CyberWire Daily - Who’s watching the AI watchers?

Episode Date: September 3, 2026

A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients s...pread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with the AI attack surface. Robocall report cards.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with AI attack surface. Selected Reading Trump may be forced to reveal secret rules feds use for AI safety testing (Ars Technica) Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks (The Register) 2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators (Security Affairs) Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity (Huntress) A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions (Thenextweb) Spring Ring Vishing Attack Uses Fake IT Calls on Microsoft Teams to Install Malware (Hackread) Plex warns users to patch security vulnerabilities immediately (Bleeping Computer) Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities (SecurityWeek) The FCC wants consumers to rate their telecom’s anti-robocall protections (CyberScoop) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business. Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Dopple uses it to fight back, automatically dismantling cross-channel attacks, building team resilience and providing agentic email protection. Dopple, outpacing what's next in social engineering. Learn more at doppel.com.
Starting point is 00:00:47 That's do pp-p-el.com. A watchdog challenges the Trump administration's secret frontier AI reviews. Meter discloses two cyber attacks. Leaked documents reveal a Russian cyber training pipeline. Rogue screen-connect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched secure email flaws.
Starting point is 00:01:34 Our guest is Rob Vandervere, chief AI officer at Software Improvement Group, discussing how we're not keeping up with the AI attack surface. And Robocall Report Cards. It's Thursday, September 3rd, 2026. I'm Dave Bittner and this is your Cyberwire Intel Briefing. Thanks for joining us here today. It's great as always to have you with us. A non-profit watchdog is suing four federal agencies
Starting point is 00:02:30 for details about the Trump administration's largely secret process for reviewing frontier AI models before release. Protect Democracy says the government has disclosed little about how models are evaluated, which companies participate, or what authority officials are using. The group is seeking unclassified records covering the framework, participation terms, review criteria,
Starting point is 00:02:56 and the government's Gold Eagle cybersecurity program. It argues that secrecy makes it difficult to determine whether reviews are effective, politically influenced, or even applied consistently. The dispute comes as Congress considers renewing liability protections under the Cybersecurity Information Sharing Act, which the administration says are important to Gold Eagle.
Starting point is 00:03:22 Protect Democracy argues lawmakers can't properly evaluate those protections without knowing how the program operates. The lawsuit seeks release of the records by September 30th and an injunction preventing agencies from improperly withholding unclassified information. AI model testing nonprofit Meeter has disclosed two attacks from earlier this year, though it found no evidence that sensitive information was accessed. In March, attackers exploited a fail-open authentication bug in a researcher's publicly accessible app. They persuaded an AI agent to reveal an API key,
Starting point is 00:04:04 established persistent access, and spent three weeks consuming roughly $600,000 worth of credits for public models. meter didn't immediately notice because heavy API usage was routine, and the credits had been provided for free. Then in May, attackers launched a sustained campaign probing meters infrastructure using automated vulnerability discovery, credential stuffing, o-off attempts, scanning, and fishing. Separately, a bug exposed some unpublished evaluation and sensitive model data through a public-facing service. An independent researcher discovered the flaw, and Meador says there's no evidence attackers exploited it. More than 2,000 leaked documents reportedly reveal a hidden program at Bauman Moscow State Technical University that trained students for Russian military intelligence and cyber operations.
Starting point is 00:05:03 Department number four, or special training, operated within the university's military training center, preparing roughly 250 students in espionage, offensive and defensive cyber operations, electronic reconnaissance, malware analysis, secure systems, and influence operations. The records also connect the program to senior GRU officials and military units associated with prominent Russian threat groups. Former Unit 26165 commander Victor Natikso, whose unit is linked to APT-28, reportedly helped oversee students. Graduates were also assigned to Unit 74-455, associated with Sandworm and Unit 29-155. The documents don't establish that individual graduates participated in specific cyber attacks. Instead, they offer a rare look at the institutional
Starting point is 00:06:00 pipeline used to recruit, train, assess, and place personnel supporting Russia's broader cyber-intelligence and influence operations. Huntress has uncovered a campaign using social engineering and rogue screen-connect installations to spread malware with worm-like behavior. Across several organizations, attackers persuaded victims to install remote access software, then used screen connect to launch a four-stage VB script chain.
Starting point is 00:06:34 The scripts profile-infected systems checking for security tools, memory, and existing. screen-connect installations before selecting additional payloads. Depending on the system, those payloads can establish persistence, escalate privileges, weaken Microsoft Defender protections, install cryptocurrency mining and tunneling tools, or deploy a concealed screen-connect backdoor. The most notable feature is a modified screen-connect client
Starting point is 00:07:05 that detects new remote sessions and automatically pushes the malicious scripts to connected systems, allowing the infection to propagate. Huntress recommends rebuilding affected machines from known-good media and closely reviewing screen-connect audit logs for suspicious script execution. Thompson Reuters says an unauthorized party accessed files belonging to C-Track, its court case management platform, exposing records from appellate courts across at least a dozen U.S. jurisdictions and Ontario, Canada. The files were taken in March, but Thompson Reuters didn't detect the activity in its cloud environment until June 30th. Public disclosures followed September 2nd. Potentially exposed information includes names, social security and driver's license numbers, medical and
Starting point is 00:08:00 insurance information, birth dates, and possibly confidential or sealed court documents. Thompson Reuters says C-Track remained operational throughout the incident and that it has brought in outside cybersecurity experts and notified law enforcement. The company is offering affected individuals credit monitoring and identity theft protection. The number of people affected, the intrusion method, and the attacker's identity have not been disclosed. Palo Alto Netifes, Network's Unit 42 has uncovered a voice fishing campaign dubbed Spring Ring that used Microsoft Teams to impersonate corporate IT support. Between January and April, attackers targeted more than 150 employees at over 10 organizations worldwide. Using external teams accounts with names such as
Starting point is 00:08:53 Help Desk, the attackers called employees and persuaded them to launch legitimate remote support tools such as quick assist or install other software. Once connected, they surveyed privileges and deployed malware, including a remote access Trojan. In another attack chain, they sideloded a malicious browser extension, scanned internal systems, and attempted an NTLM relay attack to gain domain level privileges. Unit 42 emphasizes that Spring Ring didn't exploit a team's vulnerability. Instead, Instead, attackers exploited employees' trust in familiar collaboration tools and seemingly legitimate IT support requests. Plex is urging users to update its media server and desktop software to address multiple security vulnerabilities. The flaws affect multiple versions, though technical details and CVE identifiers haven't yet been released.
Starting point is 00:09:54 Plex recommends upgrading servers to the most recent version. NAS users may need to install the server update manually if it's unavailable through their package manager. Plex also emailed affected users urging them to patch promptly. Cisco is warning about two publicly disclosed, unpatched vulnerabilities in its secure email product. The vulnerabilities affect S-MIME decryption in multiple versions of ASync OS, Cisco says an attacker positioned between email gateways could modify traffic and potentially recover plain text from encrypted communications. The company isn't aware of active exploitation.
Starting point is 00:10:39 Cisco also released patches for several more serious vulnerabilities, including critical flaws in iOS XR and Nexus 9,000 switches that could enable remote code execution, authentication bypass, and other attacks. One nexus vulnerability could allow unauthenticated attackers to execute code with root privileges. Cisco also patched a high severity denial of service vulnerability, affecting several of its phone product lines. Coming up after the break, my conversation with Rob VanderVier from Software Improvement Group. We're discussing how we may not be keeping up with the AI attack surface. And Robo Call Report Cards. Stay with us.
Starting point is 00:11:32 Today's cybercriminals aren't just launching attacks. They're building businesses around them. They have subscription models. They have a marketplace. They have affiliate program. If you want to do referrals, you can get credits. They make it really easy. It really looks like a legitimate SaaS product that somebody might use.
Starting point is 00:12:01 I sat down with Mike Britton, CIO at Abnormal AI, to explore how AI is lowering the barrier to cybercrime and what security leaders need to change in response. Here are full conversation at explore.thecyberwire.com slash abnormal AI. Rob Vandervere is chief AI officer at Software Improvement Group. Our conversation today focuses on how we might not be keeping up with the AI attack surface. If you look at the change in attack service, I think there are three perspectives here. It's shadow AI, it's open source dependencies, and you,
Starting point is 00:12:50 using AI to help in software engineering. So to start with these open source dependencies, they have suddenly become much more critical now that AI is so much better in finding vulnerabilities in that. This puts a lot of pressure on organizations. Patching needs to improve and speed up. And the same goes for incident response and security posture in general because you really need to assume that you can't keep up.
Starting point is 00:13:17 So you need to deal with the fact that these vulnerabilities are going to result in incidents, and you need to respond to them and also have defense in depth in order you can deal with these vulnerabilities. And what people sometimes forget to do is to have a good look at their dependencies. Maybe it's time to get rid of some of them,
Starting point is 00:13:38 especially those where there's hardly any maintenance activity. So those are the dependencies that are an increasing challenge. Then Shadow AI, it's a challenge. it's a challenge that every organization faces. My recommendation is to also see it as a potential demand signal. If your team members are using other AI, then you have provided and prescribed, yes, that's a security risk.
Starting point is 00:14:04 But you also should treat it as a signal that you're apparently not providing the AI that they need. So providing AI that people need is one of the ways to deal with this shadow AI. And then we have AI, generated code or agentic programming or loop engineering for software engineering. In that realm, everything is out of control because all the existing ways to control security are out of the door. Everybody's exploring.
Starting point is 00:14:34 Everybody's trying the best. The human code review gets a lower priority simply because organizations feel it defeats the whole purpose of AI increasing productivity. So there you have it. A lot of change, a lot of new things, a lot of pressure. and the threat of burnout for security professionals. Where do you suppose we're headed? How do you think organizations are going to get a handle on these challenges? Well, we're figuring things out together.
Starting point is 00:15:03 The new way of software engineering is really bleeding edge. So finding help and experience and advice with your peers is, I think, an important direction. We are organizing roundtables, for example, for organizations to exchange ideas, but constantly exploring. So improving the way you explore and learn is essential when it comes to software engineering. You need to build a harness around AI generating code,
Starting point is 00:15:37 giving it proper requirements and verifications. And you need to make sure that you have a mix between AI tools and humans during these verifications. And that's the bleeding Azure software engineering right now, finding the right mix of tools, AI, and humans that do the review. Now, when it comes to open source, of course, you need to know what you have. You need to scrutinize your dependencies. I see a lot of organizations starting to do that,
Starting point is 00:16:07 but many of them are focusing currently on improving their ability to patch as soon as possible by automating that. And not just look at individual vulnerability scores, but really assume that very harmless vulnerabilities can be combined by AI. And also these need attention. And last but not least, organizations increasingly are putting effort in doing this in such a way
Starting point is 00:16:38 that you're not burning out your security professionals. So really by prioritizing what comes first. How do you recommend that security leaders communicate the reality of this situation to the powers that be, to their boards of directors, to their managers? I think the media are helping with, you know, the attention for what AI is capable of, and rightfully so. And I see security leaders taking that as, you know, a good argument in their organization.
Starting point is 00:17:13 to create more budget and create more attention. So the examples of what happened with Open AI, hacking into Hugging Phase, the whole Glasswing project, mythos, using those as examples, why it's important to pay attention to security is, I think, at best practice. Are you optimistic that we're facing a future here
Starting point is 00:17:38 where we might find ourselves in some kind of equilibrium? Yes. I see a lot of improvement in the way organizations are dealing with AI. Of course, everything is new. We're in all uncharted territory, but we're slowly but steadily charting this territory and sort of keeping up with the pace of innovation. Well, it's hard to tell what that is going to do for certain aspects, such as the workforce and skill development and how teams are going to look like. so a lot is unknown, but the direction of creating more clarity, more overview is, I think, very promising. Do you have any thoughts for the folks who are coming up in the industry, people who are at the beginning of their career journey, how they can face this kind of chaotic, volatile situation that we seem to find ourselves in these days? Yeah, it's super hard for people who, who, want to make career decisions where to go right now. It is almost like what the industry is doing right now, which is don't take any bets that are long term. So make sure that you remain agile
Starting point is 00:18:56 in how you can move as a company. And I think the same applies to professionals. Make decisions that allow you to maintain agile and be in a way T-shaped, be a generalist. A generalist. so that you can move around with how the world is evolving. Don't go too deep into certain topics, unless you're 100% sure that that is the thing that's going to be the future. That's Rob Vandervier, chief AI officer at Software Improvement Group. And finally, the FCC wants to give consumers a new way to judge whether their phone company is actually keeping robocalls at bay.
Starting point is 00:19:56 The agency is proposing a public scorecard measuring how effectively domestic voice providers combat illegal calls, using real-world outcomes rather than simply checking whether the proper paperwork has been filed. Potential metrics could include consumer complaints, enforcement actions, traceback data, and how often providers accidentally block legitimate calls, because stopping robocalls loses some of its charm when grandma can't get through either. Their proposal doesn't create new requirements, and the FCC is still seeking input on which providers and metrics to include. Meanwhile, the agency is applying some existing muscle. It removed 14 providers from its
Starting point is 00:20:42 robocall mitigation database for compliance failures, effectively cutting them off from U.S. telecom networks. For persistent robocallers, apparent Currently, the FCC is considering both report cards and detention. And that's the Cyberwire. Or links to all of today's stories, check out our daily briefing at thecyberwire.com. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app.
Starting point is 00:21:30 Please also fill out the survey and the show notes or send an email to your email to you. to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ivan.
Starting point is 00:21:49 Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.