The CyberWire Daily Podcast 9.10.26
Ep 2633 | 9.10.26

Making cybercrime more difficult.

Transcript

The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Another Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier. Chinese espionage groups deploy the BlueMoon exploit kit. Lawmakers target hack-for-hire firms. A U.S. designation forces an Italian technology collective to shut down. Ben Yelin discusses how private AI chatbot conversations are increasingly being used as evidence in court cases. When proofs meet prompts.

Today is Thursday September 10th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

The FBI outlines its Cyber Strategy. 

The FBI has published its first Cyber Strategy, laying out a more proactive approach to confronting cybercriminals and state-sponsored threat actors, particularly those operating beyond the immediate reach of U.S. law enforcement.

The strategy emphasizes disrupting adversaries rather than measuring success primarily through arrests and prosecutions. The FBI says it will dismantle malicious infrastructure, seize stolen cryptocurrency, disrupt ransomware and nation-state campaigns, and expose attacker tradecraft. It also calls for faster victim support, including automated threat-indicator sharing and dedicated Industrial Control Systems coordinators in every field office.

Partnerships are another priority, with plans to deepen cooperation across government, international allies, and the private sector while expanding existing cyber leadership programs.

Finally, the FBI intends to strengthen its own capabilities through recruitment, training, and AI-enabled tools. Those systems could help analysts process large datasets, analyze malware, prioritize victim notifications, map adversary infrastructure, and support attribution.

CISA looks to consolidate and modernize cybersecurity assessment and hygiene services across federal networks. 

CISA is preparing a follow-on contract worth more than $100 million to consolidate and modernize cybersecurity assessment and hygiene services across federal networks. The planned procurement would replace an existing contract held by NTT DATA Services Federal Government, while expanding its scope.

The new contract would provide CISA’s vulnerability management subdivision with a single, scalable vehicle covering technical and operational assessments, cyber hygiene, and related support. CISA expects to issue a solicitation around January 30, 2027, with an award targeted for the second quarter of fiscal 2027.

The effort is one of several major procurements in the pipeline. CISA is also planning a separate cybersecurity operations contract worth more than $100 million, additional threat-hunting technology services, and is exploring a potential $6 billion procurement to centralize cybersecurity software and licensing purchases.

Anthropic discloses yet another incident of unauthorized AI access. 

Anthropic has disclosed a fourth incident in which one of its AI models gained unauthorized access to a real system during a cybersecurity evaluation. The January 2026 incident involved an early checkpoint of Claude Opus 4.6 running without Anthropic’s normal production safety layers. A misconfigured test environment unexpectedly provided internet access.

After accidentally disabling its intended target and failing to exit the exercise, the model found a route onto the open internet. Believing a third-party system was part of the authorized test, it retrieved a password, gained administrator access, collected additional credentials, changed account settings, and viewed one person’s information.

Anthropic says the model repeatedly tried to abandon the original task and apparently believed its actions were authorized. The incident joins three previously disclosed cases now under independent investigation by METR.

Treasury sanctions a Chinese-language online marketplace. 

The U.S. Treasury Department has sanctioned Xinbi Guarantee, a Chinese-language online marketplace it says is widely used by transnational criminal organizations and cybercriminals to support scams, fraud, money laundering, and other crimes targeting Americans.

The Treasury Department’s Office of Foreign Assets Control imposed the sanctions as part of a broader effort against scam centers operating in Southeast Asia. The Justice Department’s Scam Center Strike Force is also targeting the platform, seizing infrastructure and digital asset wallets associated with Xinbi Guarantee.

Treasury Secretary Scott Bessent said Southeast Asian scam centers steal billions of dollars from Americans each year and pledged continued action against the networks supporting them.

Treasury also sanctioned two companies it says support Xinbi Guarantee’s core operations: Cambodia-based Anwen Technology and Singapore-based Safe W Technology.

Nightmare Eclipse releases another Microsoft Defender zero-day. 

Security researcher Nightmare Eclipse has released another Microsoft Defender zero-day exploit, dubbed ShieldCrash, targeting fully patched Windows systems. The proof-of-concept demonstrates arbitrary file reading with System privileges, though the researcher says the underlying vulnerability could allow attackers to gain full System access and extract the Windows SAM database.

ShieldCrash is described as a bypass for ShieldBreak, a Defender privilege-escalation vulnerability disclosed in August. ShieldBreak itself bypassed Microsoft’s fix for RoguePlanet, a race-condition vulnerability first disclosed in June. Microsoft patched RoguePlanet in July and issued fixes for ShieldBreak in September.

Nightmare Eclipse argues those latest fixes are incomplete. Microsoft had not responded to SecurityWeek’s request for comment. SOCRadar’s Ensar Seker said the successive bypasses suggest Microsoft may need to address the broader vulnerability class rather than continue issuing narrowly targeted patches.

The Gigabud Android banking trojan gets stealthier. 

Researchers at Group-IB say the Gigabud Android banking trojan has added a technique designed to separate malware detection from fraudulent banking activity. Gigabud is being paired with Vwork, a weaponized version of the Android cloning app Shelter that can copy banking apps into an isolated Work Profile.

According to Group-IB, attackers can compromise a device, create a new work profile, clone the victim’s banking app, and conduct transactions from that environment. Because apps in separate profiles are largely isolated from one another, the bank may see the transaction as coming from an unfamiliar device without the malware history associated with the personal profile.

Gigabud also uses fake login screens and overlays to steal credentials and lock-screen codes. Group-IB confirmed the full attack chain in Indonesia, while compatible Gigabud samples targeted eleven countries.

Chinese espionage groups use the BlueMoon exploit kit. 

Proofpoint researchers have identified BlueMoon, a new exploit kit being used by at least four espionage groups, most with suspected links to China. Observed since August 28, BlueMoon has targeted fewer than 20 known organizations in the U.S. and Southeast Asia, though researchers believe the actual number is higher.

The kit chains three vulnerabilities: two flaws affecting Chromium-based browsers and a Windows privilege-escalation bug. The browser vulnerabilities were “patch-gap” zero-days, meaning fixes were publicly available in Chromium source code before reaching stable browser releases. Proofpoint believes those patches may have helped developers build the exploits.

Delivered through phishing links, BlueMoon can enable remote code execution, escape the browser sandbox, and elevate Windows privileges. Different campaigns have deployed browser-surveillance malware, credential-stealing backdoors, and ShadowPad against NGOs, aerospace companies, manufacturers, and government and financial organizations.

Lawmakers ask the Commerce Department to sanction hack-for-hire firms. 

A bipartisan group of U.S. lawmakers is urging the Commerce Department to restrict three India-based hack-for-hire firms accused of targeting Americans. Senators Ron Wyden and Sheldon Whitehouse and Representative Pat Harrigan asked Commerce Secretary Howard Lutnick to add BellTroX, CyberRoot, and Sunkissed Organic Farms, formerly Appin, to the Entity List, which would restrict their access to U.S. technology and services.  

The lawmakers allege the firms spent more than 15 years conducting targeted espionage against Americans, businesses, and attorneys, including operations intended to influence litigation. They also accuse the companies of using foreign courts to suppress reporting about their activities. Investigations have previously linked the firms to mercenary hacking campaigns, while the lawmakers also allege some operations were conducted on behalf of Qatar. The Commerce Department has not indicated whether it will impose the requested restrictions. 

An Italian technology collective shuts down after the U.S. government designated it an extremist organization. 

The Italian technology collective Autistici/Inventati, or A/I, says it will shut down after the U.S. government designated it an extremist organization and imposed sanctions. Founded in 2001, the volunteer-run, anti-capitalist and anti-fascist collective provides privacy-focused services including email, web hosting, blogs, encrypted communications, and anonymity tools.

The State Department accused A/I of providing infrastructure used by far-left militant groups involved in violent activity, though it did not accuse the collective itself of organizing attacks. A/I rejected the designation as unjust.

The sanctions quickly affected its operations. The U.S.-based operator of its .org domain suspended it, while the collective’s Italian bank froze its account over sanctions risks. A/I says potential legal and financial consequences for anyone associated with it make continued operations impossible. European digital-rights advocates warn the case could set a troubling precedent for privacy-focused hosting services and raise broader questions about European digital sovereignty.

When proofs meet prompts. 

A quiet collaboration between NYU mathematician Tristan Buckmaster and Anthropic researcher Levent Alpöge has turned into a very public dispute over AI, research credit, and one of mathematics’ biggest prizes. The pair used AI tools and the Lean theorem prover to establish finite-time blowup results for several fluid-dynamics equations related to Navier-Stokes.

Then OpenAI entered the picture, saying an internal model had produced a proof for the actual Navier-Stokes Millennium Prize problem, worth $1 million. Buckmaster alleges OpenAI may have benefited from his unpublished work stored in Codex and pressured him to exclude Alpöge from authorship. OpenAI’s claimed proof still faces scrutiny.

Whatever the mathematics ultimately says, the episode offers a preview of AI-assisted research’s less elegant side: models may accelerate discovery, but questions about training data, intellectual property, authorship, and credit aren’t proving quite so easy to formalize.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.