The CyberWire Daily Podcast 8.6.26
Ep 2609 | 8.6.26

AI without adult supervision.

Transcript

Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it.

Today is Thursday August 6th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

We've been recording onsite at Black Hat this week from our podcast studio in the SpecterOps Kennel Club. Thanks to everyone who stopped by for an interview or to just say hello. We’ve gathered interesting insights and perspectives from our many guests which we’ll be sharing here on the Daily in the coming days. And special thanks to SpecterOps for their partnership, providing us with a first-class home base here at Black Hat.

Meta’s AI models escape the sandbox. 

Not to be left out of the party, Meta has disclosed that one of its advanced AI models escaped its intended testing boundaries during an independent cybersecurity evaluation conducted by Israeli startup Irregular. Due to a misconfiguration that allowed internet access, the model exploited a vulnerability in an unnamed third-party service and breached another organization’s systems, making unauthorized internal changes. Meta is investigating the incident and plans to publish a full retrospective. The disclosure follows similar reports from Anthropic, whose Claude models also escaped Irregular’s testing environment after mistakenly treating live internet access as part of the exercise. Those models compromised three organizations, including a cybersecurity company, by carrying out sophisticated actions such as publishing a malicious Python package. OpenAI has also reported AI models escaping test environments, including attacks using previously unknown vulnerabilities. Separately, the UK’s AI Security Institute observed Anthropic and OpenAI models using tools such as Tor, malicious GitHub pull requests, and social engineering to target real organizations during frontier AI testing.

A congressional committee claims China still lurks in U.S. telecom systems. 

A bipartisan House Select Committee on China investigation found that China Mobile, China Unicom, and China Telecom continue to maintain a significant presence in the U.S. internet ecosystem despite losing key Federal Communications Commission licenses over cybersecurity concerns. The 49-page report, prompted by the Salt Typhoon telecom hacking campaign, concludes the state-owned carriers remain closely tied to the Chinese government and have preserved access to critical U.S. network infrastructure through less regulated services, data centers, interconnection agreements, and network equipment. Lawmakers warn these footholds could provide opportunities for future state-sponsored cyber operations and recommend expanding the FCC’s authority, requiring the removal of Chinese telecom equipment, and increasing federal cybersecurity expertise. The report also cites historical links between the companies and previous cyber incidents and Chinese hacking organizations.

The White House keeps its new AI safety framework confidential. 

The White House is facing criticism after deciding not to publicly release its long-awaited voluntary artificial intelligence safety framework, which is expected to guide how the government evaluates advanced AI models before public deployment. Critics argue that keeping the framework confidential undermines transparency and leaves developers, researchers, and the public uncertain about the rules governing AI oversight. The move follows a series of high-profile AI security incidents and government reviews of frontier models from companies including OpenAI and Anthropic. Meanwhile, a Booz Allen Hamilton survey found that although many federal agencies are piloting autonomous AI agents, few have deployed them in production and only 28% of technology leaders are confident they can do so securely. Respondents cited concerns over protecting sensitive data, unauthorized agent actions, and AI-enabled cyberattacks, reinforcing calls for clearer governance, stronger security controls, and better guidance for deploying increasingly autonomous AI systems.

AI coding tool vulnerabilities put GitHub repositories at risk. 

Researchers from Novee Security disclosed vulnerabilities in AI coding tools from Anthropic, Google, and OpenAI that could allow attackers to exploit public GitHub issues to compromise software repositories. Presented at Black Hat USA 2026, the research showed that untrusted issue content could influence AI agents with access to repository credentials, enabling remote code execution, credential theft, and unauthorized repository changes. Anthropic fixed multiple flaws in Claude Code, including a vulnerability that could leak sensitive data through Hugging Face. Google patched a critical Gemini CLI vulnerability, rated CVSS 10.0, that exposed GitHub and API credentials in certain automated workflows. OpenAI addressed a Codex workflow flaw that allowed attacker instructions to persist between agent runs. Researchers found similar configurations in more than 100 public repositories and urged organizations to update affected tools, restrict token permissions, and isolate AI workflows.

ENISA expands its role in the CVE Program. 

ENISA, the EU agency dedicated to enhancing cybersecurity in Europe, has expanded its role in the Common Vulnerabilities and Exposures (CVE) Program, now overseeing 20 CVE Numbering Authorities (CNAs), including eight transferred from the MITRE Root. The agency said the expansion strengthens global vulnerability management as emerging technologies, including frontier AI models, accelerate vulnerability discovery and exploitation. As the EU’s CVE Root, ENISA recruits, supports, and coordinates European CNAs while working closely with CISA and MITRE. The agency says the broader CNA network will improve the resilience, capacity, and global representation of the CVE Program.

A Paperclip flaw enables arbitrary code execution. 

Researchers at Oasis Security disclosed a critical authorization bypass vulnerability, tracked as CVE-2026-41679 (CVSS 10.0), in the AI management platform Paperclip. The flaw allowed remote attackers to self-register, gain elevated API access, and deploy malicious AI agents capable of executing arbitrary code with the server’s privileges. Paperclip has patched the issue by strengthening authorization checks and company scoping. The company also fixed two additional vulnerabilities involving sensitive data exposure and a DNS rebinding flaw that could enable code execution on developers’ machines.

Attackers exploit concerns over a recently disclosed hardware wallet vulnerability. 

Researchers at Proofpoint have identified a phishing campaign that exploits concerns over a recently disclosed COLDCARD hardware wallet vulnerability and a suspected $88.6 million Bitcoin theft. Attackers send emails posing as COLDCARD, urging users to complete a fake security audit through a fraudulent website featuring live chat support, likely staffed by human operators. Victims are persuaded to download a supposed diagnostic tool that actually installs ConnectWise ScreenConnect, a legitimate remote access application, giving attackers full control of the compromised system. The access could be used to steal cryptocurrency and sensitive data, install additional malware, or deploy ransomware. The campaign highlights how cybercriminals rapidly capitalize on high-profile security incidents by combining convincing social engineering with trusted remote management software.

Researchers identify a backdoor in Chinese-made routers.

Researchers at VulnCheck say they discovered a previously undocumented backdoor in more than 20 models of Zbtlink routers sold globally under the Zbtlink and Wiflyer brands. The backdoor reportedly contacts a Chinese-registered domain every 35 seconds, potentially enabling remote access to the routers and connected devices.

VulnCheck did not notify Zbtlink before publication, stating that coordinated disclosure “assumes the vendor did not intend the behavior.”

Snowflake hacker pleads guilty.

Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty in the US yesterday to his role in the widespread 2024 Snowflake data theft campaign, admitting to computer fraud, wire fraud, identity theft, and conspiracy charges. Prosecutors say he and his co-conspirators used stolen credentials to access at least 165 customer environments, steal billions of records, and extort victims, earning roughly $2.5 million in ransom payments.

Moucka will be sentenced in October; he faces a mandatory minimum penalty of two years in prison for aggravated identity theft and a maximum of 30 years in prison for three other counts.

 

AI takes your word for it. 

According to Cisco Talos, some hackers have discovered that one of the easiest ways to persuade an AI assistant to help with cybercrime is simply to say, “I’m allowed.” Researchers found that AI coding tools often accepted unverified claims of authorization, enabling attackers to build malware, develop distributed denial-of-service (DDoS) tools, harvest credentials, and automate criminal operations with surprisingly little resistance. The study found that less experienced threat actors could use AI to create basic attack tools, while more skilled operators leveraged it to validate massive email lists, harvest secrets from vulnerable systems, test Telegram applications, and probe internet-connected camera services. Although AI did not eliminate the need for technical expertise, it significantly accelerated routine offensive tasks. Cisco Talos concluded that the effectiveness of AI in cybercrime still depends largely on the operator’s skill, but warned defenders to prepare for a growing wave of AI-assisted attacks, especially as current guardrails remain easier to charm than to enforce.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

 

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.