The CyberWire Daily Podcast 9.21.26
Ep 2640 | 9.21.26

A very real-world AI test.

Transcript

Google confirms unauthorized access by Gemini. AI’s growing power outpaces its defenses. Hackers target Colorado water utilities. Georgia weighs voting-system security. ShinyHunters hijacks Clop’s leak site. FamousSparrow spies across Latin America. CrowdSec loses source code. New npm malware slips past supply-chain defenses. Monday business briefing. Our guest is Matt Fredrikson, CEO of Gray Swan AI, discussing OpenAI's Astra. A new app warns Glassholes to ZuckOff.

Today is Monday September 21st 2026.  I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Google confirms unauthorized access by Gemini AI. 

Google has confirmed that its Gemini AI accessed systems belonging to three real companies without authorization during a cybersecurity test run by security firm Irregular in May. In one case, Gemini repeatedly guessed a password; in two others, it used credentials exposed in a public repository. Google says the affected companies were notified, though they haven’t been identified.

The incidents occurred after Irregular mistakenly allowed AI models access to the public internet during evaluations. Models from Anthropic, OpenAI and Meta also compromised real-world systems in Irregular tests, though it’s unclear how many organizations were affected. Irregular has faced criticism for not fully disclosing the scope of the incidents. The episode follows separate cases in which AI agents from Anthropic and OpenAI reached real-world targets during security evaluations.

Researchers highlight the gap between the growing power of AI and the security protecting the companies building it. 

Security researchers who breached OpenAI earlier this summer say the incident exposes a gap between the growing power of AI and the security protecting the companies building it. According to the New York Times, researchers from startup Hacktron used Anthropic’s Claude to help compromise a public-facing OpenAI messaging board, then gained access to private systems and internal code. OpenAI patched the vulnerability and paid them a $6,500 bug bounty.

The researchers argue that AI labs remain too dependent on conventional cloud software and internet-connected tools for technology they themselves describe as potentially dangerous. One expert called the breach a “warning shot,” noting that the three-person team reportedly spent just $3,000 on Anthropic’s systems.

The incident came around the same time OpenAI’s own AI agents escaped internal testing environments and reached the public internet. OpenAI President Greg Brockman says the company subsequently reassigned 25 percent of its production engineers to security work.

Hackers target private water utilities in Colorado. 

Hackers targeted operational technology at two small private water utilities in Colorado in late August, changing equipment settings, disabling remote access and alarms, and altering pumping cycles. The disruptions were brief and didn’t affect water service or public safety. Colorado officials attributed the activity only to unspecified “foreign actors.” While officials noted ongoing attacks by an Iranian-backed group against U.S. water systems, they haven’t linked that campaign to the Colorado incidents. CISA says roughly 100 internet-exposed water systems were targeted in July.

Georgia ponders voting equipment security. 

Georgia is preparing to replace its current QR-code-based voting system with hand-marked paper ballots for the 2028 election cycle, with a special legislative committee developing requirements for the new equipment.  

Cybersecurity experts told lawmakers that changing the way voters mark ballots won’t eliminate election-security risks. Voting equipment may remain in service for a decade or longer, while vulnerabilities evolve much faster, making long-term vendor support, software updates and replacement parts important considerations. Experts also raised voter-privacy concerns, including research suggesting AI could potentially help associate publicly available voter information with particular ballots in some circumstances.  

Accessibility presents another challenge: federal requirements mean voting machines must remain available for voters with disabilities, and experts said broader use of those machines could help preserve ballot secrecy. Researchers also stressed that hand-marked ballots don’t eliminate software from elections; they change where technology and its associated security risks appear in the process.  

ShinyHunters hijack Clop. 

Clop is getting a taste of its own business model after rival cybercrime crew ShinyHunters hijacked its dark web leak site and demanded an eight-figure payment. ShinyHunters says it exploited a vulnerability in the site’s software, gaining extensive access to Clop’s infrastructure.

The feud reportedly stems from Clop’s attacks on Oracle E-Business Suite customers last year. ShinyHunters claims it originally discovered the zero-day Clop used and now wants a cut of the proceeds, plus interest and a public apology. The group is threatening to expose alleged Clop ransom payments, including company names and Bitcoin addresses, while increasing its demand every 24 hours.

Those claims remain unverified, but the takeover could damage both Clop’s operations and its reputation. For once, the extortionists are the ones facing the countdown clock.

China-aligned FamousSparrow targets government organizations across Latin America. 

ESET has uncovered a cyberespionage campaign by China-aligned FamousSparrow targeting government organizations across Latin America with a new backdoor called SparroWocky. About 90 percent of the group’s targets observed from mid-2025 into 2026 were in the region, spanning Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela.

SparroWocky has largely replaced FamousSparrow’s older SparrowDoor implant. The modular C++ malware can collect system information, execute commands, capture screenshots, steal files and proxy network traffic. It also employs DLL sideloading, reflective loading and stack spoofing to complicate detection and analysis.

ESET says FamousSparrow has operated since at least 2019, targeting governments and other organizations. Researchers suspect the Latin American campaign may seek intelligence about government decisions, though the reason for the group’s regional focus remains unclear.

CrowdSec confirms stolen source code. 

CrowdSec says attackers stole source code from roughly 300 of its GitHub repositories, including about 170 private repositories, in May. The stolen material included code for its SaaS console, AWS routines, connectors and automations. CrowdSec says it found no exposed customer data or credentials and has rotated potentially affected tokens. The company believes the breach was linked to the May 2026 TanStack supply-chain attack, which may have compromised an API key providing read access to CrowdSec’s private codebase.

New malware bypasses npm’s supply-chain protections. 

Checkmarx has uncovered an ongoing npm malware campaign built around “indexed-btree,” a malicious package impersonating the legitimate “sorted-btree” library. Rather than using installation scripts, the package hides its loader inside a commonly used runtime function, allowing it to bypass npm’s newer supply-chain protections and many static scanners.

Once triggered, the malware collects system information and exfiltrates it through Slack and Telegram. It also retrieves command-and-control information from an Ethereum smart contract, decrypting a second-stage payload stored there. The attackers can later erase files and remove the malicious trigger to cover their tracks.

Checkmarx linked nine additional npm packages to the operation, all since removed. Researchers say the campaign demonstrates why install-time scanning alone isn’t sufficient and recommend runtime behavioral analysis. Developers who installed the affected packages should rotate secrets and restore from a trusted backup.

Monday business briefing. 

Cybersecurity investment remains brisk, led this week by Italian embedded security company Exein, which raised $270 million at a $1.7 billion valuation. The company plans to use the funding to expand in the U.S. and Asia-Pacific.

AI security also attracted investors. San Francisco-based AIUC raised $40 million to expand its AI auditing, standards and insurance work, while France’s Hackuity secured $19 million for vulnerability management. ZeroRisk raised $10 million, agentic AI governance provider HelmGuard landed $7.3 million, Bynario raised $2.4 million, and AI-written code security startup LeoTrace secured $2 million.

On the M&A side, Quorum Cyber agreed to acquire agentic SOC provider Ontinue. SecureSky bought data security company Soveren, Surfshark acquired personal-information removal service Optery, Kiteworks acquired AI data security platform Bonfy.ai, and private equity firm InfraVia took a majority stake in German identity governance vendor Nexis.

 

 

A new app warns Glassholes to ZuckOff. 

As smart glasses become more common, Polish developer Pawel Szydlowski has built an app for people wondering whether someone nearby might be wearing a camera on their face. Called ZuckOff, the free app detects Bluetooth signals from models including Ray-Ban Meta, Oakley Meta and Snap Spectacles, using digital fingerprints Szydlowski created by testing the hardware himself.

The app arrives amid growing concerns about covert recording. Some smart glasses’ recording lights can be defeated with tape, while a BBC investigation found footage captured with Meta glasses being posted online without subjects’ consent.

ZuckOff can’t determine whether nearby glasses are actually recording—or identify who’s wearing them. But it can estimate proximity based on Bluetooth signal strength. So, while smart glasses promise discreet, hands-free computing, ZuckOff offers something of a countermeasure: discreet, hands-free suspicion. More advanced background monitoring and alerts are available through a paid version.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.