
Passkey phishing attack, Anthropic's blockbuster report, airline cybersecurity loophole
About this episode
Cybersecurity Headlines is made possible by:
Attackers use passkey phishing to hijack Microsoft cloud accounts
Anthropic blockbuster report reveals sophisticated hacks
Airlines compliance with new cybersecurity regulations means fewer passenger conveniences
Get the show notes here: https://cisoseries.com/cybersecurity-news-september-14-2026/
Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Get every episode summarized
Each time Cybersecurity Headlines publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
51 searchable segments. Every word is indexed and playable.
Full transcript
Cybersecurity Headlines — Passkey phishing attack, Anthropic's blockbuster report, airline cybersecurity loophole. Machine-transcribed; use the interactive transcript above to jump the player to any line.
From the CISO series, it's Cybersecurity Headlines. These are the Cybersecurity Headlines for Monday, September 14th, 2026. I'm Steve Prentice. Attackers use pass key phishing to hijack Microsoft Cloud accounts. Microsoft describes this attack which has been observed since May is one that starts with identity-focused social engineering. The threat actors call or message a user's personal phone number while claiming to be from the organization's IT help desk, urging them to immediately update their pass key, multifactor authentication or single sign-on configuration to avoid access disruptions. The victims are redirected to counterfeit websites that mimic the legitimate Microsoft sign-on experience via SMS messages sent to their personal devices. Microsoft pointed out these threat actors do their homework, gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms.
Sometimes they communicate with victims via Microsoft Teams and have taken the time to register legitimate looking domains that include the company's name. Anthropic called Russia-linked spies using Claude in hacking operations. In a somewhat blockbuster threat report covering activity between December 2025 and August of this year, Anthropic says it, quote, detected and disrupted a Russia-link cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations. Anthropic said the activity aligned with Midnight Blizzard, which used to be known as Cosimere, a group attributed to Russia's Foreign Intelligence Service. In one instance, the group, quote, targeted members of the Ukrainian government, military and diplomatic staff alongside entities involved in the drone supply chain. They were able to steal a complete proprietary software development kit for a drone vision system and then used Claude to reverse engineer that vision system,
recovering its product architecture, its hardware bill of materials, its supplier dependencies and details of an unannounced product. Shiny Hunters also abused Claude to extract secrets from Android apps. This same Anthropic threat report just mentioned also detailed activities by the Shiny Hunters collective involving a credential harvesting pipeline across 10 AWS EC2 worker nodes that, quote, downloaded from the website, downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs. The same actor used a separate automated process to collect GitHub organization email addresses and used them to obtain GitHub personal access tokens, end quote. One of these projects allowed the offenders to spoof the French national police in order to sell stolen payment card records, full cardholder information and an interactive map of victim addresses. A link to this lengthy Anthropic report which contains many other separate stories and discoveries is available in the show notes to this episode.
Airlines compliance with new cybersecurity regulations means fewer passenger conveniences. Starting next month airlines whose flights are canceled or delayed due to a cyber attack will not have to hand out meal vouchers or hotel rooms to inconvenienced passengers. This is due to a change made last week by the Transportation Department that establishes a new cause of delay category which reduces air carrier responsibilities to customers for 10 kinds of events including cybersecurity attacks provided that the air carrier is in compliance with applicable cybersecurity regulations. Huge thanks to our sponsor Vanta. Risk and regulation ramping up and customers expect proof of security just to do business. Vanta's automation brings compliance, risk and customer trust together on one AI powered platform. So whether you're prepping for a SOC 2 or running an enterprise DRC program Vanta keeps you secure and keeps your deals moving.
Learn more at vanta.com slash cso. Dutch authorities warn off imminent checkpoint VPN flaws exploitation. The Dutch National Cybersecurity Centrum NCSC attributes this warning to the presence of two critical flaws in checkpoint VPN. These flaws have CVE numbers. No public proof of concept exploit has been reported but the likelihood of exploitation and the potential impact is high according to the agency. Checkpoint VPN is an enterprise solution that allows remote employees to securely connect to their company's internal network via encrypted connections. Florida says motor vehicle data breach tied to officers personal device. Very briefly following up on a story we covered on Wednesday, officials in Florida now say the data breach that affected the state department of motor vehicles was due to the shiny hunter's extortion group stealing login credentials from a police officer who had stored this information on their personal device.
Conti malware developer sentenced to four years for ransomware attacks. Following up on a story we have been covering for a few months former lawyer turned malware writer Alexi Alexiovich Litvnenkoal has been sentenced to four years in prison this week for conspiracy to commit wire fraud. His work with the Conti gang infected more than 1000 organizations worldwide between 2020 and 2022 leading to victim payouts exceeding 150 million dollars before the operation was shut down. CISA adds five actively exploited flaws to K.E.V. The five security flaws impact J Frog Artifactory connect wise screen connect and micro tick router OS. They were added to the known exploded vulnerabilities catalog following reports of active exploitation in the wild. Federal civilian executive branch agencies were required to patch the router OS flaws by yesterday Sunday September 13th with the screen connect floor needing to be patched today September 14th and the Artifactory flaws by September 25th.
A link to a summary of these five flaws and their CV numbers is available in the show notes to this episode. If you have some thoughts on the news from today or about this show in general, please be sure to reach out to us at feedback at CISA series dot com. We would love to hear from you. I'm Steve Prentice reporting for the CISA series. Thank you for watching.
More episodes
More from Cybersecurity Headlines

The Department of Know: Liquid drained, CISA urges change, agentic whistleblower...
Cybersecurity Headlines

NetScaler vulnerability exploited, AdaptHealth suffers breach, new Android malwa...
Cybersecurity Headlines

Fortinet auth holes, China distills AI, Mythos vulnerability
Cybersecurity Headlines

Florida DMV breach, zero-click WeChat worm, AI whistleblowers
Cybersecurity Headlines