The CyberWire Daily Podcast 9.3.26
Ep 2629 | 9.3.26

Who’s watching the AI watchers?

Transcript

 

A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S. and Canada. Spring Ring impersonates IT support on Microsoft Teams. Plex urges users to patch, and Cisco warns of unpatched Secure Email flaws. Our guest is Rob van der Veer, Chief AI Officer at Software Improvement Group, discussing how we are not keeping up with the AI attack surface. Robocall report cards. 

Today is Thursday September 3rd 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

A nonprofit watchdog challenges the Trump administration’s secret process for reviewing frontier AI models. 

A nonprofit watchdog is suing four federal agencies for details about the Trump administration’s largely secret process for reviewing frontier AI models before release. Protect Democracy says the government has disclosed little about how models are evaluated, which companies participate, or what authority officials are using.

The group is seeking unclassified records covering the framework, participation terms, review criteria, and the government’s GOLD EAGLE cybersecurity program. It argues that secrecy makes it difficult to determine whether reviews are effective, politically influenced, or even applied consistently.

The dispute comes as Congress considers renewing liability protections under the Cybersecurity Information Sharing Act, which the administration says are important to GOLD EAGLE. Protect Democracy argues lawmakers can’t properly evaluate those protections without knowing how the program operates.

The lawsuit seeks release of the records by September 30 and an injunction preventing agencies from improperly withholding unclassified information.

METR discloses two attacks from earlier this year. 

AI model testing nonprofit METR has disclosed two attacks from earlier this year, though it found no evidence that sensitive information was accessed.

In March, attackers exploited a fail-open authentication bug in a researcher’s publicly accessible app. They persuaded an AI agent to reveal an API key, established persistent access, and spent three weeks consuming roughly $600,000 worth of credits for public models. METR didn’t immediately notice because heavy API usage was routine and the credits had been provided for free.

Then in May, attackers launched a sustained campaign probing METR’s infrastructure using automated vulnerability discovery, credential stuffing, OAuth attempts, scanning, and phishing. Separately, a bug exposed some unpublished evaluation and sensitive model data through a public-facing service. An independent researcher discovered the flaw, and METR says there’s no evidence attackers exploited it.

Leaked documents provide a rare look inside Russian cyber training. 

More than 2,000 leaked documents reportedly reveal a hidden program at Bauman Moscow State Technical University that trained students for Russian military intelligence and cyber operations. Department No. 4, or “Special Training,” operated within the university’s Military Training Center, preparing roughly 250 students in espionage, offensive and defensive cyber operations, electronic reconnaissance, malware analysis, secure systems, and influence operations.

The records also connect the program to senior GRU officers and military units associated with prominent Russian threat groups. Former Unit 26165 commander Viktor Netyksho, whose unit is linked to APT28, reportedly helped oversee students. Graduates were also assigned to Unit 74455, associated with Sandworm, and Unit 29155.

The documents don’t establish that individual graduates participated in specific cyberattacks. Instead, they offer a rare look at the institutional pipeline used to recruit, train, assess, and place personnel supporting Russia’s broader cyber, intelligence, and influence operations.

Rogue ScreenConnect installations spread malware with worm-like behavior. 

Huntress has uncovered a campaign using social engineering and rogue ScreenConnect installations to spread malware with worm-like behavior. Across several organizations, attackers persuaded victims to install remote-access software, then used ScreenConnect to launch a four-stage VBScript chain.

The scripts profile infected systems, checking for security tools, memory, and existing ScreenConnect installations before selecting additional payloads. Depending on the system, those payloads can establish persistence, escalate privileges, weaken Microsoft Defender protections, install cryptocurrency mining and tunneling tools, or deploy a concealed ScreenConnect backdoor.

The most notable feature is a modified ScreenConnect client that detects new remote sessions and automatically pushes the malicious scripts to connected systems, allowing the infection to propagate.

Huntress recommends rebuilding affected machines from known-good media and closely reviewing ScreenConnect audit logs for suspicious script execution.

A breach exposes records from appellate courts across at least a dozen U.S. and Canadian jurisdictions.

 Thomson Reuters says an unauthorized party accessed files belonging to C-Track, its court case-management platform, exposing records from appellate courts across at least a dozen U.S. jurisdictions and Ontario, Canada.

The files were taken in March, but Thomson Reuters didn’t detect the activity in its cloud environment until June 30. Public disclosures followed September 2. Potentially exposed information includes names, Social Security and driver’s license numbers, medical and insurance information, birth dates, and possibly confidential or sealed court documents.

Thomson Reuters says C-Track remained operational throughout the incident and that it has brought in outside cybersecurity experts and notified law enforcement. The company is offering affected individuals credit monitoring and identity-theft protection.

The number of people affected, the intrusion method, and the attacker’s identity haven’t been disclosed.

Spring Ring uses Microsoft Teams to impersonate corporate IT support.

Palo Alto Networks’ Unit 42 has uncovered a voice-phishing campaign dubbed Spring Ring that used Microsoft Teams to impersonate corporate IT support. Between January and April, attackers targeted more than 150 employees at over 10 organizations worldwide.

Using external Teams accounts with names such as “help desk,” the attackers called employees and persuaded them to launch legitimate remote-support tools such as Quick Assist or install other software. Once connected, they surveyed privileges and deployed malware, including a remote-access Trojan. In another attack chain, they sideloaded a malicious browser extension, scanned internal systems, and attempted an NTLM relay attack to gain domain-level privileges.

Unit 42 emphasizes that Spring Ring didn’t exploit a Teams vulnerability. Instead, attackers exploited employees’ trust in familiar collaboration tools and seemingly legitimate IT support requests.

Plex urges prompt patching. 

Plex is urging users to update its Media Server and Desktop software to address multiple security vulnerabilities. The flaws affect Plex Media Server version 1.43.2 and earlier, though technical details and CVE identifiers haven’t yet been released. Plex recommends upgrading servers to version 1.43.3 and Desktop clients to 1.115.0. NAS users may need to install the server update manually if it’s unavailable through their package manager. Plex also emailed affected users urging them to patch promptly.

Cisco warns of unpatched vulnerabilities in its Secure Email product. 

Cisco is warning about two publicly disclosed, unpatched vulnerabilities in its Secure Email product. CVE-2026-20354 and CVE-2026-20355 affect S/MIME decryption in AsyncOS 16.5.0 and earlier. Cisco says an attacker positioned between email gateways could modify traffic and potentially recover plaintext from encrypted communications. The company isn’t aware of active exploitation.

Cisco also released patches for several more serious vulnerabilities, including critical flaws in IOS XR and Nexus 9000 switches that could enable remote code execution, authentication bypass, and other attacks. One Nexus vulnerability could allow unauthenticated attackers to execute code with root privileges. Cisco also patched a high-severity denial-of-service vulnerability affecting several of its phone product lines.

 

Robocall report cards. 

The FCC wants to give consumers a new way to judge whether their phone company is actually keeping robocalls at bay. The agency is proposing a public scorecard measuring how effectively domestic voice providers combat illegal calls, using real-world outcomes rather than simply checking whether the proper paperwork has been filed.

Potential metrics could include consumer complaints, enforcement actions, traceback data, and how often providers accidentally block legitimate calls — because stopping robocalls loses some of its charm when Grandma can’t get through either.

The proposal doesn’t create new requirements, and the FCC is still seeking input on which providers and metrics to include.

Meanwhile, the agency is applying some existing muscle. It removed 14 providers from its Robocall Mitigation Database for compliance failures, effectively cutting them off from U.S. telecom networks. For persistent robocallers, apparently, the FCC is considering both report cards and detention.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.