The CyberWire Daily Podcast 9.16.26
Ep 2637 | 9.16.26

Cybercrime finds its sea legs.

Transcript

Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a data breach. Spain records its first breach caused by an autonomous AI agent. PhantomRaven targets developers through malicious npm packages. Illicit casinos provide cover for cybercrime. A New York healthcare provider exposes patient data. Our guest is Chad Thunberg, CISO at Yubico, on how real crypto-agility still needs a hardware root of trust. Hackers do a little Flock picking.

Today is Wednesday September 16th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Officials investigate suspected cyberattacks on U.S.-bound oil tankers. 

The Coast Guard and FBI are investigating suspected cyberattacks against two oil tankers bound for the United States last month. One vessel was reportedly compromised while transiting the Strait of Gibraltar, losing communications for more than 30 hours. On August 21, a specialized Coast Guard and FBI team boarded the foreign-flagged tanker in the Gulf of Mexico to assess and secure its operational and information technology systems. A second tanker, also reportedly targeted, was boarded three days later for a similar assessment.

Authorities say neither incident caused operational disruption, vessel instability, danger to crews, or environmental damage. Investigators are examining whether Iran or another foreign actor may have been responsible, potentially in connection with ongoing tensions between Iran and the United States.

Chosen Brick is Iranian-used surveillance malware. 

Cybersecurity and intelligence agencies in the U.S., U.K., and Netherlands are warning about Chosen Brick, a Windows malware family used by Iranian state actors to surveil dissidents, activists, and journalists worldwide. Active since at least 2025, the malware can steal emails and messages, capture screenshots, record microphone audio, track victims’ activities, and even wipe data.

Operators typically approach targets through WhatsApp or Telegram, posing as acquaintances or technical support before delivering malicious files disguised as utilities or medical documents. If corporate security blocks the attack, they may try moving victims to personal devices. Once installed, Chosen Brick establishes persistence, attempts to weaken Microsoft Defender protections, and uses Telegram and cloud storage for command-and-control and data exfiltration. Authorities say the campaign supports Iranian state-sponsored repression and harassment of perceived opponents.

Ukraine’s parliament targets fraudulent call centers. 

Ukraine’s parliament has approved tougher penalties targeting fraudulent call centers and electronic fraud, following a corruption investigation involving alleged protection payments to prosecutors. The legislation makes using electronic communications to commit fraud a separate crime and criminalizes organizing, operating, working for, or recruiting for scam call centers. Convictions could bring prison sentences of seven to 12 years.

The bill, first introduced in 2023, gained momentum after anti-corruption investigators alleged that officials accepted bribes beginning in 2025 to shield scam operations targeting victims in Ukraine and abroad. Five people have been named as suspects. Prosecutor General Ruslan Kravchenko, who denied protecting scam centers and has not been charged, resigned and was subsequently dismissed. The legislation now awaits President Volodymyr Zelenskyy’s signature.

Space-Cyber Story

For decades, the idea of weapons in orbit has lived somewhere between Cold War planning and science fiction. Now, the U.S. government is saying the quiet part out loud. Air Force Secretary Troy Meink has publicly acknowledged for the first time that the United States has deployed what he calls “on-orbit space control weapons”, though exactly what they are remains classified.  

Maria Varmazis joins us with what we know about America’s newly acknowledged arsenal in the final frontier.

On Monday, the Pentagon publicly acknowledged that the US Space Force not only has weaponry in space, but that the weaponry has already been deployed. Secretary of the US Air Force Troy Meink said this during a speech at the annual Air, Space and Cyber conference: “Today, we continue to ensure we remain ready to meet the challenges of evolving threats wherever they exist. This is why the United States now has on-orbit space control weapons capable of defending the joint force against hostile adversary actions."

The exact nature and number of the weaponry is not known, but this acknowledgement is extremely notable - it has been widely believed for some time now that the United States has some kind of space weaponry to counter threats on the ground or on orbit, but this statement was essentially saying the quiet part out loud - the first time a US official has publicly confirmed the existence of such weapons. 

While the phrase space weapon might spring to mind something kinetic to potentially destroy, for example, an adversarial satellite - physically destroying a satellite could create a cloud of space debris, and disable whole swaths of orbital space from use for decades, causing more problems than it would solve. Instead it's far more likely that space weaponry, or 'counterspace' in the lingo, would use either cyber attacks, electromagnetic spoofing or jamming, or laser dazzling - yes that is the term - to jam signals or links, or otherwise non-kinetically disable a target satellite. 

Researchers uncover a pair of TP-Link security camera zero-days. 

Researchers at OPSWAT have disclosed two zero-day vulnerabilities in TP-Link’s Tapo C200 security camera, commonly used in homes and small offices. The more serious flaw, CVE-2026-15315, could let an attacker with network access bypass authentication and gain an administrative session, potentially exposing live video and stored recordings. A second vulnerability, CVE-2026-15316, could allow an unauthenticated attacker on the network to crash the camera’s HTTPS service, causing a denial of service.

TP-Link patched both flaws in firmware version V5_1.4.6, released August 18. OPSWAT is also working with TP-Link on a third, undisclosed vulnerability it rates as critical. Researchers say that flaw could potentially allow full compromise of the camera and turn the device into a foothold for further activity on the victim’s network.

CenterPoint Energy reports a data breach. 

CenterPoint Energy reported a data breach affecting some of its seven million customers across four states. A threat actor claims an inadequately protected company API allowed the theft of 7.49 million records containing personal, account, billing, and potentially sensitive information, including driver’s license data and partial Social Security numbers. CenterPoint hasn’t confirmed that figure. The utility has brought in outside cybersecurity experts and notified authorities. Electric and gas services remain unaffected, and impacted customers will be notified as required.

Spain reports its first data breach caused by an autonomous AI agent. 

Spain’s data protection agency has reported what it says is the country’s first personal data breach caused by an autonomous AI agent. According to AEPD president Francisco Pérez Bes, an individual deployed an agent powered by an unnamed large language model against an organization. The agent scanned files, probed the target for vulnerabilities, and chained together multiple attack stages to gain read-and-write access to files containing personal data and invoices.

Pérez Bes said the incident demonstrates that AI-supported attacks are no longer theoretical and warned that their speed could challenge traditional defenses. He called for human oversight backed by automated detection, containment, and response capabilities. The case comes amid broader concerns about autonomous agents performing unintended or unauthorized actions against third-party systems.

PhantomRaven steals information through malicious npm packages. 

CrowdStrike has identified PhantomRaven, a JavaScript information stealer distributed through malicious npm packages by a self-described bug bounty hunter. Researchers assess with high confidence that the malware was likely generated using a large language model, citing statistical token patterns, verbose comments, placeholder code, and unusual design choices.

PhantomRaven uses typosquatted packages and remote dependencies to execute malicious preinstall scripts. Once running, it collects system details, user information, and CI/CD environment variables that could expose credentials, then exfiltrates the data over HTTP. CrowdStrike says the operator appears to use compromised systems to identify potential bug bounty opportunities rather than sell stolen logs. The researchers say the campaign illustrates how AI-generated tooling can lower technical barriers and accelerate malware development, even for relatively unsophisticated operators.

A sprawling ecosystem of illicit online casinos provides cover for cybercrime. 

Infoblox researchers say the sprawling ecosystem of illicit online casinos is providing cover for three distinct forms of cybercrime. They track more than 1.7 million Chinese-language gambling domains that facilitate illegal betting and money laundering, including activity tied to transnational organized crime. A second category, dubbed “scambling,” uses fake or rigged casino sites to lure victims into depositing money they ultimately can’t withdraw.

The third category has little to do with gambling at all. China-aligned threat actors are disguising malware command-and-control infrastructure as low-quality casino and adult websites. Infoblox says groups using the PeckBirdy framework have employed the technique since 2023 in espionage campaigns against corporate and government targets across Asia. The sites can look nearly identical, making their very different purposes difficult to distinguish from appearances alone. 

A New York health care provider suffers a data breach. 

New York healthcare provider Premier Medical Group is notifying more than 282,000 patients after attackers stole personal and medical information during a June cyberattack. PMG says attackers accessed files on June 14 containing names, contact details, birth dates, treatment and diagnostic information, medications, insurance data, and other patient records. The company has not disclosed how attackers gained access or identified who was responsible. No known ransomware or extortion group has publicly claimed the incident.

Hackers do a little Flock picking. 

A group of hackers decided that simply tearing down a Flock Safety license-plate camera wasn’t enough. They took it apart, copied much of its storage, recovered an encryption key, and handed the results to WIRED and 404 Media for a look under the hood.

What they found was a remarkably busy little roadside computer. Across roughly 21 days of recovered logs, the camera photographed about 50,200 vehicles and generated 1.6 million images. A typical passing car prompted around 28 shots, while some got more than 100. The camera’s software detects vehicles, license plates, bicycles, and, notably, people—although researchers found no evidence that Flock’s software was performing facial recognition.

The system also occasionally got creative. Its license-plate detector mistook bumper stickers, dealership frames, and even an American flag patch on a motorcycle for plates.

The findings raise questions about Flock’s on-device encryption. Much of the sensitive storage remained inaccessible, but the hackers found an encryption key elsewhere on the device that unlocked stored images and video. Flock says it hasn’t received the findings through its vulnerability disclosure program and doesn’t have enough information to assess the claims.

And surveillance technology, apparently, has mundane problems too. Logs contained more than 27,000 “no space left on device” errors, plus crashes and reboots. A watchdog process nevertheless kept checking in every couple of minutes with: “Who’s a good boy?!” Even the surveillance state, it seems, appreciates positive reinforcement.
And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.