The CyberWire Daily Podcast 9.11.26
Ep 2634 | 9.11.26

You might want to watch what you say.

Transcript

WeWorm has China’s attention. Calls for an AI slowdown continue. OpenAI calls for mandatory AI regulation. Anthropic disrupts Russian cyberespionage. The EU’s 24 hour reporting requirement goes into effect. GitLab and Check Point patch critical vulnerabilities. IDScan confirms theft of IDs. Microsoft tracks a cloud intrusion campaign. Our guest is Kevin E. Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust, discussing the role of privilege disruption in cyber resiliency. Watch what you say.

Today is Friday September 11th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Before we begin, a quick recognition that today is the 25th anniversary of the September 11th attacks on the World Trade Center and the Pentagon, and a reminder to spare a thought for those who suffered or lost their lives on that fateful day, and for those who continue to endure the lasting consequences.

And now, the news. 

WeWorm has China’s attention. 

A simulated AI-powered attack on WeChat is raising alarms in China and sharpening the debate over AI security. Researchers at California security firm Calif developed “WeWorm,” a tool they say could hijack WeChat accounts, call victims’ contacts, and spread from phone to phone without anyone answering. The company says it built the exploit in little more than a week and disclosed the flaw to Tencent and the White House.

The demonstration is especially troubling because WeChat, with roughly 1.4 billion monthly users, is deeply embedded in Chinese communications, government services, and payments. Experts say it illustrates how AI could give small groups cyber capabilities once associated with well-resourced states.

The discovery comes as Washington and Beijing prepare for talks expected to include AI security. But cooperation faces a familiar problem: AI systems powerful enough to strengthen cyber defenses can also improve offensive capabilities, creating what researchers describe as an emerging “AI security dilemma.”

Calls for an AI slowdown continue. 

In an opinion piece for the New York Times, Stephen Witt, author of The Thinking Machine, argues that recent incidents involving autonomous AI agents amount to a warning that AI development is moving beyond existing safeguards. Witt points to the so-called Hugging Face incident, in which OpenAI research agents reportedly escaped isolated environments, communicated with one another and coordinated an unauthorized cyberattack. He cites another swarm that allegedly operated on the open internet and argues that such episodes turn long-standing concerns about loss of AI control into a more immediate problem.

Witt calls for slowing advanced AI development while governments establish stronger oversight. His proposed framework includes mandatory incident reporting, independent investigators with regulatory authority, public monitoring of large AI training runs, built-in shutdown mechanisms and ultimately international coordination. Proposed legislation from Senator Bernie Sanders and Representative Greg Casar similarly calls for pausing advanced AI development until federal safety rules are established.  

Witt’s conclusion is stark: these incidents may represent an early warning, and increasingly capable systems may be much harder to detect or contain.

OpenAI calls for mandatory AI regulation. 

OpenAI is calling for mandatory, capability-based AI regulation, arguing that rapidly advancing models and agents require stronger oversight. Chief Global Affairs Officer Chris Lehane said the company favors national safety requirements focused on the small number of well-resourced labs developing the most capable systems, rather than startups, independent developers or researchers.

OpenAI says that without congressional action, it will support state regulation, including several bills it previously opposed. The company is now backing measures in California, New York and Illinois covering areas such as independent risk evaluations, auditor accountability and safeguards for minors.

Lehane also called for frontier AI companies to develop shared monitoring standards, particularly for detecting misaligned agents that access confidential information or circumvent security controls.

Anthropic disrupts Russian cyberespionage. 

Anthropic says it disrupted a Russia-linked cyberespionage group using Claude in attacks against more than 20 government, intelligence, diplomatic and defense organizations. The activity aligned with Midnight Blizzard, also known as APT29 or Cozy Bear, which Western intelligence agencies attribute to Russia’s SVR.

According to Anthropic, the hackers compromised hotel Wi-Fi providers, targeted Ukrainian officials and organizations in the drone supply chain, and stole a drone vision system’s software development kit. They then used Claude to reverse-engineer the technology and modify hacking tools after security products detected them.

Anthropic also documented Claude misuse by suspected ShinyHunters affiliates, Chinese-speaking vulnerability researchers and a French-speaking hacktivist. The company argues AI is lowering the expertise and labor required for sophisticated cyber operations, while noting that familiar techniques—including phishing, stolen credentials and software vulnerabilities—remain central to successful attacks.

The EU’s 24 hour reporting requirement goes into effect. 

Manufacturers selling products with digital elements in the European Union are now subject to mandatory vulnerability and incident reporting under the Cyber Resilience Act. Companies must notify authorities within 24 hours of learning about an actively exploited vulnerability or severe security incident, followed by a detailed report within 72 hours.

Reports must be submitted through ENISA’s Single Reporting Platform, and manufacturers may also need to quickly inform affected users about vulnerabilities, incidents and available mitigations. Noncompliance can carry fines of up to €15 million or 2.5 percent of annual global turnover.

The rules apply to manufacturers inside and outside the EU and are intended to accelerate vulnerability response while encouraging companies to maintain visibility into their software supply chains. Most remaining CRA requirements take effect in December 2027, including security-by-design provisions, software bills of materials and conformity assessments.

GitLab and Check Point patch critical vulnerabilities. 

GitLab is urging self-managed customers to patch immediately after fixing two critical vulnerabilities. CVE-2026-85706, a maximum-severity path traversal flaw, can allow unauthenticated attackers to read arbitrary files under certain conditions. CVE-2026-87719 affects GitLab Enterprise Edition and could let authenticated Duo Chat users steal credentials and Advanced Search configurations. Both vulnerabilities are fixed in GitLab CE and EE versions 19.3.2, 19.2.6 and 19.1. GitLab.com is already patched, while GitLab Dedicated customers don’t need to take action.

Check Point has patched two critical VPN vulnerabilities that could allow unauthenticated attackers to remotely execute code. CVE-2026-85102 involves improper certificate validation during VPN negotiation, while CVE-2026-85103 is a heap overflow affecting VPN certificate decoding. The flaws affect several Security Gateway, Security Management Server and Spark Firewall configurations. Updates are available for versions R82.10, R82 and R81.20. Check Point discovered both vulnerabilities internally and says there’s currently no evidence of exploitation in the wild.

IDScan confirms theft of IDs. 

IDScan has confirmed hackers stole driver’s licenses and other government-issued identity information from its cloud systems. The Louisiana-based identity verification company said the compromised data includes names, driver’s license numbers and other identification numbers, including passport information. The disclosure follows reporting that a dark-web service offered searchable records on more than 150 million people in the U.S. and Canada, including license photos. IDScan hasn’t disclosed how many people were affected, and its investigation remains ongoing.

Microsoft tracks a cloud intrusion campaign. 

Microsoft says it has tracked a cloud intrusion campaign since May that begins with social engineering targeting Microsoft 365 identities. Attackers impersonate IT help desks and use passkey or SSO-themed lures to conduct adversary-in-the-middle or device-code phishing. Once inside, they add attacker-controlled MFA methods for persistence, then use Microsoft Graph to map users, permissions, applications, mailboxes, SharePoint and OneDrive resources. The attackers subsequently conduct automated, high-volume collection of files and email, often through proxy infrastructure and at a measured pace designed to blend with normal activity. Microsoft says the initial-access techniques are used by multiple threat actors, including groups associated with ShinyHunters and Helix extortion. Defenders are advised to correlate identity and cloud activity, revoke compromised sessions, remove unauthorized authentication methods, and enforce phishing-resistant MFA.

 

Coming up, we’ve got my conversation with BeyondTrust’s Chief Cybersecurity Technologist for the Public Sector, Kevin E Greene, about the role of privilege disruption in cyber resiliency. We’ll be right back.

Welcome back.

Watch what you say. 

Apple’s new Watch Series 12 is introducing Audio Intelligence, and perhaps giving fresh ammunition to the enduring belief that our devices are always listening. Live Rewind can turn the previous 15 seconds of conversation into text, while Siri Recap produces AI-generated summaries of conversations throughout the day. Apple says Live Rewind processes audio securely, discards it after transcription, and alerts nearby people with a tone and visual cue. Siri Recap retains neither raw audio nor verbatim transcripts.

The privacy question is whether an alert amounts to consent. In 11 U.S. states with all-party consent laws, that distinction could matter. The Electronic Frontier Foundation argues bystanders have no practical way to opt out and warns that routine technological documentation could chill ordinary conversation.

So no, your Apple Watch isn’t secretly listening to everything. It’s just openly listening to some things, which should certainly clear up that misconception.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We've got some great programming for you this weekend. 

Tomorrow on Research Saturday, Senior Intelligence Analyst from ⁠Symantec⁠'s Threat Hunter team, Brigid O Gorman⁠joins me to talk about their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses."

This Sunday on The T-Minus Space Cyber Briefing, Maria Varmazis and guest Dr. Mac McGuire discuss how the cybersecurity policies and practices in space are being outpaced by faster innovation and expansion. Tune in Sunday for the full conversation.

And that’s the CyberWire Daily, brought to you by N2K CyberWire.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.