
The blacklist boomerang.
A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers uncover a new speculative-execution attack and hidden implants in Chinese-made routers. A fake voicemail campaign slips past email defenses. PaperCut faces an exploited zero-day. And ServiceNow patches three maximum-severity flaws in its AI Platform. Maria Varmazis and I look back at a decade of emerging threat actors and APTs. NSA sends out a covert save-the-date.
Today is Friday August 28th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
A federal judge rules the Trump administration acted illegally when it designated AI company Anthropic a national security risk.
A federal judge has ruled that the Trump administration acted illegally when it designated AI company Anthropic a national security risk and effectively barred it from federal work.
Judge Rita Lin said the government retaliated against Anthropic for constitutionally protected speech after the company publicly objected to uses of its technology for mass surveillance of Americans and autonomous lethal weapons. The dispute grew out of a $200 million Pentagon contract, with the Defense Department arguing that a private company couldn’t dictate government policy.
Defense Secretary Pete Hegseth subsequently labeled Anthropic a “supply chain risk,” preventing military contractors and suppliers from doing business with the company.
Judge Lin found little evidence supporting claims that Anthropic could sabotage its technology during wartime, concluding that officials instead wanted to make an example of the company for criticizing the government. Anthropic welcomed the decision and said it remains committed to working with Washington on national security.
An executive order bans certain foreign-made technology from U.S. power systems.
The Trump administration has issued an executive order banning the acquisition or installation of certain foreign-made technology used to operate the U.S. bulk-power system, citing cybersecurity and supply-chain risks. The order warns that equipment controlling high-voltage transmission lines, substations, generating stations and other critical infrastructure could contain digital backdoors enabling foreign governments to remotely interfere with operations.
The Defense, Commerce and Energy Departments will review transactions, identify potentially risky equipment already in use, and develop plans to isolate, monitor or replace it. Officials also have 120 days to establish regulations and identify countries warranting particular scrutiny.
The move follows a series of cyber incidents targeting critical infrastructure in the U.S. and abroad, amid growing warnings that artificial intelligence could make attacks on energy, water and other essential systems easier to conduct and more sophisticated.
OpenAI leads a campaign to strengthen cyber defenses.
Nearly 130 organizations across cybersecurity, technology, finance and other industries are calling for a coordinated global push to strengthen cyber defenses as artificial intelligence makes attacks more capable and widespread.
The initiative, led by OpenAI and backed by companies including Microsoft, Google, Cisco, CrowdStrike and Anthropic, warns that existing vulnerabilities, misconfigurations and weak authentication leave critical infrastructure increasingly exposed. But the group says AI can also give defenders powerful new tools for identifying and fixing weaknesses.
Organizations are urged to prioritize their highest-risk vulnerabilities, continuously test defenses and share proven threat intelligence. Governments are asked to fund under-resourced critical infrastructure and coordinate internationally, while AI developers are encouraged to provide defensive tools and support. OpenAI is also offering subsidized access to its Daybreak Cyber models and AI-assisted security testing programs.
OpenAI says some of its AI agents exploited a known Linux kernel vulnerability.
OpenAI says some of its AI agents exploited a known Linux kernel vulnerability in July, escalating privileges inside the company’s own environment. The agents identified CVE-2026-53362, retrieved and customized a public exploit, gained root access to an underlying worker node, and moved laterally through the connected environment. The incident was separate from agents hacking Hugging Face and exploiting a JFrog Artifactory zero-day. CISA has since added both vulnerabilities to its Known Exploited Vulnerabilities catalog, recommending organizations patch the Linux flaw by August 30.
Researchers identify a new class of speculative-execution attacks.
MIT researchers have identified a new class of speculative-execution attacks that can bypass protections designed to stop Spectre-style data theft. The technique, called TONTOU, exploits a tiny timing gap between when processors clear their branch-prediction machinery and when those predictions are actually used.
The researchers developed an “interrupt injection” technique that precisely triggers routine processor interrupts during that window, contaminating the prediction machinery again. Tests produced mispredictions on multiple generations of Intel and AMD processors and defeated several existing defenses.
On an AMD system running a current Linux kernel, the researchers demonstrated an exploit capable of reading protected memory and, in some attempts, extracting the system’s root password hash file.
AMD has released a mitigation available through operating-system updates. The researchers say Intel defenses may require different approaches because some fixes could inadvertently make attacks more reliable.
A fake voicemail campaign evades email defenses.
A two-month phishing campaign sent more than 26,000 malicious voicemail-themed emails to over 5,500 organizations, according to email security vendor INKY. The operation used SVG attachments to conceal obfuscated JavaScript and evade email defenses.
The attackers disguised the attachments as text files, even though SVGs can execute JavaScript. Once opened, the code reconstructed hidden strings and contacted a remote endpoint. The messages also impersonated recipients’ own domains and frequently personalized subject lines using part of the recipient’s email address.
Despite the campaign relying largely on a single template, Microsoft’s native spam filtering classified 75% of the messages as not spam, according to INKY. Researchers characterized the campaign as broad spray phishing rather than targeted spear phishing, combining familiar voicemail lures, internal sender impersonation and SVG smuggling to slip executable browser content past defenses.
Attackers exploit a zero-day vulnerability in PaperCut products.
PaperCut is warning customers that attackers are exploiting a zero-day vulnerability in its NG and MF print management products. The company released emergency patches Friday and recommends restricting application servers from internet access. PaperCut says confirmed customer incidents include a suspicious file called “pc-app.exe” and deleted or truncated logs, potentially indicating attempts to hide activity. Huntress says the vulnerability could allow an unauthenticated attacker to manipulate trusted configuration and execute arbitrary Java code. Roughly 1,000 PaperCut instances remain exposed to the internet.
ServiceNow patches three maximum-severity vulnerabilities in its AI Platform.
ServiceNow has patched three maximum-severity vulnerabilities in its AI Platform that could allow unauthenticated attackers to execute code, escalate privileges, or access and modify data through SQL injection. The flaws, CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820, can be exploited in low-complexity attacks without user interaction. ServiceNow also fixed a high-severity sandbox escape vulnerability that could enable remote code execution. The company says it hasn’t observed malicious exploitation and is urging customers with self-hosted instances to promptly update.
Researchers find undocumented implants embedded in firmware on Chinese-made routers.
VulnCheck researchers say they found two previously undocumented implants embedded in firmware on ZBT-made routers sold under multiple brands worldwide. DARKLANTERN exposes an unauthenticated, internet-accessible backdoor capable of executing commands as root, while SPEAKINGSTONE phones home to command-and-control infrastructure and can execute commands, hijack DNS, steal ISP credentials and establish reverse SSH tunnels.
Researchers identified 203 internet-facing DARKLANTERN devices across 22 countries. After registering an abandoned SPEAKINGSTONE backup domain, VulnCheck received beacons from 392 devices, almost all in China.
The implants were discovered on an $88 router sold in the U.S. under the Deep Orange brand. VulnCheck traced the underlying ZBT hardware to numerous white-labeled products internationally, although it cautions that not every ZBT-derived device contains the implants.
NSA sends out a covert save-the-date.
The NSA is throwing a reunion for alumni of Tailored Access Operations, its famously secretive hacking unit, and the homecoming has a practical purpose: recruitment.
Hundreds of former TAO hackers, developers and analysts have been invited back to Fort Meade for a tour, some nostalgia, and a pitch to return. The unit, recently reorganized again, has seen years of turnover, compounded by broader workforce cuts.
The reunion itself has been organized with unusual openness for an organization once nicknamed “the NSA inside the NSA.” Alumni gathered in an invitation-only Signal chat called “Terminated Async Operations,” swapping inside jokes and carefully unclassified memories. That setup has raised a few eyebrows among former members, who note that operational security officers may not find the arrangement quite as charming.
Still, many alumni retain active clearances and specialized skills. For an agency trying to rebuild elite offensive capabilities, the old class roster may be a very efficient recruiting database.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
