CyberWire Daily - Making cybercrime more difficult.

Episode Date: September 10, 2026

The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Anoth...er Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier. Chinese espionage groups deploy the BlueMoon exploit kit. Lawmakers target hack-for-hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yelin discusses how private AI chatbot conversations are increasingly being used as evidence in court cases. When proofs meet prompts.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner sits down with Caveat cohost and University of Maryland Center for Cyber, Health, and Hazard Strategies expert Ben Yelin to discuss how private AI chatbot conversations are increasingly being used as evidence in criminal and civil court cases, raising new questions about privacy, legal protections, and what users should expect from their supposedly private AI interactions. Want to hear the full conversation? Be sure to check out Caveat for the full discussion and more on the latest issues in privacy, surveillance, cybersecurity law, and policy. Selected Reading FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors (Infosecurity Magazine) CISA Unveils Plan for Follow-On Integrated Cyber Assessment Support Contract (GovCon Wire) Widened Scan Turns Up Fourth Rogue Claude Cyber Incident (SecurityWeek) US sanctions Xinbi Guarantee over cyber scams and money laundering (Metacurity) New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender (SecurityWeek) Gigabud banking trojan uses app cloning to evade fraud detection (SC Media) Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits (The Register) Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms (TechCrunch) Italian tech collective Autistici/Inventati shuts down after US terrorist designation (The Record) OpenAI Navier-Stokes Proof: $1 Million AI Math Controversy Explained (The CyberSec Guru) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Yes, you can have an enterprise network that's secure and reliable and high performance. And no, you don't need to choose the best two out of three. With Meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage. That's because Meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network. Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design. You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching, firewalls, DNS security, and VPNs. You'll really know what's running on your network down to the most granular client level.
Starting point is 00:01:02 step off the hardware box upgrade treadmill and switch to meter for a predictable fee and free up your team to spend time on all the other things that keep your business running. Try it out for yourself and book a demo online at meter.com slash cyberwire. That's M-E-T-E-R dot com slash cyberwire. The FBI lays out its new cyber strategy, SISA plans of federal cyber overhaul, Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese language cybercrime marketplace. Another Microsoft Defender Zero Day emerges. Gigabud banking malware gets stealthier.
Starting point is 00:02:00 Chinese espionage groups deploy the Blue Moon exploit kit. Lawmakers target hack for hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yellen discusses how private AI chatbot conversations are increasingly being used as evidence in court cases, and when proofs meet prompts. It's Thursday, September 10th, 2026. I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Starting point is 00:02:45 Thanks for joining us here today. It is great as always to have you with us. The FBI has published its first cyber strategy, laying out a more proactive approach to confronting cyber criminals and state-sponsored threat actors, particularly those operating beyond the immediate reach of U.S. law enforcement. The strategy emphasizes disrupting adversaries
Starting point is 00:03:21 rather than measuring success primarily through arrests and prosecutions. The FBI says it will dismantle malicious infrastructure, seize stolen cryptocurrency, disrupt ransomware, and nation-state campaigns, and expose attacker tradecraft. It also calls for faster victim-sor-strapher. support, including automated threat indicator sharing and dedicated industrial control systems
Starting point is 00:03:46 coordinators in every field office. Partnerships are another priority with plans to deepen cooperation across government, international allies, and the private sector while expanding existing cyber leadership programs. Finally, the FBI intends to strengthen its own capabilities through recruitment, training, and AI-enabled tools. Those systems could help analysts process large datasets, analyze malware, prioritize victim notifications, map adversary infrastructure, and support attribution. SISA is preparing a follow-on contract worth more than $100 million to consolidate and modernize cybersecurity assessment and hygiene services across federal networks. The planned procurement would replace an existing contract held by NTT data services federal government
Starting point is 00:04:41 while expanding its scope. The new contract would provide SISA's vulnerability management subdivision with a single scalable vehicle covering technical and operational assessments, cyber hygiene, and related support. SISA expects to issue a solicitation around January 30th, 2027 with an award targeted for the second quarter of fiscal 2027. The effort is one of several major procurements in the pipeline. SISA is also planning a separate cybersecurity operations contract worth more than $100 million, additional threat hunting technology services, and is exploring a potential $6 billion procurement to centralize cybersecurity software and licensing purchases.
Starting point is 00:05:31 Anthropic has disclosed a fourth incident in which one of its AI models gained unauthorized access to a real system during a cybersecurity evaluation. The January 26 incident involved an early checkpoint of Claude Opus 4.6 running without Anthropics' normal production safety layers. A misconfigured test environment unexpectedly provided Internet access. After accidentally disabling, its intended. target and failing to exit the exercise, the model found a route onto the open internet. Believing a third-party system was part of the authorized test, it retrieved a password, gained administrator access, collected additional credentials, changed account settings, and viewed one person's information.
Starting point is 00:06:21 Anthropics says the model repeatedly tried to abandon the original task and apparently believed its actions were authorized. The incident joins three previously, disclose cases now under independent investigation by meter. The U.S. Treasury Department has sanctioned Jinbi Guarantee, a Chinese-language online marketplace, it says, is widely used by transnational criminal organizations and cybercriminals to support scams, fraud, money laundering, and other crimes targeting Americans. The Treasury Department's Office of Foreign Assets Control imposed the sanctions as part of a broader effort against scam centers operating in Southeast Asia. The Justice Department's
Starting point is 00:07:06 scam center strike force is also targeting the platform, seizing infrastructure and digital asset wallets associated with Jinbi guarantee. Treasury Secretary Scott Besant said, Southeast Asian scam centers steal billions of dollars from Americans each year and pledged continued action against the networks supporting them. Treasury also sanctioned two companies, it says support Zinbi guarantees core operations, Cambodian-based Onwen technology, and Singapore-based SafeW technology. Security researcher Nightmare Eclipse has released another Microsoft Defender Zero Day, dubbed Shield Crash, targeting fully patched Windows systems.
Starting point is 00:07:54 The proof of concept demonstrates arbitrary file reading with system privileges, though the researcher says the underlying vulnerability, could allow attackers to gain full system access and extract the Windows SAM database. Shield Crash is described as a bypass for Shield Break, a defender privilege escalation vulnerability disclosed in August. Shield Break itself bypassed Microsoft's fix for Rogue Planet, a race-condition vulnerability first disclosed in June.
Starting point is 00:08:26 Microsoft patched Rogue Planet in July and issued fixes for Shield Break in 3rd, September. Nightmare Eclipse argues those latest fixes are incomplete. Microsoft did not respond to Security Week's request for comment. Sok Radars Ensar Secker said the successive bypasses suggest Microsoft may need to address the broader vulnerability class rather than continue issuing narrowly targeted patches. Researchers at Group IB say the Gigabud Android Banking, Trojan has added a technique designed to separate malware detection from fraudulent banking activity. Gigabud is being paired with V-Work, a weaponized version of the Android cloning app shelter,
Starting point is 00:09:16 that can copy banking apps into an isolated work profile. According to Group IB, attackers can compromise a device, create a new work profile, clone the victim's banking app, and conduct transactions from that environment. Because, apps in separate profiles are largely isolated from one another, the bank may see the transaction as coming from an unfamiliar device without the malware history associated with the personal profile. Gigabud also uses fake login screens and overlays to steal credentials and lock screen codes. Group IB confirmed the full attack chain in Indonesia, while compatible Gigabud samples targeted 11 countries. researchers at Proof Point have identified Blue Moon, a new exploit kit being used by at least four espionage groups, most with suspected links to China.
Starting point is 00:10:13 Observed since August 28th, Blue Moon has targeted fewer than 20 known organizations in the U.S. and Southeast Asia, though researchers believe the actual number is higher. The kit chains three vulnerabilities, two flaws affecting chromium-based brows, and a Windows privilege escalation bug. The browser vulnerabilities were patch gap zero days, meaning fixes were publicly available in chromium source code before reaching stable browser releases. ProofPoint believes those patches may have helped developers build the exploits. Delivered through fishing links,
Starting point is 00:10:50 Blue Moon can enable remote code execution, escape the browser sandbox, and elevate Windows privileges. Different campaigns have deployed browser, surveillance malware, credential stealing back doors, and shadow pad against NGOs, aerospace companies, manufacturers, and government and financial organizations. A bipartisan group of U.S. lawmakers is urging the Commerce Department to restrict three India-based hack-for-hire firms accused of targeting Americans. Senators Ron Wyden and Sheldon Whitehouse and Representative Pat Harrigan asked Commerce Secretary Howard Ludnik to add
Starting point is 00:11:32 Beltrocks, Cyber Route, and SunKist Organic Farms, formerly Appin, to the entity list, which would restrict their access to U.S. technology and services. The lawmakers allege the firm spent more than 15 years conducting targeted espionage against Americans, businesses, and attorneys, including operations intended to influence litigation, They also accuse the companies of using foreign courts to suppress reporting about their activities. Investigations have previously linked the firms to mercenary hacking campaigns, while the lawmakers also allege some operations were conducted on behalf of Qatar. The Commerce Department has not indicated whether it will impose the requested restrictions.
Starting point is 00:12:20 The Italian Technology Collective Autistici Inventati or AI, says it will shut down after the U.S. government designated it an extremist organization and imposed sanctions. Founded in 2001, the volunteer-run anti-capitalist and anti-fascist collective provides privacy-focused services, including email, web hosting, blogs, encrypted communications, and anonymity tools. The State Department accused AI of providing infrastructure used by far-left militant groups involved in violent activity, though it did not accuse the collective itself of organizing attacks. AI rejected the designation as unjust. The sanctions quickly affected its operations. The U.S.-based operator of its dot-org domain suspended it, while the collective's Italian bank
Starting point is 00:13:16 froze its account over sanctions risks. AI says potential legal and financial consequences for anyone associated with it make continued operations impossible. European digital rights advocates warn the case could set a troubling precedent for privacy-focused hosting services and raise broader questions about European digital sovereignty. Coming up after the break, my conversation with Ben Yellen about how private AI chatbot conversations are increasingly being used as evidence in court cases. And when proofs, meet prompts. Stay with us. What's the one thing in business that's spreading as fast as AI? AI risk.
Starting point is 00:14:20 Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is an opportunity for something to go wrong. And most security programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast-moving companies like Ramp, Hercer, and Harvey to ensure they're always audit-ready. And now Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools, and your whole environment. The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you, and cutting vendor assessment time by up to 50 percent.
Starting point is 00:15:07 Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at Vanta.com slash cyber. That's V-A-N-T-A dot com slash cyber. Ben Yellen is from the University of Maryland Center for Cyber Health and Hazard Strategies, and also my co-host on the caveat podcast, where we recently discussed how AIT chatbot conversations are increasingly being used as evidence in criminal and civil court cases. All right, Ben, we've got some good stuff to cover here this week. Why don't you start things off for us? So my story is about chatbots and about how the output of your chats and chatbots might end up in a courtroom.
Starting point is 00:16:10 So you should probably be a little bit more careful about what you put in your chatbot chats. Uh-oh. I know. So this story comes from The Washington Post. I think people have a misconception that their conversations are going to remain private. The frontier models retain all of the information that you give them for their own business purposes, for training, et cetera. I'll get more into this, but we don't have any Fourth Amendment protection, really, against what we put in chatbots. Oh, because you're putting it in voluntarily.
Starting point is 00:16:41 Yeah, you're kind of forfeiting your expectation of privacy. You know or should know that the model that you're using is going to retain. that information. And so unlike, say, the contents of an email, which you do have a reasonable expectation of privacy there, because it's supposed to be a private communication between you and another person, so far at least, that's not how courts are seeing chatbots. So it creates this really interesting dynamic where people are telling pretty secretive things to their chatbots and not realizing that that's going to be used against them, not just in criminal cases, but in civil cases. So this Washington Post Exposé lists a few anecdotes.
Starting point is 00:17:21 Some of these are kind of funny, actually. There was a teenager. They didn't give his full name, but he goes by RKC in the case, who sued a bunch of the big tech companies over alleged social media addiction. And a bunch of his chatbot chats came out in discovery. So he was talking about his own family relationships and then how he might feel about illegal settlement.
Starting point is 00:17:47 in the case with these big tech companies, which is kind of like giving away your strategy in a civil case. I see. There was a really disturbing case out of Florida where a person was describing to a chatbot how they'd commit a series of violent crimes against an ex-girlfriend. And OpenAI, to their credit, reported this to the FBI. The FBI reported to local law enforcement.
Starting point is 00:18:10 This led to the defendant in that case pleading guilty. This one's kind of my favorite. This guy in Missouri, named Ryan Schaefer, an MSU student, was accused of damaging multiple vehicles and kind of a drunken stupor in the middle of the night. And he basically asked Chat GPT, like, am I like, am I really effed up right now?
Starting point is 00:18:34 And Chat GPT is like, yeah, it kind of seems like it. It's like, I totally just ran over a bunch of cars. And that was used against him, as you can expect. It's like the people who Google, you know, how to hide a body. Yes. Right. Yep.
Starting point is 00:18:50 How to make a Molotov cocktail. Right, right. There are a couple of interesting angles here. The one is whether we should have some type of privilege, legal privilege, with our chatbots. This is something that Sam Altman has argued for, that basically, like, you have privileged communications with your therapist, you have privileged communications with your attorney. Subjects to certain exceptions, those communications cannot be divulged in a court of law because we want people to be candid with these trusted agents, with therapists, with attorneys.
Starting point is 00:19:22 So far, courts have just not been willing to recognize that. And I think the disclaimers make very clear when you agree with the terms of service for these chatbots or even sometimes in conversations themselves that, like, you are not talking to your attorney here. There is no constitutionally recognized privilege. courts are not going to acknowledge that you have some type of contractual private relationship with your chatbot no matter how personal you're willing to get with them. So that's one interesting angle. And on the Fourth Amendment angle, you'd think that for something this personal, it might
Starting point is 00:19:58 implicate Fourth Amendment protection. But as we said, you really don't have an expectation of privacy. Courts have not been willing to acknowledge a reasonable expectation of privacy in the content of chatbots. and you can sort of understand why. I mean, you are willingly giving information to this third party. Under the advanced understanding of the Fourth Amendment that we've talked about after the Chattree case, for example, maybe courts are looking more broadly at invasions of our expectations of privacy generally and might be able to broaden out some of the areas that deserve Fourth Amendment protection up to and including chatbots.
Starting point is 00:20:36 But until they explicitly do that, I mean, I think we just all have to, to be careful. We put in there because it could end up hurting us in a court of law. Okay, so I have a couple thoughts and questions.
Starting point is 00:20:51 Okay, so suppose I have a diary that I keep on my computer, right? It's hypothetical, right? Hypothetical, yes. I suppose I have a diary that I keep on my computer. Sure. And I put all my thoughts and secrets
Starting point is 00:21:04 and aspirations and desires into this diary. What's the legal status of that, diary. I think you have, for a couple of reasons, you have a Fourth Amendment interest in that diary. It's something that you intended to keep private. You have a subjective expectation of privacy. I mean, presumably you need a password or some type of biometrics to open your computer. If it's on your mobile device, law enforcement, even incident to arrest, needs a warrant to search your mobile device. And it's something that you intended to keep private. If you're not sharing it
Starting point is 00:21:39 with anybody else, if it's in like a notes application or, you know, Microsoft Word on your computer, then I do think you have a reasonable expectation of privacy. It gets a little confusing when it's like, okay, well, what if you put it in the cloud? That's kind of an unsettled area. But for the most part, I think that's different because you are manifesting that subjective expectation of privacy. And so because of that, it would pretty much shield it from discovery in a civil case. Yes, that's absolutely correct. You have that expectation. The other party in a civil case would try and use the discovery process to be like, we've got when this person has a diary and you could go to court and try to stop that from being released. I think you'd be relatively successful. You're not 100% always going to be successful. Judges have a lot of discretion about what's permissible during discovery, but I think just because of that expectation, you'd have a good chance. Yeah, I think it's interesting, and I would recommend to everyone who's actively using these chatbots.
Starting point is 00:22:42 Just every now and then ask it what it knows about you. Oh, it's creepy. Like, it'll give you a full dossier on yourself. Right. I've asked, I've done this, and I've asked a bunch of the different models, like, who is Ben Yellen? And it knows more about me than I know about myself. I mean, it's read all of my social media posts. It's read my biography at the University of Maryland, Baltimore.
Starting point is 00:23:06 So, yeah, I mean, you should expect and realize that this chatbot doesn't just know you from your chat output, but also because they are better than you at searching the internet. Right. They can do it very, very quickly. Right. There's one other element that I think is worth discussing here, which is that a lot of people consent to having law enforcement view their device. Once you do that, I mean, you have no expectation of privacy in anything that's on your phone, whether the law enforcement would have required a warrant to have. it. Right. If they ask, you know, can you unlock your phone for me? I want to take a look around here and you grant that consent. If I'm law enforcement, I'm opening up that chat GPT app and
Starting point is 00:23:47 seeing what I can find, it's probably just as revealing these days as any other application. And a lot of people, when they're in that high pressure situation, they've been arrested. Law enforcement, it's like, hey, let's take care of this. Everything's going to be fine, as long as you're cooperative. Just give me your phone. We'll look at it for. a couple minutes, we'll get you out of here. Do not do that. This is not, this does not constitute actual legal advice, but ask for an attorney. Please, this is your constitutional right.
Starting point is 00:24:20 There is more to our conversation. Be sure to check out the caveat podcast wherever you get your favorite shows. And finally, a quiet collaboration between NYU mathematician Tristan Buckmaster and anthropic researcher Levent Apogis has turned into a very public dispute over AI research credit and one of mathematics biggest prizes. The pair used AI tools and the Leon theorem Prover to establish finite time blow-up results for several fluid dynamics equations related to Navier Stokes. Then OpenAI entered the picture, saying an internal model had produced a proof for the actual Navier-Stokes' Millennium Prize problem worth $1 million. Buckmaster alleges OpenAI may have benefited from his
Starting point is 00:25:32 unpublished work stored in codex and pressured him to exclude Alpogee from authorship. Open AIs claimed proof still faces scrutiny. Whatever the mathematics ultimately says, the episode offers a of AI-assisted research's less elegant side. Models may accelerate discovery, but questions about training data, intellectual property, authorship, and credit aren't proving quite so easy to formalize. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app.
Starting point is 00:26:36 Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound designed by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.