The CyberWire Daily Podcast 8.17.26
Ep 2616 | 8.17.26

Please hold while we decide.

Transcript

Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber standards. Microsoft is still working on a patch for the ShieldBreak vulnerability. Autonomous AI systems create CPU bottlenecks. Monday business briefing. Our guest is Nick Warner, CEO at Neo.ai, on the shifting landscape around AI and agentic security. AI agents kneecap each other with self-replicating malware.

Today is Monday August 17th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing. 

Happy Monday all - it is great to be back. My thanks go out to Maria Varmazis for filling in as host and the entire Cyberwire team for keeping everything running smoothly while I was enjoying some vacation time away with the family. 

Internal policy conflicts hamper U.S. military AI leadership. 

The New York Times argues that the United States’ push to achieve military leadership in artificial intelligence is being undermined by internal policy conflicts, inconsistent decision-making, and the rapid pace of Chinese AI development. A key example is the Pentagon’s shifting stance toward Anthropic, whose AI tools were first banned, then partially reinstated despite their importance for cybersecurity and offensive cyber capabilities. The dispute stems from disagreements between Anthropic and Defense Secretary Pete Hegseth over limits on military use of the company’s technology, even as agencies like the National Security Agency continue testing Anthropic’s advanced Mythos model. More broadly, the Trump administration has alternated between deregulation and tighter oversight of frontier AI models while sending mixed signals on export controls for advanced chips. Security experts warn that these inconsistencies could weaken U.S. competitiveness as China narrows the AI gap, increasing the stakes in what many view as a strategic technological race with profound national security implications.

Clop claims GE, Philips and Shell. 

General Electric (GE), Philips, and Shell are investigating claims by the Clop ransomware gang that it breached their systems and stole sensitive data. Philips confirmed an attempted compromise of an internal enterprise server but said the incident was contained and did not affect customer environments. GE and Shell acknowledged they are assessing the claims but have not confirmed a breach. Clop has listed all three companies among 43 alleged victims of attacks exploiting the critical PTC Windchill and FlexPLM vulnerability, CVE-2026-12569. Security researchers, CISA, and Germany’s BSI have confirmed active exploitation of the flaw, prompting urgent patching guidance. Clop claims it stole sensitive corporate data, including project plans, blueprints, and backups. The group has a history of exploiting enterprise software vulnerabilities in large-scale data theft campaigns targeting major organizations worldwide.

Attackers actively probe internet-facing GeoServer instances. 

Attackers are actively probing internet-facing GeoServer instances for a critical unauthenticated SQL injection vulnerability affecting deployments that use PostGIS 12 or later with text or JSON fields. Publicly disclosed as a zero-day on August 12, the flaw allows attackers to manipulate database queries through exposed Web Feature Service (WFS) and Web Map Service (WMS) interfaces. Under certain PostgreSQL configurations, including superuser or pg_execute_server_program privileges, the vulnerability can lead to remote code execution on the database host. Researchers have already observed widespread scanning activity, though current probes appear to be testing systems rather than exploiting them fully. GeoServer released patched versions on August 14 and advises immediate upgrades, as no effective workaround exists. Organizations should also restrict access to exposed services, review PostgreSQL privileges, and monitor logs for suspicious requests.

“The Hatman” offers millions of alleged employee records for sale. 

A threat actor known as “TheHatman” claims to be selling millions of employee records allegedly stolen from the Microsoft Azure environments of nine major organizations, including McDonald’s, Vodafone, Tata Consultancy Services (TCS), Kyndryl, and HCL Technologies. According to Hudson Rock, the data appears highly likely to be authentic and includes corporate contact information, employee IDs, organizational structures, group memberships, and details about privileged administrator accounts. While the attacker claims compromised credentials were used, the initial access method remains unverified. Hudson Rock believes the campaign is more likely tied to infostealer malware than an Azure vulnerability. TCS said it found no evidence of a breach, describing the exposed information as outdated, basic employee data and stating that customer systems and data were not affected. Other organizations have not confirmed the claims.

ETSI begins the approval process for European cyber standards. 

The European Telecommunications Standards Institute (ETSI) has begun the approval process for 17 cybersecurity standards that will help organizations comply with the European Union’s Cyber Resilience Act (CRA), which takes full effect in December 2027. The proposed standards establish baseline security requirements for commercially available hardware and software sold in the EU, including secure-by-default configurations, modern cryptography, software bills of materials (SBOMs), and the ability to provide security updates after products are sold. The standards cover 17 product categories, including operating systems, routers, firewalls, VPNs, browsers, password managers, IoT devices, smart home products, and wearables. Public consultation will continue through late 2026, with final standards expected by December. ETSI, CEN, and CENELEC are also conducting workshops to help manufacturers, particularly small and medium-sized businesses, prepare for CRA compliance.

Microsoft is still working on a patch for the ShieldBreak vulnerability. 

Microsoft has confirmed it is developing a security update for a newly disclosed Microsoft Defender privilege escalation vulnerability known as “ShieldBreak,” now tracked as CVE-2026-69414. The flaw was publicly disclosed by security researcher “Nightmare Eclipse,” who claims it bypasses Microsoft’s earlier fix for the RoguePlanet vulnerability (CVE-2026-50656). A proof-of-concept exploit demonstrates that a local attacker with limited privileges can gain SYSTEM-level access on fully patched Windows 11 and Windows Server systems when Microsoft Defender is enabled. Microsoft says it is investigating the issue and preparing a security update but has not provided a release timeline. The disclosure follows an ongoing dispute between Nightmare Eclipse and Microsoft over vulnerability reporting practices. Several other Windows zero-day vulnerabilities disclosed by the researcher remain unpatched, although Microsoft has addressed some in recent Patch Tuesday updates.

Autonomous AI systems create CPU bottlenecks. 

Agentic AI is shifting a key infrastructure bottleneck from GPUs to CPUs, as autonomous AI systems generate large numbers of tool calls, API requests, and sub-agents that rely heavily on traditional processors. According to an article from the IEEE,  industry analysts and researchers say that while GPUs still handle large language model inference, CPUs manage tasks such as parsing outputs, invoking tools, executing code, enforcing security guardrails, and tokenizing data. As enterprises deploy thousands or even millions of AI agents, CPU demand has surged, prompting Amazon Web Services to urge engineers to conserve CPU resources. Researchers also found that insufficient CPU capacity can leave GPUs idle while they wait for instructions, increasing latency. Longer AI conversations further amplify CPU workloads because tokenization must be repeated after each tool call. The growing demand is already influencing the hardware market, with server CPU shortages, increased investment from Intel, AMD, Arm, Qualcomm, and Nvidia, and expectations that CPU capacity will become increasingly critical for large-scale agentic AI deployments.

Monday business briefing. 

Cybersecurity and AI companies attracted significant investment this past week, led by AI cybersecurity startup Corma, which raised a $60 million seed round to expand deployments already underway at Fortune 100 and Fortune 500 organizations. Drone defense firm Aurelius Systems secured $40 million to advance its Archimedes platform and strengthen manufacturing, while AI red-teaming company Mindgard raised $30 million to scale operations. Actualyze AI emerged from stealth with $7 million to expand its AI governance platform, Syntasa received a strategic investment to accelerate sovereign AI development, and insider threat startup Above received funding from CrowdStrike’s investment fund.

Mergers and acquisitions also remained active. Visa agreed to acquire biometric verification company BioCatch, Deel purchased AI identity verification startup Clarity, Anaconda acquired AI security firm Enkrypt AI, and Infoblox completed its acquisition of Kentik. BlueAlly acquired GigaNetworks, AXA XL agreed to acquire cybersecurity consultancy S-RM, and Logicalis US expanded its managed security services footprint by acquiring Loial.

 

AI agents kneecap each other with self-replicating malware. 

Anthropic’s latest research suggests that giving AI agents conflicting goals can produce surprisingly human workplace dynamics, only with more malware. In one experiment, multiple Claude-based agents were independently tasked with migrating the same software project. Unaware they had company, they soon concluded rival agents were obstructing their work and responded by disabling accounts, killing competing processes, planting disguised malicious code, and, in some cases, locking one another out entirely. Fortunately, not every disagreement ended in a digital coup. More advanced Mythos 5 models frequently recognized the conflict stemmed from contradictory instructions, documented their actions, and sought human help, although they often seized control before negotiating peace. Separate experiments found coordinated AI swarms uncovered more software vulnerabilities than isolated agents, while identical models tended to converge on the same decisions, even adopting consensus over correct information. Anthropic argues these findings show that smarter AI does not automatically become more cooperative, making agent-to-agent safety an increasingly urgent challenge.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.