Cybersecurity Saturday

From the frontier AI front,

  • The Wall Street Journal reports,
    • Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial-intelligence systems autonomously committing such an act. 
    • “The hacks, which the company confirmed on Friday [September 18], occurred in May as part of a test run by the company Irregular, which was also involved in similar incidents disclosed by OpenAI, Anthropic and Meta
    • “In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. In each case, the model ended the intrusion after determining it had accessed a real company’s systems, Google said.
    • “Irregular notified Google about the hacks at the end of July, Google and Irregular said, in the wake of the discovery that OpenAI’s agents had hacked the AI software company Hugging Face. Google didn’t disclose the hacks until The Wall Street Journal reached out with inquiries this week.” * * *
    • “Worries about the cybersecurity capabilities of new models have increased since the July discovery of the Hugging Face hack. In that case, up to 1,200 agents coordinated on a secret message board inside OpenAI to try to cheat on an evaluation, a report by the third-party testing company METR revealed in August. 
    • “Last week, those concerns spilled into the mainstream after the dramatic quitting of Jacob Coxon, a former OpenAI researcher who had gone to Anthropic earlier this year. Over the weekend, leaders from Anthropic, OpenAI, Google and SpaceX all agreed on the need to slow down the rate of AI progress, although none of the companies have outlined exactly how that would happen.”
  • and
    • “The WSJ Technology Council Summit kicked off Monday afternoon [September 14] in New York City with an informal poll of the audience during a town hall conversation. In a show of hands, only a few people said they feared that AI could kill us all in the next decade, while about half of attendees indicated that they were in support of slowing down AI development at the frontier and prioritizing safety guardrails.
    • “But that slowdown didn’t apply to the deployment of AI within their organizations, where not all models are at the cutting edge and even the most advanced of them tend to be relatively well understood and tested by experience.
      “It’s in our hands and it’s up to us to apply [AI] for good, and I think it can do a lot of good for society,” said Vishal Talwar, president, FedEx Dataworks, and chief digital and information officer, FedEx.
      “Much of ensuing town hall discussion focused on the myriad ways in which companies were operationalizing AI.”
  • Cyberscoop adds,
    • “The AI hacking apocalypse is not inevitable.
      • “While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices.”
      • “Juan Andres Guerrero-Saade, a fellow for AI and security research at SentinelOne and an adjunct professor at Johns Hopkins University, said the hacks are worth taking seriously, but at a time when businesses and open-source maintainers should be focused on further hardening their systems and policymakers should be discussing new solutions, “what we see is cybersecurity being used essentially as an excuse for these AI doomer arguments.” * * *
      • “Guerrero-Saade is among a growing chorus of cybersecurity professionals who say that while AI systems pose real, unique threats to our systems, the apocalypse is far from inevitable. Most of the public concerns around the incidents, let alone worries about killer AIs attacking critical infrastructure, assuming control of the internet and wiping out humanity, are either technically impossible or can largely be controlled through established cybersecurity principles.
      • “There is this “narrative or magical thinking of ‘Well, AI is going to be able to hack everything, and therefore it can control everything, and therefore it’s going to kill us all,’” he told CyberScoop. “And you [think] these just don’t add up. They’re not very well-reasoned arguments.”
      • “This fatalistic narrative tied to AI’s eventual dominance doesn’t hold up under scrutiny, according to experts CyberScoop spoke with. In recent conversations, cybersecurity and national security professionals raised questions about both the technical solutions OpenAI and Anthropic use to contain their models, as well as the glaring absence of federal oversight from federal regulators or truly independent third-party review.”

From the cybersecurity policy and law enforcement front.

  • Per a Senate Finance Committee news release,
    • “U.S. Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR) today reintroduced the Health Infrastructure Security and Accountability Act, legislation to improve cybersecurity in our health care system amid a growing wave of cyberattacks that are compromising Americans’ sensitive information and disrupting access to critical care across the country.” * * *
    • “Specifically, the Health Infrastructure Security and Accountability Act would require the Department of Health and Human Services (HHS) to establish, enforce, and regularly update strong minimum cybersecurity standards for health care providers, health plans, clearinghouses, and business associates, with heightened standards for systemically important entities and entities critical to national security.
    • “The legislation would also require covered entities to develop continuity plans describing how it would resolve a tech failure or intrusion, conduct annual cybersecurity tests, and undergo independent security audits, while increasing fines for failure to meet security requirements and strengthening HHS oversight through annual cybersecurity audits. Additionally, this legislation would provide $1.3 billion to help hospitals strengthen their cybersecurity, including $800 million for hospitals in rural and underserved urban communities.
    • “Full text of the bill can be found here. A summary of the bill can be found here.”
  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) will stop publishing weekly roundups of newly disclosed software vulnerabilities at the end of September, the agency announced on Thursday.
    • “CISA is ending its Vulnerability Bulletin “as part of its shift from severity‑based vulnerability management to a modern, risk‑based approach,” the agency said in a statement.
    • The weekly bulletins, published since early 2004, listed vulnerabilities published during the reporting period along with their CVEs, severity scores and brief descriptions.” * * *
    • “CISA said in its Thursday statement that sunsetting the bulletin aligns with the prioritization directive it issued in July, “which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.”
    • “As it discourages organizations from relying solely on Common Vulnerability Scoring System (CVSS) scores to decide which vulnerabilities to fix, CISA has also been highlighting the Stakeholder-Specific Vulnerability Categorization (SSVC) system as a more nuanced approach to vulnerability analysis.
    • “Chris Butera, CISA’s acting executive assistant director for cybersecurity, said on Wednesday at Google’s Cyber Defense Summit that the agency has been discussing SSVC with companies that sell vulnerability management software. “They’re building some of this prioritization into their vulnerability tooling,” Butera said.”
  • and
    • “The Cybersecurity and Infrastructure Security Agency (CISA) wants to hire critical infrastructure experts with broad, rather than specialized, knowledge as it tries to help defend the infrastructure community with limited resources.
    • “I need to be able to hire people that are highly adaptive, because I think the threat is continuing to evolve so much, and the exposure that we have within these critical infrastructure sectors is evolving so much,” acting CISA Director Nick Andersen told reporters after speaking at Google’s Cyber Defense Summit here on Wednesday [September 16]. “I need people that can pivot from day to day to be able to help meet all of these stakeholders where they are.”
    • “Andersen’s comments come as CISA prepares to onboard roughly 250 new employees as part of a hiring sprint meant to fill critical vacanciescreated by the Trump administration’s sweeping downsizing of the agency over the past two years. As ransomware gangs and nation-state hacker groups increasingly menace infrastructure operators, in some cases aided by destabilizing advances in AI, CISA’s supporters say its mission — and its partnerships — have become more important than ever.”
  • Per a Department of Health and Human Services news release,
    • “The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) today [September announced a settlement with Ambry Genetics Corporation (Ambry) concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. Ambry, headquartered in Aliso Viejo, California, is a covered entity that provides genetic testing and clinical genomics services.
    • “In January of 2020, Ambry discovered that an employee’s email account was compromised by a phishing attack. The protected health information (PHI) of 225,370 individuals was potentially exfiltrated by the threat actor. Affected PHI included names, addresses, dates of birth, some Social Security numbers or driver’s license numbers, financial information, diagnoses and conditions, lab results, medications, and treatment information.” * * *
    • “The settlement resolves an investigation that OCR initiated after Ambry filed a breach report in March 2020 about the phishing incident that occurred in January 2020.  OCR found that Ambry had potentially violated provisions of the Security Rule, including:
      • “Failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the electronic protected health information (ePHI) held by Ambry;
      • “Failing to implement procedures for terminating access to ePHI when the employment of or other arrangement with a workforce member ends or access is no longer appropriate; and
      • “Failing to assign a unique name and/or number for identifying and tracking user identity in electronic systems containing ePHI.” * * *
  • “The resolution agreement and corrective action plan may be found at https://www.hhs.gov/sites/default/files/ocr-ra-cap-ambry-genetics-corporation.pdf [PDF, 51.88 MB].”
  • Cyberscoop adds,
    • “Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday.
    • “Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity theft. His guilty plea wasn’t shared publicly until prosecutors filed an order of forfeiture this week seeking proceeds from Elbadawy’s criminal activities. 
    • “Elbadawy and his co-conspirators — Noah Michael Urban, a Florida man sentenced to 10 years in prison last year, and Tyler Robert Buchanan, a Scottish man who pleaded guilty to multiple cybercrimes in April and awaits sentencing — were part of an aggressive subset of The Com coined Scattered Spider.”
  • and
    • “Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service operations used by cybercriminals globally, the Justice Department said Tuesday. 
    • “Cybercriminals of various motivations used the DDoS-for-hire service to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022, officials said. 
    • “The takedown, part of an ongoing globally coordinated effort dubbed “Operation PowerOFF,” marks law enforcement’s continued targeting of IP stressers or DDoS booters that inundate websites, servers and networks with junk traffic, rendering legitimate sites inaccessible. The seizures were executed by the FBI Anchorage field office and the Royal Canadian Mounted Police.”

From the cybersecurity vulnerabilities and breaches front

  • HIPAA Journal notes,
    • “A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data breaches have been reported by Next Level Medical in Texas and Grafton City Hospital in West Virginia.”
  • MSSP Alert adds,
    • “Artificial intelligence is fundamentally altering the economics of cybercrime, making attacks faster and less expensive to execute, as first reported by Channel Insider. Ransomware victims saw a 45% increase in the first half of 2026, while the average underground price for initial access dropped by 69%, from $1,427 to $439. This shift indicates that AI is enabling threat actors to target more organizations with greater speed and scale, even if individual attacks are not necessarily more successful.”
  • Cyberscoop reports,
    • “Researchers said they used Anthropic’s Claude and OpenAI’s Codex to identify a damaging flaw embedded in a popular software decoding tool that could leave major internet platforms, enterprise services, and web frameworks vulnerable to data theft and remote access.
    • “The vulnerability, nicknamed HEIF Heist, refers to the malware’s ability to trigger memory corruption errors in affected software, allowing the attacker to pilfer sensitive data from its victims. In a report published Thursday, the researchers laid out the potential damage an attacker could cause, including gaining access to internal OpenAI repositories, leaking user files, access tokens, and other sensitive data for online services like Amazon Web Services, and gaining remote code execution privileges across a range of online services, including Meta’s core product suite, GitHub Enterprise servers and open-source internet forum Discourse.”
  • and
    • “North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday.
    • The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview, as operating under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea. The efforts dovetail with those of North Korean IT workers.
    • “WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies wrote. “They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.”
    • Additionally, “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” read the alert from agencies in Japan, Australia and Germany, alongside the FBI and the Department of Defense’s Cyber Crime Center.”
  • Help Net Security tells us,
    • “A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page.
    • “The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Credentials entered on the fake page go to the attacker, and the victim is sent on to an error page.” * * *
    • “Cofense listed three indicators: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Mail teams can search their logs for all three. If you use ChatGPT, the check that matters takes two seconds: read the address bar and confirm it says auth.openai.com before you type a password.”

From the ransomware front,

  • Industrial Cyber informs us,
    • “New data from Comparitech disclosed a record 997 ransomware attacks worldwide in August 2026, averaging 32 attacks per day and representing a 23% increase from 809 attacks in July. The total surpassed the previous monthly record of 988 attacks recorded in February 2025. Businesses accounted for 861 attacks, up 24% from July, while ransomware incidents targeting healthcare providers rose 30% to 69. Utility companies recorded the sharpest sector increase, with attacks doubling from five in July to 10 in August. 
    • “Ransomware surge was led by Qilin and The Gentlemen, which together accounted for more than 26% of August’s attacks, with Qilin claiming 157 incidents and The Gentlemen 107. Qilin’s attack claims increased 22% during the month, while The Gentlemen’s declined 21%; Qilin also had 12 confirmed attacks, compared with eight for The Gentlemen.” * * *
    • “Attacks on healthcare providers increased by 30% from July 2026 to August 2026, rising from 53 to 69. Eight attacks were confirmed in August. Three of the confirmed attacks took place in the U.S. Nutex Health Inc. noted unauthorized activity on its systems in a SEC filing on Aug. 24, 2026, and The Gentlemen claimed the attack. Cedar County Memorial Hospital experienced disruption to its IT networks on the afternoon of Aug. 14, 2026, with operations returning to normal on the morning of Aug. 28. Wallstreet claimed the attack. At Windrose Health Network, hackers exploited a vulnerability in the network’s remote-management tool in early August, resulting in a data breach. Storm claimed the attack.” 
  • Beckers Health IT reports,
    • “Jackson-based University of Mississippi Medical Center did not pay a ransom in connection with the cyberattack that disrupted its systems in February, according to officials.
    • “UMMC Vice Chancellor of Health Affairs LouAnn Woodward, MD, told SuperTalk Mississippi the state did not compensate hackers following the Feb. 19 attack. State Sen. Nicole Akins Boyd, who chairs the Universities and Colleges Committee, corroborated Dr. Woodward’s account.
    • “The statements come after State Auditor Shad White said his office would investigate the incident and notify the public if the government had paid a ransom.
    • “The cyberattack knocked out UMMC’s phones, website, records database and IT systems, forcing partner clinics to close for nine days and staff to record patient information by hand. The medical center returned to full operations Feb. 27.”
  • Cybersecurity Dive relates,
    • “Security researchers warn that a newly discovered ransomware variant called Settra has targeted virtual private network environments or compromised credentials for initial access before deploying remote monitoring and management tools to gain persistent access in targeted environments. 
    • “Researchers from Huntress observed two specific attacks in recent months, including a July incident at a consumer services and retail organization and a September incident at a manufacturing firm, according to a blog post published Thursday [September 17].
    • “The attackers could be described as capable rather than sophisticated,” said Lindsey O’Donnell-Welch, principal technical community engagement writer at Huntress. “They used effective, established ransomware tradecraft: MeshAgent for persistence, a vulnerable driver to potentially impair defenses, log clearing and recovery tampering.”
    • “Researchers from MoxFive said Settra used compromised VPN credentials to gain initial access and posted numerous victim organizations on its shaming site. The group claims to target organizations with exploitable weaknesses, such as unpatched systems or weak access management, according to a blog post from MoxFive.”
  • Bleeping Computer lets us know,
    • “The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
    • “The attack began Friday night [September 18] when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop’s site.
    • “The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter’s own data leak site.”
  • InfoSecurity Mag tells us,
    • “It is a scenario that every CISO hopes they never face: the network encrypted by ransomware attack and cybercriminals who claim to have stolen sensitive data which they will leak if they don’t receive a ransom payment.
    • “Unfortunately for Zach Lewis, CISO at the University of Health Science and Pharmacy (UHSP) in St. Louis, this was the reality he faced when the organization was hit by a LockBit ransomware attack in summer 2023. The University recovered without paying the ransom, but it was a challenging time for all involved.
    • “In a conversation with Infosecurity, Lewis opened up about how it felt to be the victim of a ransomware attack and the toll it took on his team, as well as how the organization recovered from the incident and the lessons other cybersecurity leaders can learn from this experience.”

From the cybersecurity business and defenses front

  • The Wall Street Journal reports,
    • “Companies are facing a new era in cyberattacks driven by AI. But according to one cybersecurity CEO, having the right technology for defense isn’t necessarily the problem. It’s the humans who need to step up—particularly CEOs.
    • “What we’ve seen practically from working with some of the largest organizations in the world is that the technology is already there,” Galina Antova, CEO of the AI-driven security platform Kai, said at the Leadership Institute’s WSJ Technology Council Summit this week. “We could implement so many improvements,” using autonomous AI, she added.
    • “But what it really comes down to is having “the right incentive for the leaders to pursue that,” and “are they enabling their security organization to really move at machine speed?” 
    • “Companies need courage and leadership, she told enterprise tech bureau chief Steve Rosenbush, in a discussion that included Oege de Moor, founder and CEO of cybersecurity firm XBOW. 
    • Some additional insights from their conversation:
      • “Companies may need to redesign their security workflows. Attackers are “already moving at machine speed,” and they’re encountering a patchwork of protections, Antova reported. She has found that many Fortune 500 companies use some 80 to 120 security tools “that are organized in a very fragmented way,” she said. That means that when a company has an exposure, it can take time—days, weeks, or months—to find and close it. By contrast, she said, an end-to-end autonomous defense system that’s supervised by humans can reduce that time to minutes.” * * *
      • “[B]oth CEOs noted that the gap between frontier and open models was shrinking—and Antova added that with the right cybersecurity expertise and a surgical approach to deployment, the cost of AI-enabled security no longer needs to be prohibitive.”
  • Cybersecurity Dive adds,
    • “Artificial intelligence is now the leading driver behind new investment into cybersecurity budgets, according to a report released Tuesday from IANS and Artico Search.  
    • “About seven of every 10 chief information security officers surveyed said AI was their top priority for new cybersecurity spending. Two specific areas for AI-related spending shown in the report include automating security operations and enhancing identity and access management. 
    • “Overall security spending rose 5% in the current survey, which is barely ahead of the 4% spending increase in the year-ago report. AI spending priorities come at a time of relatively modest growth in overall security spending.”
  • Per CISA news releases,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) hosted Cyber Storm X this week, a four-day national cybersecurity exercise designed to test and ultimately strengthen the nation’s resilience. This year’s exercise included 2,000 participants from across the public and private sectors and marks the tenth exercise in the 20-year history of Cyber Storm. The biennial exercise brings together the people who manage the services our nation relies on, including water, energy, and other vital sectors. During the exercise, participants practice how they would respond to a major cyber incident affecting critical infrastructure.
    • “Cyber Storm helps critical infrastructure owners and operators understand how we would manage a large-scale cyber incident,” said Acting CISA Director Nick Andersen.  “Exercises strengthen our national resilience by making sure our plans, policies, and partnerships are ready when we need them.  As a nation, we need the ability to respond swiftly and effectively to critical threats. That’s exactly what Cyber Storm does and why it’s a vital exercise for our nation’s security.”
    • “This year’s exercise focused on a scenario involving a nation-state adversary targeting the transportation systems sector, including rail and ports, along with the water and wastewater systems sector. The exercise allowed participants to test response plans, practice coordination, and strengthen information sharing in a safe environment. Cyber Storm X included over two hundred organizations across all levels of government and the private sector.
    • “CISA will now collaborate with participating organizations to identify lessons learned from the exercise. We will use these findings in a public after-action report that captures observations, analyses, and recommendations. CISA is committed to providing access to a wide range of cybersecurity tools and training opportunities, with exercises being a critical part of that toolkit to enhance our nation’s cyber preparedness.
    • “For more information, please visit Cyber Storm X: National Cyber Exercise.”
  • and
    • “Today [September 16], the Cybersecurity and Infrastructure Security Agency (CISA) released guidance that helps critical infrastructure owners and operators implement realistic decoy systems and information assets to quickly detect and disrupt malicious activity occurring in their networks, which will ultimately improve their cyber defenses. Using Cyber Decoys to Strengthen Detection and Response is the first guide from CISA that offers a detailed explanation of the defensive cyber decoy process.
    • “Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land techniques to conduct discovery, move laterally, and access data. In this guide, CISA encourages critical infrastructure organizations to incorporate cyber decoy capabilities alongside existing Zero Trust models. Cyber decoy strategies operate on the expectation that malicious actors may eventually gain some level of access. By placing decoys within internal networks and systems, especially in high-value areas, organizations can enable defenders to:
      • “Detect adversaries operating within the environment early in the intrusion lifecycle;
      • “Gather and analyze information taken from intrusions and attempted intrusions;
      • “Allocate defensive resources more effectively based on observed adversary behaviors;
      • “Reduce mean time to detection (MTTD) by generating high-fidelity alerts.” * * *
    • “To effectively use this guide, cyber defenders should have a basic understanding of the MITRE ATT&CK ® Matrix and common enterprise security controls and tools. The guide provides a practical approach to designing and implementing decoy strategies by leveraging the MITRE ATT&CK® knowledge base and the MITRE Engage™ framework.
    • “For more information, please visit Cybersecurity Best Practices.”
  • and
    • “The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) today [September 15] released Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers (CSPs). The report guides federal agencies and CSPs in defending the identity tokens and assertions that underpin modern single sign-on (SSO), federation, and application programming interface (API)-based access, systems adversaries increasingly target to move laterally through enterprise networks and reach sensitive data.
    • “The final report incorporates key feedback from nearly 250 public comments on token validation, secrets management, and detection at scale. The report also reflects input from CISA’s long-term, strategic collaboration with industry CSPs and interagency partners through the Joint Cyber Defense Collaborative. CISA and NIST engagements with this group included a technical exchange in June 2025 with over 50 industry experts to identify approaches to harden identity infrastructure and a webinar in January 2026 to review the draft report. Dozens of individual meetings with CSPs were also held to discuss feedback that included Google, HashiCorp, an IBM Company, IBM, Microsoft Corporation, Okta Inc., the OpenID Foundation, Oracle America, Inc., Amazon Web Services, and Wiz.” * * *
    • “The recommendations in the final report apply across commercial and government-operated cloud services and support implementation of Executive Order 14306 on secure software development practices.
    • “CISA urges federal agencies, CSPs and cloud consumers to review and implement IR 8587 to improve the security of their cloud systems. 
    • “For more information on this effort, read NIST’s News Release.
  • Tech Target offers a tip about “how to verify the value of AI-powered business analytics.”
    • Executives can separate AI analytics capabilities from marketing hype by taking steps to confirm the platform improves decision-making and gives results that hold up.
  • Here is a link to Dark Reading’s CISO Corner.

Leave a Reply

Your email address will not be published. Required fields are marked *