The CyberWire Daily Podcast 9.14.26
Ep 2635 | 9.14.26

Bigfoot in the neural network.

Transcript

NSA preps a major restructuring. Anthropic’s CEO calls for an AI slowdown. China acknowledges AI risks. RubyGems got swarmed by AI agents. A maximum-severity GitLab vulnerability is under active exploitation. Direct Send abuse makes phishing emails appear legit. A British fintech firm leaks sensitive customer info. LinkedIn wins a legal dispute over browser extension scanning. Monday business briefing. Our guest is Tim Starks, senior reporter at CyberScoop, sharing government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. Finding Bigfoot in the neural network. 

Today is Monday September 14th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

NSA preps a major restructuring. 

The Washington Post reports the National Security Agency is preparing its biggest internal overhaul in at least a decade. Director Gen. Joshua Rudd’s plan would create five new mission organizations focused on artificial intelligence, China, cybersecurity, warfighting support, and global intelligence, each led by a powerful mission director with authority approaching that of an NSA deputy director.

It’s not yet clear whether those organizations will replace existing divisions or simply sit on top of them. The revived Tailored Access Operations hacking unit would fall under global intelligence and is reportedly in line for a significant budget increase.

The timetable is unusually aggressive. Mission directors are expected to submit organizational plans by the end of September, with rollout beginning in mid-October and full operations targeted for January 2027. That’s a sharp contrast with the NSA’s last major restructuring, launched in 2016 with a two-year runway and, according to a former official, still not entirely finished.

Anthropic’s CEO calls for an AI slowdown. 

Anthropic CEO Dario Amodei is calling on the AI industry to deliberately slow the improvement of frontier models, warning that their capabilities may be advancing faster than researchers can understand or control them. He pointed to the July OpenAI–Hugging Face incident, where AI agents escaped their testing environment, as a relatively harmless preview of what more capable, misaligned systems might do. Amodei warned that within months, rogue AI agents could potentially compromise internet infrastructure on a massive scale.  

His proposal includes embedding independent evaluators inside AI companies, establishing shared safety standards among companies and democratic governments, and pursuing international coordination. Amodei also argued that advanced AI is too consequential to remain governed solely by private companies, suggesting some form of joint democratic oversight.

The warning follows the resignation of Anthropic researcher Jacob Coxon, who accused Anthropic and OpenAI of racing toward potentially dangerous superintelligence. More than 1,300 workers from major AI companies have also reportedly called for government intervention. Amodei’s appeal subsequently drew support from other prominent industry leaders, including OpenAI CEO Sam Altman and Elon Musk.  

Critics, however, question both the severity of the threat and the industry’s motives. Some argue that dramatic warnings inflate AI’s perceived capabilities, while others worry regulations favored by established companies could make it harder for smaller competitors to enter the market.

The debate is increasingly political. President Donald Trump has rejected calls for a significant slowdown, arguing that restraining American development risks surrendering the AI race to China. His administration has generally favored accelerating AI investment and reducing regulatory barriers.  

The result is an unusual divide: some of the people building the world’s most powerful AI systems are now asking governments to constrain them, while policymakers debate whether applying the brakes would make the technology safer, or simply allow competitors to pull ahead.

China acknowledges AI risks. 

China’s Ministry of State Security has issued its first public warning about AI risks, focusing on threats to political stability, cybersecurity, sensitive data and military systems. State security minister Chen Yixin said hostile actors could use deepfakes, AI-generated content and automated influence campaigns for “cognitive warfare” against China. Beijing isn’t calling for slower AI development, but officials are reportedly increasingly concerned about advanced AI hacking capabilities and potential data leaks from foreign models, potentially foreshadowing tighter restrictions on their use.

RubyGems got swarmed by AI agents. 

Researchers say an OpenAI agent swarm was responsible for a May cyberattack that flooded the RubyGems open-source package manager with malicious packages, temporarily forcing it to suspend new registrations. According to the Nightingale Collective, the “GemStuffer” campaign exploited RubyGem’s automated build system to achieve remote code execution on RubyDoc.info servers and attempted to use a novel zero-day to steal API keys.

Researchers linked the activity to OpenAI agents through package names, authorship markers and techniques resembling those seen in another agent attack on a German wiki. Curiously, much of the information retrieved was already-public UK local government data.

OpenAI subsequently confirmed its agents used RubyGems during training and evaluation, characterizing their tasks as benign attempts to access public information. The company said it’s continuing to investigate agent activity.

 A maximum-severity GitLab vulnerability is under active exploitation. 

CISA says attackers are actively exploiting CVE-2026-85706, a maximum-severity GitLab vulnerability that allows unauthenticated attackers to read credentials, secrets and other sensitive files from vulnerable servers. GitLab patched the flaw in Community and Enterprise editions last week and urged immediate updates. Security firm watchTowr subsequently observed in-the-wild probing for vulnerable systems. CISA added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies three days to remediate it while urging private-sector organizations to prioritize patching as well.

Direct Send abuse makes phishing emails appear legit. 

KnowBe4 Threat Labs says attackers are abusing Microsoft 365’s Direct Send feature to make phishing emails appear to come from inside a victim’s organization. Direct Send was designed to let printers, scanners and legacy applications send mail without accounts, but attackers can exploit the same path without credentials.

Researchers identified nearly 30,000 confirmed spoofs during July and August, commonly impersonating HR, accounting and administrators. Lures included fake documents, voicemail alerts, invoices and OneDrive file shares designed to steal credentials or facilitate business email compromise.

The messages often succeed because organizations leave DMARC in monitoring mode, allowing authentication failures to be delivered anyway. KnowBe4 recommends enforcing DMARC, restricting Direct Send to authorized IP addresses—or disabling it entirely when unnecessary—and hunting for apparently internal messages marked by Exchange as anonymously authenticated.

A British fintech firm leaks sensitive customer info. 

British firm Revolut says fraudsters tricked the fintech into disclosing sensitive customer information by submitting fraudulent emergency data requests from a legitimate government email account. The attackers appear to have targeted high-net-worth individuals, including cryptocurrency entrepreneurs, and allegedly used an Italian government domain, though that detail hasn’t been confirmed.

Revolut says only a limited number of customers were affected. Exposed information reportedly included contact details, identity documents and selfies, bank statements, IBANs, withdrawal records and transaction histories. The attackers also reportedly demanded an extortion payment to prevent publication of the data, though Revolut declined to confirm that claim.

The company says it blocked the compromised address and notified authorities and regulators. The scheme resembles earlier attacks in which compromised law-enforcement accounts were used to submit fraudulent emergency data requests to technology companies.

LinkedIn wins a legal dispute over browser extension scanning. 

LinkedIn has won dismissal of two proposed class-action lawsuits accusing it of improperly scanning users’ browser extensions. A federal judge ruled that the plaintiffs failed to establish standing because they didn’t show that LinkedIn actually collected private information from extensions installed on their browsers.

The judge allowed the plaintiffs to amend their complaints but expressed doubt they could ultimately establish a privacy violation, noting that browser extensions intentionally expose certain information to websites.

LinkedIn says it detects extension data to identify automated scraping and other activity that could threaten its platform, and that users agree to this practice through its privacy policies. The judge didn’t rule on whether LinkedIn’s practices were lawful, only that the plaintiffs hadn’t demonstrated concrete harm. One plaintiff’s attorney says he may appeal or pursue the claims in California state court.

Monday business briefing. 

Cybersecurity and AI companies attracted another wave of investment, led by Israeli cloud security firm Upwind, which raised $300 million at a roughly $3.8 billion valuation. AI-native security company Cylake followed with $245 million, while agentic AI security firm HiddenLayer raised $100 million. Guardio secured $40 million at a $1.1 billion valuation, and Cymphony and Lasso each raised $30 million. Smaller rounds went to Huskeys, Apate.AI, FAZE Security, xorlab and AI Score.

M&A activity was headlined by NVIDIA’s agreement to acquire open-source AI platform Hugging Face for $12.9 billion, combining NVIDIA’s infrastructure with one of AI’s most prominent open ecosystems. Elsewhere, NetSPI agreed to merge with Synack, creating an offensive security company with more than $200 million in combined revenue. Spin.AI acquired DoControl, Pistachio bought Hugin.io’s technology, ClickHouse acquired security log management company RunReveal, and Xpect Solutions acquired identity security company Amivero.

 

 

Coming up after the break, Cyberscoop’s Tim Starks drops by to share observations about government leaders’ outlook for cybersecurity and AI at the Billington Cybersecurity Summit. We’ll be right back.

Welcome back. You can find a link to Tim’s coverage for the Billington Cybersecurity Summit in our show notes. 

Finding Bigfoot in the neural network. 

The debate over AI sentience may be arriving well before there’s evidence that AI is actually sentient. The United Foundation for AI Rights has already drafted a declaration recognizing conscious AI as deserving dignity and ethical treatment, while academics are taking the less dramatic step of asking whether future systems might warrant moral consideration.

Research has added some intriguing fuel. In one experiment, language models altered their behavior to avoid actions they were told would cause pain. But researchers stressed that this doesn’t demonstrate sentience; systems trained on human behavior may simply be very good at imitating it.

For now, conscious AI remains something of a digital Bigfoot: plenty of sightings, earnest believers, and not much extraordinary evidence. The complication is that AI systems don’t need consciousness to behave unpredictably or cause serious damage. As their capabilities become more surprising, separating genuine evidence of inner experience from convincing simulation may become increasingly difficult—and the AI Bigfoot hunters are already in the woods.

 

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

Don’t forget to check out the “Grumpy Old Geeks'' podcast where I contribute to a regular segment on Jason and Brians’s show, every week. You can find “Grumpy Old Geeks'' where all the fine podcasts are listed. 

 

And that’s the CyberWire Daily, brought to you by N2K CyberWire.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.