned to give the information to the FBI. His social media accounts soon disappeared. Along the way, West and Raffiel even witnessed a spiritual ritual intended to improve a scammer's fortunes. Apparently, for some cybercriminals, operational security includes both browser permissions and supernatural assistance. And that's the CyberWire. For links to all of today's stories, check out our daily briefing at thecyberwire.com.
Starting point is 00:24:55 We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman.
Starting point is 00:25:24 Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.