The CyberWire Daily Podcast 9.18.26
Ep 2639 | 9.18.26

The Cisco root route.

Transcript

Cisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilities to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabilities. Manufacturing remains ransomware’s favorite target. Hackers compromise a Japanese image-sharing service. The Settra ransomware group leverages remote management software. An Australian think-tank warns of Chinese AI-enabled surveillance in Venezuela. Maria Varmazis joins me for a look back at ten years of critical infrastructure exploits. Everything you wanted to know about AI but were afraid to prompt.

Today is Friday September 18th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Cisco patches a maximum-severity vulnerability in its Identity Services Engine. 

Cisco is urging customers to patch a maximum-severity vulnerability in its Identity Services Engine that’s already under active attack. CVE-2026-76460 carries a CVSS score of 10.0 and affects ISE and ISE Passive Identity Connector. The authentication bypass requires no credentials or user interaction and could give a remote attacker root-level command execution.

CISA has added the flaw to its Known Exploited Vulnerabilities catalog. Cisco says there’s no workaround, though access-control lists can temporarily restrict traffic to affected systems. The company recommends checking ISE and external network logs for signs of compromise and reimaging nodes if exploitation is suspected. The disclosure follows another actively exploited critical Cisco flaw affecting its email security products, making September an especially busy patching month for Cisco administrators.

Court documents describe AI as “an astonishing theft of unprecedented proportions.”

An unredacted filing in The New York Times’ copyright lawsuit against OpenAI and Microsoft is offering a revealing look at how executives inside the companies have discussed generative AI’s impact on creators and the web.

The Times cites internal Microsoft documents describing AI training as potentially “an astonishing theft of unprecedented proportions,” while another warns of a “doom loop” in which AI systems depend on online content while simultaneously undermining the businesses that produce it. Microsoft CEO Satya Nadella testified that clicks from Bing to news sites fell by more than 90 percent after AI features began using their content.

The filing also cites OpenAI discussions about bypassing the Times’ paywall and internal concerns that AI could substitute for the labor that produced its training data. The statements now figure prominently in the Times’ argument against OpenAI and Microsoft’s claims that model training qualifies as transformative fair use.

Researchers chain vulnerabilities to take over employee ChatGPT accounts. 

Security researchers at Hacktron chained vulnerabilities in OpenAI’s community forum and sign-in system to take over employee ChatGPT and Codex accounts and reach internal code repositories.

The initial flaw was an unpatched libheif vulnerability used by Discourse’s image-processing stack. Hacktron used Claude Opus models to develop a working exploit, gaining remote code execution through a malicious image. Researchers then discovered that OpenAI community sign-in tokens carried excessive permissions, potentially allowing forum users’ ChatGPT and Codex accounts to be hijacked.

Hacktron demonstrated the chain by compromising an employee account linked to OpenAI’s GitHub organization and opening a pull request in an internal repository, without reading internal code. OpenAI fixed the account-takeover issue about 14 hours after notification, while Discourse patched the image-processing flaw within two days.

Microsoft and Check Point patch vulnerabilities. 

Microsoft has patched 18 vulnerabilities across its Azure cloud services and Copilot AI products. Most involve elevation of privilege, with additional information disclosure flaws affecting Copilot products and Azure Machine Learning, plus a spoofing vulnerability in Azure Portal. Microsoft labeled all 18 vulnerabilities critical, though some carry CVSS scores corresponding to high or medium severity. None are known to have been exploited. The fixes were applied server-side, so Microsoft says customers don’t need to take any action.

Check Point has patched a critical vulnerability that could allow unauthenticated attackers to execute code with root privileges on its Security Management Server and Log Server products. CVE-2026-91843 is a stack-based buffer overflow in the login process, and Check Point says all Security Management Server deployments are vulnerable regardless of configuration. The company hasn’t reported active exploitation. Customers unable to apply the latest LivePatch can temporarily restrict management access to trusted IP addresses and monitor logs for unusually long username login failures.

Manufacturing remains ransomware’s favorite target. 

Manufacturing remains ransomware’s favorite target, accounting for 22% of victims from April 2025 through March 2026, according to Black Kite. The sector has now ranked first for five consecutive years, with disclosed incidents rising about 40% year-over-year during the first seven months of 2026.

Europe saw particularly sharp growth, with manufacturing victims climbing 85% to 369. Germany led the region with 77 victims, partly driven by SafePay’s focus on German manufacturers. U.S. incidents remained comparatively stable, falling slightly from 443 to 412.

Researchers say manufacturing is attractive because operational downtime can create enormous financial pressure, potentially encouraging ransom payments. Growing convergence between IT and operational technology also expands the attack surface. The emerging Gentlemen ransomware group has been especially active, with manufacturers representing 23% of its leak-site listings.

Hackers compromise a Japanese image-sharing service. 

In Japan, Helpfeel says hackers compromised its Gyazo image-sharing service, accessing a database containing roughly 23.6 million user records. The attacker exploited a vulnerability in an image upload server on September 11 to execute malicious commands before being removed the following day. Exposed data includes names, email addresses, password hashes, device IDs, X integration tokens and billing information, though payment card data wasn’t compromised. The attacker also accessed about 490 million image metadata records, potentially allowing some uploaded image URLs to be reconstructed.

The Settra ransomware group uses remote management software. 

Huntress researchers have observed the emerging Settra ransomware group using remote management software and possible Bring Your Own Vulnerable Driver tactics. Active since June, Settra has claimed 93 victims and uses double extortion, though researchers haven’t found evidence that it operates as ransomware-as-a-service.

In two recent attacks, Settra deployed the open-source MeshAgent remote management tool. One incident also involved installation of a vulnerable Gigabyte kernel driver, potentially to interfere with security software. The ransomware attempted to hinder detection and recovery by clearing Windows event logs, disabling the Windows Recovery Environment, deleting recovery partitions, and overwriting free disk space.

Researchers say Settra appears to target organizations opportunistically through exposed credentials and unpatched systems. Huntress recommends watching for unauthorized MeshAgent deployments, suspicious drivers, log clearing, and recovery-system tampering.

An Australian think-tank warns of Chinese AI-enabled surveillance in Venezuela. 

The Australian Strategic Policy Institute is warning that Venezuela could become one of the most advanced users of Chinese AI-enabled surveillance outside China. ASPI says Venezuela signed an agreement in 2025 to integrate Chinese AI systems into an existing surveillance infrastructure that already relies heavily on Chinese technology.  

The report says the initiative was led by Delcy Rodríguez, now Venezuela’s interim president, and that her government has shown no indication it intends to abandon the plan. ASPI argues that AI could make Venezuela’s existing surveillance systems more integrated and effective at monitoring dissent and controlling information, even without replicating China’s full surveillance apparatus. The think tank is calling on the United States to push for dismantling that infrastructure as Washington plays a larger role in Venezuela. 

Everything you wanted to know about AI but were afraid to prompt.

The New York Times asked readers what they really want to know about artificial intelligence, and nearly a thousand responded with questions ranging from “Will it take my job?” to the slightly more consequential “Will it destroy humanity?”

The Times’ answers are, reassuringly or frustratingly, mostly: not yet, maybe, and nobody really knows.

Today’s AI agents can send emails, edit files, write code and perform other tasks, but they still require human direction. Predictions that autonomous AI could commandeer infrastructure, launch weapons or otherwise end civilization remain highly speculative. Guardrails exist, but researchers continue finding creative ways around them — apparently including poetry, proving that verse retains at least one practical application.

Closer to home, AI poses more immediate concerns. White-collar jobs, particularly programming, writing and design, could face disruption. Data centers consume substantial water and energy. And while ChatGPT can’t simply rummage through your phone for banking credentials, AI agents become considerably riskier when users deliberately give them access to files, email and credit cards.

As for superintelligence curing cancer and ending world hunger, the Times recommends keeping expectations terrestrial. AI is already remarkably capable at coding, mathematics and accelerating scientific research, while remaining surprisingly bad at common sense.

So, will AI save humanity or destroy it? The Times’ survey suggests we’re still somewhere in the much less cinematic middle: powerful technology, imperfect safeguards, real risks, considerable promise — and plenty we simply don’t know yet.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.