Today on CISO Series…
- Security You Should Know:”Cloaking the Network from Discovery with AppGate”
- Video:”Guardrails: Limits or Just Suggestions?”
In todays cybersecurity news…
Attackers use passkey phishing to hijack Microsoft cloud accounts
Microsoftdescribes this attack, which has been observed since May 2026, as one that starts with identity-focused social engineering. “The threat actors call or message a user’s personal phone number, while claiming to be from the organization’s IT help desk and urging them to immediately update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid access disruptions.” The victims are redirected to counterfeit websites that “mimic the legitimate Microsoft sign-in experience via SMS messages sent to their personal devices.” Microsoft pointed out these threat actors do their homework, “gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms.” Sometimes they communicate with victims via Microsoft Teams, and have taken the time to register legitimate looking domains that include the company’s name.
Anthropic caught Russia-linked spies using Claude in hacking operations
In a blockbuster threat report covering activity between December 2025 and August 2026,Anthropicsays it “detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.” Anthropic said the activity aligned with Midnight Blizzard, which used to be known as Cozy Bear, a group attributed to Russia’s Foreign Intelligence Service (SVR). In one instance, the group “targeted members of the Ukrainian government, military, and diplomatic staff alongside entities involved in the drone supply chain. They were able to steal a complete proprietary software development kit for a drone vision system, and then used Claude to reverse-engineer the drone’s vision system, “recovering its product architecture, its hardware bill of materials, its supplier dependencies, and details of an unannounced product.”
ShinyHunters also abused Claude to extract secrets from 1.8M Android apps
The sameAnthropicthreat report just mentioned also detailed activities by the ShinyHunters collective, involving a credential-harvesting pipeline across tenAmazon Web Services (AWS)EC2 worker nodes that “downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs. …The same actor used a separate automated process to collectGitHuborganization email addresses and used them to obtain GitHub Personal Access Tokens (PATs).” One of these projects allowed the offenders to spoof the French national police in order to sell stolen payment-card records, full cardholder information, and an interactive map of victim addresses. A link to this lengthy report, which contains many other separate stories and discoveries, is available in the show notes to this episode.
Airlines compliance with new cybersecurity regulations means fewer passenger conveniences
Starting next month, airlines whose flights are canceled or delayed due to a cyberattack will not have to hand out meal vouchers or hotel rooms to inconvenienced passengers. This is due to a change made last week by the Transportation Department that establishes a new “cause of delay” category which reduces air carrier responsibilities to customers for 10 kinds of events, including: “cybersecurity attacks (provided that the air carrier is in compliance with applicable cybersecurity regulations).”
Big thanks to our sponsor,Vanta
Dutch authorities warn of imminent Check Point VPN flaws exploitation
The Dutch National Cyber Security Centrum (NCSC) attributes this warning to the presence of two critical flaws in Check Point VPN. These flaws have CVE numbers (CVE-2026-85102 and CVE-2026-85103). No public proof-of-concept exploit has been reported, but the likelihood of exploitation and the potential impact is high, the agency warns. Check Point VPN is an enterprise solution that allows remote employees to securely connect to their company’s internal network
Florida says motor vehicle data breach tied to officer’s personal device
Very briefly following up on a story we covered on Wednesday, officials in Florida now say the data breach that affected the state Department of Motor Vehicles was due to the ShinyHunters extortion group stealing login credentials from a police officer who had stored this information on a personal device.
Conti malware developer sentenced to four years for ransomware attacks
Following up on a story we have been covering for a few months, former lawyer-turned malware writer Oleksii Oleksiyovych Lytvynenko has been sentenced to four years in prison this week for conspiracy to commit wire fraud. His work with the Conti gang infected more than 1,000 organizations worldwide between 2020 and 2022, leading to victim payouts exceeding $150,000,000 before the operation shut down.
CISA adds five actively exploited flaws to KEV
The five security flaws impact JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. They were added to the Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Federal Civilian Executive Branch (FCEB) agencies were required to patch the RouterOS flaws by yesterday, Sunday September 13, 2026, with the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026. A link to a summary of these five flaws and their CVE numbers is available in the show notes to this episode.
Spotify,Apple Podcasts,YouTube,RSS link,Amazon Music, add as anAlexa Skill, or search “Cybersecurity Headlines” on your favorite podcast app.