
Let’s kill the kill switch.
Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart phishing scams spread malware. Two alleged sextortionists face U.S. charges. A former DIA insider walks into an FBI sting. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing a controversial retail security bill. Getting local with Nigerian scammers.
Today is Monday August 31st 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Could an AI kill switch prove counter-productive?
In an op-ed, Luke O’Grady, a senior analyst at Venable LLP and the Center for Cybersecurity Policy & Law, argues that Congress’s proposed AI Kill Switch Act could create the very security risks it’s intended to prevent.
The bipartisan bill would give CISA authority to require frontier AI companies to build mechanisms capable of throttling, suspending, or shutting down their systems. O’Grady compares that approach to the NSA’s ill-fated Clipper Chip, which provided government access to encrypted communications but was found to contain a serious security flaw.
He acknowledges the analogy isn’t exact: an AI kill switch threatens system availability rather than communications confidentiality. But he argues both approaches deliberately introduce potential points of failure. As AI agents become embedded in critical infrastructure, he says those controls could undermine resilience and international confidence in American technology.
O’Grady instead calls for stronger red-teaming, security requirements, liability frameworks, and completed AI-agent security standards before Congress acts.
A Ruby on Rails vulnerability is under active exploitation.
Hackers are actively exploiting a critical Ruby on Rails vulnerability that can lead to remote code execution, according to VulnCheck. CVE-2026-66066, dubbed KindaRails2Shell, carries a CVSS score of 9.5 and exploits differences in how Rails and image-processing libraries interpret uploaded files. Attackers can craft malicious files that ultimately cause the server to read and expose arbitrary files, including credentials and storage keys. Those stolen secrets can then be used to forge sessions, move laterally, and potentially execute code remotely.
Rails patched the vulnerability in late July, but VulnCheck says exploitation began roughly a month later. Researchers had identified about 7,000 exposed, vulnerable Rails instances in early August. VulnCheck also warns that its testing found a related deserialization path could still enable code execution on a patched server if an attacker possesses a valid signature.
A malware campaign uses Chrome and Edge extensions to steal cryptocurrency.
Researchers at Socket have uncovered a malware campaign using Chrome and Edge extensions to steal cryptocurrency, credentials, browser history, and other sensitive data. The operation, potentially active since early 2024, includes 19 specialized malware modules. Some extensions initially behaved legitimately before being acquired from their original developers and turned malicious through automatic updates.
Once installed, the malware connects to command-and-control servers and injects malicious scripts into websites. Its capabilities include hijacking cryptocurrency transactions, stealing wallet seed phrases, harvesting sessions and account data from major crypto platforms, recording credentials, and collecting Facebook and LinkedIn information. It can also display ClickFix-style fake browser updates that trick users into executing malicious commands.
Google has removed the identified extensions from the Chrome Web Store. Socket advises affected users to change passwords and cryptocurrency holders to move assets to new wallets.
Chinese-linked cyberespionage group Fire Ant expands its operations.
Chinese-linked cyberespionage group Fire Ant has expanded its operations from individual systems to the network infrastructure connecting high-value targets, according to Sygnia. Investigators found the group compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts, using trusted infrastructure as a pathway into connected networks, including critical infrastructure.
Fire Ant deployed specialized router implants that manipulated logging and concealed malicious activity, while malware injected into a TACACS authentication process captured credentials from legitimate administrator sessions. On Linux systems, persistent backdoors were disguised as legitimate services, and attackers altered login and system logs to erase evidence of their activity.
Sygnia says the campaign demonstrates that routers, authentication servers, and jump hosts can themselves become strategic targets, and warns defenders that logs on deeply compromised infrastructure can no longer automatically be treated as ground truth.
Claude Code gets tricked by summarizing a malicious website.
Security researcher Johann Rehberger says Anthropic’s Claude Code running Opus 5 in Auto Mode can be manipulated into executing attacker-controlled code through an indirect prompt-injection attack. The exploit begins when Claude is asked to summarize a malicious website. After its normal retrieval tool fails, the agent uses curl, downloads a crafted ZIP archive, and ultimately writes its own Python decoder.
That safety-driven decision opens the door to Python module shadowing: a malicious struct.py file in the archive is loaded instead of Python’s legitimate module, triggering a remote payload. Rehberger also demonstrated an attack that launches a second Claude Code agent with its own tool access.
In limited testing, the techniques succeeded 60 to 80 percent of the time. Rehberger says coding agents should be sandboxed, with OS isolation and network controls providing the real security boundary.
Phishing campaigns impersonate MyChart to steal personal information or install malware.
Health systems are warning patients about phishing campaigns impersonating MyChart to steal personal information or install malware. Epic, the company behind MyChart, says scammers are increasingly copying its branding in emails, texts, calls, and fake websites, but stresses that the activity doesn’t stem from a security problem with MyChart itself.
One campaign tells recipients that test results are ready, then directs them to a convincing fake login page. Victims may then see fabricated medical records and alarming claims that an AI review found serious health problems. The manufactured urgency pushes users toward supposed verification steps or downloads that can install malware.
Epic says legitimate MyChart results don’t require downloading software. Anyone who falls for the scam should reset their password, verify their account contact information, and contact their healthcare organization’s help desk.
Two Nigerian men face U.S. charges in deadly sextortion cases.
Two Nigerian men extradited to the United States have been charged in connection with sextortion schemes that authorities say resulted in the deaths of two minors in Mississippi and North Carolina.
Adebola Festus Adekunle, 26, and Mudasiru Afeez Olawale, 24, were arrested in Nigeria in 2023 during Operation Artemis, an international effort targeting Nigerian sextortion rings accused of victimizing minors worldwide. The men face multiple charges involving sexual exploitation, coercion, extortion, and child sexual abuse material. Adekunle is also charged with sexual exploitation of a minor resulting in death, which carries a minimum 30-year prison sentence.
The extraditions follow renewed FBI warnings about criminals stealing or coercing victims into providing explicit images and then using the material for blackmail. Authorities advise victims to stop communicating with extortionists and contact law enforcement immediately.
A former DIA IT specialist pleads guilty after walking into an FBI sting.
A former Defense Intelligence Agency IT specialist has pleaded guilty to attempting to transmit classified information to a foreign government after walking into an FBI sting.
Nathan Vilas Laatsch, who held a top-secret clearance, contacted what court documents describe only as a friendly foreign government in March 2025 and offered classified intelligence. The FBI intercepted the outreach and posed as a foreign intelligence contact.
Laatsch then copied classified material by hand at work, concealed pages in his socks and lunchbox, and transferred the information to digital media. At his first dead drop in an Arlington, Virginia, park, the FBI recovered nine documents, eight containing top-secret information, including intelligence collection methods and material on foreign military exercises.
Laatsch, ironically assigned to DIA’s Insider Threat Division, was arrested during a second transfer in May 2025. His plea agreement recommends a prison sentence of 11 to 18 years, though the court could impose a life sentence.
Monday business briefing.
Cybersecurity and AI companies announced roughly $146 million in new funding across two deals. Israeli AI safety company Alice, formerly ActiveFence, raised $140 million in a round led by Apax Digital. The company plans to expand its AI testing, defense, and monitoring platform, its Rabbit Hole threat dataset, and its go-to-market operation. Danish AI visibility startup Velatir raised about $5.8 million to support European expansion.
On the M&A front, Munich Re agreed to acquire cyber insurer At-Bay for $575 million, aiming to combine insurance with continuous cyber risk mitigation. Exposure management company Brinqa acquired pentest management firm PlexTrac, adding remediation verification capabilities.
Elsewhere, British MSSP Redsquid acquired IT consultancy ARK ICT, strengthening its education-sector business. Utah-based Nexus IT acquired Austin’s Loyal IT, while TalkTalk Business is merging with MSSP ARO to create a UK technology group with roughly 650 employees and 70,000 organizational customers.
Getting local with Nigerian scammers.
Scam experts Erin West and Paul Raffile decided to chase Nigerian sextortionists all the way to their home turf and discovered an industry operating with remarkable confidence.
In an interview with 404 media, the pair describe creating fake teenage social media accounts and quickly attracting scammers posing as young women. They then offered Bitcoin payments through a tracking site that captured the scammers’ IP addresses, pointing them toward Lagos. Once in Nigeria, additional tracking revealed one suspect’s face, phone number, social media accounts, and eventually his apparent location.
Their investigation led them to a scammer known as “Big Dollar.” He refused to meet, but West called to tell him they knew his identity and location and planned to give the information to the FBI. His social media accounts soon disappeared.
Along the way, West and Raffile even witnessed a spiritual ritual intended to improve a scammer’s fortunes. Apparently, for some cybercriminals, operational security includes both browser permissions and supernatural assistance.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
