CyberWire Daily - The Cisco root route.

Episode Date: September 18, 2026

Cisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilitie...s to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabilities. Manufacturing remains ransomware’s favorite target. Hackers compromise a Japanese image-sharing service. The Settra ransomware group leverages remote management software. An Australian think-tank warns of Chinese AI-enabled surveillance in Venezuela. Maria Varmazis joins me for a look back at ten years of critical infrastructure exploits. Everything you wanted to know about AI but were afraid to prompt. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Dave Bittner and Maria Varmazis reflect on the past decade of critical infrastructure attacks, looking at major incidents like the Ukraine power grid attack and Colonial Pipeline and the lessons they’ve taught the industry about resilience and preparedness. If you enjoyed this conversation, be sure to tune in this Sunday for a special edition of the show, where Dave and Maria continue the conversation. Selected Reading Cisco drops another exploited zero-day, this time a perfect 10 (The Register) ‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft (404 Media) AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code (SecurityWeek) Microsoft Patches 18 Vulnerabilities in AI, Cloud Products (SecurityWeek) New Check Point flaw lets hackers execute code with root privileges (Bleeping Computer) Manufacturing Accounts for 22% of all Ransomware Victims (Infosecurity Magazine) 23 Million User Records Compromised in Gyazo Data Breach (SecurityWeek) Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM (Huntress) USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech (The Register) Will A.I. Kill Us? Can It Hack My Bank Account? Your A.I. Questions Answered (New York Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. So what happens when an AI agent isn't malicious, but still does something it shouldn't? I recently sat down with Cal Al-Dubabe, principal technologist at Rubrik, to talk about why agentic AI is challenging the way security teams think about detection, permissions, and recovery. If your organization is deploying AI agents, this conversation will help you think differently about where the risks are and how to prepare when things go wrong. Listen to our full conversation at explore. thecyberwire.com slash rubric. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is an opportunity for something to go wrong. And most security
Starting point is 00:01:05 programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast-moving companies like Ramp, Cursor, and Harvey to ensure they're always audit-ready. And now Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools, and your whole environment. The Vanta agent works like a 24-7 GRC engineer in the back. background, finding issues, drafting fixes for you, and cutting vendor assessment time by up to 50%.
Starting point is 00:01:42 Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at vanta.com slash cyber. That's v-a-a-ta.com slash cyber. Cisco patches a maximum severity vulnerability in its identity services engine. Court documents describe AI as an astonishing theft of unprecedented proportions. Researchers chain vulnerabilities to take over employee chat GPT accounts. Microsoft and Checkpoint patch vulnerabilities. Manufacturing remains ransomware's favorite target.
Starting point is 00:02:38 Hackers compromise a Japanese image sharing service. The Sectoro Ransomware Group leverages. remote management software, an Australian think tank warns of Chinese AI-enabled surveillance in Venezuela. Maria Vermazas joins me for a look back at 10 years of critical infrastructure exploits and everything you wanted to know about AI but were afraid to prompt. It's Friday, September 18th, 2026. I'm Dave Bittner, and this is your Cyberwire Intel briefing. Thanks for joining us here today, and happy Friday. It is great as always. to have you with us.
Starting point is 00:03:40 Cisco is urging customers to patch a maximum severity vulnerability in its identity services engine that's already under active attack. The vulnerability carries a CVSS score of 10.0 and affects ISE and ISC passive identity connector. The authentication bypass requires no credentials or user interaction and could give a remote attacker root-level command execution. SISA has added. the flaw to its known exploited vulnerabilities catalog. Cisco says there's no workaround,
Starting point is 00:04:14 though access control lists can temporarily restrict traffic to affected systems. The company recommends checking ISCE and external network logs for signs of compromise and reimaging nodes if exploitation is suspected. The disclosure follows another actively exploited critical Cisco flaw affecting its email security products, making September and a specially busy patching month for Cisco administrators. An unredacted filing in the New York Times' copyright lawsuit against OpenAI and Microsoft is offering a revealing look at how executives inside the companies have discussed generative AI's impact on creators and the web. The Times cites internal Microsoft documents describing
Starting point is 00:05:02 AI training as potentially an astonishing theft of unprecedented proportions, while another warns of a doom loop in which AI systems depend on online content while simultaneously undermining the businesses that produce it. Microsoft CEO Sachinadella testified that clicks from Bing to news sites fell by more than 90% after AI features began using their content. The filing also sites OpenAI discussions about bypassing the Times' paywall and internal concerns that AI could substitute for the labor that produced its training data. The statements now figure prominently in the Times' argument against OpenAI and Microsoft claims that model training qualifies as transformative fair use. Security researchers at Hacktron chained vulnerabilities in OpenAI's community forum and sign-in
Starting point is 00:06:01 system to take over employee chat GPT and codex accounts and reach internal code repositories. The initial flaw was an unpatched Libhife vulnerability used by Discourse's image processing stack. Hacktron used clawed opus models to develop a working exploit, gaining remote code execution through a malicious image. Researchers then discovered that OpenAI community sign-in tokens carried excessive permissions, potentially allowing forum users, chat GPT, and codex accounts to be hijacked. Hacktron demonstrated the chain by compromising an employee account linked to OpenAI's GitHub organization and opening a pull request in an internal repository
Starting point is 00:06:46 without reading internal code. OpenAI fixed the account takeover issue about 14 hours after notification, while discourse patched the image processing flaw within two days. Microsoft has patched 18 vulnerabilities across its Azure cloud services and co-pilot AI products. Most involve elevation of privilege, with additional information disclosure flaws affecting copilot products and Azure machine learning, plus a spoofing vulnerability in Azure portal. Microsoft labeled all 18 vulnerabilities critical, though some carry CVSS scores corresponding to high or medium severity.
Starting point is 00:07:30 None are known to have been exploited. The fixes were applied server-side, so Microsoft says customers don't need to take any action. Checkpoint has patched a critical vulnerability that could allow unauthenticated attackers to execute code with root privileges on its security management server and log server products. The vulnerability is a stack-based buffer overflow in the login process, and Checkpoint says all security management server deployments are voluntary. regardless of configuration. The company hasn't reported active exploitation.
Starting point is 00:08:06 Customers unable to apply the latest live patch can temporarily restrict management access to trusted IP addresses and monitor logs for unusually long username login failures. Manufacturing remains ransomware's favorite target, accounting for 22% of victims from April 2025 through March 26, according to Black Kite. The sector has now ranked first for five consecutive years, with disclosed incidents rising about 40 percent year over year during the first seven months of 26. Europe saw particularly sharp growth, with manufacturing victims climbing 85 percent to 369. Germany led the region with 77 victims, partly driven by Safe Pays' focus on German manufacturers. U.S. incidents remained comparatively stable, falling slightly from
Starting point is 00:09:03 443 to 412. Researchers say manufacturing is attractive because operational downtime can create enormous financial pressure, potentially encouraging ransom payments. Growing convergence between IT and operational technology also expands the attack surface. The emerging gentleman Ransomware Group has been especially active, with manufacturers representing 23% of its leak site listings. In Japan, HelpFiel says hackers compromised its Yazo image sharing service, accessing a database containing roughly 23 million user records. The attacker exploited a vulnerability in an image upload server on September 11th to execute
Starting point is 00:09:51 malicious commands before being removed the following day. Exposed data includes names, email addresses, password hashes, device IDs, X integration tokens, and billing information, though payment card data wasn't compromised. The attacker also accessed about 490 million image metadata records, potentially allowing some uploaded image URLs to be reconstructed. Researchers at Huntress have observed the emerging CETRA ransomware group using remote management software and possible Bring Your Own Vulnerable Driver Tactics. Active since June, CETRA has claimed 93 victims and uses double extortion, though researchers haven't found evidence that it operates as ransomware
Starting point is 00:10:39 as a service. In two recent attacks, CETRA deployed the open source mesh agent remote management tool. One incident also involved installation of a vulnerable gigabyte kernel driver, potentially to interfere with security software. The ransomware attempted to hinder detection and recovery by clearing Windows event logs, disabling the Windows recovery environment, deleting recovery partitions, and overwriting free disk space. Researchers say CETRA appears to target organizations opportunistically through exposed credentials and unpatched systems. Huntress recommends watching for unauthorized mesh agent deployments, suspicious drivers, log clearing, and recovery system tampering. The Australian Strategic Policy Institute is warning that Venezuela could become one of the most advanced users of Chinese AI-enabled surveillance outside China.
Starting point is 00:11:40 ASPI says Venezuela signed an agreement in 2025 to integrate Chinese AI-examined. systems into an existing surveillance infrastructure that already relies heavily on Chinese technology. The report says the initiative was led by Delci Rodriguez, now Venezuela's interim president, and that her government has shown no indication it intends to abandon the plan. ASPI argues that AI could make Venezuela's existing surveillance systems more integrated and effective at monitoring dissent and controlling information, even without replicating China's full surveillance apparatus. The think tank is calling on the United States
Starting point is 00:12:23 to push for dismantling that infrastructure as Washington plays a larger role in Venezuela. Coming up after the break, Maria Vermazas joins me for a look back at 10 years of critical infrastructure exploits and everything you wanted to know about AI but were afraid to prompt. Stay with us. Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call.
Starting point is 00:13:11 But Dopple sees through the disguise. Their AI-native platform detects and disrupts attacks across every channel, trains employees to recognize deepfakes and deception, and investigates every fish to take down the campaign behind it. They fight relentlessly to protect your business, brand, and people. Dopple, outpacing what's next in social engineering. Learn more at doppel.com. That's doppel.com.
Starting point is 00:13:54 To celebrate our 10-year anniversary of the Cyberwire Daily podcast, Maria Vermazes and I have been looking back at some of the key events over the past decade. Today, we look back at 10 years of critical infrastructure exploits. It is my distinct honor and pleasure to once again welcome back, Dave Bittner, host of the Cyberwire Daily to talk with me about the past 10 years of cybersecurity stories. Hi, Dave. Hello.
Starting point is 00:14:21 It's good to be back. Yeah. We've been doing a bunch of these retrospectives over the last year. Hard to believe that there's still so much that we haven't even begun to speak about. Yeah, a lot's happened in the past 10 years, huh? Imagine.
Starting point is 00:14:37 Imagine in cybersecurity. And one area that we've actually touched on quite a bit because these things do interweave and interrelate, is critical infrastructure and the types of fascinating, scary, interesting, all the above types of attacks we've seen on infrastructure. And honestly, your definition of infrastructure, your mileage may vary on that one. But let's think about, like, very generally, critical infrastructure around the world, what we've seen in the last 10 years, because this is an area where things have really evolved,
Starting point is 00:15:12 or at least that's my impression. I'm curious what you think about that, Dave. I think you're right. And I think sometimes it's better to be lucky than good. And I think we were just lucky in that, we were lucky even if the world was not, that 10 years ago, when we were just getting started on this thing, it kind of coincided with a Ukraine power grid attack, which was back in December 2015 or so. And so I think this was the realization of things that people have been talking about and warning about. And it was a lot of question here in the U.S., like, was this a test run for capabilities that perhaps could come to our shores? So I think it was a bit of a wake-up call.
Starting point is 00:16:02 And just more clarification, I guess. This was Russian-linked sandworm attackers. They compromised the Ukrainian electricity distribution companies. It was what? Over 200,000 customers lost their power. And my recollection is this was the first really publicly acknowledged cyber attack that caused a power outage. Yeah.
Starting point is 00:16:27 And what's fascinating about that incident to me is in my previous to that incident, I remember within the cybersecurity industry are experts in ICS or industrial control systems. I'm going to be throwing that acronym around a lot. The ICS experts had been saying, listen, it's inevitable. There are going to be disabling attacks.
Starting point is 00:16:49 We're not trying to do FUD, fear uncertainty, and doubt. We're not trying to, you know, but we need to also be realistic that we recognize that, you know, ICS are huge targets. They're a very appealing target. and it doesn't require much sophistication to necessarily take them out, which was very unsexy
Starting point is 00:17:08 for a lot of people to hear that. It's like they're very important and very hard to defend and not a priority in the way that you would think they should be and good luck sleeping tonight when you think about it. And then one of these days
Starting point is 00:17:22 it's going to happen and then it did. I guess and then everything changed, she said in the movie narration. Well, you had sent over a clip that reminded me that there was congressional testimony about this, you know, going far, predating all of this. There were some experts, some familiar names in, I don't know, OG hackers, right? Yeah, the Loft Crew, right? The Loft Crew, yeah. The Loft Crew, yeah. Who went to Congress and basically said, if you turned us loose on this system,
Starting point is 00:18:00 yeah, we could shut it down, no problem. It wouldn't take long. It would be pretty easy to do. So the warnings go back pretty far. I think we have a clip from that. I'm informed that you think that within 30 minutes, the seven of you could make the Internet unusable for the entire nation. Is that correct?
Starting point is 00:18:24 That's correct, actually, one of us with just a few packets. We've told a few agencies about this. It's kind of funny because we think that this is something that the various government agencies should be actively going after. We know the Department of Defense just did a very large investigation into what's known as denial of service attacks against the infrastructure. In our various day jobs, we contributed a large portion of the information to that actual investigation. much to our chagrin, the learnings from it were instantly classified, which we were giving them largely public information. It is very trivial with the old protocols to segregate and separate the different major long-haul providers,
Starting point is 00:19:15 which would then be the national access points, the metropolitan area ether sections, AT&T can't talk to MCI, can't talk to PSI, can't talk to PSINet, can't talk to alternate, et cetera, et cetera, and keep it down that way as long as we really wanted to. It would definitely take a few days for people to figure out what was going on. Yeah, I mean, the loft guys were very prescient, and, you know, I'm sure it annoys them, heartbreaks them to no end that they were right. And, you know, their warnings still bear out to this day. It stinks to be a Cassandra, but it's the reality often of being in this world.
Starting point is 00:19:52 And I feel like, again, this is just impressive. of what I remember pre-2016 or so. I feel like there was some discussion of maybe the still extant gentleman's agreement around we're not going to have, no one's going to really go after ICS because if they do that to us, they know we're going to do that to them and then it's all over for everybody. I think you're right. Yeah. And I think in the pre-Ransomware days,
Starting point is 00:20:18 it was also kind of considered off limits in the same way that hospitals were considered off limits, you know, critical infrastructure, right? Things affecting the public, non-military targets, I think you're right. There was this gentleman's agreement right up until the moment
Starting point is 00:20:36 when there wasn't. And so the Russians demonstrating this capability really, it was a shift. Yeah. And I think there was also an element of security through obscurity for a lot of ICS that that's a very
Starting point is 00:20:50 rarefied skill set. Not everybody understands, how ICS work. Not everybody wants to. A lot of people are just straight up, not interested. That village DefCon is not as well attended as you might want it to be. Right. You know, it's, who wants to talk about sewage plants when we could be talking about cool stuff, you know?
Starting point is 00:21:06 Ooh, valves. Yeah. It's always a valve. I don't know about you, but especially during 2020, when COVID shut down the world, I remember thinking, well, all those really unsexy things are what keeps civilization going. And I appreciate them a lot more now. But yeah, I think a lot of people didn't and still don't understand how these systems work. They're very, very old, both the physical parts and then try tacking on an internet-enabled thing.
Starting point is 00:21:37 It's probably not necessarily going to be the newest and greatest, sitting in some plant somewhere that's not frequently updated. And that's a big part of it, that a lot of these old legacy systems that get, you know, they have service lives in the decades. So over the intervening decades, like you say, they'd had these automation components literally grafted on to many of them. And so they weren't designed in from the outset. And that led to all sorts of vulnerabilities. Yeah, it became a security through obscurity thing for ICS until again, even then everything changed yet again. And then malware authors and adversaries started understanding how to actually speak the language of, industrial control systems and actually target them specifically.
Starting point is 00:22:26 And in destroyer, industrialer, indistroar. Yeah, that's the name that comes to mind. Yeah, what do you remember about that story? I mean, it was in destroyer, which I think was also called Crash Override. And that was just malware that had been tuned to communicate using those ICS protocols. And so the malware could interact directly with that. equipment rather than just to breaking into the computers that were kind of adjacent to the grid,
Starting point is 00:22:59 the bad guys could get in and interact with the grid directly. And so that set people back on their heels, I think. There is more to our conversation. You will find that in your Cyberwire feed this weekend. And finally, the New York Times ask readers what they really want to know about artificial intelligence, and nearly a thousand responded with questions ranging from, will it take my job, to the slightly more consequential, will it destroy humanity? The Times' answers are reassuringly or frustratingly, mostly, not yet, maybe, and nobody really knows. Today's AI agents can send emails, edit files, write code, and perform other tasks, but they still
Starting point is 00:24:05 require human direction. Predictions that autonomous AI could commandeer infrastructure, launch weapons, or otherwise end civilization remain highly speculative. Guard rails exist, but researchers continue finding creative ways around them, apparently including poetry, proving that verse retains at least one practical application. Closer to home, AI poses more immediate concerns, white-collar jobs, particularly programming, writing, and design could face disruption. Data centers consume substantial water and energy. While chat GPT can't simply rummage through your phone for banking credentials, AI agents become considerably riskier when users deliberately give them access to files,
Starting point is 00:24:54 email, and credit cards. As for the superintelligence curing cancer and ending world hunger, the Times recommends keeping expectations terrestrial. AI is already remarkably capable at coding mathematics and accelerating scientific research, while remaining surprisingly bad at common sense. So, will AI save humanity or destroy it? The Times' survey suggests we're still somewhere in the much less cinematic middle. Powerful technology, imperfect safeguards, real risks,
Starting point is 00:25:31 considerable promise, and plenty we simply don't know yet. And that's the CyberWire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. Be sure to check out this weekend's Research Saturday, and my conversation with Renee Burton from InfoBlocks. We're discussing their work on Lurking Lizard, titled Fake Installers, Fake Reviews, Fake Services, real proxies, real victims. That's Research Saturday.
Starting point is 00:26:09 Check it out. And hello, Maria Vermazza is here. On Sunday's T-minus space cyber briefing, I'm speaking with Sean McCurdy, area vice president for national security at Elastic Government Solutions, on security frameworks for space as critical infrastructure. That's Sunday on T-minus. Don't miss it. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead
Starting point is 00:26:33 in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review. in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester
Starting point is 00:26:51 with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilpe as our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here next week.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.