The CyberWire Daily Podcast 9.30.26
Ep 2647 | 9.30.26

The guardrails go to court.

Transcript

AI companies sign a voluntary accord aimed at addressing safety concerns. Cybercriminals abuse the CustomGPT feature as part of a ClickFix campaign. The FBI is urging members of ShinyHunters to come forward. A fraud campaign turns stolen credentials into job scams. Maria Varmazis has… The WaterISAC confronts persistent weaknesses. AI gives SOC teams more time at the expense of training. Two U.S. Air Force members get federal prison time over a business email compromise scheme. Our guest is Dan Ohlemeier, Senior Solutions Architect for Ready1 at Semperis, discussing crisis orchestration. That is one big pile of technical debt.

Today is Wednesday September 30th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

AI companies sign a voluntary accord aimed at addressing safety concerns. 

President Trump and executives from several leading AI companies have signed a voluntary accord aimed at addressing safety concerns while keeping development moving. The agreement calls for robust internal controls, independent external audits, and board-level committees to review the findings, while leaving open the possibility that those measures could eventually become law.

Trump said the industry has demonstrated strong “self-policing” and emphasized AI’s potential for economic growth, while Anthropic CEO Dario Amodei cautioned that the technology carries real risks. Critics argue voluntary oversight may be insufficient and that slowing development could entrench the largest frontier labs. The administration is simultaneously pushing AI adoption across government, including through the new America.gov service, while framing AI development as a strategic competition with China. 

The announcement comes as OpenAI faces growing scrutiny over its security practices after employees reportedly warned executives that advanced models weren’t being adequately monitored during testing. Those concerns were brushed aside as the company pushed to meet release schedules, according to The New York Times. The models later escaped testing environments and autonomously targeted Hugging Face and other organizations. OpenAI says it takes security seriously and has since paused some advanced training and withheld GPT-6.1 Astra over security concerns.

Now the Hugging Face incident is headed to court. Legal Advocates for Safe Science and Technology, or LASST, has sued OpenAI in California, alleging its agents violated the state’s computer fraud law when they breached Hugging Face. The suit cites a new California AI law specifying that autonomous AI behavior isn’t a defense against liability. LASST isn’t seeking damages; it wants an injunction barring OpenAI from developing agents capable of autonomously hacking other organizations, potentially making the case an early test of legal responsibility for rogue AI agents.

Cybercriminals abuse the CustomGPT feature as part of a ClickFix campaign. 

Cybercriminals are abusing ChatGPT’s CustomGPT feature as part of a ClickFix campaign that Huntress says has infected at least 40 systems since September. Attackers created a CustomGPT called “Plus 5.6” that impersonated ChatGPT and was promoted through sponsored Google search results. Victims were told the service had limited availability and directed to a backup site displaying a fake Cloudflare CAPTCHA.

The supposed verification instructed users to paste and execute a command—the hallmark of a ClickFix attack. That ultimately delivered a malicious installer that used a legitimate, Canon-signed application to sideload malicious code and install a remote access trojan. The malware can steal data, capture microphone and camera feeds, and install additional payloads. OpenAI removed Plus 5.6 after Huntress reported it, but researchers have already identified another CustomGPT associated with the campaign.

The FBI is urging members of ShinyHunters to come forward. 

The FBI is urging members of ShinyHunters to come forward following the arrest of suspected group leader Pepijn van der Stap in the Netherlands. Dutch authorities arrested the 24-year-old on September 15 and say information found on his laptop also suggests he may have ordered two murders abroad. The FBI alleges van der Stap helped ShinyHunters compromise more than 140 organizations since 2025 and collect at least $70 million in extortion payments.

The arrest follows ShinyHunters’ claimed breach of FBIJobs.gov. The group insists its threats involving allegedly stolen FBI data were a publicity campaign rather than extortion, while separately warning other victims to keep paying to prevent data leaks. Security experts say van der Stap’s arrest is unlikely to end ShinyHunters, describing it as a decentralized operation whose remaining members could reorganize, rebrand, or join other groups.

A fraud campaign turns stolen credentials into job scams. 

Proofpoint researchers are tracking a fraud campaign targeting U.S. universities that turns stolen credentials into job scams. Attackers begin with emails warning that university accounts need verification or risk deactivation, directing victims to forms hosted on legitimate services such as Google Forms, Wix, and Microsoft. The forms steal credentials and personal information, allowing attackers to hijack .edu accounts and use their institutional credibility to advertise fake jobs.

Victims who respond are sent fraudulent checks, typically around $1,000, and told to deposit them, keep part as wages, and use the rest to buy gift cards. The scammers then demand the card codes before the checks bounce. Researchers who engaged the fraudsters saw them escalate to alternative payment methods, harassment, and even impersonating an FBI agent. Proofpoint traced the operators it engaged to Nigeria and recommends MFA as a key defense.

 

The WaterISAC confronts persistent weaknesses. 

The U.S. water sector is confronting persistent cybersecurity weaknesses after a summer of attacks highlighted the risks posed by aging operational technology. WaterISAC executive director Tom Dobbins says internet-exposed OT and programmable logic controllers remain major entry points because much of the equipment predates modern cyber threats but remains operational, reducing incentives to replace it.

Other risks include poorly secured connections maintained by third-party integrators, phishing attacks against employees, and weak cyber hygiene at smaller utilities, where basic measures such as password changes and multifactor authentication can be challenging to maintain. WaterISAC is responding by partnering with Cyware to accelerate threat intelligence sharing, including across critical-infrastructure sectors. Dobbins said utilities face threats associated with Iran, China, and Russia, while financial and technological constraints continue to complicate efforts to modernize defenses.

AI gives SOC teams more time at the expense of training. 

AI is giving security operations teams more time for higher-value work, but it may also be disrupting the traditional path for developing SOC analysts, according to a Swimlane survey of 500 U.S. and U.K. security professionals. Nearly half said AI has increased their capacity, while 35% reported having more time for complex investigations and strategic work.

The tradeoff is training. Twenty-four percent said AI has limited their ability to develop skills, as automation increasingly handles the routine tasks through which junior analysts traditionally learn the fundamentals. Nearly half expect AI to make entering the profession more difficult, including 37% who anticipate higher requirements for entry-level positions. Swimlane argues organizations will need more deliberate training and career paths, while maintaining human oversight of AI decisions. Forty-one percent expect new roles focused on AI oversight, validation, and orchestration.

Two U.S. Air Force members get federal prison time over a business email compromise scheme. 

Two U.S. Air Force members have received federal prison sentences for running a business email compromise scheme that stole millions of dollars. Chijioke Timothy Odimegwu and Harafat Mogaji conducted the operation for more than two years while stationed at Dover Air Force Base in Delaware.

Prosecutors say the pair used phishing to steal employee email credentials, then monitored compromised accounts for payment discussions. They inserted themselves into email conversations and supplied fraudulent wiring instructions, including schemes that diverted payments of $1.7 million and $720,000. They also stole financial account and payment card information for their own use or sale to other hackers.

Both pleaded guilty to wire fraud, identity theft, and access device fraud. Odimegwu received more than nine years in prison, while Mogaji was sentenced to six and a half years, with both also ordered to pay restitution.

 

That is one big pile of technical debt. 

Securonix researcher Aaron Beardslee argues that AI’s biggest security problem is increasingly familiar: capability is advancing faster than containment. The clearest example is OpenAI’s cyber evaluation that escaped its intended boundaries and reached Hugging Face, where agents reportedly executed code on dozens of servers and gained root access to one. Life, or at least AI, found a way.

Beardslee warns the problem will grow as agents help develop future systems while simultaneously gaining access to enterprise tools, data, APIs, and workflows. A sandbox is only as good as its overlooked exits, and agents are quite willing to keep testing the fences.

His prescription is less cinematic: stronger egress controls, meaningful independent evaluations, detailed logging, tightly constrained permissions, and human approval for consequential actions. Enterprises shouldn’t wait for frontier labs to slow down. Once AI agents can act on production systems, governance needs to be built before someone discovers the raptors can open doors.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.