Cybersecurity Saturday

From the AI frontier front,

  • CNBC reports,
    • “Anthropic and OpenAI on Tuesday each announced new, less costly artificial intelligence models as both frontier labs continue to face stiff competition from cheaper, open-weight competitors.
    • “OpenAI introduced additional tiers to its GPT-6 family, with GPT-6 Sol and GPT-6 Luna, slashing the API prices by 50% compared with GPT-5.6 promotional pricing. 
    • Sol, which is a tier below Astra, is meant for more complex workloads like coding, while the company’s Luna offering is geared toward “high-volume tasks” such as extracting information or summarizing documents, the company wrote. 
    • “Anthropic unveiled Claude Opus 5.5 on Tuesday, its latest release in the new Claude 5.5 model family. The company described the latest release as a more token-efficient version that will cost around 40% less to run than the company’s Opus 5.
    • “One of the things we’re continuing to innovate on is how to make that thinking, how to make the answering more efficient, so it uses less tokens depending on your effort setting,” Dianne Penn, head of product management, research and labs at Anthropic, told CNBC in an interview. 
    • “The separate releases are the first to roll out since Anthropic CEO Dario Amodei called for an industrywide slowdown on developing advanced AI as the debate about model safety reached a fever pitch in recent weeks.’
  • The Wall Street Journal relates,
    • “A swarm of OpenAI agents accessed U.S. government websites as part of a monthslong incident during which tests conducted by the artificial-intelligence company went awry, leading to unexpected internet activity.
    • “The AI agents accessed the websites belonging to the Commerce Department and the Securities and Exchange Commission and engaged in activity that OpenAI described as “misaligned.” That is the word AI companies use to describe bad behavior by their agents. In this case the misalignment appears to have been aggressive web browsing.
    • “In the case of the SEC, OpenAI’s agents copied and posted public data—something they were not supposed to do. In the case of the Commerce Department, an agent accessed a U.S. Census data website using a programming interface that wasn’t intended for this purpose, OpenAI said.
    • “OpenAI’s revelation came after the AI research nonprofit Transluce alleged that OpenAI agents “used an array of gray-area tactics to probe U.S. Government websites,” and attempted a “rudimentary,” but unsuccessful hack of an Education Department website. This was reported earlier by the New York Times.”
  • Bleeping Computer adds,
    • “OpenAI has confirmed it’s aware of a new security incident in which its AI agents uploaded user-provided images to third-party image-hosting services.
    • “OpenAI says most users were not affected, as it could only identify 53 incidents where agents accidentally uploaded images to the internet.
    • “The disclosure comes from OpenAI’s broader investigation into misaligned agent behavior following the Hugging Face security incident.”
  • The Wall Street Journal notes,
    • “President Trump said on Saturday [August 19] he was launching a new unit focused on artificial intelligence after leading figures in the industry publicly sounded the alarm over the growing technology.
    • “I am forming the AI Force, much like I did Space Force, which has been a tremendous SUCCESS, in my First Term,” Trump said on Truth Social. He added he is also recruiting an AI “czar.” The president had appointed investor David Sacks as his AI and crypto czar before the businessman stepped down from that role to become co-chair of the president’s Council of Advisors on Science and Technology, a role in which he is still one of Trump’s top advisers on AI policy.
    • “Saturday marks the first time the president has suggested there could be a new federal government entity solely dedicated to AI, but it isn’t clear what role it would play. Several other units of the government work on tech policy including the White House Office of Science and Technology Policy, the Commerce Department and the Defense Department.

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “The Cybersecurity and Infrastructure Security Agency published a paper Wednesday that lays out its plan for improving the Common Vulnerabilities and Exposures (CVE) program, a contract for which nearly ended last year before a last-minute reprieve.
    • “The white paper outlines the components of a “Quality Era” for the program, widely used as the definitive clearinghouse for data on vulnerabilities in software and other products, even as the number of CVEs surges. 
    • “CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail,” said Chris Butera, acting executive assistant director for cybersecurity. “Informed by CVE community feedback, this whitepaper communicates CISA’s effort to support and enable stronger participation and governance, a program-wide maturation effort.” * * *
    • “The plan calls for advancing data quality across four key dimensions: transparent and effective program governance, broad and active participation across the global software community, data infrastructure that supports CVE operational functions and reliable CVE record content. * * *
    • “Butera invited further feedback from the CVE community on the white paper, which stems from an earlier strategy document on the future of the program.
    • “Some CVE experts that CyberScoop spoke to were supportive of what CISA wants to achieve, but skeptical about elements of the white paper.”
  • and
    • “Nearly early nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found.
    • “The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs.
    • “The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses.” 
  • SC World tells us,
    • “The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the launch of Vulnerability Information and Coordination Environment – New Technology (VINCE-NT) on Thursday [September 17], an upgraded, fully CISA-hosted system that will replace the original VINCE for coordinated vulnerability disclosure (CVD).
    • “VINCE has been used by researchers, suppliers and stakeholders since 2020 to coordinate the disclosure of cybersecurity vulnerabilities, and was originally sponsored by CISA and hosted by Carnegie Mellon University’s CERT Coordination Center (CERT/CC) under its Software Engineering Institute.
    • “The new VINCE-NT system, officially live as of Sept. 17, 2026, is now fully sponsored, hosted and managed by CISA and includes several improvements to streamline CVD, the agency said in an FAQ.”
  • Per a National Institutes of Standards and Technology news release,
    • “NIST has released the initial public draft of Special Publication (SP) 800-82r4 (Revision 4),  Guide to Operational Technology (OT) Security, which provides guidelines for improving the security of OT systems while addressing their unique performance, reliability, and safety requirements.” * * *
    • “Updates in this revision include:
      • “Expanded introduction to OT sectors to include Building Automation and Control Systems (BACS), Water and Wastewater Systems (WWS), food and agriculture, freight rail, maritime vessels, and Industrial Internet of Things (IIoT) and cloud convergence
      • “Restructured around the NIST Cybersecurity Framework (CSF) 2.0, including a reorganization of the previous risk management section to focus on the CSF Govern Function
      • “Expanded discussion of how OT risk management aligns with broader enterprise risk management, as described in NIST IR 8286r1
      • “Discussion of the adoption of the NIST Risk Management Framework (RMF) in Appendix F
      • “Expanded guidelines for implementing OT security controls, including asset management and network monitoring and detection
      • Security architecture guidelines focused on protecting system management functions and applying zero trust principles
    • “The comment period on this initial public draft is open now through November 30, 2026. See the publication details for a copy of the draft and instructions for submitting comments.”
  • Per a Justice Department news release,
    • “Ardit Kutleshi, 28, a Kosovar national, pleaded guilty [on September 24] to charges related to his creation and operation of Rydox, an illicit website and marketplace for cybercriminals to buy, sell and trade stolen personal information, and to access devices and other tools for carrying out cybercrime and fraud.” 
  • Cyberscoop points out,
    • “A 35-year-old Armenian national was sentenced to two years in prison for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020, the Justice Department said Tuesday.
    • “Karen Vardanyan was extradited from Ukraine to the United States last year and pleaded guilty to computer fraud and conspiracy to commit fraud and extortion in July. Vardanyan’s sentencing, which also calls for about $1.2 million in restitution to victims, matches terms of a plea agreement he reached with prosecutors.
    • “Vardanyan and his co-conspirators’ victims include a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020, a Watsonville, Oregon-based technology company that was attacked in December 2019 and a Texas-based school breached in February 2020, according to court records.”

From the cybersecurity breaches and vulnerabilities front,

  • Cybersecurity Dive reports,
    • “The FBI is investigating a cyberattack on its jobs portal after the cybercrime group ShinyHunters said it hacked the system and stole a vast trove of sensitive data from the bureau.
    • “The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” the bureau said in a statement on Wednesday [September 23]. “While the point of breach is still undetermined—whether a third-party or the FBI’s enterprise—we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.” * * *
    • “ShinyHunters told 404 Media that it hacked into the jobs portal using a zero-day vulnerability in Oracle’s PeopleSoft human-resources platform, a tactic it has used before. The potentially wide-ranging breach highlights the supply chain risks facing organizations of all sizes and levels of sophistication. ShinyHunters specializes in supply chain attacks, and its intrusions have illuminated weaknesses in the security protocols at widely used software and infrastructure providers.”
  • and
    • “The healthcare and pharmaceutical sectors are facing a heightened risk of social-engineering attacks, according to cybersecurity researchers and threat intelligence experts.
    • “The Health Information Sharing and Analysis Center recently warned that the group ShinyHunters was using voice-phishing attacks to target the healthcare sector. The hackers used medical-themed impersonation domains to trick healthcare employees into exposing their credentials. 
    • “More than a dozen member organizations have been hit by social-engineering attacks over the past couple of months, Errol Weiss, chief security officer at Health-ISAC, told Cybersecurity Dive. The actors involved are using aggressive tactics to try to compromise targeted companies. 
    • “They’re pretty belligerent when it comes to getting somebody on the phone and convincing them they need to click on a password reset or an MFA reset,” Weiss said.”
  • Beckers Health IT adds,
    • “Home medical equipment provider AdaptHealth disclosed that a June cyberattack exposed personal and health information belonging to more than 4.1 million patients, according to a filing with the HHS Office for Civil Rights.
    • “The company said the breach stemmed from a social engineering attack that compromised a third-party contractor’s user session, giving a threat actor access to AdaptHealth’s cloud-based patient management and document storage systems. AdaptHealth first disclosed the intrusion in a July 2 SEC filing after the attacker contacted the company June 15 claiming to have stolen data.”
    • “In an Aug. 14 notice, AdaptHealth said the threat actor exfiltrated names, contact information, demographic data, health insurance information and health information, along with a password file tied to insurance billing. Social Security numbers, financial account information and payment card data were not affected, the company said.”
  • and
    • “Eskenazi Health is notifying patients of a data breach after an employee’s cloud-based work account was compromised through a phishing email that appeared to come from a trusted business contact.
    • “The Indianapolis-based health system discovered the unauthorized access July 27, according to a Sept. 25 notice. A forensic investigation determined the unauthorized access began June 3 and continued until Eskenazi Health terminated it July 27.
    • “The incident began after the email account of one of Eskenazi Health’s business contacts was compromised and used to send thousands of unauthorized emails to individuals in the contact’s address book. An Eskenazi Health employee received one of the messages, which appeared to contain a secure document notification.
    • “After the employee interacted with the link and completed the requested authentication process, an unauthorized individual gained access to the employee’s work account, according to the notice.”
  • CISA added ten known exploited vulnerabilities (KVE) to its catalog this week.
    • September 21, 2026
      • CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
        • Aviatrix discusses this KVE here.
    • September 22, 2026
      • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
      • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
      • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
      • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
        • Cybersecurity News discusses the Check Point KVEs here.
        • Bleeping Computer discusses the Arista KVE here.
        • SOC Prime discusses the F5 KVE here.
    • September 24, 2026
      • CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
      • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability
        • Cybersecurity News discusses the WS02 vulnerabilities here.
        • Recent Breaches discusses the Abode and Magento KVE here.
    • September 25, 2026
      • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
      • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
        • The Hacker News discusses the Microsoft KVE here.
        • Recent Breaches discusses the Mikrotik KVE here.
    • September 25, 2026
      • CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability
        • Recent Breaches discusses the WordPress KVE here.

From the ransomware front,

  • HIPAA Journal reports,
    • “A new analysis of ransomware activity reveals broad, consistent targeting pressure across the United States. Ransomware activity is not limited to any specific industry, with all sectors attacked to varying degrees. The analysis was conducted by the AI-driven cybersecurity and threat intelligence platform provider Anomali, with the findings published in its US Ransomware Industry Targeting Report.
    • “Anomali observed ransomware targeting across 8 industry sectors by 200 distinct ransomware entities, with its analysis showing that technology was the most targeted sector, followed by manufacturing and healthcare.
    • “Anomali looked at ransomware targeting across eight industry sectors – technology, manufacturing, healthcare, financial services, government public services, construction, education, and energy. There was in excess of 50% observed targeting presence in all eight sectors, with technology companies targeted by 172 of the 200 ransomware entities (86%), followed by manufacturing with 166 (83%), and healthcare in third place with 154 (77%).”
  • Infosecurity Magazine relates,
    • “A newly formed ransomware group has claimed that if its victims don’t give into their extortion demands and pay a ransom, that they will destroy their backup infrastructure, in a move which could prevent a targeted organization from operating entirely.
    • “Named n0n, the emergence of the ransomware crew has been detailed by cybersecurity researchers at CyberXTron. In a blog post published on September 23, researchers said activity by n0n was first spotted on September 18 and by September 22 the group’s Tor-hosted leak site had published information about over a dozen victims.
    • “The group operates on a double extortion model which has become highly popular and highly effective among ransomware threat groups.”
  • Kaspersky adds,
    • “Kaspersky’s Global Emergency Response Team (GERT) has published a new report analyzing a sophisticated new tactic in the Payload ransomware family. Discovered during an incident response at a manufacturing company in the Middle East, this attack demonstrates a major shift in cybercrime: the attackers took complete control of the company’s network and forced its computers to lock up, display ransom notes, and change desktop wallpapers – all without deploying a conventional ransomware encryptor.
    • “This incident illustrates one of the trends mentioned in Kaspersky’s State of Ransomware 2026 reportreleased earlier this year: attackers are increasingly moving away from traditional file encryption. Instead, they are adopting “encryptionless extortion” – focusing on immediate operational disruption and leaking sensitive, stolen data on the dark web rather than relying on cryptographic keys to squeeze payments out of victims.”
  • Bleeping Computer notes,
    • “The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.
    • “The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.”

From the cybersecurity business and defenses front,

  • The American Hospital Association News reports,
    • “The FBI and the Cybersecurity and Infrastructure Security Agency have released a fact sheet for critical infrastructure organizations on ways to reduce risk and minimize vulnerabilities when working with third-party hardware and software networks designed to monitor and automate physical processes for control systems and devices, such as pumps, sensors and industrial computers for operating essential equipment. In healthcare, such applications are common throughout facilities and include climate control, building automation, access control and other systems. Such operational technology systems are essential for maintaining clinical operations. The agencies said that organizations should maintain caution when granting third-party networks high levels of access or control over such operations, allowing only the minimum access necessary to perform their assigned tasks. Granting additional access could expose owners and operators to malicious cyber actors attempting to exploit and compromise equipment and critical functions. The fact sheet includes recommendations for organizations to assess and reduce risk of attacks.”
  • Cybersecurity Dive relates,
    • “Google-owned cloud security firm Wiz said on Thursday that it is using AI tools to identify vulnerabilities in internet-facing critical infrastructure, from operational technology maintained by under-resourced utilities to software packages that are foundational to online activity.
    • “Where authorized, we will use the Wiz Red Agent and additional internal AI research capabilities to examine publicly facing websites, APIs, and applications,” Wiz’s Ami Luttwak and Gal Nagli wrote in a blog post about the company’s Scan for Good initiative. “This work will help organizations find and fix critical exposures before attackers do, allowing them to stay ahead of adversaries as AI capabilities advance.”
  • and
    • “Nearly nine out of 10 industrial security leaders said they believe their companies could contain a cyber incident, and nearly half of those same companies experienced a breach or attack over the past 12 months, according to a report released Tuesday by Rockwell Automation. 
    • “More than one-third of industrial firms described cyber risk as the top obstacle to growth. 
    • The report highlights a continued resilience gap in industrial environments, where maintaining operational technology is critical. More than 60% of industrial firms have invested in various security technologies, including asset inventory, intruder detection and secure remote access.” * * *
    • “A separate benchmark report out Tuesday from Honeywell Technologies also showed a significant gap in OT security readiness. The report, based on responses from more than 600 IT security leaders globally, showed only one in five organizations had complete visibility into their OT assets.” 
  • and
    • “As the cyber insurance industry has worked to regain momentum against a rising wave of cyber risk, the rapid emergence of AI has put increased pressure on determining whether the sector could afford to cover potentially billions in losses from a catastrophic event. 
    • “After months of uncertainty, Beazley, a leading specialist in the cyber sector, on Thursday confirmed it would provide “AI-afffirmative cover,” meaning it would cover losses stemming from an incident, even if the attacker utilized artificial intelligence.” 
  • Help Net Security notes,
    • “To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the malware, no running it.”
  • Dark Reading explains that “Stopping IT Worker Scams Requires Revamped HR Process.”
    • “Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.”
  • Here is a link to Dark Reading’s CISO Corner.

Leave a Reply

Your email address will not be published. Required fields are marked *