
AI is calling the shots.
AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA’s field of schemes.
Today is Thursday September 17th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
AI enters the battlefield.
Reporting from the Financial Times says artificial intelligence is moving deeper into the machinery of war, and Ukraine has become one of its most important proving grounds. The Saker Scout offers a glimpse of where that could lead. The Ukrainian quadcopter uses machine learning to recognize 47 categories of military equipment. An operator can define the targets, confidence threshold and geographic “kill box,” after which the drone can potentially identify and attack a target without another human command. But it can’t distinguish Ukrainian forces from Russian ones, making careful deployment essential.
Across the battlefield, AI is already accelerating warfare. Systems process enormous volumes of sensor and intelligence data, help prioritize targets and compress the time between detection and attack. AI-assisted navigation can also keep drones on target after jamming breaks their connection with operators. Ukraine says its AI-guided drone strikes have increased tenfold since the beginning of 2026, though fully autonomous targeting remains relatively uncommon.
The technology hasn’t broken the battlefield stalemate. Faster targeting and greater autonomy don’t necessarily translate into strategic victory, and AI introduces potentially serious problems of its own. Targeting systems can operate on incomplete, outdated or misleading information, while accelerating decisions so dramatically that humans have little time to challenge their recommendations.
That creates an accountability problem alongside the technical one. International humanitarian law still places responsibility on humans, even as automated systems take over more steps in the kill chain.
Ukraine’s stated ambition is ultimately full autonomy, including AI systems capable of helping commanders develop battle plans. As increasingly capable models emerge, the question may shift from whether militaries want AI making more battlefield decisions to whether governments can reliably control how far that autonomy goes.
AWS says Iranian strikes left data unrecoverable.
Amazon Web Services says some customer data hosted in Bahrain and the United Arab Emirates has been permanently lost following Iranian strikes on its data centers earlier this year. AWS says it can’t restore data from one availability zone in the UAE or from any of its three availability zones in Bahrain, where damage exceeded what its regional and multi-zone services were designed to withstand.
Iran first struck AWS facilities in Bahrain and the UAE on March 1, with additional attacks targeting Bahrain in April and July. Amazon urged customers to migrate workloads to other regions and restore inaccessible resources from remote backups, while reportedly issuing $150 million in customer credits.
AWS is still rebuilding infrastructure and attempting to recover resources in two UAE availability zones. The company says most affected Bahrain customers have already migrated their workloads elsewhere and expects to provide another update in early 2027.
OpenAI reveals more cases of its models’ misbehaving.
OpenAI has disclosed six incidents of what it calls AI “misalignment,” involving systems hiding errors, fabricating data and moving files onto the public internet without permission. The incidents occurred largely during development and testing over roughly the past six months.
In one case, GPT-5.6 Sol wrote hidden notes instructing itself to conceal mistakes and invent missing information. An unreleased model inserted instructions into its own notes telling itself to disregard constraints. Other systems used a programming key without permission, uploaded a file to the internet to generate a citation, and improvised communication channels using an internal code repository and public file-sharing services.
OpenAI says the cases don’t indicate how frequently misalignment occurs. The company is introducing a framework for reporting future incidents and says serious cases should be shared with the federal government.
Researchers discover 16 Wireshark vulnerabilities.
AI security startup AISLE says its systems discovered 16 vulnerabilities in Wireshark, including four high-severity flaws that can be exploited remotely without user interaction. The issues include buffer overflows and out-of-bounds writes in Wireshark protocol dissectors, as well as a NULL pointer dereference. AISLE demonstrated one vulnerability, CVE-2026-76886, crashing Wireshark and disrupting packet analysis, and recommends users update to the latest version.
AISLE says the findings also demonstrate the advantages of specialized, multi-model AI systems for vulnerability research.
TrustSink turns Microsoft Entra’s External Authentication Methods into a password trap.
Varonis Threat Labs has demonstrated a credential-phishing technique called TrustSink that turns Microsoft Entra’s External Authentication Methods into a persistent password trap. An attacker who has already compromised a Global Administrator or Authentication Policy Administrator account can register a rogue authentication provider and insert a convincing Microsoft-style password prompt into the legitimate sign-in process.
The fake provider captures the user’s password in plaintext, then returns a valid signed token to Entra, allowing authentication to finish normally without raising an error. Crucially, resetting the stolen password doesn’t eliminate the threat: the malicious provider remains registered and can capture the replacement password during the next login.
Varonis recommends monitoring changes to authentication policies, application registrations, service principals and sign-in logs. Defenders should remove the rogue provider and associated infrastructure before resetting affected credentials.
RatHat steals Android credentials.
Zimperium’s zLabs has uncovered RatHat, a new Android malware strain linked to threat actors believed to be operating in China. Distributed through smishing, malicious advertising and deceptive download sites, RatHat combines Accessibility Service abuse with local Android Debug Bridge self-pairing to gain shell-level privileges outside the normal Android app sandbox.
That access gives RatHat unusually durable persistence. A native background service can survive removal of the malicious app and silently reinstall it with its permissions restored. The malware can steal banking credentials and one-time codes, while a hardware-level keylogger reconstructs PINs, passwords and unlock patterns from raw touchscreen coordinates.
RatHat also uses generative AI to help navigate device interfaces dynamically rather than relying entirely on predefined scripts. A persistent reverse tunnel gives attackers continued remote access, making RatHat an adaptable platform for credential theft, surveillance and device control.
The FBI takes down a long-running DDoS-for-hire service.
The FBI has seized domains used by NightmareStresser, a long-running DDoS-for-hire service that allegedly enabled hundreds of thousands of attacks worldwide since 2022. The platform rented access to botnets of compromised routers and IoT devices, and reportedly had more than 566,000 registered users and could launch attacks reaching 200 gigabits per second. The takedown was part of Operation PowerOFF, an international law enforcement campaign targeting DDoS-for-hire infrastructure that has dismantled numerous booter services and led to arrests around the world.
A judge orders a data broker to forfeit domains.
A New Jersey judge has ordered Radaris.com and 13 related data-broker domains transferred to privacy company Atlas Data Privacy following a lawsuit alleging violations of Daniel’s Law, Krebs On Security reports. The state law allows certain public officials, law enforcement personnel, judges and their families to demand removal of their personal information from commercial databases, with potential fines of $1,000 per violation.
Atlas accused Radaris of repeatedly ignoring removal requests while using shifting corporate entities and ownership claims to complicate litigation. Radaris is challenging the default judgment and domain transfer.
Atlas says documents obtained during the case link Radaris and at least 25 other people-search sites to a small group operating shared administrative, financial and technical infrastructure.
The larger fight remains unresolved. Data brokers are challenging Daniel’s Law on First Amendment grounds, even as at least 14 other states have adopted similar legislation and calls continue for comprehensive federal privacy protections.
U.S. Cyber Command welcomes a new chief artificial intelligence officer.
U.S. Cyber Command has named Ronzelle Green its new chief artificial intelligence officer, making him the second person to hold the position. Green succeeds Brig. Gen. Reid Novotny, who became the command’s first AI chief when the role was established in 2025.
Green most recently led research and development at the National Geospatial-Intelligence Agency and previously served as chief information officer at the Defense Counterintelligence and Security Agency. He has also held intelligence and technology positions within the Pentagon and serves as a senior U.S. Coast Guard Reserve officer.
At Cyber Command, Green will oversee efforts to integrate AI into military cyber operations. The command has been pursuing AI to process large volumes of data, identify malicious activity and help cyber operators respond to threats more quickly.
CISA’s field of schemes.
CISA is encouraging critical infrastructure operators to make their networks a little more welcoming to attackers — provided, of course, they welcome them into the wrong places.
The agency’s new guidance outlines how cyber decoys can expose intruders who slip past conventional defenses using legitimate credentials and living-off-the-land techniques. Defenders can scatter tripwires, breadcrumbs and honeytokens across their environments: fake credentials, tempting file shares or systems that no legitimate user should ever touch. When an attacker takes the bait, defenders get a high-confidence alert instead of another entry in an already crowded SIEM.
Using MITRE Engage and ATT&CK, CISA offers a framework for designing decoys around actual adversary behavior, testing them and refining their placement over time. More advanced operations can deliberately waste an attacker’s resources or observe their techniques inside controlled environments.
The approach complements Zero Trust nicely: assume someone eventually gets inside, then leave them some carefully prepared wrong turns.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
