The CyberWire Daily Podcast 10.9.26
Ep 2654 | 10.9.26

The Flax Typhoon gets a cold front.

Transcript

An international coalition disrupts Chinese state-backed hacking operations. Officials dismantle cybercrime centers in Ghana. Anthropic launches initiatives aimed at quicker remediation. A maximum-severity SonicWall vulnerability is under active exploitation. The Cybersecurity Information Sharing Act remains in legislative limbo. Ransomware spikes. Attackers exploiting unpatched vulnerabilities in AhsayCBS backup software. Midnight Mimosa targets cheap Android device firmware. Prosecutors saddle a money mule. Maria Varmazis joins Dave to continue our CyberWire’s 10th anniversary celebration with a conversation about public-private partnerships. Open AI does the math.

Today is Friday October 9th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

An international coalition disrupts Chinese state-backed hacking operations. 

An international coalition has disrupted infrastructure used by Integrity Technology Group, a Chinese cybersecurity company that U.S. officials say supports state-backed hacking operations. The Justice Department seized websites supporting two Integrity Tech tools, Microscan and FishHub, used in the long-running Flax Typhoon campaign.

Microscan automated reconnaissance and vulnerability scanning against targets including power companies, airports and other critical infrastructure. FishHub helped attackers conduct phishing operations and deploy malware after gaining access to victim networks. Authorities say Chinese actors have also targeted poorly monitored edge devices to maintain persistent access, potentially positioning themselves to disrupt critical infrastructure later.

Agencies from the U.S., Australia, Japan, the U.K., Spain, New Zealand and Canada contributed to a detailed advisory describing Integrity Tech’s tools and operations.

Officials dismantle cybercrime centers in Ghana. 

Ghanaian authorities say they dismantled suspected cybercrime centers in the Greater Accra Region, arresting eight suspects and rescuing 120 people believed to have been trafficked and forced into online fraud, including romance scams. Investigators seized 136 phones, 130 laptops, networking equipment, vehicles and other evidence.

The operation has also prompted a dispute over who was in charge. FBI Director Kash Patel portrayed the raid as part of the bureau’s global “Operation Blackout,” but Ghana’s Cyber Security Authority says the operation was planned, coordinated and executed by Ghanaian authorities. The CSA acknowledged intelligence support from the FBI and Britain’s National Crime Agency, while stressing that foreign agencies cannot independently exercise police powers in Ghana. Most of those rescued were Nigerians, and authorities are working to repatriate them.

Anthropic launches initiatives aimed at quicker remediation. 

Anthropic has launched two cybersecurity initiatives aimed at turning AI-discovered vulnerabilities into fixes more quickly. Its free OSS Scanner lets open source maintainers opt in to periodic scans using Anthropic’s most capable models. Reports include vulnerability details, proof-of-concept exploits and, when available, suggested fixes. To speed disclosure, reports are sent without human review, meaning some may contain errors, though Anthropic expects a true-positive rate above 90 percent.

The company is also launching its Critical Infrastructure Defense Program, bringing Claude models, engineers and threat research to companies that secure operational technology. Anthropic says OT vulnerabilities are particularly challenging because industrial systems often can’t be taken offline for patching. The initial program includes security vendors, consultancies and industrial manufacturers, with plans to expand to additional partners and sectors.

A maximum-severity SonicWall vulnerability is under active exploitation. 

Attackers appear to be targeting a maximum-severity vulnerability in SonicWall SMA1000 remote-access appliances just days after a patch became available. CVE-2026-102255 affects the WorkPlace interface on several SMA1000 models and could allow an unauthenticated attacker to make the appliance access internal functionality and perform unauthorized operations.

Security firm Previdian says its honeypots detected exploitation attempts consistent with the flaw, though researchers haven’t confirmed that those attempts successfully compromised systems. Shadowserver is tracking more than 400 internet-exposed SMA1000 appliances, but it’s unclear how many remain vulnerable.

The activity continues a rough stretch for SonicWall’s SMA1000 line. Attackers exploited multiple zero-days earlier this year, including vulnerabilities used to install custom malware and others that CISA later linked to ransomware operations.

The Cybersecurity Information Sharing Act remains in legislative limbo. 

More than a year after permanent authorization for the Cybersecurity Information Sharing Act of 2015 expired, Congress remains deadlocked over its future. CISA 2015 protects companies from certain liabilities when they share cyber threat indicators with the government or one another. Short-term extensions have kept those protections alive, but tied them to recurring government funding battles.

Senate Homeland Security Chairman Rand Paul continues to block a long-term extension, seeking an amendment restricting government efforts to influence social media content moderation. Bipartisan proposals in both chambers would extend the law through 2035, but none has advanced.

The Cyber Threat Alliance says uncertainty hasn’t dramatically reduced existing information sharing, though it may discourage new participants. Its president, Michael Daniel, favors a medium-term extension that would give Congress time to modernize the law for AI-era threats, including information about attacks such as model distillation.

Ransomware spikes. 

Ransomware activity reached a record high in the third quarter of 2026, according to Comparitech, which counted 2,627 claimed attacks—up 27 percent from Q2 and 61 percent year over year. Only 247 have been confirmed by the targeted organizations.

Finance and technology saw the sharpest quarterly increases, while education, healthcare, government and utilities also experienced substantial growth. Comparitech suggested advances in AI could be helping attackers scale and accelerate their campaigns.

Researchers also noted growing use of triple extortion, in which attackers encrypt systems, steal data and then pressure individuals or customers connected to the victim. The average ransom demand was about $602,000.

Qilin and The Gentlemen were the most prolific groups, while the United States accounted for 1,066 claimed attacks, or 41 percent of the worldwide total.

Attackers exploiting unpatched vulnerabilities in AhsayCBS backup software. 

Attackers are exploiting two unpatched vulnerabilities in AhsayCBS backup software to gain unauthenticated remote code execution. Huntress says CVE-2026-105133 and CVE-2026-105134 affect even the latest version and have targeted at least five organizations. Attackers chained the flaws to deploy webshells, conduct reconnaissance, install XMRig cryptocurrency miners and establish persistence. With no patch available, Huntress recommends restricting the AhsayCBS management interface to trusted IP addresses or requiring VPN access and checking systems for compromise.

Midnight Mimosa targets cheap Android device firmware. 

Bitdefender has uncovered Midnight Mimosa, a supply-chain malware campaign affecting low-cost Android devices built on MediaTek platforms. The malware is embedded in device firmware before sale, giving it system-level privileges and persistence that survives normal uninstall attempts. Operators can remotely install or remove apps, grant permissions and load additional code, enabling ad fraud, click fraud and botnet activity.

Bitdefender has observed thousands of affected devices across more than 150 countries over two years, with Western Europe and the Americas particularly represented. Researchers also found 13 Google Play apps containing related ad-fraud code, though without the firmware malware’s privileged access.

Midnight Mimosa can temporarily disable Google Play and Play Protect while installing additional payloads, giving its operators extensive control over compromised devices from the moment they’re activated.

Prosecutors saddle a money mule. 

A Ukrainian-Russian dual citizen has pleaded guilty to helping run Your Mule Cashout, a money-laundering operation that processed millions of dollars for cybercriminals worldwide. Prosecutors say 42-year-old Oleg Korniev helped manage the organization, which operated since 2007 and recruited more than 15,000 U.S. money mules through fake job offers.

The mules received stolen funds in their bank accounts and wired the money to cash-out contractors in Eastern Europe. YMCO allegedly processed more than $10 million stolen from over 750 U.S. bank accounts.

Korniev admitted the operation caused more than $14.7 million in actual and intended losses and that he laundered at least $7 million. He pleaded guilty to charges including money laundering, identity theft and computer fraud conspiracy, and faces between two and 50 years in prison.

Stick with us after the break, I will be joined by Maria Varmazis to continue our CyberWire Daily 10th anniversary coverage, where we will speak on public-private partnerships and law enforcement operations over the last decade. And Open AI does the math.

Maria Varmazis and I sit down to continue our CyberWire Daily 10th anniversary coverage, as we will speak on public-private partnerships and law enforcement operations over the last decade. Here’s our conversation.

That was Maria Varmazis and I discussing public-private partnerships and law enforcement operations over the last decade. If you enjoyed this conversation, be sure to check out the full interview on Monday.

Open AI does the math. 

OpenAI dropped more than 350 AI-generated mathematical findings in a single day, prompting reactions ranging from “breathtaking” to something closer to professional vertigo. The results span algebra, number theory, topology and other fields, including a proof of the quasi-Riemann hypothesis that Rutgers mathematician Alex Kontorovich said would merit a Fields Medal if produced by a human.

But mathematics has not simply packed up and gone home. The enormous collection still needs verification, and OpenAI had withdrawn three papers and corrected others by Thursday. Researchers are also wrestling with what industrial-scale AI discovery means for peer review, graduate education and the pleasure of doing mathematics itself.

The consensus seems to be that the machines have climbed some formidable mountains. Mathematicians now get to verify the routes—and contemplate what happens when the climbing equipment starts choosing the peaks.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

 

N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.