the daily brief
Cyber / Brief — 21 Sep 2026
The most alarming disclosure of the weekend had nothing to do with a hacker: CNN revealed that a hallucinated AI intelligence report — a chatbot's fabricated claim that a Chinese ship was carrying nuclear-weapons components — nearly sent US forces to board the vessel this spring, aircraft…
The most alarming disclosure of the weekend had nothing to do with a hacker: CNN revealed that a hallucinated AI intelligence report — a chatbot's fabricated claim that a Chinese ship was carrying nuclear-weapons components — nearly sent US forces to board the vessel this spring, aircraft already in the air, before officials realised the evidence had been invented and pulled back from what one source called almost starting a war. The industry's safety reckoning, meanwhile, reached the courtroom: a lawsuit accused Anthropic, OpenAI, xAI and Google of illegal collusion over their joint call to slow AI development, testing whether coordinating on caution is itself a cartel. In the criminal underworld, the extortion crew ShinyHunters broke into and defaced the Clop ransomware gang's own leak site and threatened to extort the extortionists, while Google revealed that one of its analysts had spent six months undercover inside the supply-chain gang TeamPCP — watching it poison hundreds of open-source packages and breach a thousand companies — before police made arrests. And Europe absorbed a political jolt as Chancellor Merz's conservatives crashed in German state elections with the far right rising, even as Ukraine struck Moscow with its largest-ever drone attack during Russia's stage-managed parliamentary vote.
Top Stories
- Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Technology · AI & Power
- AI Hallucinations Nearly Triggered a US-China Military Confrontation — Security Affairs · Defence & National Security
- Merz’s Conservatives Crash Out of German State Parliament — Bloomberg Politics · EU & Technology
- Researchers escape OpenAI Codex sandbox to run commands on host — BleepingComputer · Cybersecurity & Threats
- An undercover Google analyst infiltrated a notorious supply-chain hacking gang — Ars Technica - All content · Threat Intelligence (CTI)
AI & Power
Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Technology
Why it matters: A lawsuit accusing Anthropic, OpenAI, xAI and Google of illegally colluding when they jointly called to slow AI development is the safety turn's first courtroom test — an antitrust claim that the labs' rare moment of agreement was a cartel in disguise, and a warning that even coordinating on caution carries legal peril.
A lawsuit filed in the US District Court for the Northern District of California accuses Anthropic, OpenAI, SpaceXAI (xAI) and Google of violating antitrust law by making an illegal agreement to slow the pace of their AI development, arguing the coordination reduced the value consumers get from paid AI subscriptions. The complaint centres on 12 September, when Anthropic's Dario Amodei published an essay urging industry-wide cooperation on decelerating advances in favour of safety, and Sam Altman, Elon Musk and Demis Hassabis publicly agreed the same day; it also points to a July 2026 statement, signed by senior lab employees, acknowledging 'intense competitive pressure not to unilaterally slow.' The suit matters because it turns the fortnight's defining AI-safety development — the frontier labs' collective call to 'pace the frontier' — into a legal liability, testing whether coordinated restraint among competitors constitutes unlawful collusion; notably, Amodei's own essay anticipated the antitrust problem, suggesting the US government would need to mediate or issue 'a narrow waiver for certain kinds of safety conversations.' For Europe, watching the US debate over whether and how to slow AI, the lawsuit underscores a real structural obstacle to voluntary industry restraint: competition law may forbid the very coordination that a safety-driven slowdown requires, strengthening the argument that meaningful pacing needs a government-sanctioned or regulatory framework (as the EU's AI Act provides) rather than private agreement among rivals.
Trump wants a new AI czar and an "AI Force" modeled on Space Force — Axios
Why it matters: President Trump reportedly wanting a new AI czar and an 'AI Force' modelled on the Space Force is the administration answering the safety clamour with organisation charts rather than guardrails — a bid to project seriousness about AI's national-security stakes while keeping its posture firmly accelerationist.
President Trump is reportedly planning to appoint a new AI czar and create an 'AI Force' modelled on the Space Force, a move to institutionalise the government's focus on artificial intelligence for national-security and competitiveness ends. The proposal matters because it signals how the administration intends to channel the surge of AI concern — not toward the guardrails and slowdown the labs and European leaders urge, but toward mobilising and militarising AI capability, consistent with its 'win the race against China' framing and its dismissal of safety fears as a 'hoax.' The tech industry's reaction has been mixed-to-puzzled (a 'scratches its head' response to the AI Force idea), reflecting uncertainty about what such a body would do. It fits the fortnight's US-政府 thread (the Pentagon pressing ahead on AI, the 'US can't lose' posture) and the broader pattern of the US treating AI primarily as a strategic asset. For Europe, the AI-czar-and-AI-Force plan is another marker of the transatlantic divergence: while Brussels builds regulatory and safety architecture, Washington builds competitive and military capacity, and the gap between the two approaches — precaution versus acceleration — continues to widen, shaping the global environment in which the EU's own AI governance must operate.
Microsoft AI Chief Says China Isn’t Excuse to Forego Regulation — Bloomberg Technology
Why it matters: Microsoft's AI chief arguing that competition with China is no excuse to abandon AI regulation is a rare voice from the top of Big Tech pushing back on the race-to-the-bottom logic — insisting that guardrails and competitiveness need not be mutually exclusive, against an industry chorus that increasingly says otherwise.
Mustafa Suleyman, Microsoft's AI chief, argued that competition with China should not be used as an excuse to forego AI regulation, pushing back on the dominant industry-and-administration framing that guardrails would cede the field to Beijing. The intervention matters because it challenges the central rhetorical move of the accelerationist camp — the claim that any US restraint hands victory to China — from within Big Tech itself, insisting that sensible regulation and competitiveness can coexist. It offers a counterweight to Nvidia's Huang ('no new laws,' '0% chance' of doom), the Trump administration's 'hoax' dismissal, and the broader use of the China threat to resist rules, and it aligns more closely with the European view that rights-respecting, well-regulated AI is compatible with — even conducive to — durable competitiveness. For Europe, whose AI Act embodies exactly the bet that regulation and innovation are not opposites, a senior Microsoft voice rejecting the China-as-excuse argument is a notable data point: it suggests the accelerationist consensus is not uniform even within the US industry, and that the case for governance has advocates among the companies building the technology, not only among regulators and civil society.
Australia’s Albanese Urges World to Act for Humanity in AI Race — Bloomberg Technology
Why it matters: Australia's prime minister urging the world to 'act for humanity' in the AI race is another head of government stepping into the safety debate — a call for international cooperation on guardrails that adds a Global-South-adjacent, middle-power voice to a conversation dominated by the US, China and the EU.
Australian Prime Minister Anthony Albanese urged the world to act for humanity in the AI race, calling for international cooperation to ensure the technology's development serves human interests rather than a purely competitive dynamic. The appeal matters because it adds another head-of-government voice to the intensifying global AI-safety debate, and a middle-power one: as the US tilts accelerationist and the EU builds its regulatory architecture, other democracies are staking out positions, generally favouring international coordination and guardrails. It connects to the fortnight's proliferation of governance interventions (von der Leyen's frontier-lab convening, King Charles's summit, the UN's outreach to the AI industry, warnings of AI warfare risk) and reflects growing international consensus that AI governance cannot be left to the two superpowers and a handful of companies alone. For Europe, which favours multilateral, rules-based approaches, allied middle-power voices like Australia's are potential partners in building the international cooperation the EU has long advocated — and a reminder that the constituency for AI guardrails extends well beyond Brussels, even as the US administration resists them.
Citi CEO Sees ‘Tsunami’ of Patching to Secure AI Defense — Bloomberg Technology
Why it matters: Citi's chief executive warning of a coming 'tsunami' of patching to secure AI defences is a frank acknowledgment from the financial sector that the rush to deploy AI has opened a vast new attack surface — and that the bill for securing it, in effort and cost, is only starting to come due.
Citigroup's CEO warned of a 'tsunami' of patching and remediation work ahead as organisations scramble to secure their AI deployments, framing AI security as a large and growing burden for enterprises. The warning matters because it comes from the head of a major global bank — an institution both heavily targeted and heavily invested in AI — and it captures the security reality beneath the AI-adoption rush the fortnight has documented from many angles (the agentic-AI breaches, the AI-coding-agent flaws, the vulnerabilities in AI platforms like Azure AI Foundry): deploying AI at scale creates a large new attack surface that must be secured, patched and monitored, and the work of doing so is substantial and ongoing. It aligns with the EY finding that autonomous-AI adoption is outpacing oversight, and with the broader theme that AI is reshaping the threat landscape faster than defences can adapt. For Europe, where financial institutions operate under DORA's operational-resilience regime and the AI Act, the 'tsunami of patching' framing is a candid reminder that the cost of securing AI — not just building and deploying it — is a first-order consideration, and that the sectors racing to adopt AI are also taking on a significant, sustained security workload that regulation and risk management must account for.
EU & Technology
Merz’s Conservatives Crash Out of German State Parliament — Bloomberg Politics
Why it matters: Chancellor Merz's conservatives crashing out of a German state parliament — with the far right advancing — is a jolt to the stability of Europe's central power at a fraught moment, weakening the government Berlin needs to lead the continent's defence build-out and digital-sovereignty push.
Chancellor Friedrich Merz's Christian Democrats suffered a heavy defeat in German state elections, in one case crashing out of a state parliament, as the far right advanced — a 'disaster,' in the words of coverage, that Merz insists will not unseat him but that visibly weakens his position. The result matters because Germany is Europe's largest economy and, under Merz, a central driver of the continent's rearmament, defence-spending surge and strategic-autonomy agenda; political instability in Berlin and the rise of the far right complicate the governing coalition's ability to sustain that leadership at a moment when Europe faces an 'intensified threat' from Russia and pressure from the US. It connects to the fortnight's European-strategy thread (von der Leyen's ambitious defence-and-sovereignty agenda, which depends heavily on Franco-German leadership) and to the broader political turbulence across the bloc (France's instability, the far right's advance). For European digital and strategic sovereignty, a weakened German government is a significant variable: the continent's defence build-out, technology investment and unified stance toward Russia, China and the US all rest partly on German political stability, and its erosion introduces uncertainty into the leadership Europe's autonomy ambitions require.
Ukraine hits Moscow with ‘largest ever’ drone attack — myFT following
Why it matters: Ukraine hitting Moscow with what it calls its largest-ever drone attack — striking a refinery as Russians voted — is Kyiv carrying the war deep into the Russian capital, a demonstration of long-range strike capability that reshapes the conflict Europe's security now revolves around.
Ukraine launched what it described as its largest-ever drone attack on Moscow, striking a refinery and other targets in the Russian capital as Russians were voting in State Duma elections. The strike matters because it demonstrates Ukraine's growing long-range drone-strike capability and its willingness to bring the war to Moscow itself — hitting the energy infrastructure that funds the Russian war effort and puncturing any sense of insulation in the capital, with symbolic force given the timing during the parliamentary vote. It connects to the fortnight's Russia-Ukraine and European-security threads (the drone incursions rattling NATO's eastern flank, the warnings of an 'intensified threat' from Putin, the HUR breach of Russian election systems) and to the drone-centric evolution of the conflict that is reshaping European defence priorities. For European security, Ukraine's deep-strike capability is doubly consequential: it affects the trajectory of the war on which the continent's security depends, and the proliferation and effectiveness of long-range drones — on both sides — underscores the drone-and-counter-drone challenge that is now central to Europe's own rearmament and air-defence planning.
Ruling Party Heads for Big Win in Russian Parliament Elections — Bloomberg Politics
Why it matters: United Russia heading for a sweeping win in State Duma elections that observers call neither free nor fair is the Kremlin stage-managing a vote to project stability — held under wartime conditions, shadowed by a hacker breach of the voting system and Ukrainian strikes on the capital.
Russia's ruling United Russia party headed for a large victory in State Duma elections widely regarded as neither free nor fair, a managed outcome that lets the Kremlin project domestic stability and legitimacy amid the war in Ukraine. The vote matters as a demonstration of the Putin system's control over the political process — the first federal campaign conducted on the new state-run electronic-voting platform (the same system a hacking group claiming links to Ukrainian military intelligence said it breached days earlier) — and it comes as Ukraine strikes Moscow and European leaders warn of intensified Russian aggression. It connects to the fortnight's Russia threads (the election-system breach, the drone attacks, the 'intensified threat' warnings) and to the broader question of how a wartime authoritarian system manages consent. For Europe, the managed Duma vote is a reminder that the adversary shaping the continent's security environment is politically entrenched and unconstrained by genuine electoral accountability, that its e-voting infrastructure is both a control tool and a contested cyber target, and that Russia's internal consolidation underpins the sustained external pressure — military, hybrid and cyber — that Europe's security posture must now assume as a durable condition.
NATO backs US, Denmark deal over Greenland security — Semafor
Why it matters: NATO endorsing the US-Denmark security arrangement over Greenland is the alliance papering over a rift that Washington's designs on the Arctic island had opened — a face-saving resolution that keeps the peace while leaving the underlying tension over Greenland's future unresolved.
NATO backed the security deal struck between the United States and Denmark over Greenland, lending alliance endorsement to an arrangement that defused a dispute Washington's interest in the strategically vital Arctic island had provoked. The development matters because Greenland — its Arctic location, minerals and role in missile-defence and polar geography — had become a genuine source of intra-alliance friction, with the Trump administration's designs on it straining relations with Denmark and raising sovereignty concerns; NATO's backing of the deal signals a collective interest in containing the row and preserving cohesion on the increasingly contested Arctic flank. It connects to the fortnight's Arctic-and-alliance thread (the earlier US-Denmark Greenland deal, the transatlantic strains from US assertiveness) and to the rising strategic salience of the High North. For European sovereignty and security, the NATO-endorsed Greenland arrangement is a reminder that the Arctic is an emerging arena of great-power competition where European (Danish, and by extension EU) sovereignty intersects US strategic ambition, and that managing alliance cohesion under a more transactional Washington — over Greenland, tariffs and burden-sharing — is an ongoing test for a Europe seeking greater strategic autonomy.
China & Technology
In China, A.I. Is Moving Forward While the Economy Lags Behind — NYT > Technology
Why it matters: The paradox of China charging ahead on AI even as its broader economy stumbles is a reminder that Beijing's technological ambition runs on political will as much as market strength — the state pouring resources into AI leadership while growth, consumption and confidence sag.
A New York Times analysis describes the paradox of China pushing aggressively forward on artificial intelligence while its broader economy lags — subdued growth, weak consumption, property-sector strain and faltering confidence coexisting with heavy state-and-market investment in AI capability and infrastructure. The dynamic matters because it shows how central AI leadership has become to China's strategic and economic self-conception: even amid economic headwinds, Beijing prioritises AI (chips, models, applications, the self-sufficiency drive) as a domain where it intends to lead, treating technological advance as both an economic engine and a matter of national power. It connects to the fortnight's China-technology thread (Huawei's accelerated AI chip, the AI-for-propaganda system, the pressure on Chinese AI stocks, the US-China AI rivalry) and to the question of whether China's AI push can compensate for or transcend its economic difficulties. For Europe, the picture of a China advancing on AI despite economic strain is a reminder that Beijing's technological competition is durable and state-driven, not contingent on broad economic health, and that the EU's technology-sovereignty and competitiveness calculations must reckon with a Chinese AI drive that continues regardless of the wider economic cycle.
Threat Intelligence (CTI)
[P2] An undercover Google analyst infiltrated a notorious supply-chain hacking gang — Ars Technica - All content
Why it matters: Google revealed that one of its threat analysts spent six months undercover inside the private channels of TeamPCP — the supply-chain gang that poisoned hundreds of open-source packages and breached over a thousand companies — watching the rampage in real time, warning victims, and helping blunt attacks until police made arrests.
Google's Threat Intelligence Group (via Mandiant) disclosed that an undercover analyst had been embedded inside the internal communications channel of the supply-chain hacking group TeamPCP — a channel known as CanisterWorm — since March 2026. TeamPCP tainted hundreds of open-source packages, stole developer accounts, released a self-spreading worm, and ultimately compromised more than 1,000 organisations, exfiltrated at least 300 GB of data and stole over 500,000 credentials. The infiltration let Google monitor the campaign in real time, gain visibility into which organisations were being targeted and the group's tooling and tactics, alert breached companies, and actively help disrupt follow-on exploitation as it happened, until Australian police arrested two alleged members (Ruben Thomson and Louis Gaebler).
severity high · exploited in the wild · EU: NIS2, CRA · actor TeamPCP (Google/Mandiant; 2 alleged members arrested) (70%)
[P2] ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — BleepingComputer
Why it matters: In a rare bit of criminal-underworld theatre, the extortion crew ShinyHunters broke into and defaced the Clop ransomware gang's own dark-web leak site — claiming to have stolen its source code and the private keys to its onion service — and is now threatening to extort the extortionists, retaliation for threats Clop allegedly made during a falling-out.
The ShinyHunters extortion group breached and defaced the Clop ransomware operation's Tor data-leak site, exploiting what it claims was an unauthenticated file-upload vulnerability in the Grav CMS running the site. ShinyHunters says it stole source code, system logs, plugins and the Tor onion-service private keys, and posted a defacement reading 'THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES.' The group says it will publish a message on its own leak site giving Clop 72 hours to make contact — an apparent threat to extort the ransomware gang — and frames the attack as retaliation for threats of violence and doxxing allegedly made by a Clop representative during a dispute over Clop's 2025 Oracle E-Business Suite data-theft campaign. BleepingComputer independently confirmed the defacement and an uploaded file but has not verified the claims of stolen source code, logs or onion keys.
severity high · exploited in the wild · actor ShinyHunters (self-claimed; defacement confirmed) (70%)
[P2] Settra Ransomware: How a Typo Exposed a Sophisticated Attack Chain — Threat Intelligence on Medium
Why it matters: A newer ransomware operation called Settra is quietly hitting retail and manufacturing firms — including in Europe — by logging in through stolen VPN credentials, installing legitimate remote-management software to keep its grip, and disabling recovery before it encrypts, a workmanlike double-extortion crew whose sloppiness (a revealing typo) helped researchers map its playbook.
Researchers (Huntress, among others) detailed Settra, a ransomware variant first observed in June 2026 and deployed in double-extortion attacks against retail, consumer-services and manufacturing organisations. Settra's operators gain access through compromised VPNs or stolen credentials, then deploy remote monitoring and management (RMM) tooling — notably MeshAgent — for persistence and command-and-control, install a vulnerable driver (BYOVD) to disable defenses, disable Windows recovery options, clear event logs, and encrypt files using executables named after the victim's domain, dropping RESTORE_FILES.txt ransom notes. Claimed victims span Taiwan, the US, Singapore, Canada, South Korea, Portugal, Germany and the UK, across e-commerce, retail, consumer goods, manufacturing, healthcare-adjacent services, security services and agriculture; one analysis noted a revealing operator typo that helped expose the attack chain.
severity high · exploited in the wild · EU: NIS2, GDPR
Defence & National Security
AI Hallucinations Nearly Triggered a US-China Military Confrontation — Security Affairs
Why it matters: A hallucinated AI intelligence report nearly sent US forces to board a Chinese ship on a false nuclear-smuggling claim — planes in the air, boarding party ready, before officials realised a chatbot had invented the evidence — the starkest warning yet that letting unverified AI into the intelligence loop can push nations to the brink of war.
CNN reported that this spring, amid the war with Iran, an intelligence report circulated across the US military claiming a Chinese ship in the Middle East was carrying components of a nuclear-weapons program; the military moved to intercept, with aircraft airborne and armed personnel preparing to board, before officials discovered the intelligence had been hallucinated by an AI chatbot and aborted the operation at the last minute — a near-miss one source said 'almost started a war' with China. The chatbot had fused open-source intelligence with classified signals intelligence and formatted the false findings into an official-looking summary that moved through the system unverified. The episode matters as perhaps the starkest documented case of AI-hallucination risk in high-stakes national-security decision-making: it shows how a confident, well-formatted but fabricated AI output can propagate rapidly toward irreversible action when human verification fails, and it lands as the US Defense Secretary's 'AI Acceleration Strategy' pushes to put AI models into the hands of three million military and civilian personnel across all classification levels. For Europe — pursuing its own defence AI and weighing the AI Act's treatment of high-risk and military-adjacent uses — the near-catastrophe is a sobering, concrete argument for keeping rigorous human verification in the loop of AI-informed intelligence and military decisions, and a warning that the rush to embed AI in defence outpaces the safeguards against exactly this failure mode.
Cybersecurity & Threats
[P2] Researchers escape OpenAI Codex sandbox to run commands on host — BleepingComputer
Why it matters: Researchers found two ways out of OpenAI's Codex coding-agent sandbox — one that runs commands on a developer's machine merely by having Codex analyse a malicious repository, even in its most locked-down read-only mode, with no prompt and nothing on screen — the latest proof that the sandboxes meant to contain AI coding agents are themselves escapable.
Researcher Oren Yomtov (Accomplish AI) disclosed two OpenAI Codex sandbox-escape flaws (reported 12 August, patched within eight days). 'Heapjack' exploits a shared memory heap between trusted and untrusted JavaScript contexts in Codex Desktop's node_repl component, letting an attacker steal an authorization token and achieve unsandboxed command execution merely by having Codex analyse a malicious repository — even in the strictest read-only sandbox mode, with no approval prompt. 'Overpatch' abuses Codex CLI's apply_patch tool, which derives write permissions from attacker-supplied paths, to escape workspace-write restrictions and write to the home directory via a symlink, executing code the next time a terminal opens. OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0. Broader research (Pillar) found similar sandbox escapes across Cursor, Codex, Gemini CLI and Antigravity, pointing to a containment gap common to AI coding agents.
severity high · EU: NIS2, CRA
[P2] SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE — The Hacker News
Why it matters: SolarWinds — the company at the centre of the 2020 supply-chain disaster — shipped a hard-coded secret key in its Access Rights Manager, the very tool meant to control who can access what, letting an unauthenticated attacker run code on it; a pointed reminder that the most basic secrets mistakes still reach production.
SolarWinds released fixes for CVE-2026-28326, a high-severity (CVSS 8.8) flaw in Access Rights Manager (ARM) stemming from a hard-coded static key that could allow unauthenticated remote code execution. It affects all ARM versions 2026.2 and prior and is fixed in ARM 2026.2.1; SolarWinds credited researcher Kai Huang (Armadin) and makes no mention of in-the-wild exploitation. Access Rights Manager is a privileged tool used to manage and audit who has access to what across an organisation's systems, so an unauthenticated-RCE flaw in it is consequential out of proportion to its role, and a hard-coded key is a basic secrets-management failure — the same anti-pattern seen elsewhere this fortnight (Issabel's shared JWT key, Brevo's hard-coded Cloudflare key).
severity high (CVSS 8.8) · CVE-2026-28326 · EU: NIS2, DORA, CRA
[P2] Malicious npm packages evade install-script defenses at runtime — BleepingComputer
Why it matters: Attackers slipped malicious code into a popular npm package by hiding it not in the install scripts everyone now watches, but inside a core function every user calls at runtime — a typosquat of a 2-million-download library that runs clean at install and only strikes when the code is used, neatly sidestepping the defence GitHub rolled out this summer.
An ongoing npm supply-chain campaign uses the malicious package 'indexed-btree' (impersonating the legitimate 'sorted-btree' library, which has some 2 million weekly downloads) to evade install-time defenses by hiding its loader in a core runtime method — BTree.prototype.set() — rather than in preinstall/postinstall hooks. Because nothing malicious runs at install, the package passes clean and evades taint-analysis and static scanners; when the method is called at runtime it collects system details, exfiltrates them via Slack and Telegram, and polls an Ethereum Sepolia smart contract for command-and-control (using X25519 key exchange and AES decryption) to fetch a second-stage payload. Checkmarx identified nine additional related packages (combined downloads in the millions), all removed from npm. The technique specifically sidesteps GitHub's June 2026 measure of blocking dependency lifecycle scripts (preinstall/install/postinstall) unless explicitly approved.
severity high · exploited in the wild · EU: NIS2, CRA