
You can’t secure what you can’t see.
An OT cyber coalition urges CISA to establish baseline security requirements. Another OpenAI safety worker resigns. Maryland lawmakers seek funding for Cyber Command’s mental health initiatives. Hackers compromised country-code domain registries for TLS certs. The FBI and French authorities shut down alleged CSAM AI deepfake websites. Ransomware recovery firm CEO indicted for secretly paying attackers. MATCHBOIL keeps simmering. Apollo software pioneer Margaret Hamilton dies. On today’s Industry Voices Sanjay Jeyakumar, Co-Founder of Abnormal AI, discusses why AI agents are challenging traditional security models. And how do I hack thee? Let me count the ways.
Today is Thursday October 8th 2026. I’m Dave Bittner Maria Varmazis. And this is your CyberWire Intel Briefing.
An OT cyber coalition urges CISA to establish baseline security requirements.
The Operational Technology Cybersecurity Coalition is urging CISA to establish mandatory baseline security requirements for operational technology across federal civilian agencies.
The coalition says federal agencies depend on OT in more than 8,000 government-managed facilities, including hospitals, laboratories, and ports of entry, but CISA lacks sufficient visibility into the associated risks. A recent GAO report found that only seven of 22 agencies reviewed had fully met federal requirements to inventory their networked OT and Internet of Things devices.
OTCC wants a binding operational directive covering asset inventories, network segmentation, remote access, configuration management, incident preparedness, and verified recovery. Outside experts say inventories alone won’t solve the problem, warning that unmanaged passwords, obsolete firmware, and patching backlogs can leave systems exposed.
The coalition argues that a federal OT baseline could also influence security practices among private critical-infrastructure operators and vendors.
Another OpenAI safety worker resigns.
David Robinson, who helped write OpenAI’s safety documentation, has resigned, warning that the AI industry isn’t prepared for increasingly capable systems.
Robinson joined OpenAI in 2023 skeptical of catastrophic AI risks. But after working closely with safety teams, he says that changed. In an interview with The New York Times’ Ezra Klein, he points to models getting better at hacking, recognizing when they’re being evaluated, and potentially behaving differently during testing than in deployment. Meanwhile, new capabilities are arriving faster, leaving limited time to test them.
Robinson stresses that this isn’t uniquely an OpenAI problem. He sees an industry-wide mismatch between the potential risks and the rigor of existing safeguards. He argues frontier AI should have operational controls comparable to nuclear power or aviation, while acknowledging that researchers still don’t know how to reliably align increasingly capable systems.
His broader concern is straightforward: the industry is racing toward systems that may exceed human understanding before it has figured out how to control them.
Maryland lawmakers seek funding for Cyber Command’s mental health initiatives.
Maryland’s nine Democratic members of Congress are urging appropriators to approve an additional $11 million for U.S. Cyber Command following five suicides among personnel associated with the command at Fort Meade over a five-week period this summer.
The funding, requested by Cyber Command and NSA chief Gen. Joshua Rudd, would support “High Performance Team Training,” including embedding cleared mental health professionals within cyber units. Lawmakers say cyber operators face unusual strains, including years-long assignments, around-the-clock operations, limited recovery periods, and classified work they often can’t discuss with family members or medical professionals without appropriate clearances.
The delegation argues those conditions can isolate personnel, delay treatment, and ultimately weaken operational readiness. The lawmakers want Congress to establish sustained mental health and suicide-prevention support rather than relying on short-term interventions following tragedies.
Hackers compromised country-code domain registries for TLS certs.
Hackers compromised three country-code domain registries, allowing them to obtain unauthorized TLS certificates for Google and other major services. By manipulating DNS records and nameserver delegations, the attackers could demonstrate apparent control of targeted domains and pass standard certificate validation checks. Google says Chrome has blocked all known fraudulent certificates, but warns others may remain undiscovered and non-Chrome users may still be exposed. The incident did not compromise affected domain owners or certificate authorities, which followed existing validation requirements.
The FBI and French authorities shut down alleged CSAM AI deepfake websites.
The FBI and French authorities have shut down two websites allegedly used to distribute child sexual abuse material, including AI-generated deepfakes, and French authorities arrested a 25-year-old suspected administrator.
The FBI seized the two domains after investigators found the sites advertising hacked, leaked, and stolen material involving minors. Some content allegedly came from victims’ compromised social media accounts, while the sites also sold collections organized by victim and encouraged cryptocurrency payments.
Court documents say the sites distributed material violating the TAKE IT DOWN Act, which criminalizes certain nonconsensual intimate imagery, including deepfakes of real people. Although the sites carried disclaimers denying they hosted illegal material, investigators say administrators facilitated access to it through links and direct transactions.
Ransomware recovery firm CEO indicted for secretly paying attackers.
The US Justice Department has charged the owner of ransomware recovery company MonsterCloud with fraud for allegedly telling customers that he could use proprietary technology to recover their data without paying a ransom, then secretly paying off the attackers. 50-year-old Zohar Pinhasi turned himself in yesterday and pleaded not guilty, then was released on a $2 million bond.
According to prosecutors, between 2018 and 2023, Pinhasi and his co-conspirators paid over $8 million in ransoms to attackers, but billed hundreds of victims more than $19 million in massively inflated recovery fees.
MATCHBOIL keeps simmering.
ESET researchers are tracking the evolution of MATCHBOIL, a custom downloader linked to the Russia-aligned threat group UAC-0099. The malware arrives through spearphishing and is designed to install additional payloads, establish persistence, and maintain contact with command-and-control infrastructure. Since at least 2024, MATCHBOIL has steadily grown more sophisticated, adding stronger obfuscation, sandbox detection, deceptive interfaces, and more persistent communications. ESET says observed victims have all been in Ukraine, including organizations in transportation, manufacturing, and energy.
Apollo software pioneer Margaret Hamilton dies.
And finally, we want to mark the passing of a giant in the world of software engineering - in fact, one of its founders. Margaret Hamilton, the pioneering computer scientist who famously led the team that developed the Apollo missions’ onboard flight software and helped define software engineering as a discipline, has died at the age of 90. After completing her work on the Apollo mission, she continued to work at Draper Labs, and then later founded two software companies of her own and created a software systems modeling language she called the Universal Systems Language or USL.
It should be noted that her work on the Apollo mission was early in her career, and indeed in the nascent days of the entire software engineering discipline, a field she directly helped define. In Margaret Hamilton's own words: "I fought to bring the software legitimacy so that it — and those building it — would be given its due respect, and thus I began to use the term ‘software engineering’ to distinguish it from hardware and other kinds of engineering, yet treat each type of engineering as part of the overall systems engineering process." We honor her legacy today. May she rest in peace.
Stick with us after the break, where we are joined by Sanjay Jeyakumar (San-jay Jake-mar), Co-Founder of Abnormal AI, discussing why AI agents are challenging traditional security models. And how do I hack thee? Let me count the ways.
On our Industry Voices segment, Dave Bittner sat down with Sanjay Jeyakumar, Co-Founder of Abnormal AI, discussing why AI agents are challenging traditional security models. Here’s our conversation.
That was Sanjay Jeyakumar, Co-Founder of Abnormal AI, discussing why AI agents are challenging traditional security models. If you enjoyed this conversation, check out the full interview in the show notes.
How do I hack thee? Let me count the ways.
A suspected Italian cybercriminal has found an unusually literary way to run a botnet. Since April, the PoeLLM malware has infected more than 3,000 servers, primarily by exploiting vulnerable, internet-facing AI services including LiteLLM and Ollama.
Lumen’s Black Lotus Labs says the campaign, dubbed Canto Incognito, is the first real-world attack it has seen using “adversarial poetry.” The malware reads specific words from a seemingly innocuous poem hosted on GitHub and converts them into the IP address of its current command-and-control server. Change the verse, change the C2. Somewhere, Edgar Allan Poe is presumably reconsidering his licensing terms.
Compromised servers are used to mine cryptocurrency and scan for additional victims. Researchers warn that rapidly proliferating, poorly secured AI infrastructure is giving campaigns like this an increasingly large pool of potential targets.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.

