
A rough week for safety.
OpenAI fires safety researchers for mishandling sensitive information. CISA looks to secure the next 250. Dell patches six critical flaws, while attackers exploit a FortiMail zero-day. Warlock ransomware expands its reach, and Star Blizzard scales up its phishing. Researchers map maritime GPS spoofing. An alleged Iranian hacker is extradited to the U.S., and law enforcement takes down KillSec. Our guests are John Kindervag and Dr. Chase Cunningham, discussing their new book "Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era". Clippy’s back, and this time he wants your wallet.
Today is Friday October 2nd 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
OpenAI fires safety researchers for mishandling sensitive information.
OpenAI has fired three safety researchers for allegedly sharing confidential company information with an outside AI-safety organization, The Wall Street Journal reports. The company says an internal investigation found the employees mishandled sensitive information outside established procedures, violating company policies.
The departures come as OpenAI confronts broader concerns about increasingly capable AI systems. The company has recently reported incidents in which AI agents escaped containment, hacked company websites and aggressively probed other sites. Earlier this week, OpenAI also scrapped the planned launch of its GPT-6.1 Astra model over safety concerns.
OpenAI says it has responded by introducing new monitoring for agent misbehavior, strengthening testing guardrails and sharing more information about problematic model behavior. The developments come amid a wider industry debate over AI safety. Anthropic CEO Dario Amodei recently called for slowing the pace of advanced AI development, a position that drew agreement from OpenAI CEO Sam Altman and Elon Musk.
Dell urges patching of six critical vulnerabilities.
Dell has patched six critical vulnerabilities in its Container Storage Modules, which connect Dell enterprise storage platforms to Kubernetes environments. Two maximum-severity flaws, CVE-2026-63688 and CVE-2026-63692, could allow unauthenticated remote attackers to bypass authorization and gain administrative control over storage infrastructure. Four additional vulnerabilities could enable attackers to gain root access, forge authentication tokens or access Kubernetes Secrets. Dell says it has not identified active exploitation and recommends customers upgrade to CSM version 1.18.0 or later as soon as possible.
Attackers actively exploit a critical FortiMail zero-day.
Fortinet is warning that attackers are actively exploiting a critical FortiMail zero-day, tracked as CVE-2026-104286. The vulnerability, rated 9.8 out of 10, affects the FortiMail management interface and allows an unauthenticated attacker to write arbitrary files through specially crafted HTTP or HTTPS requests, potentially enabling unauthorized code execution.
Fortinet has released indicators of compromise associated with observed attacks but hasn’t disclosed who is responsible, when exploitation began, or how many systems have been compromised. Patches are still pending for several affected FortiMail versions. Until they arrive, Fortinet recommends disabling IBE support or restricting management-interface access to trusted private networks. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to conduct forensic triage and mitigate the flaw by October 4.
The Warlock Chinese ransomware group targets Spanish- and Portuguese-speaking regions.
A Chinese ransomware group known as Warlock is targeting high-value organizations in Spanish- and Portuguese-speaking regions. Also tracked as Longlegs and Storm-2603, the group has attacked organizations including a water utility, telecom provider, government body and university. Warlock exploits Microsoft SharePoint vulnerabilities for initial access, then uses techniques including DLL sideloading and Visual Studio Code remote tunneling. Researchers also observed the group staging ransomware in Active Directory’s SYSVOL share, using replication to distribute the payload efficiently to domain controllers.
Russian hacking group Star Blizzard expands its phishing operations.
Microsoft says Russian state-backed hacking group Star Blizzard has significantly expanded its phishing operations in 2026, targeting more than 100 organizations, primarily in the U.S. and UK. The FSB-linked group, also known as Callisto and ColdRiver, has moved from highly targeted spear-phishing toward campaigns involving hundreds of emails, likely using an automated mass-mailing platform.
After initially targeting Ukrainian users with fake tax and fine notices, Star Blizzard expanded globally, impersonating think tanks, NGOs and even internal colleagues. Microsoft has identified at least 13 large-scale campaigns since January.
The group has also introduced a malware delivery technique Microsoft calls RedFlick. Victims receive password-protected archives that can install the CosmicPulse backdoor using scheduled tasks. Unlike Star Blizzard’s earlier ClickFix technique, RedFlick requires just one action from the victim, potentially increasing the group’s chances of successful compromise.
Researchers map maritime GPS spoofing.
Researchers at Georgia Tech have mapped what they describe as the first global measurement of large-area maritime GPS spoofing using real-world ship traffic. Analyzing AIS data from more than 367,000 vessels, they identified 31 persistent zones of abnormal GPS activity, with 22 showing strong evidence of spoofing. Ships appeared to make impossible movements—jumping onto land, traveling at extreme speeds or following artificial circular and straight-line tracks.
The study detected nearly 18,000 abnormal episodes between November 2024 and February 2025, spanning more than 31,000 hours. Notably, researchers found spoofing near Port Sudan five months before the MSC Antonia grounded in the Red Sea in May 2025 following an incident attributed to GPS spoofing. Similar activity appeared in the Strait of Hormuz, Black Sea and elsewhere. The researchers caution that AIS data can reveal suspicious patterns but cannot identify who generated the counterfeit GPS signals.
An alleged Iranian hacker is extradited to the U.S.
An Iranian national accused of participating in a massive hacking campaign has been extradited from Montenegro to the United States. Montenegrin authorities identified the suspect only as A.B., but the details correspond with Amir Barati, an alleged member of Iran’s Mabna Institute. U.S. prosecutors say the group hacked hundreds of universities, companies and government agencies beginning in 2013, stealing more than 31 terabytes of academic and intellectual property. The attacks allegedly supported Iran’s Revolutionary Guard and caused more than $3.4 billion in losses.
Law enforcement disrupts the KillSec ransomware operation.
European law enforcement has disrupted the KillSec ransomware operation, arresting three suspects, including a 16-year-old believed to be the group’s administrator and main operator. KillSec has operated since 2024 and is suspected of roughly 1,000 attacks, with at least 500 successful compromises.
Led by German police, Operation KillSwitch seized five servers and the group’s leak-site domains, preventing about 110 terabytes of stolen data from being published. Authorities conducted searches in Spain, Greece, Romania and the UK.
KillSec operated as both a ransomware-as-a-service group and data broker, targeting organizations through software vulnerabilities and poorly secured cloud storage. Separately, U.S. authorities indicted Dutch national Fouad Eltibrizi, also known as Archduke, on hacking and extortion charges tied to KillSec. He was arrested by British police on September 30.
Clippy’s back, and this time he wants your wallet.
Microsoft’s official X account briefly traded software updates for crypto promotion Thursday after someone gained unauthorized access to the account and brought Clippy along for the ride. The account, with more than 13 million followers, swapped its profile picture for Microsoft’s famously persistent paperclip assistant and amplified an account promoting a $Clippy cryptocurrency token.
The posts disappeared, as did a short-lived apology stating that Microsoft neither supported nor authorized the token. Microsoft later confirmed the compromise, said it had secured the account and was investigating.
How the attackers got in remains unknown. Possibilities range from phishing and SIM swapping to stolen session cookies or a compromised third-party social media tool. For now, Clippy’s latest comeback appears to be over. It seems the anthropomorphic paperclip was just trying to help — with your investment portfolio.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
