Cybersecurity Saturday

From the frontier AI and Project Glasswing front,

  • OPM’s CIO Adam Starr, writing in the OPM Director’s Secrets of OPM blog, lets us know,
    • “OPM has joined Anthropic’s Project Glasswing and OpenAI’s Daybreak, two industry initiatives that provide cyber defenders with access to advanced AI tools. Early results across Glasswing’s partner organizations are promising — more than 10,000 high- or critical-severity vulnerabilities identified in the first month. OPM will continue to pursue partnerships and capabilities that strengthen our defensive posture and protect the federal workforce data we are entrusted to secure.
    • “That moves the bottleneck. The hard part isn’t finding the hole anymore. It’s patching it.
    • “The flaws attackers are already exploiting have a name: KEVs, for the Known Exploited Vulnerabilities in the Cybersecurity and Infrastructure Security Agency’s catalog. My top security metric at OPM is simple: whether we’ve patched every KEV, and how fast.
    • “Now do that 119 times.
    • “The federal government runs roughly 119 separate HR IT systems. When a vendor ships a critical fix, every agency running that software applies it separately, on its own timeline. An attacker only needs one that’s behind.”
  • Tech Target adds,
    • “When Anthropic introduced Project Glasswing in April, the tech industry braced for impact. Five months in, DevSecOps teams are wading through the glut of discoveries to find out what’s worth patching – and so far, it isn’t much, according to one cybersecurity researcher.
    • “Anthropic updated its Vulnerability Disclosure ledger for the first time in August. A small percentage of initial Mythos vulnerability findings made it into the ledger, and fewer than 1% of the vulnerabilities Mythos found were marked as fixed, according to Patrick Garrity, a security researcher at vulnerability prioritization tool maker Vulncheck.
    • “Garrity and Vulncheck have also been tracking whether vulnerabilities discovered with AI are actually exploited in the wild. This research combined vulnerabilities attributed to Anthropic’s model with data from the Berkeley Vulnerability Research Initiative and correlated them with Vulncheck’s known-exploited vulnerability data.
    • “Of the 1,061 vulnerabilities attributed to AI-assisted discovery, only 14 had been listed as exploited in the wild as of June 2026. That’s roughly 1%.
    • “You discover a vulnerability — that doesn’t mean it’s necessarily useful for an attacker. It doesn’t mean it’s necessarily going to be exploitable with certain conditions,” Garrity said.”
  • The Wall Street Journal relates,
    • “OpenAI says it is scrapping the release of its next-generation AI model over safety concerns that researchers raised during internal testing, in one of the clearest signs so far that agent misbehavior could stymie the industry’s rapid progression.
    • “The move follows a summer punctuated by reports of artificial-intelligence systems industrywide going rogue, and marks a rare case of a major AI developer ditching a new release because of safety concerns.
    • “The company had planned to launch the model, known as GPT-6.1 Astra, in the coming days or weeks, aiming for an October debut. The model was more capable than the company’s previous models in completing challenging tasks from end-to-end without human assistance, as well as writing.
    • “The company instead will focus on improving the safety of future models, which it expects to be even more capable.”
  • and
    • “Nvidia NVDA  launched a software platform to help developers test and deploy artificial-intelligence agents and keep them in a secure environment, ramping up efforts to contain the technology following a string of rogue incidents in recent months.
    • “The chip giant said its Nvidia Open Agent Safety Platform includes tools that let developers continuously monitor and govern AI behavior, ensuring agents follow the rules. Nvidia said the platform included a watchdog that can quarantine agents that attempt to move outside their boundaries in milliseconds, as well as software to enforce what agents can see, do, and interact with.”

From the cybersecurity policy and law enforcement front

  • Beckers Health IT reports,
    • “The Senate passed the bipartisan Health Care Cybersecurity and Resilience Act (S. 3315) by unanimous consent.
    • “The legislation aims to help healthcare providers strengthen their cybersecurity defenses and protect patient information, according to an Oct. 1 news release from the Senate Committee on Health, Education, Labor and Pensions.
    • “Sens. Bill Cassidy, MD, R-La., Maggie Hassan, D-N.H., John Cornyn, R-Texas, and Mark Warner, D-Va., released statements on the Senate’s passage. Sens. Cindy Hyde-Smith, R-Miss., and Angus King, I-Maine, also co-sponsored the bill.
    • “Mr. Cornyn said the legislation would strengthen coordination among federal agencies and improve security practices for rural providers. Ms. Hassan said it would help hospitals and other providers, particularly rural organizations with fewer resources, strengthen cybersecurity and respond faster to attacks.”
  • The Wall Street Journal notes,
    • “President Trump is expected to name Director of National Intelligence Jay Clayton as the new artificial intelligence czar, spearheading AI policy across the administration, according to people familiar with the decision.
    • “The decision isn’t final, the people said, and no official announcement has been made. But the appointment comes as the White House is racing to address the threats posed by the latest models and boost the technology’s popularity. 
    • “Before Clayton was confirmed in July to lead the Office of the Director of National Intelligence, he served as the U.S. attorney for the Southern District of New York. He attended Tuesday’s meeting at the White House with AI leaders including OpenAI President Greg Brockman, Anthropic’s Dario Amodei, and Nvidia CEO Jensen Huang. Afterward, Trump was asked by a reporter if Clayton was under consideration for the role. He responded that Clayton is a “good man” and a “good idea.” CBS News earlier reported the potential appointment.”
  • The Wall Street Journal further relates,
    • “The Federal Trade Commission is investigating Anthropic and OpenAI to determine whether they deceived consumers about the potential harms of their artificial intelligence, the WSJ reports. The agency plans to send civil subpoenas to the two companies in the coming weeks, as well as third-party AI evaluator METR, author of an August report revealing how OpenAI agents secretly collaborated on a message board they built inside OpenAI.
    • “AI CEOs publicly signed White House safety principles alongside President Trump this week, but privately executives like Nvidia’s Jensen Huang pressed Anthropic’s Dario Amodei over his stark public warnings about AI risks, revealing tensions that could complicate the industry’s self-regulation plans, the WSJ reports.”
  • Cyberscoop tells us,
    • “Collaboration with industry is key to balancing AI security risks and benefits, as well as staying ahead of China and other adversarial nations, National Cyber Director Sean Cairncross said Thursday [October 1].
    • “The Trump administration is facing pressure from some quarters of Capitol Hill and even some artificial intelligence executives to establish regulations or embrace legislation to guard against the technology’s risks, something the president himself has rejected.
    • “We’ve never faced a world where our adversaries have the frontier in this space, and so our attempts to optimize that innovation and security is is something that is ongoing, but is increasingly efficient, and it depends on our relationship with industry and our ability to work collaboratively among the the interagency,” Cairncross said at the AI Edge event hosted by The Washington Post.
    • “That collaboration is ever-increasing, he said, such as with the National Institute of Standards and Technology’s Center for Advancing Innovation and Standards for Super Intelligence (CAISSI).
    • “Industry coordination on this, across critical infrastructure sectors, is improving both on industry-to-government and within industry,” he said. “There is collaboration with CAISSI and others as well to do evaluation and testing on these models. That includes work on guardrailing, sandboxing, et cetera.”
  • Cybersecurity Dive points out,
    • Policymakers should fix duplicative and contradictory regulations that currently impede the government’s ability to oversee the cybersecurity of critical infrastructure, industry representatives told the Government Accountability Office during a recent panel discussion.
    • The industry feedback, revealed in a GAO report published on Monday, is the latest evidence that the private sector is deeply unsatisfied with the patchwork of rules governing infrastructure security in the U.S. The new report also comes as the Cybersecurity and Infrastructure Security Agency (CISA) works to finish a congressionally mandated cybersecurity incident reporting rule that could impose sweeping requirements on a broad swath of infrastructure operators.
  • Per a Cybersecurity and Infrastructure Security Agency news release.
    • “The Cybersecurity and Infrastructure Security Agency (CISA) kicks off Cybersecurity Awareness Month today [October 1]. CISA updated our Cybersecurity Awareness Monthpage with additional information, tips, and resources, including for business and government organizations—if you haven’t done so yet, be sure to check out this year’s toolkit.  
    • This year’s theme is Securing the Next 250, highlighting the need for everyone to play their part in strengthening the country’s infrastructure against cyber threats. At a time when nation-state backed cyber threats continue to increase and super intelligence is transforming both threats and security, it is more important than ever that those that own and operate the nation’s critical infrastructure take steps to protect it. 
    • “Whenever critical infrastructure is disrupted, so are the businesses and communities that depend on vital services,” said Acting CISA Director Nick Andersen. “That’s why CISA is prioritizing the security and resilience of critical infrastructure, and state, local, tribal, and territorial government (SLTT), whose systems and services sustain us every day. This includes things like clean water, secure transportation, quality healthcare, secure financial transactions, rapid communications, and more. However great or small—every organization that touches critical infrastructure is vital to ensuring uninterrupted services to America’s communities.” 
  • The American Hospital Association News informs us,
    • “The AHA provided comments Sept. 30 to the Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia and Census for a hearing, “Rogue AI: Securing the Homeland Against AI Agent Attacks.” The AHA discussed how it has worked closely with federal agencies to build relationships and channels for the mutual exchange of cyber threat information, risk mitigation practices and resources to implement such practices. The AHA shared information on a rise of cyberattacks in healthcare and increased risk from artificial intelligence tools, the need for federal agencies to protect hospitals and health systems from nation-state-level cyberattacks, and the unique risks rural hospitals face when defending against cyberattacks.”
  • and
    • “The FBI Sept. 29 announced an arrest of one of the alleged leaders of ShinyHunters, a cybercriminal group linked to cyberattacks in the U.S. and internationally on more than 140 organizations, including healthcare, with at least $70 million taken in extortion payments. ShinyHunters has used targeted voice phishing campaigns to deceive personnel into exposing credentials on malicious, medical-themed impersonation domains, Health-ISAC announced in August. ShinyHunters threat actors have been observed contacting employees directly on personal devices through calls, voicemail messages and emails from multiple random accounts.
    • “ShinyHunters is currently one of the most prolific and aggressive cybercriminal groups targeting healthcare and third-party healthcare vendors,” said John Riggi, AHA national advisor for cybersecurity and risk. “They are known for stealing highly sensitive personal information, including health information and extorting victims with threats to publish it. Today’s highly commendable arrest and other recent enforcement actions align with the FBI’s new cyber strategy to impose costs on adversaries, support victims of cybercrime, and join forces with the private sector, including healthcare.”

From the cybersecurity breaches and vulnerabilities front

  • The New York Times reports,
    • “A criminal hacking group known as ShinyHunters revealed last week that it had stolen a vast trove of sensitive personal data from the F.B.I., potentially one of the worst breaches of sensitive government information in the internet age.
    • “The breach may have compromised information about tens of thousands of former and current F.B.I. employees, including data like home addresses, Social Security numbers and even secretive job assignments.
    • “In a series of cryptic statements, ShinyHunters demanded that the F.B.I. retract a public advisory the bureau had issued this springwarning of the group’s cyberattacks. In an email to The New York Times on Friday, ShinyHunters said that the bureau had until the end of Tuesday to fulfill its request. But on Monday, it appeared to walk back that demand, saying it would not publish the data, as it typically does with the information it steals.
    • “In a video posted online on Tuesday, the F.B.I. warned the group that it would aggressively pursue its members as it promoted the recent arrest of a suspect it said was affiliated with the group.”
  • The HIPAA Journal relates,
    • “There has been a 5.9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026, 397 data breaches affecting 500 or more individuals were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights – the lowest H1 total since 2023. While the year-over-year reduction in healthcare data breaches is a step in the right direction, healthcare data breaches continue to be reported in high numbers. In the first six months of the year, large healthcare data breaches were reported at a rate of more than 2.2 per day.
    • “Across the 397 reported data breaches, the protected health information of 33.77 million individuals was exposed or impermissibly disclosed. That represents a 22.6% reduction in affected individuals compared to H1 2025, and it is the lowest number of affected individuals in H1 since 2023.”
  • Cybersecurity Dive tells us,
    • “Fortinet on Thursday [October 1] warned of a critical path traversal vulnerability in Fortinet FortiMail, which has been exploited in the wild. 
    • “The zero-day vulnerability, tracked as CVE-2026-104286, allows an unauthenticated attacker to write arbitrary files on a system through the use of specially crafted HTTP or HTTPS requests. 
    • “Fortinet said it has been in touch with government authorities and other stakeholders regarding the threat, and urged customers to apply a workaround. The company did not say when a security patch would be available. 
    • “We are communicating with relevant government organizations, including CISA, on the content of this advisory,” a spokesperson told Cybersecurity Dive.
    • “FortiMail is a platform that provides companies protection from phishing, malware, business email compromise and other potential attacks.”
  • and
    • “Exploitation activity linked to zero-day vulnerabilities in Citrix NetScaler were initially detected on Thursday, days before public disclosure, according to a report Monday [September 28] from GreyNoise. 
    • A malicious cyber actor tried to exploit a zero-day flaw against Citrix NetScaler on Thursday [September 24], according to GreyNoise researchers. At the time, there were no detections available that were specific to this CVE, but researchers labeled the activity malicious. 
    • Two days later, Citrix NetScaler customers began receiving warnings to disconnect their servers due to suspected exploitation activity. By Sunday, Citrix released an official security bulletin warning of multiple vulnerabilities in NetScaler ADC and NetScaler Gateway. 
    • The exploitation activity involved a remote code execution (RCE) vulnerability, tracked as CVE-2026-88771 and a memory overflow vulnerability, tracked as CVE-2026-88772. 
    • Citrix urged customers to immediately patch their systems, warning that successful exploitation could result in RCE, denial of service, HTTP request smuggling and other consequences. 
  • The Cybersecurity Hub Newsletter, posted on LinkedIn, notes,
    • “Dell has released security updates for its Container Storage Modules (CSM) after disclosing vulnerabilities that could allow attackers to take control of infrastructure connecting Kubernetes applications to enterprise storage.
    • “Two flaws carry the maximum CVSS severity score of 10.0. They affect the CSM Authorization module, putting a security component responsible for controlling storage access at the centre of the disclosure. Additional critical vulnerabilities raise concerns about cluster privileges, authentication tokens and sensitive credentials.
    • “The advisory was published on October 1. Dell had not flagged the issues as actively exploited at the time of publication. That distinction matters: the disclosure describes serious opportunities for compromise, but does not establish that customers have already been attacked.
    • “The potential impact deserves attention beyond infrastructure teams. Storage services underpin the availability and integrity of business applications. A failure in the systems governing access to those services can affect several workloads at once, making the scope of a deployment as important to an organisation’s response as the severity score.”

From the ransomware front,

  • Tech Target lets us know that “August’s ransomware activity hit new high for the year.
    • “NCC Group identified 83 ransomware groups active last month, but it said AI wasn’t necessarily what drove the increase in the number of bad actors.”
  • VMblog reports,
    • “Most ransomware defenses rest on a simple assumption: if files look encrypted, you’ve been hit, and if they look normal, you’re safe. New research suggests that assumption is outdated. After detonating 1,064 real ransomware strains in a controlled environment during the first half of 2026, Index Engines’ CyberSense Research Lab found that directory-entry destruction (47.8%) was far more common than full encryption (18.3%). Some strains even scrambled data while leaving filenames, file sizes, timestamps, and entropy untouched, so corrupted files looked perfectly healthy.
    • “To mark Cybersecurity Awareness Month, we spoke with Jim McGann, CMO of Index Engines, about what these findings mean for detection, recovery, and the role of AI in modern attacks. He explains why signature-based detection is losing ground, how quickly damage can spread, and why leaders should move from asking “Do we have backups?” to “Can we prove our recovery data is clean?”
  • Dark Reading tells us,
    • “German authorities have identified a 16-year-old as the alleged mastermind of the KillSec ransomware operation, following a coordinated law enforcement operation that resulted in the arrests of three suspects and searches of eight properties in Spain, Greece, Romania, and the UK.
    • “In an Oct. 1 statement, Hamburg police said investigators also took control of KillSec’s leak website and secured at least 110TB of data to prevent further unauthorized access.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • “Google unveiled its latest AI model, Gemini 4 Argon, with a notice up top that its release would be limited, at least for now, to a list of “trusted cybersecurity vendors.” Such has become the new normal for frontier-model announcements in the post-Mythos age, where touting the guardrails can seem to outweigh posting the wins.
    • “And Gemini 4 Argon, which comes out nearly a year after Gemini 3 enabled the company to leapfrog rivals, clocks some wins. According to the company, the model sets new highs on several coding and knowledge-work benchmarks.
    • “Google says Gemini 4 Argon is already in use inside the company. It has helped quantum computing researchers “optimize the spacetime resources” of certain subroutines and has optimized memory use across its data centers. Argon agents are also migrating C/C++ codebases to Rust across Google.”
  • Beckers Health IT adds,
    • “Google says its new frontier AI model, Gemini 4 Argon, uncovered a critical vulnerability in healthcare software used by hospitals worldwide that put sensitive personal information at risk.
    • “Google-owned cybersecurity company Wiz found the flaw through its Scan for Good initiative, which offers free scanning to find and fix high-risk exposures at organizations that run critical public infrastructure. Koray Kavukcuoglu, senior vice president of Google DeepMind and chief AI architect at Google, described the finding in a Sept. 30 blog post. Mr. Kavukcuoglu said earlier frontier models had missed the risk.
    • “Google did not name the software or its vendor. It also did not say what specific data was at risk or whether the vulnerability has been patched.
    • “Wiz said Sept. 24 that Scan for Good, using Google’s Gemini 3.8 Flash Cyber model, had found exposures at two unnamed hospitals, which it said were fixed before disclosure. Google did not say whether the Argon finding is related to either case.”
  • The New York Times relates,
    • “Epic Systems, the nation’s largest medical records vendor that is relied on by thousands of hospitals and doctors’ offices, is using artificial intelligence tools to patch security risks that could give hackers undetectable access to patient health data, company officials said.
    • “The unusual nature of the vulnerability and the urgency to fix it prompted Epic to slow down development of some product lines while it sent engineers into a sprint to patch security holes.
    • “Judy Faulkner, Epic’s chief executive, revealed the security weakness and a six-week plan to shore up the gaps at an industry conference last week, but most details about the danger have not previously been reported.
    • “You worry that after a month and a half of working almost primarily on safeguarding the software, that new things will be created by those who are trying to bust the software, and it will be in a never-ending cycle,” Ms. Faulkner said.
    • “According to company representatives, Epic deployed Anthropic’s Claude Mythos artificial intelligence agent to stress-test its systems, to hunt for ways that hackers could unleash open-source A.I. agents and unlock confidential patient records.
    • “The security weaknesses pose a particularly acute threat for Epic, which maintains records of 325 million patients in the United States and other countries.
    • “And it underscores the competing forces surrounding the ever-expanding uses of artificial intelligence in health care.”
  • Cyberscoop informs us,
    • “OpenAI said it disrupted a “coordinated campaign” to distill and extract reasoning capabilities from its AI models, pointing the finger at a Chinese rival.
    • “On Wednesday [September 30], OpenAI said it first spotted low-level activity on July 1 that gradually increased until July 24 and 25, when it observed 16,000 prompts from 4,000 users that fit a similar “relevant extraction pattern.” The number of suspicious users had climbed to 15,000 by July 28, when OpenAI said it “fully disrupted” the operation.
    • “The company called the attackers’ method “novel.” They copied encrypted reasoning data from one conversation, then asked the model in a separate conversation to decrypt the content and transcribe it in plain text. Outside researchers reported a similar vulnerability to OpenAI in August.
    • “The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” OpenAI wrote in an unsigned blog post. “Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.”
  • Cybersecurity Dive tells us,
    • “Businesses need to prepare for the ways in which AI is changing the cyberattack landscape, Microsoft warned on Thursday [October 1].
    • “AI is speeding up attacks, making advanced techniques easier and putting stress on systems that organizations have long overlooked, the company said in its annual Digital Defense Report.
    • “The report also describes nation-state and cybercrime threat actors’ most significant activity from the past year, including their targets and motivations.”
  • The Wall Street Journal points out,
    • “Cybersecurity startup Armadin has raised $255.5 million to boost its force of AI agents trained to find security flaws cybercriminals are most likely to exploit—in part by attacking customers with swarms of autonomous hackers.
    • “Total funding for Armadin, which security veteran Kevin Mandia founded a year ago, is now $445 million. The company’s market valuation tops $2.5 billion. More here from my colleague Angus Loten.”
  • Here is a link to Dark Reading’s CISO Corner

Leave a Reply

Your email address will not be published. Required fields are marked *