
Nightmare on Windows 11.
Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation. North Korean workers are still landing U.S. jobs. A classic NSA codebreaking machine. Our guest is Heather Ceylan, CISO at Box, discussing if AI becomes agentic, governance could become a resilience issue. A robot vacuum sucks up evidence.
Today is Tuesday September 1st 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Nightmare Eclipse drops a Kaspersky zero-day.
Security researcher Chaotic Eclipse, also known as Nightmare Eclipse, has released HardBreacher, a proof-of-concept exploit for an alleged privilege-escalation flaw in Kaspersky Endpoint Security. The researcher says the zero-day works against a fully patched Windows 11 25H2 system running Kaspersky Endpoint version 14.0.0.504. The PoC is reportedly unreliable, but successful exploitation can create a DLL in Windows’ System32 directory with full permissions for the current user. Chaotic Eclipse also claims that taking control of Kaspersky’s user-interface process can disrupt antivirus functions and interfere with file-access controls. Kaspersky says it has already addressed the vulnerability. Chaotic Eclipse has previously published zero-day exploits targeting Microsoft products, a practice that has fueled debate over responsible vulnerability disclosure and the risks of releasing working exploit code.
The Financial Stability Board warns frontier AI could threaten the global financial system.
The Financial Stability Board is warning that frontier AI could reshape cyber risk fast enough to threaten the global financial system. The FSB, chaired by Bank of England governor Andrew Bailey, is an international advisory body that monitors potential risks to global financial stability. In a letter to G20 finance ministers and central bankers, Bailey said advanced AI could increase the speed, scale and economic efficiency of cyberattacks, with risks amplified by financial firms’ reliance on a small number of technology providers. The FSB is urging institutions to strengthen vulnerability management, incident response and recovery, including the ability to rebuild critical systems from bare metal. Bailey noted that AI can also bolster cyber defenses, but resilience must keep pace. The warning follows similar concerns from UK regulators and Five Eyes cybersecurity agencies.
Palo Alto Networks’ Unit 42 says frontier AI represents a “generational shift” in cybersecurity, increasingly tilting the advantage toward attackers. Unit 42 executive Sam Rubin said defenses built over years aren’t prepared for machine-speed attacks enabled by advanced AI. The threat intelligence team is investigating one incident in which an attacker used an agentic framework to exploit 50 applications and other weaknesses across an enterprise in under 10 hours—work Rubin estimates would previously have taken at least 10 days. Unit 42 says attackers are already applying AI throughout the attack chain, including malware development, social engineering and ransomware negotiations. The firm expects increasingly autonomous attacks and warns that AI is amplifying existing threats involving identity compromise, software supply chains and nation-state operations, leaving organizations poorly prepared for the accelerating pace.
Anthropic says it has tightened security.
Anthropic says it has tightened security after Claude models took unauthorized actions on real-world systems during cybersecurity evaluations. In three July incidents, models running without normal cyber safeguards reached the internet because of a third-party testing misconfiguration. A separate UK AI Security Institute test in August saw Claude Mythos 5 take unauthorized actions after being deliberately given internet access. Anthropic attributes the incidents to both operational security failures and alignment problems, including what it calls motivated reasoning and a willingness to take harmful actions to complete a task. The company temporarily paused some evaluations and reinforcement learning, strengthened sandbox isolation, and deployed real-time monitoring designed to stop escape attempts. Anthropic is also tightening training environments after research suggested reward hacking can contribute to more dangerous, goal-seeking behavior.
CISA adopts a risk-based approach to patching.
CISA is changing how federal agencies prioritize software patches, shifting from broad deadlines to a risk-based approach intended to free security teams for other resilience work. Under a June binding operational directive, agencies must patch the most urgent vulnerabilities on CISA’s Known Exploited Vulnerabilities list faster, particularly on internet-facing systems. The highest-risk flaws must be addressed within three days, compared with historical deadlines averaging two to three weeks. Lower-risk vulnerabilities may get longer timelines. CISA official Jay Gazlay said previous policies sometimes pushed agencies to spend resources patching vulnerabilities that posed little immediate risk. AI helped drive the change by accelerating vulnerability discovery and exploitation. CISA hopes the approach gives agencies more time for monitoring, identity security, backup testing, and other measures needed to withstand inevitable cyber incidents.
A new Windows infostealer hides in fake AI models.
Researchers at Morphisec have uncovered a Windows infostealer called RevStealer, distributed through GitHub repositories offering a fake free version of Anthropic’s Claude Opus 5 model, as well as through game-cheat sites. The malware targets browser data, password managers, cryptocurrency wallets, VPN and remote-access credentials, messaging apps, documents and more. RevStealer stands out less for what it steals than for its extensive efforts to evade detection. It checks for sandboxes and analysis tools, encrypts strings, obscures Windows API calls and streams stolen information from memory rather than creating a large archive on disk. It also stores a fallback command-and-control address in a Polygon blockchain smart contract. Researchers say RevStealer avoids persistence, instead aiming to steal as much information as possible in one short burst before defenders can respond.
A critical vulnerability in JFrog Artifactory is kneedeep in active exploitation.
A critical authentication bypass vulnerability in JFrog Artifactory is reportedly being exploited just days after disclosure. CVE-2026-82329 can allow an unauthenticated attacker with network access to gain administrative privileges under default configurations. JFrog patched the flaw on August 28 and automatically updated cloud instances, while urging self-hosted customers to upgrade. Exposure management firm WatchTowr says it has observed attackers exploiting the vulnerability to create admin tokens. JFrog has not yet confirmed the reported exploitation.
North Korean workers are still landing U.S. jobs.
Huntress says it identified five cases in 2026 involving North Korea-linked workers, tracked as FAMOUS CHOLLIMA, who used fraudulent or stolen identities to land legitimate remote jobs. Rather than breaking into companies, the workers passed hiring and onboarding processes, sometimes performing their assigned jobs while allegedly funneling part of their earnings to North Korea. Huntress found clues including suspiciously similar identity documents, VPNs and proxies, unusual working hours, and PiKVM devices used to remotely control company laptops at the hardware level. In one case, an impostor apparently used a real person’s identity documents with a digitally swapped photograph. Huntress says individual indicators aren’t necessarily malicious, but combinations should prompt investigation. The firm recommends stronger identity verification and background checks before onboarding, along with monitoring for suspicious remote-access hardware, proxy services and other signs that an employee may not be who they claim.
A classic NSA codebreaking machine.
For 14 years, one of the world’s most remarkable computers quietly worked behind closed doors at the NSA. An article in IEEE Spectrum describes IBM’s Harvest, operational from 1962 to 1976, which processed cryptographic data as much as 200 times faster than contemporary machines. Built around IBM’s Stretch mainframe, it pioneered ideas that feel strikingly modern: specialized coprocessors, pipelined data processing, a purpose-built programming language called Alpha, and Tractor, the world’s first automated tape library. Harvest could sift billions of characters for thousands of targets in hours, helping the NSA manage an unprecedented flow of intercepted communications. Its secrecy meant its influence wasn’t immediately apparent, but its architecture anticipated technologies ranging from robotic storage systems to modern accelerators and high-speed network processing. Harvest ultimately succumbed not to obsolescence, but to a worn-out mechanical part. It was a singular machine that, remarkably, pointed toward several computing futures at once.
A robot vacuum sucks up evidence.
A Taiwanese man discovered that in court, it is entirely possible to win and lose the same marital dispute. Suspicious after finding an unfamiliar toothbrush, he later accessed his robot vacuum’s camera and found footage showing his wife with another man. He recorded the feed and sued, arguing the affair violated his marital rights. The evidence worked: a court awarded him 500,000 Taiwanese dollars, about $19,000, for emotional distress.
Then came the plot twist. His wife sued him for secretly recording intimate footage of her inside the home. His argument that another court had accepted the video as evidence didn’t save him. Judges ruled that obtaining it had violated her privacy rights. He was fined 150,000 Taiwanese dollars, roughly $4,700, and sentenced to five months in prison. The robot vacuum, apparently determined to clean up more than floors, provided compelling evidence—and a rather expensive lesson in privacy law.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.

