{"id":2531,"date":"2026-09-10T18:46:00","date_gmt":"2026-09-11T00:46:00","guid":{"rendered":"https:\/\/cybersecurity.bellevue.edu\/?p=2531"},"modified":"2026-09-11T18:48:06","modified_gmt":"2026-09-12T00:48:06","slug":"whats-going-on-in-cyber-10-sep-2026","status":"publish","type":"post","link":"https:\/\/cybersecurity.bellevue.edu\/index.php\/2026\/09\/10\/whats-going-on-in-cyber-10-sep-2026\/","title":{"rendered":"What&#8217;s Going on in Cyber (10 SEP 2026)"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">The Human Take<\/h2>\n\n\n\n<div class=\"wp-block-media-text has-media-on-the-right is-stacked-on-mobile\" style=\"grid-template-columns:auto 33%\"><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Many tech\/cyber folks think in terms of memes and movie clips. The conversation between John Hammond and Dr. Ellie Satler in the 1993 movie, <em>Jurassic Park<\/em>, came to mind immediately as I read through this week&#8217;s stories. They reflect a common theme: the illusion of control as a structural flaw. We&#8217;ve never had control. We keep building faster engines and adding more complex dashboards, but we&#8217;re still leaving the keys in the ignition and the garage door wide open.<br><br>Complexity is outrunning governance. Organizations are rapidly (whether they realize it or not&#8230;&lt;cough> shadow &lt;cough>) deploying tech such as autonomous (and determined) AI coding agents, edge IoT devices, complex SaaS integrations, and multi-state data pipelines faster than they can secure, log, or legally govern them (provided they bother to add these to an asset list to begin with). And while boardrooms wring their hands over &#8220;sophisticated&#8221; (e.g. quantum decryption, geopolitical espionage) threats, actual breaches are happening because of exposed remote access ports, unpatched edge appliances, hijacked OAuth tokens, and default credentials (cue Cheeto Lock meme). No organization is an island. Security is not defined by your own perimeter. You are at the mercy of the weakest vendor in the mix. And you cannot control that vendor, or that vendor&#8217;s vendor, or that vendor&#8217;s vendor&#8217;s vendor. Whether it&#8217;s a compromised managed file transfer platform, a legacy VPN vendor, an unvetted SaaS integration, or exposed industrial hardware, we live in the wake of others&#8217; security hygiene consequences.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"680\" height=\"680\" src=\"https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto.jpg\" alt=\"\" class=\"wp-image-2543\" style=\"width:259px;height:auto\" role=\"none\" srcset=\"https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto.jpg 680w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto-300x300.jpg?crop=1 300w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto-150x150.jpg?crop=1 150w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto-600x600.jpg?crop=1 600w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto-400x400.jpg?crop=1 400w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto-200x200.jpg?crop=1 200w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto-24x24.jpg?crop=1 24w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto-48x48.jpg?crop=1 48w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/cheeto-96x96.jpg?crop=1 96w\" sizes=\"auto, (max-width: 680px) 100vw, 680px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Speaking of consequences: as we tear off another page of the <em>Data Breach of the Day<\/em> calendar, we can&#8217;t ignore the absurdity of our state-by-state data privacy patchwork. Almost every single one of the 19 states with comprehensive privacy laws explicitly exempts employee data &#8211; with California standing alone. Customers have sweeping legal rights over their personal data, but the moment employees log into their work laptops, those protections vanish. But given the rise of AI-driven &#8220;productivity&#8221; tracking and turning RTO into an algorithmic panopticon, you probably already guessed where worker data falls on the priority list.<\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><video controls src=\"https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/The-Illusion-of-Control_-Understanding-True-Freedom-1.mp4\"><\/video><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/Rebecca_Gen_GP_564485_25_00001_-1024x575.png\" alt=\"\" class=\"wp-image-2540\" style=\"aspect-ratio:1.7808990625103522;width:747px;height:auto\" role=\"none\" srcset=\"https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/Rebecca_Gen_GP_564485_25_00001_-1024x575.png 1024w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/Rebecca_Gen_GP_564485_25_00001_-300x168.png 300w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/Rebecca_Gen_GP_564485_25_00001_-768x431.png 768w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/Rebecca_Gen_GP_564485_25_00001_-1200x673.png 1200w, https:\/\/cybersecurity.bellevue.edu\/wp-content\/uploads\/2026\/09\/Rebecca_Gen_GP_564485_25_00001_.png 1440w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h1>Weekly Cyber News Summary September 10, 2026<\/h1>\nThis week in cyber:\n<ul>\n<li>Nation-states continue aggressive attacks on critical infrastructure globally.<\/li>\n<li>Campaigns are highly targeted, hitting specific industries in Asia and US.<\/li>\n<li>AI is becoming an autonomous battlefield, not just a defensive tool.<\/li>\n<li>Organizations struggle to adapt governance frameworks to AI threats.<\/li>\n<li>Zero-day exploits are hitting enterprises faster, often pre-patch.<\/li>\n<li>Major breaches continue to reshape security priorities and defenses.<\/li>\n<li>No major framework updates were reported in the last week.<\/li>\n<li>US continues patching privacy laws alongside new sector mandates.<\/li>\n<\/ul>\n<br>\n<h2>State-Sponsored Attacks<\/h2>\n<details>\n<summary><strong>What executives must know about nation-state threat actors | TechTarget<\/strong><\/summary>\nNorth Korea has solidified its role as a major cyberwarfare player, primarily using digital attacks to generate hard currency for the nation. These operations are highly strategic, moving beyond simple espionage to massive financial theft. The country&#8217;s hackers were responsible for a record-breaking theft of $1.5 billion in Ethereum.\n\nThe attack specifically targeted the Dubai-based cryptocurrency exchange, ByBit. This massive heist demonstrates the evolution of state-sponsored activity from state-level intelligence gathering to direct, high-value economic disruption, making the financial sector a prime target for Pyongyang&#8217;s cyber efforts.\n<br>\nSources:<br>\nTechTarget: <a href=\"https:\/\/www.techtarget.com\/cybersecurity\/feature\/What-executives-must-know-about-nation-state-threat-actors\" target=_top>https:\/\/www.techtarget.com\/cybersecurity\/feature\/What-executives-must-know-about-nation-state-threat-actors<\/a>\n<\/details>\n<details>\n<summary><strong>Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric and Rockwell Automation<\/strong><\/summary>\nIranian state-sponsored campaigns are actively targeting critical infrastructure organizations, particularly within the United States. The primary victims are found in the water and wastewater, energy, and government sectors. These attacks indicate a strategic effort by Iran to gain leverage or disrupt core societal functions in allied nations.\n\nBeyond the US, the campaign&#8217;s implications extend to partners like Israel. The targeted organizations include major industrial players such as Siemens, Schneider Electric, and Rockwell Automation, suggesting the attackers are aiming for control over industrial control systems (ICS) and operational technology (OT) environments.\n<br>\nSources:<br>\nRescana: <a href=\"https:\/\/www.rescana.com\/post\/active-exploitation-alert-iranian-state-sponsored-attacks-targeting-siemens-schneider-electric-and-rockwell-automation-i\" target=_top>https:\/\/www.rescana.com\/post\/active-exploitation-alert-iranian-state-sponsored-attacks-targeting-siemens-schneider-electric-and-rockwell-automation-i<\/a>\n<\/details>\n\n<h2>AI Integration<\/h2>\n<details>\n<summary><strong>Cybersecurity 2026: The Year AI Became The Battlefield And What Comes Next<\/strong><\/summary>\nIn 2026, Artificial Intelligence has transcended its role as a mere tool and is rapidly becoming the actual battlefield in cyber operations. Both attackers and defenders are now incorporating autonomous, &#8220;agentic&#8221; AI systems into their workflows. These systems possess the capability to plan complex attacks or defenses, adapt mid-operation, and act with minimal human intervention.\n\nThis shift means that security teams can no longer rely solely on human analysts to monitor every threat. AI agents are now driving the tempo of the cyber conflict, making the pace of detection and response exponentially faster.\n<br>\nSources:<br>\nForbes: <a href=\"https:\/\/www.forbes.com\/sites\/cognitiveworld\/2026\/09\/03\/cybersecurity-2026-the-year-ai-became-the-battlefield-and-what-comes-next\/\" target=_top>https:\/\/www.forbes.com\/sites\/cognitiveworld\/2026\/09\/03\/cybersecurity-2026-the-year-ai-became-the-battlefield-and-what-comes-next\/<\/a>\n<\/details>\n<details>\n<summary><strong>AI Security Daily Briefing: September 03, 2026 \u2013 TECHMANIACS.com<\/strong><\/summary>\nGoogle has significantly bolstered its defensive AI capabilities with the release of Gemini 3.8 Flash Cyber, which is touted as its most advanced cybersecurity model. This powerful tool is being deployed through a dedicated initiative called the Fairwind Program.\n\nThis program provides access to trusted defenders, allowing them to leverage Google&#8217;s cutting-edge AI to rapidly detect, analyze, and respond to complex threats. This move signals a major push toward democratizing high-end defensive AI capabilities.\n<br>\nSources:<br>\nTechManiacs: <a href=\"https:\/\/techmaniacs.com\/2026\/09\/03\/ai-security-daily-briefing-september-03-2026\/\" target=_top>https:\/\/techmaniacs.com\/2026\/09\/03\/ai-security-daily-briefing-september-03-2026\/<\/a>\n<\/details>\n\n\n\n\n\n<h2>Incident Reports<\/h2>\n<details>\n<summary><strong>Major Cybersecurity Incidents of 2025 and Lessons Learned<\/strong><\/summary>\nThe review of recent incidents serves as a critical audit of existing organizational defenses, helping security teams pinpoint where their coverage is weakest. These high-profile breaches provide concrete examples of how attackers are executing their plans in the real world.\n\nBy studying these cases, organizations can move beyond theoretical threat models to understand practical attack vectors. The lessons learned often center around failures in patch management, poor segmentation, or inadequate identity and access controls.\n<br>\nSources:<br>\nHornet Security: <a href=\"https:\/\/www.hornetsecurity.com\/en\/blog\/cybersecurity-incidents\/\" target=_top>https:\/\/www.hornetsecurity.com\/en\/blog\/cybersecurity-incidents\/<\/a>\n<\/details>\n\n<details>\n<summary><strong>Recent Cybersecurity Attacks and Data Breaches \u2013 2026<\/strong><\/summary>\nIntellizence tracks the latest data on cyber security, providing a comprehensive view of malware, ransomware, and major data breaches impacting leading companies and government agencies. This allows security professionals to benchmark their own risk posture against industry leaders.\n\nThe reports detail the specific nature of the attacks, from large-scale ransomware campaigns to targeted malware deployments, offering actionable intelligence on current adversary TTPs (Tactics, Techniques, and Procedures).\n<br>\nSources:<br>\nIntellizence: <a href=\"https:\/\/intellizence.com\/insights\/business-signals-trends\/major-cyber-attacks-data-breaches-leading-companies\/\" target=_top>https:\/\/intellizence.com\/insights\/business-signals-trends\/major-cyber-attacks-data-breaches-leading-companies\/<\/a>\n<\/details>\n\n<h2>New Legislation<\/h2>\n\n<details>\n<summary><strong>US continues patchwork comprehensive data privacy requirements &#8211; New Laws Set To Take<\/strong><\/summary>\nThe United States continues to rely on a patchwork of comprehensive data privacy laws, a trend that is steadily catching up to foreign jurisdictions like the European Economic Area. Twelve new state-level comprehensive data privacy laws are scheduled to take effect over the next two years.\n\nThis fragmented landscape forces businesses to adopt complex compliance strategies, as they must adhere to different rules depending on the state of the data subject. This patchwork is creating significant operational and legal overhead for companies operating nationally.\n<br>\nSources:<br>\nNational Law Review: <a href=\"https:\/\/natlawreview.com\/article\/us-continues-patchwork-comprehensive-data-privacy-requirements-new-laws-set-take\" target=_top>https:\/\/natlawreview.com\/article\/us-continues-patchwork-comprehensive-data-privacy-requirements-new-laws-set-take<\/a>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>The Human Take Weekly Cyber News Summary September 10, 2026 This week in cyber: Nation-states continue aggressive attacks on critical infrastructure globally. Campaigns are highly targeted, hitting specific industries in Asia and US. AI is becoming an autonomous battlefield, not just a defensive tool. Organizations struggle to adapt governance frameworks to AI threats. Zero-day exploits [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[77],"tags":[78],"class_list":["post-2531","post","type-post","status-publish","format-standard","hentry","category-cyber-news","tag-cyber-news"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/2531","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/comments?post=2531"}],"version-history":[{"count":20,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/2531\/revisions"}],"predecessor-version":[{"id":2559,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/2531\/revisions\/2559"}],"wp:attachment":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/media?parent=2531"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/categories?post=2531"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/tags?post=2531"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}