
Clear your calendar, it’s Patch Tuesday.
Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sextortion. Andy Hornegold, Chief Security Technologist from Intruder, discusses what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Putting AI at the head of the class.
Today is Wednesday September 9th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Patch Tuesday is a doozy.
Microsoft’s September Patch Tuesday is its largest on record, with the company reporting fixes for 966 vulnerabilities. Independent tallies vary slightly, but all point to an unusually heavy month: 105 vulnerabilities are rated Critical, 258 involve remote code execution, and 438 involve privilege escalation.
Two Windows zero-days were already being exploited. CVE-2026-81963 affects the Windows Update Stack and can allow a local attacker to gain SYSTEM privileges. CVE-2026-85880, a buffer overflow in Windows ALPC, can let an attacker escape a low-privilege AppContainer and reach SYSTEM. Neither provides an initial remote foothold; both are useful for escalating privileges after a system has already been compromised.
Microsoft also patched critical vulnerabilities across core networking services, including DNS, DHCP, Netlogon, Message Queuing and NFS. CrowdStrike identified at least 17 remote-code-execution flaws reachable over the network without authentication. Office received 22 Critical fixes, including vulnerabilities that could potentially execute code when a malicious file is merely previewed. Hyper-V flaws could enable attacks from a compromised guest virtual machine against its host.
The broader September patch cycle is similarly busy. Adobe fixed more than 170 vulnerabilities, including an actively exploited, unauthenticated Commerce and Magento RCE zero-day. Google patched 230 Chrome vulnerabilities, including the browser’s seventh exploited zero-day of 2026. Ivanti addressed six Critical RCE vulnerabilities in Neurons for ITSM, while Schneider Electric, Siemens, Aveva and Rockwell Automation issued updates covering industrial systems.
The Feds warn China-based AI companies are distilling U.S. AI models.
CISA, the NSA, and FBI are warning that China-based AI companies have been systematically extracting capabilities from leading U.S. AI models through large-scale knowledge distillation campaigns. The agencies say DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have extracted billions of tokens through millions of requests involving models including Claude, GPT, Gemini, and Grok since at least late 2024.
Knowledge distillation is a legitimate technique for training smaller models using outputs from more capable ones, but the advisory says these campaigns violate U.S. providers’ terms of service and accelerate Chinese AI development. The agencies assess the activity is occurring likely with Chinese government awareness.
The advisory urges U.S. AI companies to improve detection of suspicious accounts and usage patterns, alter responses to suspected distillation attempts to reduce their value, and share intelligence across model providers, cloud platforms, and API aggregators.
Space-Cyber story
This past Saturday, September 5th, Isar Aerospace of Germany made history with the first launch to orbit from the European continent. Isar's Spectrum rocket launched from Andoya Spaceport in Norway, and successfully deployed six satellites to low earth orbit. Isar is a commercial space company with large backing from the European space agency, and this successful launch from Norway means Europe will now have launch options much closer to home, beyond the ESA spaceport in French Guiana. With the proven ability to launch to orbit from European soil with homegrown European rocketry, the push now is to scale up and increase launch cadence to meet growing demand from European customers. Isar says four additional Spectrum rockets are already in production, and that the company plans to manufacture up to 40 Spectrum launch vehicles a year when their new production facility is complete. In all, Isar's successful orbital launch is a major step forward for European space sovereignty, especially as Europe continues to build out its high-priority secure satellite communications constellation, the Iris^2.
A new ClickFix campaign goes straight for the browser.
Cisco Talos is tracking a cryptocurrency theft campaign that puts a twist on ClickFix social engineering: instead of persuading victims to execute commands on their computers, attackers convince them to inject malicious JavaScript directly into their browsers.
The lure is a fake vulnerability report promising bigger payouts from cryptocurrency exchanges. Victims are instructed either to paste JavaScript into Chrome or install it through the legitimate Tampermonkey extension, which gives the malware persistence. The attackers have promoted the supposed exploit through Telegram, dark web forums, and paste sites.
The injected code uses Google’s Visualization API to retrieve obfuscated JavaScript stored in publicly accessible Google Sheets, making command-and-control traffic look like legitimate browser activity. Once running, the script acts as a web skimmer, replacing cryptocurrency deposit addresses in website responses and the clipboard with attacker-controlled wallets while displaying fake bonus information.
Talos identified 49 Bitcoin addresses associated with the campaign and traced roughly $10,000 to known victim payments, though the actual haul may be higher.
Smart TVs get nosy.
An investigation by Gamers Nexus, Level1Techs, and independent security researchers found LG smart TVs extensively collecting information about owners and their homes. Tests found the TVs scanning local networks for nearby devices, gathering location and Wi-Fi data, and sending information to LG Ad Solutions. Researchers also found the TVs could record microphone audio while in standby, storing recordings offline until internet access returned. LG’s Automatic Content Recognition technology additionally samples audio and video to identify content viewed through smart TV apps and connected devices, including HDMI inputs.
Hackers gift themselves a $47 million bug bounty.
A $320 million cryptocurrency theft from Liquid Network ended with the attackers returning most of the money — and keeping about $47 million as a self-appointed bug bounty.
Liquid said “purported white-hat hackers” withdrew 4,000 bitcoin from one of its wallets Sunday, prompting operator Blockstream to pause deposits and withdrawals. The attackers then opened negotiations through messages embedded in blockchain transactions, claiming they were white hats and demanding that Blockstream patch an alleged vulnerability before they returned the funds.
After roughly 12 hours of public and private exchanges, the hackers returned about $266.5 million Monday and retained 598.5 bitcoin as their “reward.” Blockstream said updated software had been deployed as it prepared to restart the system.
The vulnerability’s source remains debated, although SideSwap and several blockchain security experts have pointed to a flaw in Elements, the software underlying Blockstream’s Liquid sidechain.
An Ohio man gets 15 years in federal prison for cyberstalking and sextortion.
An Ohio man has been sentenced to 15 years in federal prison for a cyberstalking and sextortion campaign that used artificial intelligence to create sexually explicit material depicting his victims.
Prosecutors say 37-year-old James Strahler II used more than 100 AI models across more than two dozen platforms to generate explicit images and videos. Between December 2024 and June 2025, he harassed at least six adult women, sending both authentic and AI-generated nude images, threatening victims with sexual violence, and sharing fabricated explicit material with their co-workers. He also threatened victims’ mothers in an effort to obtain nude photographs.
Investigators found more than 700 images Strahler had posted to a child sexual abuse website, along with thousands of potentially abusive or violent files on his phone.
Strahler pleaded guilty in April and became the first person convicted under the 2025 Take It Down Act, which prohibits publishing intimate images and AI-generated explicit forgeries without consent.
Putting AI at the head of the class.
Alpha School is betting that the future of education looks a little like a self-driving car: feed an AI enough examples of wrong turns, unexpected obstacles and student misconceptions, and eventually it learns to navigate.
At Alpha, students spend about two hours each morning with adaptive AI tutors, followed by workshops in coding, entrepreneurship and other “life skills.” The private-school company, where tuition can reach $75,000 a year, plans to expand to roughly 50 U.S. campuses this fall.
There’s evidence behind parts of the concept. Research has found adaptive AI tutoring can improve learning, including a Harvard study where students using an AI tutor achieved more than twice the median learning gains of students using classroom active-learning strategies.
But researchers caution that effective tutoring isn’t necessarily effective schooling. Critics worry about replacing trained teachers, weakening teacher-student relationships, and producing knowledge that works inside the software but doesn’t travel well outside it. The AI tutor may know the route. Whether it should drive the whole school bus remains another question.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
