You're listening to the CyberWire Network, powered by N2K.
Maybe that's an urgent email from your CEO, or maybe it's a deepfake targeting your business.
Doppel is the AI native social engineering defense platform,
fighting back against impersonation and manipulation.
As attackers use AI to make their tactics more sophisticated,
Doppel uses it to fight back, automatically dismantling cross-channel attacks,
building team resilience, and providing agentech email protection.
Doppel, outtacing what's next in social engineering.
Learn more at Doppel.com. That's D-O-P-P-E-L dot com.
[Music]
Could an AI kill switch create more problems than it solves?
A critical rail's flaw is under active attack.
Militious browser extensions steal cryptocurrency.
Fire and targets trusted network infrastructure.
Claude gets tricked into running attacker-controlled code.
My chart fishing scams spread malware.
To alleged extortionist face US charges,
a former DIA insider walks into an FBI sting.
We got your Monday business briefing.
Our guest is Tim Starks from CyberScoop,
discussing a controversial retail security bill,
and getting local with Nigerian scammers.
[Music]
It's Monday, August 31st, 2026.
I'm Dave Bittner, and this is your CyberWire Intel Briefing.
[Music]
Thanks for joining us here today.
It's great as always to have you with us.
In an op-ed for CyberScoop,
Luke O'Grady, a senior analyst at Venable LLP
and the Center for Cybersecurity Policy and Law,
argues that Congress's proposed AI Kill Switch Act
could create the very security risk it's intended to prevent.
The bipartisan bill would give SISA authority
to require frontier AI companies to build mechanisms
capable of throttling, suspending,
or shutting down their systems.
O'Grady compares that approach to the NSA's ill-fated
clipper ship, which provided government access
to encrypted communications, but was found
to contain a serious security flaw.
He acknowledges the analogy isn't exact,
an AI Kill Switch threatened system availability
rather than communications confidentiality,
but he argues both approaches
deliberately introduce potential points of failure.
As AI agents become embedded in critical infrastructure,
he says those controls could undermine resilience
and international confidence in American technology.
O'Grady instead calls for stronger red teaming,
security requirements, liability frameworks,
and completed AI agent security standards
before Congress acts.
Hackers are actively exploiting a critical Ruby
on Rails vulnerability that can lead to remote code execution,
according to VaultnCheck, dubbed Kind of Rails to Shell,
the vulnerability carries a CVSS score of 9.5
and exploits differences in how Rails
and image processing libraries interpret uploaded files.
Attackers can craft malicious files that ultimately
cause the server to read and expose arbitrary files,
including credentials and storage keys.
Those stolen secrets can then be used
to forge sessions, move laterally,
and potentially execute code remotely.
Rails patched the vulnerability in late July,
but VaultnCheck says exploitation began roughly a month later.
Researchers had identified about 7,000 exposed
vulnerable Rails instances in early August.
VaultnCheck also warns that its testing founder
related deserialization path,
which could still enable code execution on a patched server
if an attacker possesses a valid signature.
Researchers at Socket have uncovered a malware campaign
using Chrome and Edge extensions to steal cryptocurrency,
credentials, browser history, and other sensitive data.
The operation, potentially active since early 2024,
includes 19 specialized malware modules.
Some extensions initially behaved legitimately
before being acquired from their original developers
and turned malicious through automatic updates.
Once installed, the malware connects to command and control servers
and inject malicious scripts into websites.
Its capabilities include hijacking cryptocurrency transactions,
stealing wallet seed phrases, harvesting sessions,
and account data from major crypto platforms,
recording credentials, and collecting Facebook
and LinkedIn information.
It can also display click-fix-style fake browser updates
that trick users into executing malicious commands.
Google has removed the identified extensions
from the Chrome Web Store, Socket advises affected users
to change passwords and cryptocurrency holders
to move assets to new wallets.
Chinese-linked cyber espionage group FireAnt
has expanded its operations from individual systems
to the network infrastructure connecting high-value targets
according to Signia.
Investigators found the group compromised Cisco iOS XR routers,
TacX authentication servers, and Linux management hosts,
using trusted infrastructure as a pathway into connected networks,
including critical infrastructure.
FireAnt deployed specialized router implants
that manipulated logging and concealed malicious activity
while malware injected in a TacX authentication process,
captured credentials from legitimate administrator sessions.
On Linux systems, persistent backdoors were disguised
as legitimate services, and attackers altered log-in
and system logs to erase evidence of their activity.
Signia says the campaign demonstrates
that routers, authentication servers, and jump hosts
can themselves become strategic targets,
and warns defenders that logs on deeply compromised infrastructure
can no longer automatically be treated as ground truth.
Security researcher Yohan Reberger says,
"Anthropics Clawed Code running Opus 5 in Auto Mode
can be manipulated into executing attacker-controlled code
through an indirect prompt injection attack."
The exploit begins when Clawed is asked
to summarize a malicious website.
After its normal retrieval tool fails,
the agent uses curl, downloads a crafted zip archive,
and ultimately writes its own Python decoder.
That safety-driven decision opens the door
to Python module shadowing.
A malicious file in the archive is loaded
instead of Python's legitimate module triggering a remote payload.
Reberger also demonstrated an attack
that launches a second Clawed Code agent with its own tool access.
In limited testing, the technique succeeded 60 to 80% of the time.
Reberger says coding agents should be sandboxed
with OS isolation and network controls
providing the real security boundary.
Health systems are warning patients
about fishing campaigns impersonating my chart
to steal personal information or install malware.
Epic, the company behind my chart,
says scammers are increasingly copying its branding
in emails, texts, calls, and fake websites,
but stresses that the activity doesn't stem
from a security problem with my chart itself.
One campaign tells recipients that test results are ready,
then directs them to a convincing fake login page.
Victims may then see fabricated medical records
and alarming claims that an AI review found serious health problems.
The manufactured urgency pushes users
toward supposed verification steps
or downloads that can install malware.
Epic says legitimate my chart results
don't require downloading software.
Anyone who falls for the scam should reset their password,
verify their account contact information
and contact their health care organizations help desk.
Two Nigerian men extra-dited to the United States
have been charged in connection with sextortion schemes
that authorities say resulted in the deaths of two miners
in Mississippi and North Carolina.
The men were arrested in Nigeria in 2023
during Operation Artemis
and international effort targeting Nigerian sextortion rings
accused of victimizing miners worldwide.
The men face multiple charges
involving sexual exploitation, coercion, extortion, and child sexual abuse material.
One of the men is also charged with sexual exploitation of a minor resulting in death,
which carries a minimum 30-year prison sentence. The extraditions follow renewed FBI warnings
about criminal stealing or coercing victims into providing explicit images and then using the
material for blackmail, authorities advise victims to stop communicating with extortionists
and contact law enforcement immediately. A former Defense Intelligence Agency IT specialist
has pleaded guilty to attempting to transmit classified information to a foreign government
after walking into an FBI sting. Nathan Villas Lash, who held a top secret clearance,
contacted what court documents describe only as a friendly foreign government in March 2025
and offered classified intelligence. The FBI intercepted the outreach and posed as a foreign
intelligence contact. Lash, then copied classified material by hand at work, concealed pages in his
socks and lunchbox and transferred the information to digital media. At his first dead drop in Arlington,
Virginia, the FBI recovered nine documents, eight containing top secret information,
including intelligence collection methods and materials on foreign military exercises.
Lash, ironically assigned to DIA's insider threat division, was arrested during a second
transfer in May 2025. His plea agreement recommends a prison sentence of 11 to 18 years,
though the court could impose a life sentence. Turning to our Monday business briefing,
cybersecurity and AI companies announced roughly $146 million in new funding across two deals
last week. Israeli AI Safety Company Alice, formerly active fence, raised $140 million in
around led by APAC's digital. The company plans to expand its AI testing, defense, and monitoring
platform. Its rabbit hole threat data set and its go-to-market operation. Danish AI visibility
startup Velotir raised about $5.8 million to support European expansion. On the M&A front,
Munich Ray agreed to acquire cyber insurer at Bay for $575 million, aiming to combine insurance
with continuous cyber risk mitigation. Exposure management company Brinker acquired pen test
management firm PlexTrack, adding remediation verification capabilities. Elsewhere,
British MSSP Red Squid acquired IT consultancy ARC-ICT strengthening its education sector business.
Utah-based Nexus IT acquired Austin's loyal IT, while Talk Talk Business is merging with MSSP ARO
to create a UK technology group with roughly 650 employees and 70,000 organizational customers.
Be sure to check out our complete business briefing that's on our website and part of CyberWire Pro.
Coming up after the break, my conversation with Tim Starks from Cyber Scoop on a controversial
retail security bill, and getting local with Nigerian scammers, stay with us.
Today's cyber criminals aren't just launching attacks, they're building businesses around them.
They have subscription models, they have a marketplace, they have affiliate program,
if you want to do referrals, you can get credits, they make it really easy, it really looks like
a legitimate SaaS product that somebody might use. I sat down with Mike Britton, CIO at Abnormal AI,
to explore how AI is lowering the barrier to cyber crime and what security leaders need to change
in response. Here are full conversation at explore.theciberwire.com/abnormalAI.
And joining me once again is Tim Starks, he is a senior reporter at Cyber Scoop. Tim, welcome back.
Hey, good to be back. You recently wrote about an issue here that I think has flown
under the radar when it comes to surveillance and there's a cyber crime elements to this as well.
There's a bill that's making its way through Capitol Hill that has gathered some attention from
folks on both sides of it. Yes, it's interesting that this hasn't gotten that much attention.
It certainly got an attention from people in the privacy community and civil liberties civil rights
community. It certainly got an attention from people in the retail and transportation sectors.
So if the listeners are probably listening right now and thinking what the heck kind of bill
would that be? It is a bill called the Combating Organized Retail Crime Act. It stemmed from these
fears that were popping up that had some statistical backing that there was a lot more retail crime
happening during and right after the onset of the pandemic and that it was more than just shoplifting.
So more organized. And the bill has gotten some new momentum this year. The retail sector really
likes this bill. It gives some additional powers of data collection aggregation, I suppose you might
say. Some different kinds of criminal penalties related to this kind of organized retail crime.
So they're in favor of it. It also is something that they're in favor of in the cargo and transport
worlds like the American Trucking Association because they also haven't have experienced this but in a
slightly different way that we can get into. On the other side, they're trying to slow the momentum.
Those privacy civil liberties civil rights groups, putting groups against the WACP and ACLU see this
as a huge potential expansion of federal government surveillance. That would house be house
explicitly within immigration and customs enforcement. So there's that ice angle that makes it a
hot potato I guess. It definitely does. On the side of people who are like, no, this isn't that
it's in ice but it's in the Homeland Security Investigations which is the division of ice
that isn't all that focused on immigration per se. But we've seen the HSI have some of its people
working on these enforcement issues. The other thing is that they look at the not just where it's
housed but what it allows. Their fear is that ice will be able to take all the surveillance that
they're already doing which is pretty expansive and then be able to add all sorts of stuff like
cameras at train stations, automated license freight reverse and adding that up it. You know,
the way surveillance works of course is that a little bit of surveillance can get you somewhere
but if you have other kinds of surveillance that you combine with it the power multiplies
somewhat intensely. Right. So the specific concern of the privacy advocates is that the
the government could get their hands on I guess the retail cameras and the things that they have
within their stores that I think we're all pretty accustomed to. Yeah those are some examples of
things that they're that they talked about. I mean it's it's oh it's really open ended in terms
of the kinds of data that it talks about sharing. And the issue is that they say you know right now we
see ice and other entities and federal law enforcement purchasing this kind of data from data brokers
you know and now they're worried that this is essentially going to give them that grotesque
and and already they were trying to ban the stuff from being sold to the federal government. So
this is like taking that data broker fear and adding the potential that that this is easier
than getting it from data brokers. Yeah. So let's talk about the other side of it the retailers.
You know I my I have a brother who was a retail manager and he would tell me stories he worked
at a large department store and he would tell me stories of basically groups of people who
would come in in an organized coordinated way and just come in the store and fill trash bags full
of stuff and walk out. Yeah so on the other side they're saying if you're a regular old person
and even if you're actually just kind of like a regular old shoplifter this isn't really going
to affect you that much. I mean that's again that's the condition they say that this is meant to go
after the people who are at sort of the heads of these operations. So the kinds of people who and
and this is where they kind of catered it to my audience I think when we were talking they say
things like gift card scams or e-commerce theft kind of things but also talking about things like
using cyber means to conduct theft. So they mentioned the examples of someone being able to fake
documents and do kind of fake authorizations online and instead of just like running up to a truck
and hijacking it and stealing it they can just go in and pretend to be the people who should be
having the cargo show them the the bill of lading and to use the phrase that one certain
one these are the quote persons to quote just drive out and way of way goodbye like they were like
they were supposed to be there. So they actually are making the case that you know for a cyber reader
cyber listener that this will help with cyber car.
Now, one of the things that caught my eye in your reporting on this was, there was a statement
by one of the parties involved who said that some of the lawmakers who had sponsored the
bill were perhaps having second thoughts about it as they became more educated about it.
That is the sentiment from the privacy and civility side, the people who are opposing this.
Apparently, I didn't double check this, but I'll just say it.
Some of the people who were sponsors of the bill voted against it on the floor.
That said, the vote was pretty overwhelming in the House.
I think it was like 80 people voted against it out of all of the people in the House.
And it has the support on the Senate side from the key committee leaders that will be necessary
for getting it going.
The plan there on the Senate side is to try to attach it to the annual defense authorization
bill, which is passed for something like 60 years straight, always the must pass bill.
And it has the sort of necessary clearances that they need to sign off on getting that in
there, assuming, of course, that the people who are rallying opposition to it aren't able
to convince the rank and file, or even some of the people who are supporting it right now,
that this is a bad idea.
Well, if it seems as though this is on its way to passing, and based on what we saw in
the House, I think it's probably fair to say that it's on its way to passing, what
did it face legal challenges from its opponents after that fact?
I think we'd have to see how it played out.
They didn't, the people who are concerned didn't raise any possibilities that this was
some sort of a legal legislation.
I mean, like, you know, legislation that it goes against the Constitution, say.
They didn't raise that possibility.
But of course, you know, I was speaking to the eight American civil leaders union, which
is known for taking challenging things in court.
I was talking to the NAACP Legal Defense Fund.
So they're looking at this certainly from a legal standpoint, but I think they weren't
talking about if this passes were going to challenge it.
I think they would probably want to see how it played out if I'm kind of reading the
T-Leaves to see if there were some violations of civil liberties and privacy that could
be proven and taken to court and have standing.
That's probably what I suspect is going to happen.
That said, I don't think it's a foregone conclusion that this will succeed.
I think it's the path that it's on right now.
I think it looks likely that Congress will pass this in one way, shape, or form.
But I don't roll out the fact that between now and say December and an election year,
things can change pretty rapidly, you know, especially as unpopular as ISIS and the agency,
if you look at the polling on ice, it's not positive.
And then I think the more the opponents are able to connect us to ice and say, look,
this is going to give ice more powers.
I think that's an argument they can use.
It's an argument that the other side is peed at them using, but it's one that could be
an effective lever for them in terms of that they want to try to slow this bill down.
Yeah.
All right.
Well, it's one to keep an eye on.
Very interesting.
Tim Starks is senior reporter at CyberScoop.
Tim, thanks so much for joining us.
Yeah.
Thanks for having me.
And finally, scam experts Aaron West and Paul Ruffiel decided to chase Nigerian sex
extortionists all the way to their home turf and discovered an industry operating with remarkable confidence.
In an interview with 404 Media, the pair described creating fake teenage social media accounts
and quickly attracting scammers posing as young women.
They then offered Bitcoin payments through a tracking site that captured the scammer's
IP addresses, pointing them toward logos.
Once in Nigeria, additional tracking revealed one suspect's face, phone number, social media
accounts, and eventually his apparent location.
Their investigation led them to a scammer known as Big Dollar.
He refused to meet, but West called to tell him they knew his identity and location and planned
to give the information to the FBI.
His social media accounts soon disappeared.
Along the way, West and Ruffiel even witnessed a spiritual ritual intended to improve a scammer's
fortunes.
Apparently, for some cyber criminals, operational security includes both browser permissions
and supernatural assistance.
And that's the CyberWire, for links to all of today's stories, check out our daily briefing
at the CyberWire.com.
We'd love to know what you think of this podcast, your feedback ensures we deliver the insights
that keep you a step ahead in the rapidly changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to
[email protected].
N2K's lead producer is Liz Stokes, who are mixed by Trey Hester with original music and
sound designed by Elliot Peltzman.
Our contributing host is Maria Vermaussis.
Our executive producer is Jennifer Eibin, Peter Kielphe is our publisher and I'm Dave
Bittner.
Thanks for listening.
We'll see you back here tomorrow.