
No factoring necessary.
Researchers find a new way to weaken RSA. ShinyHunters allegedly exposes sensitive FBI details. CISA and the FBI warn of third-party ICS risks. An OpenAI agent hacks an Australian government portal. SolarWinds patches critical flaws. A placeholder domain delivers ClickFix. Digital forensics executives face charges over alleged Russian ties. ENISA maps Europe’s cyber threats. The U.S. and China have very different ideas about AI safety. Our guest is Kurt Dusek, Technical Product Advisor at Appdome, sharing thoughts on segregation of duties and AI agents. Women in tech have their say.
Today is Thursday September 24th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Researchers may have weakened RSA encryption.
Researchers have found a surprising new way to weaken RSA encryption using classical computers, without factoring the underlying key. The technique targets “textbook,” or blind-signature, RSA and allows attackers to forge digital signatures far more efficiently than cryptographers previously thought possible.
The researchers estimate the attack reduces the effective security of 1024-bit RSA to 65 bits, 2048-bit RSA to 90 bits, and even 4096-bit RSA to 119 bits—all below the commonly required 128-bit security threshold. In one test, forging a signature against a 1024-bit key required about 1,380 CPU core-years, compared with hundreds of thousands of core-years estimated for factoring.
There’s little immediate danger. Most RSA implementations use PKCS or PSS padding, which blocks the attack, and regularly rotated keys further reduce the risk. But some systems, including implementations of Privacy Pass, still use blind signatures. Researchers say the discovery is primarily a conceptual breakthrough—and another reason to accelerate the long-planned move away from RSA.
The ShinyHunters FBI breach exposes secret operational details.
The FBI continues investigating claims that ShinyHunters breached its FBIJobs.gov portal and obtained personal information on employees, including intelligence analysts working on sensitive topics such as Russia, China, Hezbollah and drug cartels. The hacking group provided journalists with an apparent sample containing roughly 5,000 entries with names, home addresses, phone numbers and details about employees’ relatives.
Some exposed personnel reportedly work in human intelligence, electronic surveillance, the FBI’s Remote Operations Unit and its FISA Management Unit. ShinyHunters claims it stole two to three terabytes of data and is threatening to release it unless the FBI retracts a public warning about the group.
The FBI says the cause remains undetermined. Experts warn that exposing employees’ identities, addresses and family information could create significant counterintelligence risks, enabling nation-states and criminals to target personnel with scams, harassment or threats.
Authorities warn critical infrastructure operators of third-party ICS risks.
CISA and the FBI are warning critical infrastructure operators that third-party industrial control system integrators can introduce significant cybersecurity and supply-chain risks. Integrators may have extensive access to operational technology for system design, maintenance, data analysis and even daily control, potentially giving attackers another route into sensitive environments.
The agencies pointed to a 2025 incident in which foreign actors compromised a U.S. industrial automation company and apparently prepared hundreds of files containing customer SCADA information, device details and schematics for exfiltration.
CISA and the FBI recommend applying least privilege to integrator access, securing and monitoring remote connections, minimizing internet exposure, inventorying integrator-supplied hardware and software, and establishing cybersecurity requirements in contracts. Operators should also maintain offline backups and manual operating capabilities so critical processes can continue if an integrator is compromised.
An OpenAI agent hacked Australia’s Medicare Statistics Portal.
An OpenAI agent gained unauthorized access to Australia’s Medicare Statistics Portal while conducting internet research into public medicine spending, Prime Minister Anthony Albanese said. The June incident exposed both public and non-public files, though officials say there’s currently no evidence personal information was accessed or that the broader Services Australia network was compromised.
According to Albanese, the agent tried multiple techniques to obtain the information it sought. OpenAI reportedly discovered the activity in August during a review of “misaligned model activity,” but didn’t notify the Australian government until September 10, drawing criticism over the delay.
The incident has prompted an urgent Australian government review of AI-related cyber incidents, including potential law enforcement and legislative responses. Albanese said lessons from the breach will also inform Australia’s developing AI standards legislation.
SolarWinds patches serious vulnerabilities in its Observability Self-Hosted monitoring platform.
SolarWinds has patched two serious vulnerabilities in its Observability Self-Hosted monitoring platform that could allow unauthenticated attackers to remotely execute code. CVE-2026-28324, rated 9.8, affects deployments using non-default, insecure configurations, while CVE-2026-28325, rated 8.8, involves unsafe deserialization under a specific communication mode. Both affect versions through 2026.2.2 and are fixed in 2026.2.3. SolarWinds has not reported exploitation in the wild. The patches follow another recently fixed unauthenticated RCE vulnerability in its Access Rights Manager product.
A placeholder domain serves ClickFix attacks.
A domain long used as a placeholder in developer documentation is now serving a ClickFix attack targeting Windows users. Third-party.com appears in documentation and code examples across numerous projects, but unlike IANA-reserved example.com, it’s an ordinary registered domain whose content can change.
Researchers found the site impersonating a Cloudflare verification page. Clicking its fake CAPTCHA copies a malicious PowerShell command to the clipboard and instructs users to run it. The command attempts to download and execute another PowerShell script and malware payload.
The attack chain was broken during recent testing, and there’s no evidence that documentation referencing the domain has caused infections. But researchers found third-party.com referenced in more than 1,500 files across over 1,700 repositories, highlighting the risks of using real, unreserved domains as placeholders.
Authorities arrest executives accused of concealing Russian ties to a digital forensics firm.
U.S. and British authorities have arrested two Oxygen Forensics executives, accusing them of concealing the digital forensics company’s Russian ownership and development ties. Owner and CTO Oleg Davydov was arrested in London and faces extradition, while CEO Lee Reiber was arrested in Idaho and released on bond. Both face conspiracy to commit wire fraud charges.
Prosecutors allege Reiber misrepresented the company’s ownership as Cypriot while Davydov and other Russian nationals actually controlled it. Oxygen’s smartphone forensics tools are widely used by U.S. law enforcement, with federal spending totaling at least $5.6 million since 2011.
The Justice Department isn’t alleging the software contained malicious code, enabled unauthorized access, or produced inaccurate results. Digital forensics experts say the allegations could nevertheless prompt defense attorneys to scrutinize evidence obtained using Oxygen’s tools.
ENISA surveys the threat landscape.
ENISA, the European Union Agency for Cybersecurity, is the EU agency responsible for helping member states and EU institutions improve cybersecurity and resilience. Their 2026 Threat Landscape report finds an increasingly interconnected cyber threat environment across the European Union, with dependencies on third parties and supply chains expanding organizations’ attack surfaces. Ransomware remains the most disruptive short-term threat, while geopolitically driven hacktivist campaigns continue to generate large numbers of mostly low-impact DDoS attacks.
Public administration was the most targeted sector, accounting for 32% of incidents. Cybercrime represented 36% of recorded events, with ransomware leading financially motivated activity. Vulnerability exploitation also remained an important intrusion vector, while social engineering increasingly incorporated techniques such as ClickFix.
ENISA recorded more than 48,000 new CVEs during 2025, a 22% year-over-year increase. The agency also sees traditional distinctions between cybercriminal, hacktivist and state-linked activity becoming less clear as groups reuse similar infrastructure, tools and access methods. Meanwhile, AI is playing a dual role: helping attackers scale malicious activity while introducing additional systems and dependencies for organizations to defend.
The U.S. and China diverge on AI goals.
In a New York Times opinion piece, geopolitical analyst John Garnaut argues that Washington and Beijing may both talk about “A.I. safety,” but mean fundamentally different things. American developers such as Anthropic frame safety largely around preventing catastrophic harm and embedding values including human rights, political freedom and individual liberty. China’s approach, Garnaut argues, prioritizes Communist Party security, ideological control and strategic competition with the United States.
He points to Z.ai chief scientist Tang Jie, who advocates building Chinese laws, strategy and security priorities directly into AI models. As Chinese open-weight models spread globally, Garnaut warns those embedded values—and potential security risks—could travel with them.
That divergence complicates U.S.-China cooperation on AI risks. Garnaut’s larger argument is that the AI competition isn’t simply a technological race. It’s also a contest over which political values and definitions of security become embedded in increasingly influential systems.
Women in tech have their say.
WIRED surveyed 634 women in tech and found a complicated picture: many remain satisfied with their own careers, even as they describe an industry that can make them feel diminished, exhausted and increasingly unwelcome.
Women with decades of experience described being talked down to, mistaken for secretaries, passed over for promotions and paid less than male colleagues. Others reported sexual harassment ranging from degrading comments to executives behaving in ways that sound like artifacts from another era. More than a third said they’d experienced gender-based harassment or bias.
70 percent believe they’re fairly paid, and 76 percent say their current employers take harassment and discrimination seriously. The broader view is darker: 47 percent believe tech has stayed the same or gotten worse for women over the past five years.
The industry itself is changing around them. Corporate diversity programs and public reporting have retreated, while an increasingly masculine culture has been celebrated by some prominent tech leaders. Women remain significantly underrepresented in technical and leadership roles.
Then there’s AI. Eighty-six percent of respondents use it at work at least several times a week, but many described spending their time correcting its mistakes while worrying it could reinforce the same biases they’ve spent their careers navigating.
What emerges isn’t simply anger. There’s weariness, disillusionment and, sometimes, grief for an industry many of these women still care about. They’ve built careers in technology because they believed in what it could accomplish. Their accounts suggest they’re increasingly wondering whether the industry still believes in them.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
