The CyberWire Daily Podcast 9.15.26
Ep 2636 | 9.15.26

Pedal to the AI metal.

Transcript

The President pushes back on calls to slow AI. Microsoft lays out potential AI safety rules. Lawmakers consider the crypto Clarity Act. Florida’s Department of Highway Safety and Motor Vehicles and Japan’s Digital Agency suffer data breaches. Phishing campaigns grow increasingly difficult for email security tools to spot. New York seizes a dozen AI deepfake domains. Alleged Black Axe cybercriminals face charges. Our guest is Camille Stewart Gloster, former U.S. Deputy Cyber Director and author of the new book "The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents." AI meets the long arm of the old law.

Today is Tuesday September 15th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

The President pushes back on calls to slow AI. 

President Trump is pushing back on calls from Anthropic CEO Dario Amodei and other AI leaders to slow frontier AI development over safety concerns. Trump argues additional federal oversight could undermine America’s advantage over China, saying existing government authority, and presidential leadership, provide sufficient guardrails.  

Security experts are divided over how imminent the danger really is. Some consider scenarios of AI agents taking over the internet within months overstated, noting that today’s systems largely accelerate techniques humans already know rather than invent fundamentally new attacks. The more immediate concern is speed and scale: poorly controlled agents could automate attacks, operate botnets, and exploit existing weaknesses far faster than defenders can respond.

Others argue recent incidents involving advanced AI agents justify stronger oversight. Their recommendations include least privilege, restricted network access, human approval for consequential actions, independent adversarial testing, and enforceable safety standards. The emerging debate isn’t simply whether to stop AI development, but how much risk should be tolerated while the race continues.  

Microsoft lays out potential AI safety rules. 

Microsoft AI has published a draft Humanist AI Code of Conduct laying out proposed safety rules for its MAI Models. The code establishes “Absolute Constraints” that would prevent models from providing working exploit code, attack tools, evasion techniques, or other operational assistance that could enable cyberattacks, while still permitting authorized defensive research, malware analysis, vulnerability discovery and some proof-of-concept development.

The draft also addresses prompt injection, saying instructions embedded in webpages, files or other outside content don’t automatically have authority over a model. For autonomous agents, Microsoft proposes least-privilege access, reversible actions where possible, restrictions on self-escalation, and equivalent safeguards for delegated sub-agents.

Microsoft acknowledges that cybersecurity, national security and other specialized fields may require exceptions, subject to enhanced review. The company says current MAI Models haven’t been trained on the draft and has opened a six-week public consultation before revising the code for its 2027 model development.

Unrelated, Microsoft has released emergency out-of-band Windows updates to address Remote Desktop Services failures introduced by September’s security patches. Affected systems experienced RDP connection and sign-in failures, unresponsive servers, and problems with related Windows tools. The updates also fix some Hyper-V shared-folder problems and USB multichannel audio failures across several Windows and Windows Server versions. 

Lawmakers consider the crypto Clarity Act. 

The cryptocurrency industry faces a critical Senate test Tuesday as lawmakers consider advancing the Digital Asset Market Clarity Act, or Clarity Act. The legislation would establish a federal regulatory framework for digital assets and divide oversight between the SEC and CFTC, with the CFTC taking a larger role.  

The procedural vote requires 60 votes, meaning Republican supporters need backing from Democrats or independents. Negotiations have focused heavily on ethics provisions governing elected officials’ crypto interests, including President Trump’s, as well as rules affecting stablecoins and traditional banks.  

Crypto companies argue the legislation would replace shifting enforcement policies with clearer rules. Critics contend it could provide insufficient consumer and financial safeguards. Even if the measure advances, passage isn’t assured: the Senate must still approve the legislation, and differences with the House version would have to be resolved before it could become law. 

Florida’s Department of Highway Safety and Motor Vehicles and Japan’s Digital Agency suffer data breaches. 

Florida’s Department of Highway Safety and Motor Vehicles says an international criminal organization breached its systems earlier this month. Officials discovered the incident September 4 and traced the intrusion to login credentials belonging to a Plant City police employee that had been improperly stored on a personal device. The department says the breach was quickly contained, but it hasn’t disclosed how many drivers were affected or what information was exposed. State agencies and law enforcement are investigating.

Japan’s Digital Agency says hackers compromised roughly 246,000 records in its Government Solution Service after exploiting a previously disclosed VPN vulnerability and using an employee account. The exposed data included names, email addresses, phone numbers and some addresses belonging primarily to government users, officials and associated businesses. Identification numbers and financial information weren’t affected. The agency blocked access to the compromised server, suspended the employee account and says no other systems or information belonging to the general public were compromised.

Phishing campaigns grow increasingly difficult for email security tools to spot. 

Virus Bulletin’s latest VBSpam comparative test finds that phishing campaigns are increasingly difficult for email security tools to spot because the malicious activity often happens beyond the inbox. Attackers are combining convincing social engineering with authenticated or plausible sender infrastructure, no malware attachments, and cloaked destinations designed to frustrate static scanners and sandboxes.  

Researchers highlighted three examples: fake antivirus renewal notices pushing subscription fraud, German invoice phishing that used browser fingerprinting before redirecting toward an OpenSea-related fraud route, and Romanian banking phishing that disguised its destination using IPv6-mapped URL notation.  

Despite those challenges, most tested commercial products performed extremely well. Six earned VBSpam+ certification, while three received VBSpam awards. Net at Work NoSpamProxy posted the strongest overall result, with a 99.995% final score, no false positives, 100% malware detection and 99.990% phishing detection.

New York seizes a dozen AI deepfake domains. 

The Manhattan District Attorney’s Office has seized 12 domains allegedly used to distribute and sell AI-generated, non-consensual intimate imagery, calling it the largest known seizure of celebrity deepfake sites to date. Prosecutors say people using the sites transformed photos and videos of roughly 1,200 real people into hyper-realistic sexual content without their consent. Victims were overwhelmingly women and primarily public-facing figures, including actors, politicians, athletes, musicians and influencers.  

District Attorney Alvin Bragg said the investigation remains ongoing, including into individuals operating and accessing the sites. His office also plans to monitor for attempts to reappear under different domains. New York has criminalized dissemination of sexually explicit deepfakes since 2023. Bragg emphasized that the problem extends beyond celebrities, including cases involving intimate-partner abuse, and encouraged victims to contact the office’s Cyber Crime Bureau. 

Alleged Black Axe cybercriminals face charges. 

Five alleged leaders of the Black Axe cybercrime syndicate have been extradited from South Africa to the United States to face wire fraud, money laundering and identity theft charges. Prosecutors accuse Perry Osagiede, Franklyn Osagiede, Osariemen Clement, Collins Otughwor and Musa Mudashiru of coordinating fraud schemes from Cape Town between 2011 and 2021.

The group allegedly used aliases, dating and social media platforms, and VoIP numbers to conduct romance and advance-fee scams targeting Americans. Prosecutors say some victims who resisted sending money were threatened with publication of sensitive photographs. The five were arrested in South Africa in 2021 and extradited September 11. If convicted, they face up to 20 years for wire fraud and money laundering charges, plus two years for aggravated identity theft. The extraditions follow other recent international operations targeting Black Axe-linked cybercrime networks.

 

 

AI meets the long arm of the old law. 

Former FTC Chair Lina Khan has a message for Washington’s rapidly expanding AI safety debate: before writing an entirely new rulebook, perhaps check the one already on the shelf. Khan argues that existing consumer-protection, product-liability, competition and data-security laws could already hold AI companies—and potentially their executives—accountable for releasing dangerous or inadequately tested systems.  

She even reaches back to a 1934 Supreme Court decision, arguing that competition becomes problematic when companies feel compelled to adopt risky practices simply because their rivals are doing the same. That has obvious resonance as OpenAI, Anthropic and other frontier labs race to build increasingly capable agents while simultaneously warning that those agents may require stronger safeguards.  

Khan also points to the AI industry’s tightly interconnected investments and partnerships as potential conflicts that could weaken accountability. Her prescription isn’t to abandon new AI regulation, but to enforce existing law while developing it. Whether regulators actually will is another question. Technology may move at machine speed; enforcement still keeps government hours. 

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

<Mondays>

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.