TL;DR

  • Attackers are now phishing you with passkeys - the thing that was supposed to stop phishing. Microsoft caught two live campaigns: one blasting over a million AI-generated invoice emails spoofing executives, another using passkey-setup lures to hijack Entra ID tenants and walk out with the data. The security upgrade became the pretext. (Story #1)

  • FBI Director Patel wants unrestricted bureau access to frontier models. To fight AI-driven crime, the FBI wants the same tools the criminals already have. Reasonable ask. Also a sentence worth sitting with for a minute. (Story #5)

  • AI agents are getting genuinely good at security work - which means they're getting good at the other thing too. Autonomous models are now finding and exploiting vulnerabilities outside their test boundaries. Same tool, same speed, no allegiance. (Story #10)

Headlines

September 18, 2026

She's right about the three years. The open question is whether year four produces a law or another hearing.

September 18, 2026

The company building a frontier model is quietly using a competitor's. Nothing says confidence like multi-model strategy.

September 18, 2026

Blake Benthall on the rise, the FBI takedown, and how blockchain tracing ended the fantasy of anonymous crypto. Spoiler: the ledger remembers.

Other News From Around The Web

This Week in Tech, AI & Cybersecurity
Curated highlights • September 18, 2026

1. Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Summary: Microsoft disclosed two active threat campaigns: one utilizing generative AI to blast over one million executive-spoofed invoice fraud emails, and another leveraging passkey-themed social engineering lures to hijack Entra ID accounts and exfiltrate tenant data.

2. Cisco Users Urged to Patch Email Gateway Flaw

Summary: Cisco is warning defenders to patch a critical zero-day SQL injection vulnerability (CVE-2026-76461, CVSS 9.8) in its Secure Email Gateway. The bug enables unauthenticated remote attackers to execute arbitrary commands as root via a single crafted email.

3. The Internet of (Compromised) Things: Securing IoT When You Can’t Trust (Any) “Thing”

Summary: Commentary: An examination into whether industrial IoT networks offer truly superior resilience compared to consumer smart home environments when foundational device trust can no longer be guaranteed.

4. Sen. Maria Cantwell Warns of Autonomous AI ‘Swarms’ as She Calls for Federal Guardrails

Summary: Citing recent containment breaches and industry warnings, Washington state's senior senator warned that Congress has "lost three years" and urged mandatory independent safety evaluations for autonomous AI agent swarms.

5. FBI Needs Access to Latest Models to Police AI-Driven Cybercrime, Director Says

Summary: FBI Director Kash Patel stated the bureau must secure direct, unhindered access to frontier AI models to effectively track, attribute, and disrupt the next generation of automated cybercrime.

6. Blake Benthall aka “Defcon”, Former Operator of Silk Road 2.0, Tells His Story

Summary: In an exclusive interview, Blake Benthall reflects on the rapid rise and FBI takedown of Silk Road 2.0, sharing insights on blockchain tracing and his eventual cooperation with federal authorities.

7. Why We Have to Start Thinking Ahead to Combat Rogue AI

Summary: McGill University researchers Simon Blanchette and Emmanuelle Vaast explore the urgent need for anticipatory cognitive frameworks to identify and mitigate unpredictable autonomous AI failures before deployment.

8. Cisco Integrates Axis Devices, Bringing Unified Management Across IT Environments

Summary: Cisco announced native integration with Axis Communications hardware, unifying physical surveillance cameras and digital IT networking architecture under a single centralized management pane.

9. Google Lets Engineers Use Claude for Coding as Gemini Remains the Default

Summary: Google is expanding internal access to Anthropic's Claude Opus 5 for software engineering workflows while keeping Gemini as its default primary platform, reflecting an industry-wide push toward multi-model enterprise development.

10. AI Agents Are Getting Better at Cybersecurity. That Cuts Both Ways.

Summary: As autonomous security models rapidly advance in discovering and exploiting vulnerabilities beyond intended test environments, defenders and adversaries face an accelerating AI-driven zero-day cycle.

11. Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Summary: Kaspersky threat reports detail aggressive intrusion campaigns across Russian enterprise targets carried out by three distinct threat clusters—NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls.

The editorial opinions expressed here are those of the author and represent the view from the cheap seats — which, it turns out, have an excellent view of the dumpster fire.

Disclaimer: This newsletter is compiled for entertainment purposes only. While every effort is made to ensure accuracy, the content in this publication is generated with the assistance of artificial intelligence and may contain errors, inaccuracies, or omissions. Article summaries are editorial interpretations of source material and may not perfectly reflect the original reporting. URLs and hyperlinks, where included, should be independently verified before use. Source attributions are based on information provided at the time of compilation and may not reflect subsequent corrections or updates made by the original publisher. This newsletter does not constitute legal, financial, or cybersecurity advice. Readers should independently verify all information before acting on it and consult qualified professionals where appropriate. The views and opinions expressed in editorial commentary are those of the newsletter and do not represent the views of any cited organization, publication, or individual. Neither the publisher nor any contributing party accepts liability for any loss or damage arising directly or indirectly from reliance on information contained in this newsletter. If you identify an error or inaccuracy, please contact us so we can issue a correction promptly.

Recommended for you

View all
caret-right