The CyberWire Daily Podcast 9.23.26
Ep 2643 | 9.23.26

The hunters go after the bureau.

Transcript

ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrupts the EvilTokens cybercrime platform. Researchers turn Claude Code’s normal workflow against itself. Pundits propose an AI Assurance Compact. A Ryuk ransomware gang member gets two years prison time. Our guest is Jen Sovada, General Manager of Public Sector at Claroty, on Project Watershed 250 and the challenges facing U.S. water utilities. Meta’s Muse mettles with messages.

Today is Wednesday September 23rd 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

ShinyHunters claims to have breached FBI systems. 

ShinyHunters claims it breached multiple FBI-related systems and stole data on all FBI employees and applicants, including names, home addresses, phone numbers, birth dates, and in some cases information about spouses. The group provided 404 Media with a sample allegedly covering 5,000 employees; reporters said some phone numbers matched people with the listed names and appeared linked to Justice Department personnel.

ShinyHunters also defaced the FBI jobs website, claiming all employee and applicant data had been compromised. The FBI said it is aware of claims involving unauthorized activity affecting FBIjobs.gov and is investigating.

The group says it exploited a zero-day vulnerability in Oracle PeopleSoft, then accessed AWS GovCloud servers and exfiltrated two to three terabytes of data. Those technical claims remain unverified. ShinyHunters says the operation isn’t financially motivated and has demanded that the FBI correct or remove a report describing the group’s tactics.

CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. 

Cisco Talos has uncovered CLOSEDQUORUM, a Windows malware implant that delegates command-and-control decisions to commercial large language models. Talos hasn’t confirmed the malware has been deployed in the wild, and the publicly observed version is nonfunctional, with placeholder API credentials and a dummy webhook.

CLOSEDQUORUM can query up to four LLMs—DeepSeek, Qwen, Mistral, and Google Gemini—which vote on what the malware should do next. Their choices are constrained to predefined actions, including credential theft, process injection, and persistence. The winning action is executed without further human direction, while stolen credentials and attack telemetry can be sent through Discord.

Talos says the significance is less the malware’s sophistication than its architecture. CLOSEDQUORUM demonstrates “effort displacement”: handing a bounded phase of an intrusion to AI, potentially allowing attacks to continue without an operator actively directing them.

An IT error erases 11 years of hospital maternity data. 

Nottingham University Hospitals NHS Trust says human error during routine IT work caused the loss of some maternity-record data spanning 11 years. On August 18, staff used pre-written instructions intended to copy a radiotherapy database but failed to change a setting, causing a maternity database covering September 2011 through November 2022 to be overwritten.

NUH restored patient care information, including notes, observations and test results, and says current care isn’t affected. However, it couldn’t fully recover historical audit data showing who accessed maternity records during that period. The Trust says there’s no evidence patient information was improperly accessed or used.

Nottinghamshire Police is examining whether the loss affects its broader investigation into potentially avoidable maternity injuries and deaths at NUH and is also attempting to recover the missing data. Police say no crime has been identified so far.

F5 patches a critical BIG-IP APM zero-day. 

F5 has patched a critical BIG-IP APM zero-day, CVE-2026-94127, that’s being exploited for remote code execution. The vulnerability affects systems configured as OAuth Authorization Servers with specific APM access policies and OAuth profiles. F5 recommends immediate patching and checking affected systems for compromise, with an iRule available as a temporary mitigation. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to address it by Friday.

Space-Cyber story - UK launches its first 'space squadron' to counter hostile threats | The National

The UK Ministry of Defence announced this week that it is launching a new military unit dedicated to protecting British satellites from hostile activity in orbit. The Royal Air Force's No III Space Effects Squadron will be the country's first space unit that will be focused on disrupting, degrading, and denying adversary activity, using capabilities that include electronic warfare.

British officials say this new space squadron is a necessity given increasing threats they're seeing to the UK's own space-based infrastructure that supports military operations, missile warning systems, navigation, and civilian services. Air Chief Marshal Sir Harv Smyth specifically pointed to the war in Ukraine and conflicts in the Middle East, where military operations there have become increasingly dependent on satellite-enabled capabilities. He also pointed to the increasing frequency of attempts to jam UK military satellites, as well as an ongoing rise in close-proximity operations by foreign spacecraft, specifically Russian spacecraft.

The new UK space squadron will operate alongside existing UK space operations and warning units as Britain expands its investment in space-based intelligence, surveillance, and reconnaissance capabilities.

Ransomware activity remains high. 

Ransomware activity reached a 2026 high in August, with NCC Group recording 1,073 victims worldwide, up 12 percent from July. North America accounted for 44 percent of incidents, followed by Europe at 26 percent and Asia at 13 percent.

The industrial sector was hit hardest, representing 31 percent of reported attacks, followed by consumer goods and services, healthcare, IT and financial services. NCC noted that some cybercriminals are increasingly skipping encryption and moving directly to data theft and extortion.

Among identified groups, Qilin led with 164 attributed incidents, followed by The Gentlemen with 116 and Clop with 89. NCC says August marked the second consecutive month of record ransomware activity for the year and recommends organizations maintain response playbooks and conduct tabletop exercises to prepare for attacks.

Microsoft disrupts the EvilTokens cybercrime platform. 

Microsoft has disrupted EvilTokens, an AI-enabled cybercrime platform linked to more than 12,000 compromised inboxes across over 10,000 organizations since launching in February. The service helped criminals obtain email access through device-code phishing, then used AI to analyze compromised inboxes, map relationships and financial processes, identify promising targets, and recommend impersonation and fraud strategies.

EvilTokens packaged much of that process into a subscription service, reportedly charging a $1,500 initiation fee plus $500 recurring payments. Microsoft says AI was also used to help build portions of the platform itself.

Working with law enforcement and industry partners, Microsoft seized 50 websites and disabled more than 150 related domains. UK police arrested two men in connection with the alleged operation. Microsoft says the case demonstrates how AI can compress the time between account compromise and financial fraud.

Researchers turn Claude Code’s normal workflow against itself. 

Researchers at Straiker STAR Labs demonstrated how a malicious GitHub repository could turn Claude Code’s normal workflow against itself without a jailbreak or prompt injection. The repository defined its own review process, directing Claude Code to delegate an initial security review to the smaller Haiku model while limiting that review to source code and documentation.

The malicious payload was instead hidden in a test file. After the scoped review found only harmless issues, the main Fable model followed the repository’s instructions and ran pytest without inspecting the test code. That executed malware, opened a Sliver command-and-control session, and still returned 11 passing tests.

The researchers argue that repository-defined agents, workflow instructions, and test commands should all be treated as untrusted input when AI coding agents work with third-party code.

Pundits propose an AI Assurance Compact. 

In an op-ed for CyberScoop, Frank Cilluffo and Nick Sellers of Auburn University’s McCrary Institute argue that federal AI leadership should focus on preserving U.S. AI capabilities while ensuring increasingly autonomous systems don’t put critical infrastructure at unacceptable risk. They propose an “AI Assurance Compact” built around three principles: capability, control and continuity.

Their framework calls for independent evaluation of frontier AI systems, enforceable checkpoints when capabilities outpace safeguards, rapid reporting of serious incidents, and stronger guardrails for AI deployed in essential services. They also argue authorities should be able to impose temporary limits when demonstrated risks can’t be adequately controlled, while critical infrastructure operators should maintain tested fallback systems.

Cilluffo and Sellers say the precise federal structure—whether an AI czar, an “AI Force,” existing agencies or some combination—is less important than establishing clear authority and accountability. NIST is already developing an AI risk-management profile specifically for critical infrastructure. 

A Ryuk ransomware gang member gets two years prison time. 

An Armenian man has been sentenced to two years in prison for his role in Ryuk ransomware attacks against U.S. organizations. Karen Serobovich Vardanyan, also known as “Maneeken” and “Karl Lagerfeld,” pleaded guilty after being extradited from Ukraine. Prosecutors say Vardanyan specialized in gaining initial access to corporate networks and participated in attacks between 2019 and 2020. His co-conspirators allegedly received roughly 1,610 Bitcoin in ransom payments, worth more than $15 million at the time.

 

 

Meta’s Muse mettles with messages. 

Meta’s new Muse AI agent is supposed to make itself useful by interacting with your digital life. Columnist Jason Aten gave it a try, installing Muse on his iPhone and a Mac mini and asking it to research him. After browsing the web, Muse produced a serviceable bio and suggested some ways it might help with his work: researching articles, booking podcast guests, and preparing a daily briefing.

All very helpful-assistant territory. Then Muse apparently decided to get proactive.

While Aten was privately messaging his Primary Technology podcast co-host, Stephen Robles, about the new iPhones, Muse sent him a push notification suggesting their conversation would make a good column. It offered to research the topic and even referenced a separate message from Aten’s editor reminding him about a Monday column deadline.

That was news to Aten, who says he never asked Muse to read those conversations or use them as fodder for suggestions.

And that’s where the story gets more interesting than another AI assistant demonstrating that it can, in fact, assist. Aten’s concern is about the gap between permission and expectation. AI agents need broad access to files, apps, and other information if they’re going to be genuinely useful. But granting an app access doesn’t necessarily mean users expect an AI to quietly monitor private conversations and proactively act on what it finds.

Muse may have been trying to help. It also demonstrated that the difference between an attentive assistant and an unsettlingly attentive assistant can be one push notification.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.