CyberWire Daily - Worming its way through WeChat.

Episode Date: September 8, 2026

Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. ...MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted American technology through subsidiaries and overseas partners. An active phishing campaign abuses legitimate Google services to make malicious links appear trustworthy. Australians may soon be able to disable the algorithm. Monday business briefing. Jason Lancaster, Chief Investigations Officer at SpyCloud, discusses how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. Electromagnetic eavesdropping gets personal. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Jason Lancaster, Chief Investigations Officer at SpyCloud, discussing how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. Selected Reading A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts (The New York Times) Hackers build AI frameworks for widescale credential theft (Bleeping Computer) N-able Issues Emergency Hotfix for Maximum-Severity Unauthenticated RCE in N-central (Beyond Machines) MikroTik Patches Critical Flaws Chained to Hack Routers (SecurityWeek) How a Blacklisted Chinese Tech Giant Kept Buying America’s Best A.I. Chips (The New York Times) Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy (KnowBe4) ‘Global reckoning for big tech’: Australia to force social media platforms to allow users to opt out of algorithms (The Guardian) Socure raises $156 million and acquires agentic AI platform Fravity. (N2K Pro Business Briefing) New attack eavesdrops on headphone audio from 30 meters away (CyberInsider) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Yes, you can have an enterprise network that's secure and reliable and high performance. And no, you don't need to choose the best two out of three. With Meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage. That's because Meter is software-led for easy installation, maintenance, and control for everything running on your Enterprise network. Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design. You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching, firewalls, DNS security, and VPNs. You'll really know what's running on your network down to the most granular client level.
Starting point is 00:01:03 Step off the hardware box upgrade treadmill and switch to. to meter for a predictable fee and free up your team to spend time on all the other things that keep your business running. Try it out for yourself and book a demo online at meter.com slash cyberwire. That's METER.com slash cyberwire. Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. Enable issues an emergency patch for a maximum severity. security bug under active exploitation. Microtick patches multiple router OS vulnerabilities.
Starting point is 00:01:57 China accesses restricted American technology through subsidiaries and overseas partners. An active fishing campaign abuses legitimate Google services to make malicious links appear trustworthy. Australians may soon be able to disable the algorithm. We've got your Monday business briefing. Our guest is Jason Lancaster, chief investigations officer at SpyCloud, discussing how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. And electromagnetic eavesdropping gets personal.
Starting point is 00:02:42 It's Tuesday, September 8th, 2026. I'm Dave Bittner, and this is your Cyberwire Intel briefing. Thanks for joining us here today. It is great as always to have you with us. Researchers at Palo Alto Security Company Caliph say advanced AI models help them build a self-propagating attack against Wii chat in little more than a week. Dubbed Wii Worm, the proof of concept, exploited a zero-day vulnerability that could compromise an account when a call from an already compromised contact simply rang, no click required.
Starting point is 00:03:32 The Worm could then access messages, make calls, control the account, and automatically target saved contacts, potentially spreading exponentially across Wii chats more than 1.4 billion monthly users. Researchers said additional vulnerabilities could have turned account access into full-device compromise across both iOS and Android. Tencent confirmed the vulnerability and patched it after Caliph's disclosure, saying it had no evidence users were affected. Caliph emphasized that AI didn't create the attack autonomously, human researchers guided the process. Still, the demonstration suggests AI is dramatically accelerating the discovery and weaponization of software vulnerabilities. Google's threat intelligence group says threat actors are moving beyond simple AI coding assistance
Starting point is 00:04:29 toward multi-agent frameworks capable of automating multiple stages of cyber attacks. In one incident, a financially motivated attacker used AI agents to build and launch a mass credential harvesting campaign in under six hours. The agents scanned for vulnerabilities, collected thousands of credentials, troubleshot failures, rotated IP addresses, and used compromised cloud infrastructure to evade detection. Researchers also discovered an automated framework managing more than 23,000 stolen secrets. State-backed groups are experimenting with similar technology for exploitation, reconnaissance, monitoring, fishing, malware development, and other operations. Google cautions that fully autonomous hacking isn't yet widespread, and researchers haven't
Starting point is 00:05:21 observed autonomous pipelines discovering zero days and exploiting real-world networks. But increasing automation is shrinking defender's response windows by taking humans out of more of the attack loop. N. ABLE has issued an emergency patch for a maximum security remote code execution vulnerability in its N central management platform. The vulnerability carries a CVSS score of 10 and can be exploited without authentication. Multiple on-premises builds are vulnerable, while hosted instances have already been patched. New reporting indicates attackers are actively exploiting the flaw, creating unauthorized administrative. accounts and using N-Central's remote control capabilities to pivot into managed endpoints. Customers should install the hot fix immediately and restrict or disconnect exposed consoles until patched. Microtik has patched six router OS vulnerabilities, including two actively exploited flaws, dubbed
Starting point is 00:06:29 MicroTrick. CERT Poland says attackers are chaining and SSH authentication bypass, with a privileged manipulation vulnerability to take full control of devices exposed to the internet. Attacks have been observed since at least September 2nd with compromised routers sometimes containing an account named ops. More than 120,000 micro-tick devices recently had SSH publicly accessible. Users should update router OS immediately and block SSH access from untrusted sources. A New York Times investigation found that InSper, a Chinese technology giant blacklisted by Washington over its military ties,
Starting point is 00:07:15 has continued accessing advanced American technology through subsidiaries and overseas partners. After InSper was added to the U.S. entity list in 2003, its Silicon Valley subsidiary began operating as Ivres and continued exporting billions of dollars. in advanced equipment. From April 24 through February 2026, records show IVRIS shipped at least $5.6 billion in technology to Southeast Asia, including more than $3 billion in systems containing Nvidia's cutting-edge blackwell chips. Some equipment went to data centers serving major Chinese technology companies, while other servers apparently traveled through Malaysia before reaching China. The investigation suggests InSper's network has exploited gaps in export controls involving subsidiaries, company addresses, and remote access to overseas data centers.
Starting point is 00:08:14 Federal officials have reportedly examined Ivres, but the status of that inquiry is unclear. No Before Threat Lab says an active fishing campaign is abusing multiple legitimate Google services to make malicious links appear trustworthy to security tools and victims alike. Attackers route targets through Google properties including meet search, double-click, custom search, image search, tag manager, and analytics before reaching credential harvesting infrastructure. The final phishing page is personalized in real time, pulling the victim organization's logo, website imagery,
Starting point is 00:08:56 and email domain information to mimic a legitimate legitimate, login portal. The campaign also checks email domains and uses anti-analysis steps to filter out sandboxes and researchers. Victims are then sent down one of two paths, credential theft with stolen passwords infiltrated through telegram, or installation of screen connect for persistent remote access. Nobafor says the campaign's strength is that nearly every intermediate step looks legitimate, reducing the usefulness of simple domain-based blocking. Australia's government plans to require social media platforms to let users over 16 turn off algorithmic recommendations and instead see content only from accounts and groups they choose to follow.
Starting point is 00:09:48 The proposal called My Feed My Way would use a pop-up asking users to select their default feed, with fines exceeding $100 million Australian for noncompliance. Separate digital duty of care rules would require social media services, games, apps, and AI chatbots to protect minors from harms, including pornography, eating disorder content, misogyny, glorification of crime, bullying, and serious mental distress. Australia's e-safety commissioner would gain removal powers and require platforms. to document their safeguards. The legislation is expected before Christmas, but faces political debate over censorship, enforcement thresholds,
Starting point is 00:10:35 and whether opt-out mechanisms go far enough. Turning to our Monday business briefing, cybersecurity investment and deal-making remain active. Digital identity verification company SACURR raised $156 million at a $5.2 billion valuation and acquired fraud and compliance automation firm Fravity, whose technology will be integrated into SACUR's Risk OS platform. Israeli AI agent supply chain security startup, Air, emerged from stealth with $50 million,
Starting point is 00:11:13 while Vulnerability Remediation Company Data Agent launched with $10 million. Mobile fraud prevention startup Kazimi raised $2.6 million. Eight acquisitions and spin-on. were also announced. Hallo Alto Networks acquired Agentic Workflow Platform Console to expand automated security operations. With Secure spun off its Salesforce security business as an independent company. A-Line acquired security firm Pathfinder, while Echo purchased technology assets from the
Starting point is 00:11:47 shuttered secure container provider Minimus. Ampkis acquired security data platform SmarterD. Integrity 360 bought Identity Security Company CyberIAM, and E-plus acquired MSSP Daymark solutions to strengthen its Microsoft-focused services. Be sure to check out our weekly business briefing on our website. It is part of CyberWire Pro. Coming up after the break, my conversation with Jason Lancaster,
Starting point is 00:12:27 Chief Investigations Officer at SpyCloud. We're discussing how AI is affecting shifting, from traditional investigations to agentic AI at scale. And electromagnetic eavesdropping gets personal. Stick around. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for,
Starting point is 00:13:03 every vendor that turns on AI features, every new integration, each one is an opportunity for something to go wrong. And most security programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast-moving companies like Ramp, cursor, and Harvey to ensure they're always audit-ready.
Starting point is 00:13:28 And now Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools, and your whole environment. The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you, and cutting vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at vanta.com slash cyber. That's v-a-t-a-com slash cyber. Jason Lancaster is Chief Investigations Officer at SpyContin.
Starting point is 00:14:23 cloud. Our conversation centers on how AI is shifting cybercrime from traditional investigations to agentic AI at scale. We work with a lot of different data sources, data sets. You know, a lot of the investigative work has been link analysis and correlations across those disparate data sets to understand really the story that that data tells us as we're looking at actor attribution infrastructure that's being used in different cyber attacks. And AI has brought just a whole new real power to that work, extending our capabilities and allowing us to have further reach and to go deeper in that. Historically, we've had a lot of success on the margins where one data point connects to another one,
Starting point is 00:15:21 down a tree that has another point of correlation, a couple hops down that tells us, yes, that confirmation on that connection, that's our actor, that's infrastructure that they're using, that's an email account that belongs to that person, or this is a victim versus the actor, this is a synthetic identity versus a true identity, and leveraging AI's allows,
Starting point is 00:15:51 us to get to those outcomes much faster where an investigation may have taken a week previously and now an analyst can do that same investigation at, you know, in an hour or two. Do you have any examples of particular areas where you really see this type of acceleration? Yeah, there is, you know, the individual sort of investigation element to this where you've got some incident that's happened. From that, you've got an email address that was part of a BEC campaign or a fishing campaign, let's say, and being able to pull in domain intelligence information along with identity intelligence information. We had a case just recently looking at a government entity in another country that the finance department had been fished. And their
Starting point is 00:16:50 data was exposed in their email account to this actor. And being able to quickly understand the story that that data told us, that that actor was actually targeting just a broad array of organizations. This one person happened to get caught up in that. And it was a much broader campaign, not just a direct targeted event. And then we actually saw. that data goes sort of dormant for about two months before that actor identified a third of those victims actually had some access to financial information and put in keywords to monitor in their
Starting point is 00:17:34 email. And then within a 42-hour window, we saw them act on that once they had bank account numbers, vendor information, actual documents that were sent as invoices and payments so that they had everything that they needed to do to then implement BEC across all of these victims. And it was a case where it would have taken us, you know, probably a couple weeks to sift through all of that data and to get to that level of understanding. And we were able to do that with LLM's frontier models doing that same analysis that we would do at a much reduced scale across just really a day to understand all of that. And the nuance that was in that context, sort of between those data points,
Starting point is 00:18:22 is really what helped us understand what was going on in that incident. What were the motivations of the attackers? How are they operating? Who were they targeting? Well, you mentioned nuance, and that element really fascinates me because I think, well, when I think of people doing investigations,
Starting point is 00:18:41 in my mind, a big part of that is intuition. Do the LLMs have any? of that? Do they occasionally surprise you with the stuff they come back with? It's a really great question. You know, so yes, there is a bit of blend of art and science to some of of this, but at the end of the day, we still have to point to facts. Like, we know that this domain was used by this group in this campaign for this reason. And that may be that there was a favicon reused between this and another known domain linked to a different campaign by the same actor or a certificate that was reused. There's thousands of ways that we can connect those things together,
Starting point is 00:19:31 but we have to be able to point back to those facts. Now, the LLMs do a really great job of that sort of analysis, and particularly with just sort of a wealth of data that we have at our fingertips. The intuition is interesting, though, because being able to take that story, the pattern of life, often can characterize that in a way that's summarized. Then when we go back as the analyst and pull that apart, we can reproduce that same assessment. And that's really a key element to this, is that we're not just offloading this work to AI to do, but we're using it to augment the analyst and really determined that we can validate those findings versus, you know, it's something that was, that we couldn't validate from that. But I've had some
Starting point is 00:20:24 instances that were quite shocking. I had one case where credentials exposed by an actor clustered into an identity cluster that we were looking at and trying to understand the points of correlation between different clusters. some that indicated victims, other were associates of the primary actor. And this was actually a DPRK case where the pattern of the passwords that were being used by this DPRK actor followed some variations across those. One, we actually kind of discounted because it seemed to be gibberish and then the tail end was the same pattern as the others. and the LLM was able to deconstruct that and understand that it was actually the same password as the others
Starting point is 00:21:17 just that if you were a native Korean speaker typing on an English language keyboard, but in Korean, then these two letters actually would make phonetically the sound of the first letter in that other password. And the second two letters phonetically made the sound of the second letter in that other password all the way through. and we completely missed that.
Starting point is 00:21:42 So I'm routinely surprised by those kind of things that we can go and validate, but I don't know that if I had a Korea desk to send that to for analysis, we would have ever even found that. No, I can imagine it kind of makes you rock back in your chair and take stock for a moment when you get something back like that. I'm curious, what does this mean for you and your colleagues at SpyCloud on the investigations team in terms of how you are prioritizing your time and making use of these new enhanced capabilities? So for the longest time, we have tried to work to capture our investigative methodologies and that trade craft in code and have that be something that is repeatable and scalable.
Starting point is 00:22:33 And so we're doing the same thing now. just with prompts instead of in code. And so what that's led to is an investigative skill that runs into end, you feed it what you know, and it'll turn on that for a few minutes and give you kind of a full identity report on that. And so that allows the investigators to then spend their time where they're able to provide the most value in validating those results in using, using that intuition over decades of experience, doing investigations. And then the other sort of angle to that is broadening out the lens of the scope of the work that we're doing. I recently did a research project on U.S. water and wastewater treatment providers following some of the attacks that we've seen in the news lately.
Starting point is 00:23:29 and leveraged an agent to go and enumerate over 66,000 different organizations across the U.S. that fall into that category. I did a full study on the top 10,000 of those to understand sort of the systemic vulnerabilities that exist, particularly to identities of those organizations. And that's something that would have taken us as a whole team, maybe six months to do. previously and I did this over a weekend. Wow. So for the folks in our audience who are out there investing in the kinds of services that you and your colleagues at SpyCloud provide, and obviously there are other providers in the
Starting point is 00:24:12 space as well, how should they calibrate their expectations of the types of things that you and your colleagues are able to deliver these days? So one of the things that has been interesting is we've gone down this, journey is we historically spent a lot of effort not only developing that that methodology and tradecraft and capturing that but in developing training around that because it was often a bit of a lift to get an analyst sort of fully capable in this discipline if they're doing sort of similar things in other areas that's helpful but now with LLMs integrated into products It allows user experience to be completely different onboarding because they can ask just simple questions and get the rich responses that include all of that context.
Starting point is 00:25:11 And training becomes sort of a journey that can happen assisted by the AI as a user maybe doesn't understand a data point or has a question about how something was derived. You can simply just ask that. And I find this across a lot of different MCPs that I'm using today from different providers and with different data sets where maybe I'm new to that data. And I don't fully understand it or I don't understand sort of the ontology that a particular data provider is using. I can simply just ask in my agent that has access to that MCP,
Starting point is 00:25:50 tell me all the tools that you have available. Tell me all the data sources that you have. available, explain these to me. How do these relate in this interactive dialogue? That's Jason Lancaster from SpyCloud. And finally, researchers in Hong Kong have demonstrated inject Eve, an electromagnetic eavesdropping technique that can recover audio from ordinary headphones from as far as 30 meters away. Rather than simply listening for electromagnetic leakage, Inject Eve sends a carefully chosen radio signal at a device where electronic components unintentionally mix it with internal signals and rebroadcast useful information. In tests,
Starting point is 00:26:55 researchers recovered intelligible headphone audio, including through a 30-centimeter concrete wall. They also extracted information from smart fans and lamps that could reveal household routines and demonstrated both eavesdropping and audio manipulation on a landline phone. The good news is that this isn't exactly casual neighborhood snooping. An attacker needs specialized radio equipment, suitable frequencies, and ideally an identical device for profiling. Still, the research shows that walls, and apparently headphones, aren't always as private as their users might reasonably assume.
Starting point is 00:27:36 And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. Don't forget to check out the Grumpy Old Geeks podcast where I contribute to a regular segment on Jason and Brian's show every week. You can find Grumpy Old Geeks where all the fine podcasts are listed.
Starting point is 00:28:07 We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights and keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at N2K.com.
Starting point is 00:28:27 N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our contributing host is Maria Vermazas. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here.
Starting point is 00:28:44 Tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.