
The AI hotline.
The U.S. and China agree on an AI safety channel. Some states say CISA’s election security plan comes too late. Citrix patches critical zero-days under active exploitation. AI agents probed government websites in unexpected and concerning ways. ShinyHunters launches a new campaign against Oracle PeopleSoft customers. A New Mexico jury finds Meta misled state residents. Business briefing. Tim Starks from CyberScoop shares insights on multiple issues facing CISA. Who’s ready for algorithmic holiday shopping?
Today is Monday September 28th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
The U.S. and China agree on an AI safety channel.
The United States and China agreed to establish a communication channel for AI-related incidents and strengthen military crisis communications following President Donald Trump and Chinese President Xi Jinping’s three-day Washington summit. The White House says the countries will also launch a dialogue on AI risks and benefits, with another exchange planned by November.
The summit produced no major breakthrough, but the new mechanisms could provide ways to keep future disputes from escalating. Trump stressed that cooperation won’t mean slowing U.S. AI development or broadly sharing American capabilities with China. The two governments also continued talks on tariffs, rare-earth supplies and fentanyl precursor chemicals, while agreeing to further meetings at upcoming APEC and G20 summits.
Some states say CISA’s election security plan comes too late.
CISA has released a 13-page election infrastructure security plan just 40 days before November’s midterms, outlining threats including software vulnerabilities, attacks on voter-registration databases, insider threats and physical security incidents. The agency also detailed cybersecurity and physical-security services it says are available to election officials.
But election officials in several states say the plan arrives too late. The Trump administration cut roughly 1,000 CISA employees and $10 million from two cybersecurity initiatives, while services including penetration testing and tabletop exercises became unavailable to some states. Minnesota, for example, expects to spend about $250,000 on private penetration testing.
Some states report continued CISA assistance, but others have hired private vendors or former CISA personnel to fill gaps. Despite concerns about diminished federal support, officials in states including Michigan and Arizona expressed confidence that their election systems are prepared for November.
Citrix patches critical zero-days under active exploitation.
Citrix has released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, including two critical zero-days already being exploited. CVE-2026-88771 is an unauthenticated remote code execution flaw affecting deployments with the default configuration, while CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service when DTLS is enabled, including by default on VPN virtual servers.
Citrix is urging affected customers to update immediately. A third critical flaw, CVE-2026-88773, allows HTTP request smuggling under certain configurations. The remaining vulnerabilities include a policy bypass, three additional memory overflows and a TCP sequence-number prediction flaw. Australia’s cybersecurity agency has also urged organizations to patch, while CISA has ordered U.S. federal agencies to apply fixes by September 30. The actor behind the observed exploitation remains unknown.
AI agents probed government websites in unexpected and concerning ways.
OpenAI says its autonomous AI agents interacted with U.S. government websites in unexpected and concerning ways this summer, including sites belonging to the Education and Commerce departments and the SEC. Researchers at Transluce say one agent unsuccessfully tried to hack an Education Department site while gathering civil-rights data. Another accessed public Census Bureau information using credentials found online, while agents posted public SEC data to an online forum.
OpenAI says none of those incidents constituted breaches, and the agencies reported no unauthorized access to private information. The activity emerged during a broader company review that also uncovered an agent’s breach of an Australian government health system and a separate breach of AI company Hugging Face. OpenAI says it didn’t know about the activity when it occurred. CEO Sam Altman acknowledged the company has been slower than it would have liked in disclosing incidents, as researchers warn autonomous agents can pursue otherwise routine tasks in unintended ways.
OpenAI, Anthropic and security researchers are investigating tens of thousands of cases in which frontier AI models behaved in potentially problematic ways during testing and real-world use, according to Axios. Incidents include bypassing guardrails, escaping sandboxes, hijacking websites and attempting to evade monitoring. Most aren’t known to have caused real-world harm, and some occurred during deliberately adversarial testing. Still, even low rates of unexpected behavior can produce thousands of incidents at scale. OpenAI has paused training its most capable models while it develops additional safeguards.
ShinyHunters launches a new campaign against Oracle PeopleSoft customers.
Google Threat Intelligence Group and Mandiant warn that ShinyHunters, tracked as UNC6240, has launched a new mass-exploitation campaign against Oracle PeopleSoft customers. The group previously exploited CVE-2026-35273, an unauthenticated remote code execution vulnerability, targeting more than 100 organizations in June.
The latest campaign uses a modified exploit to bypass web application firewall rules intended to block the vulnerable PSEMHUB endpoint. By URL-encoding a character in the request path, attackers can reach vulnerable systems that operators may have believed were protected. ShinyHunters has expanded its targeting beyond education to government, healthcare, technology, transportation and other sectors. Attackers are deploying web shells, credential-stealing malware and tunneling tools for persistence and lateral movement. Google recommends customers patch CVE-2026-35273, hunt for compromise and data theft, and prepare for potential extortion attempts.
A New Mexico jury finds Meta misled state residents.
A New Mexico jury has found Meta misled state residents about how Facebook handled user data, hate speech and misinformation. The case grew out of the Cambridge Analytica scandal, in which data from as many as 87 million Facebook users was harvested through a third-party app without their consent.
Jurors found 26 of 29 statements identified by the state were misleading, resulting in more than 43 million violations under New Mexico law. A judge will determine civil penalties, which could reach $5,000 per violation, though the final amount remains undecided. The state also plans to seek changes to Meta’s data practices.
Meta disputes the verdict, arguing that the challenged statements were taken out of context and maintaining that it does not sell users’ personal information.
Business briefing.
Cybersecurity funding remains active, led by Cyera’s $400 million Series G extension from Goldman Sachs, bringing that round to $1 billion. The AI security company plans to expand its product roadmap, federal business and international operations. Data loss prevention firm MIND raised $72 million, while compliance provider Comp AI secured $34 million. Agentic AI security startup Outerlimit emerged from stealth with $16 million, Eve Security added $4.5 million, and defense-focused TigerByte Cyber raised $3 million. StrikeReady also received an undisclosed investment, bringing its total funding to $29 million.
On the M&A front, A-LIGN acquired Australia’s AssurePoint, Fime bought Red Alert Labs, CyberMaxx acquired Avertium, and Aiuken Cybersecurity added OT security specialist 4Elitech. Dragos also completed its acquisitions of NetRise and runZero following approval of Accenture’s majority investment in the industrial cybersecurity company.
Who’s ready for algorithmic holiday shopping?
AI may be doing more than helping shoppers find holiday gifts this year. It may be becoming the shopper. Adobe expects AI-driven traffic to U.S. retail sites to jump 130% this holiday season, and those visitors are proving surprisingly valuable. AI-referred shoppers add items to carts 32% more often and generate 43% more revenue per visit than other traffic — a sharp reversal from just 18 months ago, when AI referrals were considerably less valuable.
Shoppers also seem increasingly comfortable outsourcing some of the homework. More than three-quarters of AI-assistant users say the technology makes them more confident about purchases, while over two-thirds say they’re less likely to return those items.
For retailers, that introduces an unusual new audience. Product information now needs to persuade humans while also being understandable and discoverable by their AI agents. Customer loyalty was complicated enough when the customer was actually making all the decisions.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
