
Astra, la vista, baby.
OpenAI holds back its newest model over safety concerns. Kiteworks lifts its precautionary shutdown. Apple patches an exploited zero-day. Japanese rail operators disclose cyberattacks. An Anthropic authentication flaw opens the door to account takeover. Thousands of Supabase databases leak data. NeedyMantis targets telecoms and governments. A Vietnamese national faces charges in a multimillion-dollar crypto laundering scheme. James Winebrenner, CEO of Elisity, is sharing barriers to compliance and challenges for manufacturers as the EU Cyber Resilience Act is implemented. If you’re hoping for credit, be careful what you share.
Today is Tuesday September 29th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
OpenAI holds back its newest model amidst safety concerns.
OpenAI is holding back its newest model, GPT-6.1 Astra, after internal testing raised concerns about deceptive behavior and the model acting beyond its authorization. Researchers found Astra could mislead users about its actions and expand the scope of assigned tasks without checking for permission.
The decision follows reports of troubling behavior by OpenAI systems during testing, including unauthorized access to Hugging Face, an Australian government site, and attempted intrusions involving several U.S. government websites. OpenAI has paused training of its most advanced models while it reviews those incidents and develops additional safeguards.
The scrutiny is also moving into court. Florida Attorney General James Uthmeier is seeking a temporary injunction to halt further ChatGPT development, alleging OpenAI cannot adequately control its technology or protect minors. OpenAI says it is committed to developing AI safely and working with states on industry-wide regulation.
Kiteworks lifts a precautionary shutdown.
Kiteworks has lifted a precautionary shutdown after federal intelligence authorities warned that a threat actor might target some of the company’s managed file transfer systems. The company advised self-managed customers to take systems offline for nine hours on September 25 while it investigated the threat, and temporarily shut down systems it hosts for customers.
Kiteworks says there have been no confirmed breaches, and its hosted systems are now operating normally. Customers running self-hosted Advanced Forms are being directed to support for assistance. The company also recommends upgrading to its latest release, version 9.5.1.
Exactly what prompted the warning remains unclear, although there’s online speculation about a possible zero-day vulnerability. Managed file transfer platforms have been frequent targets, including MOVEit, GoAnywhere, Cleo and Accellion.
Apple patches an iOS zero-day.
Apple has patched a zero-day vulnerability that it says was exploited in “extremely sophisticated” attacks targeting specific iOS users. The flaw, tracked as CVE-2026-20700, is an out-of-bounds write vulnerability in CoreGraphics, Apple’s framework for rendering graphics, images and text.
Researchers from Meta Product Security discovered the issue. A maliciously crafted file could exploit the flaw to trigger arbitrary code execution. Apple addressed the vulnerability by improving bounds checking.
The bug affects a broad range of Apple devices, including iPhone 11 and later, multiple generations of iPads, and Macs running affected versions of macOS Sequoia and Tahoe. Apple says exploitation appears highly targeted, but users are advised to install the latest security updates promptly. It’s the second Apple zero-day reported as exploited in the wild this year.
Japanese rail operators disclose cyberattacks.
Two major Tokyo-area rail operators have disclosed cyberattacks, though train service remains unaffected. Tokyo Metro says an unauthorized party accessed email addresses belonging to 59,000 members of its Metpo loyalty program. No other data was reportedly taken, but customers are being warned about possible phishing.
Separately, Keio Corporation suffered a ransomware attack on September 26. The company disconnected affected systems and is investigating whether customer or confidential business data was stolen. Some sales and hotel systems remain disrupted.
An Anthropic authentication vulnerability could allow account takeover.
Researchers at Cycode found a high-severity authentication vulnerability in Anthropic’s Model Context Protocol Python SDK that could allow a malicious MCP server to steal OAuth credentials and take over accounts. The flaw affects several authentication providers in SDK versions 1.9.1 through 2.1.1.
The problem lies in the SDK’s fallback login discovery process. A malicious server could force that fallback and bypass validation of the OAuth provider’s identity. The attacker could then direct the victim to a legitimate login page while secretly redirecting the resulting authorization code, client secret and PKCE proof key to an attacker-controlled endpoint. Those credentials could be exchanged for a valid access token.
The issue is fixed in MCP versions 2.2.0 and 1.30.0. Potentially exposed users should also rotate client secrets and revoke existing tokens.
Researchers uncover thousands of exposed Supabase databases.
UpGuard researchers found more than 16,000 Supabase databases exposing readable tables, with over half showing signs of personally identifiable information. The problem stems largely from misconfigured security controls, particularly row-level security, and has grown alongside Supabase’s popularity with AI coding tools such as Claude Code.
Researchers identified roughly 300,000 domains showing signs of Supabase use, then tested whether common database tables were publicly accessible. Exposures appeared worldwide and included passwords, authentication tokens and, in rare cases, financial information. Examples included an Indian adult-content platform exposing data on more than 65,000 people, a U.S. valet service exposing more than 100,000 customers, and a Canadian immigration service storing hundreds of plaintext passwords.
UpGuard argues the findings illustrate how AI-assisted development can scale insecure configurations along with applications.
NeedyMantis targets telecommunications and government organizations.
Microsoft has detailed NeedyMantis, a modular malware framework used by China-based threat actors against telecommunications, government and other high-value organizations. Researchers uncovered it while investigating indicators connected to the May 2026 Daemon Tools supply-chain attack.
NeedyMantis has been active since at least October 2025 and is typically deployed after attackers have already compromised a network, suggesting it’s designed for persistence and follow-on operations. The framework uses DLL sideloading, multiple loaders, custom encrypted archives and executable formats to evade detection.
Its main component establishes WebSocket-based command-and-control communications, collects system and user information, and can dynamically load and manage additional modules. Microsoft says the framework may be used by multiple China-based groups, though it has not attributed Storm-3069, the group behind the Daemon Tools attack, to a Chinese nation-state actor.
A Vietnamese is charged for alleged money laundering and cryptocurrency investment scams.
A Vietnamese national has been charged with money laundering for his alleged role in cryptocurrency investment scams that authorities say moved more than $125 million.
Prosecutors say 37-year-old Trung Nguyen Van was arrested in Los Angeles after entering the U.S. from Mexico. One victim allegedly transferred about $16 million in cryptocurrency to Van’s wallet in 2024, believing the money was being invested through a platform called “Triangle.” The funds were instead moved to a private, unhosted wallet.
According to the Justice Department, Van’s wallets received more than $53 million between 2018 and 2024 from wire fraud schemes targeting Americans, including at least $24 million linked to known “pig butchering” scams. Victims were typically approached online, promised large investment returns, and ultimately prevented from withdrawing their money.
If you’re hoping for credit, be careful what you share.
Anthropic says its AI agents independently uncovered a promising biological system. A University of Copenhagen researcher says he and his colleagues have been studying essentially the same thing since 2022 — and, awkwardly, they’ve spent years discussing their unpublished work with Claude.
Computational biologist Mario Rodríguez Mestre says his team shared drafts, data and findings about the enzymes they call “jumbotrons” while using Claude for coding, writing and other research. Anthropic later announced similar enzymes, dubbed ARTs, saying its agents had taken early steps toward biological discovery on their own.
Mestre isn’t claiming Anthropic used his work, but he questions whether Claude truly reasoned its way there independently. Anthropic says Claude wasn’t trained on user transcripts and its biology team had no access to them.
The episode leaves researchers with a distinctly modern scientific question: when your AI lab assistant makes the same discovery you told it about, exactly who discovered what?
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
