Skip to content
TrackPodcasts
newsSep 9, 202630:40

Clear your calendar, it’s Patch Tuesday.

CyberWire Daily

About this episode

CyberWire Daily is made possible by:


Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalking and sextortion. Andy Hornegold, Chief Security Technologist from Intruder, discusses what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Putting AI at the head of the class.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Andy Hornegold, Chief Security Technologist from Intruder, discussing what makes up a reliable AI pentests and the benefits and risks that come with AI-enabled security. Selected Reading Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days (Hackread) Ivanti Patches Critical Flaws Across Enterprise Security Products (SecurityWeek) Chrome 153 Patches Seventh Zero-Day of 2026 (SecurityWeek) Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (SecurityWeek) ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws (SecurityWeek) CISA, NSA and FBI Warn Chinese AI Firms Are Targeting U.S. AI Models at Industrial Scale (HSToday) Europe's push for space sovereignty. (N2K Networks) History for European spaceflight: Isar Aerospace reaches orbit and deploys payloads on second flight (Isar Aerospace) ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 (Talos Intelligence) LG TVs caught spying even when offline or on standby (The Verge) 'White hat' hackers take $47 million bounty after $320 million crypto theft (The Record) Man gets 15 years for extorting women with AI-generated porn videos (Bleeping Computer) Alpha School’s AI teaching model is expanding. Does it work? (Scientific American) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Get every episode summarized

Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

275 searchable segments. Every word is indexed and playable.

Clear your calendar, it’s Patch Tuesday.

CyberWire Daily

0:00
30:40

Full transcript

CyberWire DailyClear your calendar, it’s Patch Tuesday.. Machine-transcribed; use the interactive transcript above to jump the player to any line.

You're listening to the CyberWire network, powered by N2K. Yes, you can have an enterprise network that's secure and reliable and high performance, and no, you don't need to choose the best two out of three. With meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage. That's because meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network. Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design. You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching firewalls, DNS security, and VPNs. You'll really know what's running on your network down to the most granular client level.

Step off the hardware box upgrade treadmill and switch to meter for a predictable fee, and free up your team to spend time on all the other things that keep your business running. Try it out for yourself and book a demo online at meter.com slash CyberWire. That's M-E-T-E-R dot com slash CyberWire. Patch Tuesday is a doozy. The Fed's Warren China-based AI companies are distilling USAI models. A new click-fix campaign goes straight for the browser. Smart TVs get nosy. Packers gift themselves a $47 million bug bounty. And a high-oh man gets 15 years in federal prison for cyber stalking and sex torsion. Our guest is Andy Horngold, chief security technologist from Intruder, discussing what

makes up a reliable AI pen test, and putting AI at the head of the class. It's Wednesday, September 9th, 2026. I'm Dave Bittner, and this is your CyberWire Intel Briefing. Thanks for joining us here today. It's great to have you with us. Microsoft's September Patch Tuesday is its largest on record with the company reporting fixes for 966 vulnerabilities. Independent tallies very slightly, but all point to an unusually heavy month. 105 vulnerabilities are rated critical.

258 involve remote code execution and 438 involve privilege escalation. Two Windows zero days were already being exploited. One affects the Windows update stack and can allow a local attacker to gain system privileges. Another, a buffer overflow in Windows ALPC can let an attacker escape a low-privilege app container and reach system. Neither provides an initial remote foothold. Both are useful for escalating privileges after a system has already been compromised. Microsoft also patched critical vulnerabilities across core networking services, including DNS, DHCP, NetLogon, MessagingQ, and NFS. CrowdStrike identified at least 17 remote code execution flaws reachable over the network without authentication. Office received 22 critical fixes, including vulnerabilities that could potentially execute code when a malicious file is merely previewed. Hyper-V flaws could enable

attacks from a compromised guest virtual machine against its host. The broader September patch cycle is similarly busy. Adobe fixed more than 170 vulnerabilities, including an actively exploited unauthenticated commerce and magento RCE zero-day. Google patch 230 Chrome vulnerabilities, including the browser's seventh exploited zero-day of 2026. Evante addressed six critical RCE vulnerabilities in neurons for ITSM, while Schneider Electric, Siemens, Aviva, and Rockwell Automation issued updates covering industrial systems. Sissa, the NSA, and FBI are warning that China-based AI companies have been systematically extracting capabilities from leading USAI models through large-scale knowledge distillation campaigns. The agencies say DeepSeek, Moonshot AI, Alibaba, Minimax, StepFun, and ZAI have

extracted billions of tokens through millions of requests involving models, including Claude, GPT, Gemini, and GROC since at least late 2024. Knowledge distillation is a legitimate technique for training smaller models using outputs for more capable ones, but the advisory says these campaigns violate US providers' terms of service and accelerate Chinese AI development. The agency's assessed the activity is occurring likely with Chinese government awareness. The advisory urges USAI companies to improve detection of suspicious accounts and usage patterns, alter responses to suspected distillation attempts to reduce their value and share intelligence across model providers, cloud platforms, and API aggregators. Maria Vermauses is host of the T-Minus Space Cyber Podcast. She joins us each Wednesday with the latest news from space. Today, it's about European sovereignty.

Thank you, Dave. This past Saturday on September 5, I saw aerospace of Germany made history with the first launch to orbit from the European continent. I saw as Spectrum Rocket launched from Andoya Spaceport in Norway and successfully deployed six satellites to low-Earth orbit. Now, ISAR is a commercial space company with a large backing from the European Space Agency, and their successful launch from Norway means Europe will now have launch options much closer to home beyond the Issa Spaceport in Kuru, French Guiana, with the proven ability to launch to orbit from European soil with homegrown European rocketry. The push now is to scale up and increase launch cadence to meet growing demand from European customers. Along those lines, ISAR says for additional Spectrum rockets are already in production and that the company plans to manufacture up to 40 Spectrum launch vehicles a year when their new production facility is complete.

In all, ISAR's successful orbital launch is a major step forward for European space sovereignty, especially as Europe continues to build out its high priority, secure satellite communications constellation, the Iris Squared. For the CyberWire Daily, I'm Maria Vermauses from T-Minus Space Cyber Briefing back to you, Dave. Be sure to check out the T-Minus Space Cyber Podcast wherever you get your favorite shows. Cisco Talos is tracking a cryptocurrency theft campaign that puts a twist on click-fix social engineering. Instead of persuading victims to execute commands on their computers, attackers convince them to inject malicious JavaScript directly into their browsers. The lure is a fake vulnerability report promising bigger payouts from cryptocurrency exchanges. Victims are instructed either to paste JavaScript into Chrome or install it through the legitimate Temper Monkey extension, which gives them malware persistence. The attackers have

promoted the supposed exploit through Telegram, dark web forums, and paste sites. The injected code uses Google's visualization API to retrieve obfuscated JavaScript stored in publicly accessible Google's sheets, making command and control traffic look like legitimate browser activity. Once running, the script acts as a web skimmer, replacing cryptocurrency deposit addresses in website responses and the clipboard with attacker-controlled wallets while displaying fake bonus information. Talos identified 49 Bitcoin addresses associated with the campaign and traced roughly $10,000 to known victim payments, though the actual haul may be higher. An investigation by Gamers Nexus, Level 1 Techs, and independent security researchers found LG Smart TVs extensively collecting information about owners and their homes. Tests found the

TV scanning local networks for nearby devices, gathering location and Wi-Fi data, and sending information to LG Add Solutions. Researchers also found that TVs could record microphone audio while in standby storing recordings offline until Internet access returned. LG's automatic content recognition technology additionally samples audio and video to identify content viewed through Smart TV apps and connected devices, including HDMI inputs. A $320 million cryptocurrency theft from Liquid Network ended with the attacker's returning most of the money and keeping about $47 million as a self-appointed bug bounty. Liquid said purported white hat hackers withdrew $4,000 Bitcoin from one of its wallets Sunday, prompting operator Blockstream to pause deposits and withdrawals.

The attackers then opened negotiations through messages embedded in blockchain transactions, claiming they were white hats and demanding that Blockstream patch an alleged vulnerability before they returned the funds. After roughly 12 hours of public and private exchanges, the hackers returned about 266.5 million on Monday and retained 598.5 Bitcoin as their reward. Blockstreams said updated software had been deployed as it prepared to restart the system. The vulnerability source remains debated, although side swap and several blockchain security experts have pointed to a flaw in elements, the software underlying Blockstreams liquid side chain. An Ohio man has been sentenced to 15 years in federal prison for a cyber stalking and sex-stortion campaign that used artificial intelligence to create sexually explicit material depicting

his victims. Prosecutors say 37-year-old James Strawler, the second, used more than 100 AI models across more than two dozen platforms to generate explicit images and videos. Between December 2024 and June 2025, he harassed at least six adult women sending both authentic and AI-generated nude images, threatening victims with sexual violence and sharing fabricated explicit material with their co-workers. He also threatened victims' mothers in an effort to obtain nude photographs. Investigators found more than 700 images Strawler had posted to a child sexual abuse website, along with thousands of potentially abusive or violent files on his phone. Strawler pleaded guilty in April and became the first person convicted under the 2025 Take It Down Act, which prohibits publishing intimate images and AI-generated explicit forgeries

without consent. Coming up after the break, my conversation with Andy Horngold from Intruder, we're discussing what makes up a reliable AI pen test and putting AI at the head of the class. Stick around. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is an opportunity for something to go wrong. And most security programs weren't built for AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform used by over 16,000 fast-moving

companies like Ramp, Kerser, and Harvey to ensure they're always audit ready. And now, Vanta is helping companies like yours watch for the risks that show up between audits across your vendors, your AI tools, and your whole environment. The Vanta agent works like a 24-7 GRC engineer in the background, finding issues, drafting fixes for you, and cutting vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at Vanta.com slash cyber. That's vant.com slash cyber. Andy Horngold is chief security technologist from Intruder. We recently sat down to discuss

what makes up a reliable AI pen test. Pen testings come on leaps and bounds probably in the last, I'd say, 24 months. I think everybody's come on leaps and bounds in the last eight, 12 months, right? The whole world seems to have shifted. I think professional services and human-led pen testing has probably been under more pressure as of late from product-led approaches to delivering security, validation, and security assurance. Obviously, pen testing, human-led pen testing has pretty much been point in time for a very long time, and anybody who is a pen tester who works in security will tell you that continuous is definitely the way to go, but historically it's been difficult to try and turn a human led approach into a continuous offering just because human time is expensive. You're capped by people being on a holiday and their availability, but with the advent of AI being able to reason across applications, being able to hold entire code bases and infrastructure configurations and cloud configurations in its context,

window and one go, being able to reason across it, has certainly shifted things. And finally, I think after probably a couple of decades of people saying that continuous is definitely the right approach, feels like it's finally within grasp of having true security validation on continuously. So the people who are tasked with pen testing, what are some of the specific things they need to be mindful of these days in this new environment? I think in the new environment, you're able to do things significantly quicker than you were previously. Like I remember doing pen tests back in the day where you were asked to do source code reviews or at least code assisted pen tests and you'd have to use one of the SAS scanners, the static code analysis tools that was out there and was available. But it was always a headache. I don't think anybody, like when I ran pen testing team over a context, nobody enjoyed doing that security code review side of things. I think there's very few people in the world who do enjoy reading other people's code. But

that's part of what we need to do when it comes to informed pen testing. But now with the AI that's available, pen testers are able to do that more quickly. So they're able to, they're able to reason across code, they're able to interrogate it, they're able to find answers to questions within a code base that historically would have taken them time to query across. I think the professional services industry is having a bit of a shake up at the moment and I put pen testing under professional services. So I think there is some difficulty. The reason is just because AI pen testing, I think, is going to take up some of that market space. That's not to say I think AI pen testing is going to hoover up every part of pen testing. I think there's still expertise, led experience, led components of pen testing that's really important, right? Like when you're dealing with safety systems, ICS, OT, we're the wonderful networks. I think that's still going to be human-led pen testing. But right now, I think we're going to start to see that human come out of

that loop for the day to day, probably more mundane business as usual style pen testing. And I think that's definitely going to impact the way people are operating within the professional services space. I know you've advocated for the importance of benchmarks provided by an independent party here. Can you explain that to us? Why is that important for AI pen testing? Sure thing. I think coming from pen testing and red teaming myself, like if you're a consumer, if you're somebody who's going out to buy a pen test, you want to make sure that you have some level of assurance of the quality of that pen test, of that red team, whatever it may be. You need to know that I'm going to have somebody on my side who is able to do what I need them to, they're not just going to be some, for lack of a better phrase, cowboy who's going to come on and potentially not do what they've told me they can do or they should be doing. And we've done

that historically, using benchmarks and using qualifications. So you'll often hear people say I have OSWE, like off-sec qualifications, and as a consumer, you can say, okay, the pen testing firm that I'm buying from is has a certain level of certification. That's not necessarily going to say that the individual pen tester that is assigned to your gig is necessarily going to have all of those qualifications, but you know you're getting it from a legitimate firm. Now, when it comes to the AI side of things, we don't really have any of that kind of understanding of what is the level of quality that each of these models with their harnesses, these AI pen testers are actually capable of delivering. Are they able to deliver at a certified level at a high level, like a highly experienced pen tester would be able to deliver, or are they just going to be able to do the basic checks that we expect of junior pen testers, graduates who are just coming out of university? And that's

really important. It's really important to be able to say with confidence that the pen test I've just received has some level of quality to it. So that's why I think over the last few months we've been investigating what does what a certification look like for this new wave of AI pen testers? What does it take for somebody to accept that the AI pen tester they've just had run for them is of quality? No, don't get me wrong. The findings that we're seeing within AI pen testing are eye-wateringly good. They are finding things that experienced pen testers haven't been able to find for kind of the last five, six years. They're training together really complicated attack parts and building this understanding of risk through applications and infrastructure that have kind of laid dormant for years. So that kind of gives you some confidence that the quality is but how do we benchmark it? And we're seeing kind of a combination of things happen to give people

that kind of trust. We're seeing benchmarks from private organizations saying, hey, this model performs slightly better at this benchmark than this other model does. We're seeing private companies kind of compare themselves against each other, but all of those are led predominantly by the marketing approach. You're going to see some favoritism in there. Now in the UK and actually US, Australia as well, one of the certification approaches we've had historically has been called Crest, the Council for Registered Ethical Security Testers. And they've put pen testers through exams, through assault courses to be able to say whether they reach a certain bar. My opinion is that I think we need something independent third party that can deliver the same kind of certification and benchmarking for AI pen testers at large. There's an increasing number of AI pen testing firms springing up. So how do we have a third party independent organization that's

able to give us that certification rather than just hearing the noise that comes with a huge multi hundreds of thousands of dollars marketing campaign? In your opinion, what are the types of things that organizations should be asking of the folks that they're engaging with to do their pen testing? I mean, if we're talking specifically around the kind of the AI pen testing approach, I think there's a bunch of different questions you can ask. One of which is kind of like, what is the history? What is the heritage, if you will, of the organization that is providing this pen test? Like, is it run by people who have security experience who have been in the trenches, who have delivered pen tests in the past, who have run red teams? Have they got a security team who have experience and expertise? Are they already qualified? And now they're applying those qualifications and that knowledge to building this new technology? I think that's super important.

As you start to see smaller businesses spring up out of nowhere and start to say they're delivering AI pen testing, being able to make sure that there is a culture of quality that has come from years of security testing. In my opinion, is super important. I don't know, Dave, if you've been involved on there, like the pen testing procurement side of things and like the kinds of questions you've asked people in the past, but have you thought about kind of the, I suppose, the heritage and the culture of the company that you're acquiring a pen test from? I have never had the privilege knowing. That might be a good thing. I can't say I stay up at night wishing that I was involved with that, but I'm glad there are people out there who know the right questions to ask, such as yourself. Thank you. I think that's one of the big questions I would ask. There's obviously one of the technical questions that the West is starting to see as well. We're starting to see people ask, what are the models that you're using under the hood? What's the methodology that you're following?

And how can you guarantee the agents of following that methodology? These are all kind of fun questions to answer. They're difficult to answer for pen testing, AI pen testing firms in particular, because AI agents and models are non-deterministic. When you try and steer these agents to follow a strict methodology, they tend to get tunnel vision and they will only follow that methodology. And as a result, within open benchmarks or in your testing EVO suite, you start to see the quality of that pen test deteriorate. It finds less vulnerabilities than if you just let the agent reason over the entire code base and follow its own nose. It's kind of funny because it follows what a human pen tester would do as well. We've had methodologies for a long time. We've had methodologies because we want to make sure that the human pen tester is doing everything that they should be doing during engagement. But a good pen tester, a good red teamer, initially will follow their nose.

They'll understand the application, they'll understand the environment, they're operating in, work out how it's all bolted together and what the workflows and user journeys are. And then they'll start to find vulnerabilities naturally. And then towards the end of that assessment, that's when they'll refer to the methodology and they'll start to say, okay, you know, I followed my nose, I found some call vulnerabilities and call risk within this app, within this environment. But now I just need to make sure I'm dotting the eyes and crossing the tees. And I'll do that by referring back to the methodology. An agent does the same thing, right? It goes through that code base. It reasons through it. And it will find interesting violence. But at the end of the day, you don't need to rely just on that agent to deliver that methodology or deliver that AI-driven pen test, right? The AI can do that call reasoning. But then you can layer on top of it, heuristic tools and deterministic tools like, you know, checking for TLS ciphers, for example. You don't need an agent to do that. You could run an agent if you want to go really deep on

pen testing, like open SSL, for example. But just to check whether a TLS cipher or weak TLS cipher is in use, you can use test SSL.SH just a tool that you can run and you'll be able to get the output. So using a combination of both the agent and then those deterministic tools as well gives you a pretty decent coverage of standard methodologies. So that's where that question of like, how are you ensuring coverage of my application is really important too? That's Andy Horngold from Intruder. And finally, an elite private school called Alpha School is betting that the future of education looks a little like a self-driving car. Feed an AI enough examples of wrong turns,

unexpected obstacles and student misconceptions, and eventually it learns to navigate. At Alpha, students spend about two hours each morning with adaptive AI tutors, followed by workshops in coding, entrepreneurship and other life skills. The private school company where tuition can reach $75,000 a year plans to expand to roughly 50 US campuses this fall. There's evidence behind parts of the concept. Research has found adaptive AI tutoring can improve learning, including a Harvard study where students using an AI tutor achieved more than twice the median learning gains of students using classroom active learning strategies. But researchers caution that effective tutoring isn't necessarily effective schooling. Critics worry about replacing trained teachers, weakening teacher student relationships, and producing knowledge that works inside the software but doesn't travel well outside it.

The AI tutor may know the route, whether it should drive the whole school bus remains another question. And that's the CyberWire for links to all of today's stories. Check out our daily briefing at the cyberwire.com. We'd love to know if you think of this podcast, your feedback and shores. We deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire at n2k.com. N2K's lead producer is Liz Stokes, who are mixed by Trey Hester with original music and sound designed by Elliott Peltzman. Our contributing host is Maria Vermazis. Our executive producer is Jennifer Ibn. Peter Kielpius, our publisher and I'm Dave Bitner. Thanks for listening. We'll see you

back here tomorrow.

More episodes

More from CyberWire Daily

View all episodes →