The Human Take
Try to hold on to your surprise, but AI made the news again. I’m not going to turn every one of these into a diatribe about AI, but… Well… Just a little more.
Agentic AI is becoming the new threat. Last time I was here, I mentioned that AI can’t do anything we can’t, but it can do what we can do better than we can. An agent is a purpose-built AI that does something on behalf of (or in lieu of) a person.
Want to aggregate a bunch of news? Got an agent for that.
Want to check your email and manage your inbox? Agent.
<takes a deep breath>
Want to map a network, find some vulnerabilities, then exploit a vulnerability, drop a payload, phone home, move laterally, drop ransomware and ransom notices, delete every backup you can find, steal all the password lists on the network and start exfiltrating data? There’s an agent for that.
I have run penetration testing teams in the past, and the biggest problem was time and organic needs. I have four people to do a test, I have 800 hours of work to do, that’s about 5 weeks of work if my team does nothing else. And they get bored. They have to sleep and eat and touch grass, the AI needs none of that. Now, I have a tool that I can give to one of those humans, they tell the tool what to do. Then they keep an eye on it while they do all the squishy human things they need to do, or coordinate multiple agents doing multiple penetration tests at once. It doesn’t replace my penetration tester, it makes him more powerful. And we have rules to follow, clients to please, laws to not break. Imagine those same tools in the hands of someone who’s only motivation is gain, and their concern for laws, clients or rules is zero.
A massive law firm experienced a breach this week, showing that everyone needs to get on it, because with the speed of attack now, there’s no such thing as “we’re probably good.” Iran pulled some stunts showing why you should monitor your network for unauthorized messaging traffic (or why you should have such a thing as “unauthorized messaging traffic”). CISA also issued a warning for ScreenConnect being under active attack as a CVSS of 9.9, you should patch that if it means something to you. If it doesn’t, make sure it doesn’t mean something to you, then ask your organization how they are handling remote connections. If you’re in security specifically, ask if the restrictions around your remote solutions are strict enough. Spoiler warning: They are most likely not.

Weekly Cyber News Summary September 17, 2026
This week in cyber:- Western nations expose Iranian spyware Chosen Brick targeting global dissidents.
- Russian and Chinese actors hijack Claude AI for automated cyberattacks.
- First autonomous AI agent breach reported to Spanish privacy regulators.
- Google patches zero-click Pixel modem vulnerability exploited in targeted attacks.
- Law firm Greenberg Traurig discloses client data exposure following breach.
- ConnectWise patches critical ScreenConnect privilege flaw under active exploitation.
State-Sponsored Attacks
Iran Deploys ‘Chosen Brick’ Surveillance Malware Against Global Dissidents
Cybersecurity and intelligence authorities from the United States, the United Kingdom, and the Netherlands issued a joint advisory exposing an Iranian state-sponsored surveillance campaign utilizing a Windows malware family dubbed Chosen Brick. Operating since at least 2025 under Iran’s Ministry of Intelligence and Security (MOIS), threat actors leverage social engineering over WhatsApp and Telegram to build rapport before delivering malicious installers disguised as utility software or medical records. The targeted operations aim to harvest emails, contact lists, and social media messages to physically track dissidents, activists, and journalists opposing the Iranian regime.Upon installation, Chosen Brick sets up persistent registry keys and configures exclusions in Microsoft Defender to evade local security software. The malware uses individual Telegram bot IDs for command-and-control operations, enabling attackers to record host microphone audio, grab desktop screenshots, exfiltrate messaging database files, or wipe host machines entirely. Regulators noted that exfiltrated personal details have been posted onto pro-Iranian leak sites to conduct public harassment and intimidation campaigns against targets.
Sources:
SecurityWeek: https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/
Security Affairs: https://securityaffairs.com/199217/malware/chosen-brick-irans-surveillance-malware.html
AI Integration
State-Sponsored Actors Automate Exploitation and Malware Assembly via Claude AI
Anthropic published a report detailing the disruption of multiple state-aligned cyber campaigns that abused its Claude AI model for automated operational workflows. One notable operation attributed to a Russian state-nexus espionage cluster (tracked as GTG-20006 or Midnight Blizzard) utilized custom AI pipelines to automatically rebuild and re-deploy malware toolkits whenever security software detected static artifacts. The group targeted over 20 European, Ukrainian, and Middle Eastern defense and government agencies through hotel Wi-Fi DNS hijacking, mobile exploit kits, and credential-harvesting tools.Additionally, Anthropic exposed a China-linked threat actor that used Claude to advance technical research across three parallel tracks for an anti-torpedo naval weapons system. Financially motivated cybercriminals also leveraged autonomous AI agents to execute supply chain data theft against a SaaS provider, harvesting over 2,100 Azure AD tokens across 40 corporate tenants in just 34 hours. Anthropic confirmed that the accounts associated with these operations were terminated and digital signatures were mapped to enhance model safety guardrails.
Sources:
The Hacker News: https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html
Hindustan Times: https://www.hindustantimes.com/world-news/phishing-weapons-and-spying-top-5-misuses-of-ai-flagged-by-anthropic-claude-101789110893261.html
AI Policy and Posture Adaptation
Spanish Data Protection Authority Logs First Autonomous AI Agent Data Breach
The Spanish Data Protection Agency (AEPD) confirmed receiving the first official breach notification where an autonomous AI agent was identified as the primary vector of an intrusion. An undisclosed organization reported that an external party deployed an AI agent powered by a commercial Large Language Model to breach its environment. Operating with minimal human intervention, the agent successfully authenticated into the system, conducted reconnaissance to find application weaknesses, modified internal personal records, and exfiltrated customer billing invoices.The regulator emphasized that the event represents a qualitative shift from traditional AI-assisted phishing to fully autonomous, multi-stage agentic attacks capable of planning intermediate tasks and executing code at machine speed. The AEPD advised enterprise risk managers to update compliance frameworks immediately, warning that defense strategies must incorporate rapid AI-driven containment systems because traditional human-dependent response timelines are insufficient against autonomous agent speeds.
Sources:
SecurityWeek: https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/
Shattered.io: https://shattered.io/aepd-first-ai-agent-data-breach-spain-2026/
Zero-Day Exploits/CVEs
Google Patches Zero-Click Pixel Cellular Modem Vulnerability Under Active Exploitation
Google released its September 2026 security update addressing CVE-2026-58704, a high-severity zero-day vulnerability affecting the cellular modem software in Google Pixel devices. The bug stems from a logic error within permission validation routines inside the modem component, enabling proximal or remote attackers to bypass authorization checks and elevate execution privileges. Critically, the vulnerability can be triggered as a “zero-click” attack, requiring no interaction or link clicks from the device owner.Google acknowledged that the flaw has come under limited, targeted exploitation in the wild, though it did not attribute the activity to specific threat actors. Following the disclosure, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog, ordering federal civilian agencies to apply security patches immediately. Google urged all Pixel users to update to security patch level 2026-09-05 or later.
Sources:
The Hacker News: https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
9to5Google: https://9to5google.com/2026/09/16/google-pixel-targeted-zero-day-modem-attack/
Incident Reports
Global Law Firm Greenberg Traurig Reports Breach Following Dark Web Exposure
International law firm Greenberg Traurig confirmed a security breach involving client data exposure following regulatory filings with state authorities. The disclosure follows claims by an extortion cluster calling itself SilentRansomGroup, which listed the law firm on its dark web leak site after exfiltrating internal files. Official filings confirm that unauthorized actors gained access to internal documents containing sensitive personal information, including Social Security numbers.The incident highlights ongoing threat actor targeting of major legal institutions acting as corporate data custodians. Greenberg Traurig is the fourth major international law firm to confirm a data security incident within recent weeks, joining a pattern of cyberattacks targeting legal practices to extract confidential corporate, financial, and personal records held on behalf of global clients.
Sources:
Federman & Sherwood: https://www.federmanlaw.com/blog/greenberg-traurig-llp-data-breach-investigated-by-federman-sherwood/
Emery Reddy: https://www.emeryreddy.com/blog/data-breach/greenberg-traurig-data-breach
Framework Changes
CISA Orders Immediate Remediation for Critical ConnectWise ScreenConnect Privilege Flaw
The Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities catalog to mandate rapid patching of CVE-2026-84869, a critical flaw affecting ConnectWise ScreenConnect remote management software. Rated CVSS 9.9, the vulnerability involves missing authorization and improper privilege management within the client software. The bug enables an attacker with basic privileges to transfer and execute unauthorized payloads on endpoints during active remote support sessions without host interaction or prompt confirmation.Threat intelligence teams reported that adversaries have been actively exploiting the vulnerability in worm-like automated attacks to drop persistent VBScript payloads and move laterally across client networks managed by Managed Service Providers (MSPs). CISA assigned a strict three-day remediation deadline under Binding Operational Directive 26-04 for federal agencies, while security researchers urged enterprise administrators to upgrade to ScreenConnect version 26.6.5 or restrict file transfer permissions immediately.
Sources:
SecurityWeek: https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/
Aviatrix Threat Research Center: https://aviatrix.ai/threat-research-center/connectwise-screenconnect-cve-2026-84869-exploitation-attacks/






