
Storm clouds over the waterworks.
CISA rides out a Cyber Storm. The EU struggles to share cyber threat information. Nightmare Eclipse drops another Defender zero-day. TASK#STOMP steals business documents. North Korean operatives fake their way through job interviews. A genetics lab pays $700,000 over a phishing breach. A zero-day in Meta’s Muse AI assistant opens the door to privilege hijacking. Marc Woolward, Senior Advisor to Humanix and former CTO for Goldman Sachs, discussing social engineering and vishing attacks. Infiltrating Team PCP.
Today is Tuesday September 22nd 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
CISA’s Cyber Storm tests the nation’s response to a major cyberattack on critical infrastructure.
CISA has wrapped up Cyber Storm X, a four-day national exercise designed to test how the country would respond to a major cyberattack on critical infrastructure. The tenth Cyber Storm exercise in the program’s 20-year history brought together roughly 2,000 participants from more than 200 public- and private-sector organizations.
This year’s scenario put a nation-state adversary behind attacks on transportation infrastructure, including rail systems and ports, as well as water and wastewater systems. Participants practiced responding to the simulated crisis, coordinating across government and industry, sharing information, and identifying gaps in resources and responsibilities.
CISA says the biennial exercise is intended to strengthen incident response plans and relationships before they’re needed in an actual emergency. The agency will now work with participants to assess what worked and what didn’t. Those findings, along with recommendations for improving national cyber resilience, will be published in a public after-action report.
Research from identity risk firm SpyCloud found that nearly 18% of the U.S. water and wastewater organizations it analyzed had identity data actively exposed by infostealer malware. Researchers examined 10,000 organizations and found 1,787 with exposure involving stolen credentials, session cookies, or other authentication data.
The supply chain can magnify that risk. In one case, a single infected device at a smart-meter technology provider contained saved logins associated with roughly 167 utility customers. SpyCloud also found that 258 affected organizations had credentials linked to operational technology or remote-access systems.
The researchers stress that identity exposure doesn’t mean an organization has been breached, and the study didn’t examine exposed operational technology devices themselves. Smaller utilities were also underrepresented. SpyCloud has begun notifying affected organizations, starting with a briefing for CISA.
The EU’s info sharing comes up short.
The European Court of Auditors says the EU’s cybersecurity efforts are being weakened by poor information sharing among member states. Despite €1.4 billion in cybersecurity spending and improved cooperation, national security laws can impede reporting of cross-border incidents. The auditors cited a 2025 ransomware attack that disrupted several European airports but went unreported through EU cybersecurity channels. Remarkably, no member state has reported a “large-scale” cyber incident since 2016, despite the designation covering attacks affecting two or more EU countries.
Nightmare Eclipse drops another Microsoft Defender zero-day.
Security researcher Abdelhamid Naceri, also known as Nightmare Eclipse, has released another Microsoft Defender zero-day exploit. Dubbed BigDiskBuster, the proof-of-concept can prevent Defender from receiving platform and signature updates while it runs in the background. Naceri says it works across all supported Windows versions, though the current code is buggy. The release is the latest in a string of Windows zero-days Naceri has published since April 2026 amid an ongoing dispute with Microsoft. Microsoft has patched some of those previously disclosed flaws, while others remain unaddressed.
The TASK#STOMP Windows backdoor campaign steals business documents through resilient remote access.
Securonix researchers have uncovered TASK#STOMP, a Windows backdoor campaign designed to steal business documents and maintain resilient remote access. The malware uses VBScript, PowerShell, Task Scheduler, and the Windows Startup folder to establish multiple persistence mechanisms that can restore one another if disrupted. It also alters file timestamps to make malicious components appear older.
Its PowerShell payloads run in memory, search drives for documents and archives, and upload them to attacker-controlled infrastructure. The backdoor can also steal Wi-Fi passwords, capture screenshots and clipboard contents, and execute arbitrary PowerShell commands. A second payload provides a redundant command-and-control channel.
Securonix hasn’t identified the initial infection vector or attributed the campaign to a known threat group. Researchers recommend watching for combinations of unusual PowerShell, VBScript, and scheduled-task activity.
Japan and its partners call out a fake North Korean recruiting campaign.
A joint advisory from Japan, the U.S., Australia and Germany has attributed a global fake-recruiting campaign to the North Korean group WaterPlum, also known as Contagious Interview. Posing as employers, the group targets developers and IT professionals, often in cryptocurrency and blockchain. Authorities say WaterPlum infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026 and stole funds or credentials from more than 7,000 cryptocurrency wallets. Investigators estimate roughly $10.7 million ultimately reached North Korea. The advisory also links WaterPlum to North Korea’s IT-worker operation, including shared infrastructure and laptop farms. Japan dismantled its first confirmed North Korean laptop farm this year. Warning signs include suspicious résumés, cryptocurrency payment requests, reluctance to meet in person, and AI face-swapping during video interviews.
A California genetic testing company agrees to pay a $700,000 HIPAA penalty over a phishing attack.
California genetic testing company Ambry Genetics has agreed to pay a $700,000 HIPAA penalty following a 2020 phishing attack that compromised information belonging to more than 225,000 patients. The exposed data potentially included names, birth dates, insurance and medical information, and, for some patients, Social Security numbers and diagnoses.
An HHS investigation found Ambry failed to conduct an adequate security risk analysis and had deficiencies in terminating former workers’ access and uniquely identifying users of systems containing protected health information. Along with the fine, Ambry agreed to a corrective action plan that HHS will monitor for two years, including stronger risk management, access controls, policies, and employee training.
The company previously settled class-action litigation over the same breach for $12.25 million in 2023. Its parent, Tempus AI, separately faces litigation over the alleged use of Ambry patients’ genetic data to train AI models.
A zero-day in Meta’s new Muse AI assistant for macOS enables privilege hijacking.
Security researcher Patrick Wardle has disclosed a local zero-day in Meta’s new Muse AI assistant for macOS that could allow malware already running on a computer to hijack the app’s privileges. Wardle’s proof-of-concept, dubbed “not-a-mused,” exploits an undocumented Muse setting that can be modified without elevated privileges to redirect dictation traffic to an attacker-controlled server.
That could expose audio and AI prompts, enable prompt injection, steal authentication material, or let malware abuse permissions users have granted Muse. The flaw isn’t remotely exploitable; an attacker must first execute code locally.
Wardle argues the broader concern is that AI assistants require extensive access to be useful, potentially creating a single point of failure that undermines macOS security boundaries. He says Meta could avoid this particular vulnerability by using Apple’s on-device dictation API. Meta has not commented.
Infiltrating Team PCP.
Before Australian police arrested two alleged TeamPCP members last month, the group had already pulled off an extraordinary supply-chain hacking spree, compromising hundreds of open-source projects and more than a thousand companies. But TeamPCP had an uninvited colleague: an undercover Mandiant analyst who had infiltrated its inner circle.
That access let Google watch the group steal credentials, warn victims and cloud providers, and help shut down an AI-assisted zero-day exploit before it could be widely abused. TeamPCP eventually expelled the mole after fellow cybercriminals ShinyHunters betrayed the group and prompted a membership purge.
By then, Google had other leads. Researcher Austin Larsen traced one alleged member through old forum records, a PayPal address, and, remarkably, stolen data backed up to a Google Drive account linked to the suspect. Google tipped off the FBI, and Australian authorities later made arrests. For a group skilled at stealing credentials, credential hygiene apparently remained a work in progress.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
