The CyberWire Daily Podcast 9.4.26
Ep 2630 | 9.4.26

What the Flock?

Transcript

The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.” Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age. 

Today is Friday September 4th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

The G7 and CISA say prepare now for quantum cybersecurity risks.

The G7 and CISA are urging governments and businesses to start preparing now for the cybersecurity risks posed by quantum computing. While the timeline for sufficiently powerful quantum machines remains uncertain, advances could eventually allow attackers to break widely used encryption.

The threat isn’t entirely in the future. Attackers can steal encrypted data today and hold onto it until quantum computers can decrypt it — the so-called “harvest now, decrypt later” strategy. That puts long-lived secrets, including government records, personal information and corporate intellectual property, at particular risk.

The advisory recommends identifying sensitive systems and critical assets, prioritizing them for migration to post-quantum cryptography, and incorporating quantum-resistant technology into routine upgrades. Starting early, officials say, should make the transition cheaper and less disruptive. The guidance follows similar efforts in the U.K., which has called for organizations to complete their migration to quantum-resistant cryptography by 2035.

Nightmare Eclipse drops a CrowdStrike zero-day. 

Security researcher Nightmare Eclipse has expanded their zero-day campaign beyond Microsoft, publishing vulnerabilities affecting several endpoint security products. The latest, dubbed FalconFlank, is a privilege-escalation flaw that allegedly abuses CrowdStrike Falcon’s Microsoft Office macro-removal feature. CrowdStrike says it’s investigating and recommends customers disable the affected policy setting while retaining other Office malware protections.

Security researcher Kevin Beaumont says he confirmed FalconFlank works, along with several other recently released exploits from Nightmare Eclipse. Those include HardBreacher, an elevation-of-privilege vulnerability affecting Kaspersky Endpoint Security, and PrettyPrague, an Avast flaw that can reportedly provide SYSTEM privileges. Gen Digital says it’s developing a patch for the Avast issue.

Nightmare Eclipse has also published GreenSection, an Nvidia memory-corruption zero-day that Beaumont says can crash affected systems. Kaspersky and Nvidia did not respond to requests for comment.

The White House’s offensive hacking initiative could strip participants’ legal protections. 

A White House initiative allowing vetted private companies to conduct cyber operations against foreign criminal groups could strip those firms of legal protections they currently use for defensive cybersecurity work, experts warn.

President Trump’s August memorandum puts participating companies under federal control, with Justice and Homeland Security officials approving operations. Former DOJ cybercrime official Leonard Bailey said that government-agent status could complicate protections under laws governing information sharing, communications interception and defensive measures.

Experts also flagged risks beyond U.S. law. Companies could violate foreign hacking statutes, face retaliation from criminal groups with government ties, and damage their standing in international markets. Threat intelligence executive Alex Orleans also warned that vendors may overestimate their ability to accurately attribute malicious infrastructure.

The risks could be especially significant for smaller, inexperienced contractors. With agencies still developing the program’s rules, experts say the legal, financial and geopolitical consequences need considerably more scrutiny.

CISA and its partners issue guidance on communications during a cyber incident. 

CISA, the FBI, and cybersecurity agencies from Australia, Canada, New Zealand and the U.K. have issued guidance urging service providers to communicate more clearly during major IT and operational technology outages. The agencies say effective communication can be as important as technical remediation in limiting disruption and speculation. 

Organizations should prepare communications plans in advance, establish clear roles and backup channels, and tailor messages for technical teams, executives, customers, regulators and the public. During an incident, providers should quickly explain what’s affected, what’s known about the cause, and what remains uncertain — while avoiding speculation and PR language.

The guidance also recommends maintaining a single source for continuous, time-stamped updates, providing actionable technical information, coordinating with legal and law enforcement partners, and eventually explaining the root cause and planned security improvements.

OpenAI pledges $1 billion to subsidize access to its cybersecurity models. 

OpenAI has pledged $1 billion to subsidize access to its Daybreak cybersecurity models for essential services, beginning in the United States and later expanding to partner countries. The Daybreak for Frontline Defenders initiative will help organizations in sectors including water, electricity, local government, banking and nonprofits integrate OpenAI’s models into existing security tools and workflows.

OpenAI says Daybreak can help resource-constrained defenders analyze suspicious activity, review legacy code, identify vulnerabilities, prioritize risks and develop fixes. A pilot with the Multi-State Information Sharing and Analysis Center will provide Daybreak access, training and hands-on support to an initial group of U.S. public-sector and water-system defenders.

The commitment follows an industry warning that defenders have a narrowing window to use frontier AI before AI-enabled attacks pose greater risks to critical public services.

Researchers uncover a severe PostgreSQL vulnerability. 

Cybersecurity firm Cyera has disclosed a severe PostgreSQL vulnerability affecting releases dating back to 2014. Dubbed PostGREShell and tracked as CVE-2026-6471, the flaw can allow attackers with Replication privileges to execute code and escalate to database superuser.

The vulnerability stems from insufficient authorization in PostgreSQL’s logical decoding functionality. Cyera found that attackers can supply a filesystem path as a plugin name, causing PostgreSQL to load malicious code with the privileges of the server process. From there, an attacker could access databases, execute operating system commands, steal sensitive files and establish persistent backdoors.

Cyera says PostgreSQL versions 9.4 through 18 are affected. Fixes are available in versions 18.6, 17.11, 16.15, 15.19 and 14.24. Organizations should patch promptly and audit accounts with Replication privileges.

Google patches an actively exploited Chrome zero-day. 

Google has updated Chrome to patch an actively exploited zero-day vulnerability in its V8 JavaScript and WebAssembly engine. Tracked as CVE-2026-85046, the high-severity type confusion flaw could potentially allow remote code execution through malicious JavaScript on a crafted webpage. Google has withheld exploitation details while users apply the fix. The update also addresses 11 other vulnerabilities, including nine high-severity memory-safety flaws. Updated Chrome versions are rolling out for Windows, macOS and Linux.

Broadcom patches serious VMware Workstation and Fusion vulnerabilities. 

Broadcom has patched two serious VMware Workstation and Fusion vulnerabilities that could allow attackers with administrative privileges inside a virtual machine to execute code on the host. CVE-2026-59346, rated critical at 9.3, is an integer overflow affecting systems using the VMXNET3 adapter. CVE-2026-59347 is a high-severity stack-based buffer overflow. Both affect versions 25H2 and 26H1 and are fixed in 26H1u1. Broadcom says no workarounds are available and recommends updating promptly.

A new WordPress plugin flaw is under active exploitation. 

Attackers are actively exploiting a critical vulnerability in the Elementor Pro WordPress plugin to upload webshells and execute arbitrary commands. CVE-2026-32475 affects versions 4.2.1 and earlier and stems from faulty validation of file-upload arrays in Elementor forms.

Wordfence says exploitation began August 19, the same day Elementor released version 4.2.2 with a fix, and has blocked nearly 200,000 attempts. Exploitation requires a published Elementor Pro Form widget with a File Upload field. Attackers can bypass validation to upload malicious PHP files, which are then accessible for remote command execution.

Administrators should immediately upgrade to Elementor Pro 4.2.2 or later and inspect the plugin’s form-upload directory for PHP files, which Wordfence says are a strong indicator of compromise.

Proposed legislation looks to tell license plate readers to “Flock off.”

Representatives Thomas Massie and Eric Burlison have introduced the “Flock-Off Act,” which would prohibit federal funding for automated license plate readers and biometric surveillance cameras. The bill wouldn’t ban Flock Safety cameras outright, but federal agencies would have to remove federally funded systems, while state and local recipients would have 180 days to stop operating them. Toll-collection systems would be exempt.

The bipartisan group of seven sponsors argues that Flock’s expanding license plate reader network enables mass surveillance of law-abiding Americans. Flock cameras record information including license plates, vehicle characteristics, time and direction of travel. Flock says its technology helps law enforcement solve crimes and locate missing people and stolen vehicles.

The proposal comes amid growing local resistance to Flock systems, with nearly 150 communities reportedly canceling contracts, rejecting deployments or deactivating cameras over privacy and oversight concerns.

Camouflage for the algorithmic age. 

Berlin artist Simon Weckert has found a fashionable way to protest AI surveillance: become invisible to the algorithm. His “digital camouflage” uses colorful patterns designed to confuse YOLO, a popular family of object-recognition models. Hold the fabric in front of a person, and the camera’s reassuringly confident “PERSON” label suddenly has second thoughts.

Weckert developed the project after Berlin police deployed the city’s first object-recognition surveillance cameras, capable of identifying people and potentially flagging behaviors such as loitering or someone lying down. By repeatedly modifying patterns and testing YOLO’s confidence, he produced designs that can prevent the algorithm from recognizing a person.

There is a catch: police haven’t disclosed what technology their cameras use, so Weckert can’t say his camouflage works against them. And as recognition systems evolve, his patterns will need updates. Surveillance-resistant fashion, apparently, also has seasonal collections.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.