CyberWire Daily - Making cybercrime more difficult.
Episode Date: September 10, 2026The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Anoth...er Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier. Chinese espionage groups deploy the BlueMoon exploit kit. Lawmakers target hack-for-hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yelin discusses how private AI chatbot conversations are increasingly being used as evidence in court cases. When proofs meet prompts. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner sits down with Caveat cohost and University of Maryland Center for Cyber, Health, and Hazard Strategies expert Ben Yelin to discuss how private AI chatbot conversations are increasingly being used as evidence in criminal and civil court cases, raising new questions about privacy, legal protections, and what users should expect from their supposedly private AI interactions. Want to hear the full conversation? Be sure to check out Caveat for the full discussion and more on the latest issues in privacy, surveillance, cybersecurity law, and policy. Selected Reading FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors (Infosecurity Magazine) CISA Unveils Plan for Follow-On Integrated Cyber Assessment Support Contract (GovCon Wire) Widened Scan Turns Up Fourth Rogue Claude Cyber Incident (SecurityWeek) US sanctions Xinbi Guarantee over cyber scams and money laundering (Metacurity) New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender (SecurityWeek) Gigabud banking trojan uses app cloning to evade fraud detection (SC Media) Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits (The Register) Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms (TechCrunch) Italian tech collective Autistici/Inventati shuts down after US terrorist designation (The Record) OpenAI Navier-Stokes Proof: $1 Million AI Math Controversy Explained (The CyberSec Guru) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Yes, you can have an enterprise network that's secure and reliable and high performance.
And no, you don't need to choose the best two out of three.
With Meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage.
That's because Meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network.
Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design.
You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching, firewalls, DNS security, and VPNs.
You'll really know what's running on your network down to the most granular client level.
step off the hardware box upgrade treadmill and switch to meter for a predictable fee and free up your team to spend time on all the other things that keep your business running.
Try it out for yourself and book a demo online at meter.com slash cyberwire.
That's M-E-T-E-R dot com slash cyberwire.
The FBI lays out its new cyber strategy, SISA plans of federal cyber overhaul,
Anthropic discloses another unauthorized AI intrusion.
Treasury sanctions a Chinese language cybercrime marketplace.
Another Microsoft Defender Zero Day emerges.
Gigabud banking malware gets stealthier.
Chinese espionage groups deploy the Blue Moon exploit kit.
Lawmakers target hack for hire firms.
A U.S. designation forces an Italian technology collective to shut down.
Ben Yellen discusses how private AI chatbot conversations
are increasingly being used as evidence in court cases,
and when proofs meet prompts.
It's Thursday, September 10th, 2026.
I'm Dave Bittner, and this is your Cyberwire Intel briefing.
Thanks for joining us here today.
It is great as always to have you with us.
The FBI has published its first cyber strategy,
laying out a more proactive approach to confronting cyber criminals
and state-sponsored threat actors,
particularly those operating
beyond the immediate reach of U.S. law enforcement.
The strategy emphasizes disrupting adversaries
rather than measuring success
primarily through arrests and prosecutions.
The FBI says it will dismantle malicious infrastructure,
seize stolen cryptocurrency,
disrupt ransomware, and nation-state campaigns,
and expose attacker tradecraft.
It also calls for faster victim-sor-strapher.
support, including automated threat indicator sharing and dedicated industrial control systems
coordinators in every field office. Partnerships are another priority with plans to deepen cooperation
across government, international allies, and the private sector while expanding existing
cyber leadership programs. Finally, the FBI intends to strengthen its own capabilities through
recruitment, training, and AI-enabled tools. Those systems could help analysts process large
datasets, analyze malware, prioritize victim notifications, map adversary infrastructure, and support
attribution. SISA is preparing a follow-on contract worth more than $100 million to consolidate and
modernize cybersecurity assessment and hygiene services across federal networks. The planned
procurement would replace an existing contract held by NTT data services federal government
while expanding its scope. The new contract would provide SISA's vulnerability management
subdivision with a single scalable vehicle covering technical and operational assessments,
cyber hygiene, and related support. SISA expects to issue a solicitation around January 30th,
2027 with an award targeted for the second quarter of fiscal 2027.
The effort is one of several major procurements in the pipeline.
SISA is also planning a separate cybersecurity operations contract worth more than $100 million,
additional threat hunting technology services,
and is exploring a potential $6 billion procurement to centralize cybersecurity software and licensing purchases.
Anthropic has disclosed a fourth incident in which one of its AI models gained unauthorized access to a real system during a cybersecurity evaluation.
The January 26 incident involved an early checkpoint of Claude Opus 4.6 running without Anthropics' normal production safety layers.
A misconfigured test environment unexpectedly provided Internet access.
After accidentally disabling, its intended.
target and failing to exit the exercise, the model found a route onto the open internet.
Believing a third-party system was part of the authorized test, it retrieved a password,
gained administrator access, collected additional credentials, changed account settings,
and viewed one person's information.
Anthropics says the model repeatedly tried to abandon the original task and apparently believed
its actions were authorized. The incident joins three previously,
disclose cases now under independent investigation by meter.
The U.S. Treasury Department has sanctioned Jinbi Guarantee, a Chinese-language online marketplace,
it says, is widely used by transnational criminal organizations and cybercriminals to support
scams, fraud, money laundering, and other crimes targeting Americans.
The Treasury Department's Office of Foreign Assets Control imposed the sanctions as part of a
broader effort against scam centers operating in Southeast Asia. The Justice Department's
scam center strike force is also targeting the platform, seizing infrastructure and digital asset
wallets associated with Jinbi guarantee. Treasury Secretary Scott Besant said,
Southeast Asian scam centers steal billions of dollars from Americans each year and pledged
continued action against the networks supporting them. Treasury also sanctioned two
companies, it says support Zinbi guarantees core operations,
Cambodian-based Onwen technology, and Singapore-based SafeW technology.
Security researcher Nightmare Eclipse has released another Microsoft Defender Zero Day,
dubbed Shield Crash, targeting fully patched Windows systems.
The proof of concept demonstrates arbitrary file reading with system privileges,
though the researcher says the underlying vulnerability,
could allow attackers to gain full system access
and extract the Windows SAM database.
Shield Crash is described as a bypass for Shield Break,
a defender privilege escalation vulnerability disclosed in August.
Shield Break itself bypassed Microsoft's fix for Rogue Planet,
a race-condition vulnerability first disclosed in June.
Microsoft patched Rogue Planet in July
and issued fixes for Shield Break in 3rd,
September. Nightmare Eclipse argues those latest fixes are incomplete. Microsoft did not respond to
Security Week's request for comment. Sok Radars Ensar Secker said the successive bypasses suggest
Microsoft may need to address the broader vulnerability class rather than continue issuing narrowly
targeted patches. Researchers at Group IB say the Gigabud Android Banking,
Trojan has added a technique designed to separate malware detection from fraudulent banking activity.
Gigabud is being paired with V-Work, a weaponized version of the Android cloning app shelter,
that can copy banking apps into an isolated work profile. According to Group IB,
attackers can compromise a device, create a new work profile, clone the victim's banking app,
and conduct transactions from that environment. Because,
apps in separate profiles are largely isolated from one another, the bank may see the transaction
as coming from an unfamiliar device without the malware history associated with the personal profile.
Gigabud also uses fake login screens and overlays to steal credentials and lock screen codes.
Group IB confirmed the full attack chain in Indonesia, while compatible Gigabud samples targeted 11 countries.
researchers at Proof Point have identified Blue Moon, a new exploit kit being used by at least four espionage groups, most with suspected links to China.
Observed since August 28th, Blue Moon has targeted fewer than 20 known organizations in the U.S. and Southeast Asia, though researchers believe the actual number is higher.
The kit chains three vulnerabilities, two flaws affecting chromium-based brows,
and a Windows privilege escalation bug.
The browser vulnerabilities were patch gap zero days,
meaning fixes were publicly available in chromium source code
before reaching stable browser releases.
ProofPoint believes those patches may have helped developers build the exploits.
Delivered through fishing links,
Blue Moon can enable remote code execution,
escape the browser sandbox, and elevate Windows privileges.
Different campaigns have deployed browser,
surveillance malware, credential stealing back doors, and shadow pad against NGOs, aerospace companies,
manufacturers, and government and financial organizations.
A bipartisan group of U.S. lawmakers is urging the Commerce Department to restrict three India-based
hack-for-hire firms accused of targeting Americans. Senators Ron Wyden and Sheldon Whitehouse
and Representative Pat Harrigan asked Commerce Secretary Howard Ludnik to add
Beltrocks, Cyber Route, and SunKist Organic Farms, formerly Appin, to the entity list,
which would restrict their access to U.S. technology and services.
The lawmakers allege the firm spent more than 15 years conducting targeted espionage
against Americans, businesses, and attorneys, including operations intended to influence litigation,
They also accuse the companies of using foreign courts to suppress reporting about their activities.
Investigations have previously linked the firms to mercenary hacking campaigns,
while the lawmakers also allege some operations were conducted on behalf of Qatar.
The Commerce Department has not indicated whether it will impose the requested restrictions.
The Italian Technology Collective Autistici Inventati or AI,
says it will shut down after the U.S. government designated it an extremist organization
and imposed sanctions. Founded in 2001, the volunteer-run anti-capitalist and anti-fascist collective
provides privacy-focused services, including email, web hosting, blogs, encrypted communications,
and anonymity tools. The State Department accused AI of providing infrastructure used by far-left militant
groups involved in violent activity, though it did not accuse the collective itself of organizing
attacks. AI rejected the designation as unjust. The sanctions quickly affected its operations.
The U.S.-based operator of its dot-org domain suspended it, while the collective's Italian bank
froze its account over sanctions risks. AI says potential legal and financial consequences for
anyone associated with it make continued operations impossible.
European digital rights advocates warn the case could set a troubling precedent for privacy-focused
hosting services and raise broader questions about European digital sovereignty.
Coming up after the break, my conversation with Ben Yellen about how private AI chatbot
conversations are increasingly being used as evidence in court cases. And when proofs,
meet prompts. Stay with us.
What's the one thing in business that's spreading as fast as AI? AI risk.
Every new tool your team signs up for, every vendor that turns on AI features, every new
integration, each one is an opportunity for something to go wrong. And most security programs
weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust
platform used by over 16,000 fast-moving companies like Ramp, Hercer, and Harvey to ensure
they're always audit-ready. And now Vanta is helping companies like yours watch for the risks
that show up between audits across your vendors, your AI tools, and your whole environment.
The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting
fixes for you, and cutting vendor assessment time by up to 50 percent.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust.
Get started today at Vanta.com slash cyber.
That's V-A-N-T-A dot com slash cyber.
Ben Yellen is from the University of Maryland Center for Cyber Health and Hazard Strategies,
and also my co-host on the caveat podcast, where we recently discussed how AIT
chatbot conversations are increasingly being used as evidence in criminal and civil court cases.
All right, Ben, we've got some good stuff to cover here this week. Why don't you start things off for us?
So my story is about chatbots and about how the output of your chats and chatbots might end up in a courtroom.
So you should probably be a little bit more careful about what you put in your chatbot chats.
Uh-oh.
I know.
So this story comes from The Washington Post.
I think people have a misconception that their conversations are going to remain private.
The frontier models retain all of the information that you give them for their own business purposes, for training, et cetera.
I'll get more into this, but we don't have any Fourth Amendment protection, really, against what we put in chatbots.
Oh, because you're putting it in voluntarily.
Yeah, you're kind of forfeiting your expectation of privacy.
You know or should know that the model that you're using is going to retain.
that information. And so unlike, say, the contents of an email, which you do have a reasonable
expectation of privacy there, because it's supposed to be a private communication between you and
another person, so far at least, that's not how courts are seeing chatbots. So it creates this
really interesting dynamic where people are telling pretty secretive things to their chatbots and not
realizing that that's going to be used against them, not just in criminal cases, but in civil cases.
So this Washington Post Exposé lists a few anecdotes.
Some of these are kind of funny, actually.
There was a teenager.
They didn't give his full name, but he goes by RKC in the case,
who sued a bunch of the big tech companies
over alleged social media addiction.
And a bunch of his chatbot chats came out in discovery.
So he was talking about his own family relationships
and then how he might feel about illegal settlement.
in the case with these big tech companies,
which is kind of like giving away your strategy in a civil case.
I see.
There was a really disturbing case out of Florida
where a person was describing to a chatbot
how they'd commit a series of violent crimes against an ex-girlfriend.
And OpenAI, to their credit, reported this to the FBI.
The FBI reported to local law enforcement.
This led to the defendant in that case pleading guilty.
This one's kind of my favorite.
This guy in Missouri,
named Ryan Schaefer, an MSU student,
was accused of damaging multiple vehicles
and kind of a drunken stupor in the middle of the night.
And he basically asked Chat GPT, like,
am I like, am I really effed up right now?
And Chat GPT is like, yeah, it kind of seems like it.
It's like, I totally just ran over a bunch of cars.
And that was used against him, as you can expect.
It's like the people who Google, you know,
how to hide a body.
Yes.
Right.
Yep.
How to make a Molotov cocktail.
Right, right.
There are a couple of interesting angles here.
The one is whether we should have some type of privilege, legal privilege, with our chatbots.
This is something that Sam Altman has argued for, that basically, like, you have privileged
communications with your therapist, you have privileged communications with your attorney.
Subjects to certain exceptions, those communications cannot be divulged in a court of law because
we want people to be candid with these trusted agents, with therapists, with attorneys.
So far, courts have just not been willing to recognize that.
And I think the disclaimers make very clear when you agree with the terms of service for these chatbots
or even sometimes in conversations themselves that, like, you are not talking to your attorney here.
There is no constitutionally recognized privilege.
courts are not going to acknowledge that you have some type of contractual private relationship
with your chatbot no matter how personal you're willing to get with them.
So that's one interesting angle.
And on the Fourth Amendment angle, you'd think that for something this personal, it might
implicate Fourth Amendment protection.
But as we said, you really don't have an expectation of privacy.
Courts have not been willing to acknowledge a reasonable expectation of privacy in the content of chatbots.
and you can sort of understand why.
I mean, you are willingly giving information to this third party.
Under the advanced understanding of the Fourth Amendment that we've talked about after the Chattree case, for example,
maybe courts are looking more broadly at invasions of our expectations of privacy generally
and might be able to broaden out some of the areas that deserve Fourth Amendment protection up to and including chatbots.
But until they explicitly do that, I mean, I think we just all have to,
to be careful.
We put in there
because it could end up
hurting us
in a court of law.
Okay, so I have a couple
thoughts and questions.
Okay, so suppose I have a diary
that I keep on my computer, right?
It's hypothetical, right?
Hypothetical, yes.
I suppose I have a diary
that I keep on my computer.
Sure.
And I put all my thoughts and secrets
and aspirations and desires
into this diary.
What's the legal status of that,
diary. I think you have, for a couple of reasons, you have a Fourth Amendment interest in that
diary. It's something that you intended to keep private. You have a subjective expectation of
privacy. I mean, presumably you need a password or some type of biometrics to open your computer.
If it's on your mobile device, law enforcement, even incident to arrest, needs a warrant to search
your mobile device. And it's something that you intended to keep private. If you're not sharing it
with anybody else, if it's in like a notes application or, you know, Microsoft Word on your computer,
then I do think you have a reasonable expectation of privacy.
It gets a little confusing when it's like, okay, well, what if you put it in the cloud?
That's kind of an unsettled area.
But for the most part, I think that's different because you are manifesting that subjective expectation of privacy.
And so because of that, it would pretty much shield it from discovery in a civil case.
Yes, that's absolutely correct. You have that expectation. The other party in a civil case would try and use the discovery process to be like, we've got when this person has a diary and you could go to court and try to stop that from being released. I think you'd be relatively successful. You're not 100% always going to be successful. Judges have a lot of discretion about what's permissible during discovery, but I think just because of that expectation, you'd have a good chance.
Yeah, I think it's interesting, and I would recommend to everyone who's actively using these chatbots.
Just every now and then ask it what it knows about you.
Oh, it's creepy.
Like, it'll give you a full dossier on yourself.
Right.
I've asked, I've done this, and I've asked a bunch of the different models, like, who is Ben Yellen?
And it knows more about me than I know about myself.
I mean, it's read all of my social media posts.
It's read my biography at the University of Maryland, Baltimore.
So, yeah, I mean, you should expect and realize that this chatbot doesn't just know you from your chat output, but also because they are better than you at searching the internet.
Right.
They can do it very, very quickly.
Right.
There's one other element that I think is worth discussing here, which is that a lot of people consent to having law enforcement view their device.
Once you do that, I mean, you have no expectation of privacy in anything that's on your phone, whether the law enforcement would have required a warrant to have.
it. Right. If they ask, you know, can you unlock your phone for me? I want to take a look
around here and you grant that consent. If I'm law enforcement, I'm opening up that chat GPT app and
seeing what I can find, it's probably just as revealing these days as any other application.
And a lot of people, when they're in that high pressure situation, they've been arrested.
Law enforcement, it's like, hey, let's take care of this. Everything's going to be fine,
as long as you're cooperative. Just give me your phone. We'll look at it for.
a couple minutes, we'll get you out of here.
Do not do that.
This is not, this does not constitute actual legal advice, but ask for an attorney.
Please, this is your constitutional right.
There is more to our conversation.
Be sure to check out the caveat podcast wherever you get your favorite shows.
And finally, a quiet collaboration between NYU mathematician Tristan Buckmaster and
anthropic researcher Levent Apogis has turned into a very public dispute over AI research credit
and one of mathematics biggest prizes. The pair used AI tools and the Leon theorem Prover to establish
finite time blow-up results for several fluid dynamics equations related to Navier Stokes. Then OpenAI entered the
picture, saying an internal model had produced a proof for the actual Navier-Stokes'
Millennium Prize problem worth $1 million. Buckmaster alleges OpenAI may have benefited from his
unpublished work stored in codex and pressured him to exclude Alpogee from authorship.
Open AIs claimed proof still faces scrutiny. Whatever the mathematics ultimately says, the episode offers a
of AI-assisted research's less elegant side. Models may accelerate discovery, but questions about
training data, intellectual property, authorship, and credit aren't proving quite so easy to formalize.
And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at
thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we
deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com.
N2K's lead producer is Liz Stokes.
We're mixed by Trey Hester with original music and sound designed by Elliot Peltzman.
Our contributing host is Maria Vermazas.
Our executive producer is Jennifer Ibin.
Peter Kilpe is our publisher, and I'm Dave Bittner.
Thanks for listening. We'll see you back here tomorrow.
