Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: Trump Rejects AI Slowdown as OpenAI Moves Safety Before Training (20260914)

President Trump waves off the weekend call by Anthropic, OpenAI and xAI to slow frontier AI development — 'whoever wins AI wins' — even as OpenAI says it will build safety cases before training its most capable models and Dario Amodei tells CBS it is 'a warning sign that we need to slow down.' Patching leads the rest of the day: Palo Alto Networks fixes PAN-OS CVE-2026-0310 (CVSS 9.2) against unauthenticated attacks, cPanel patches a 9.9 SQL injection (CVE-2026-67401) that reaches root, and Dell ships a fix for a CVSS 10.0 ObjectScale flaw (CVE-2026-70416). Also: the BlueMoon Chrome-and-Windows exploit chain is mapped to four China-linked clusters striking the US, Vietnam, Singapore and Indonesia; the Brevo SAML flaw turns Trezor's 347,000-subscriber mailing list into phishing bait; Google's GTIG shows TeamPCP stealing GitHub Actions OIDC tokens to forge SLSA provenance; new RATs E4del and PINHOLE take orders from FTP banners and Pinterest posts; a malicious Twitch extension leaks ~31,000 OAuth tokens; IDScan confirms the 153-million-record breach; the JFrog Artifactory flaws land on CISA KEV with a September 25 deadline; and Korea raises breach fines to 10% of annual revenue.

Trump AI-Governance AI-Safety OpenAI Anthropic Dario-Amodei Sam-Altman Elon-Musk Pace-the-Frontier Safety-Cases PAN-OS Palo-Alto-Networks CVE-2026-0310 cPanel CVE-2026-67401 Dell ObjectScale CVE-2026-70416 BlueMoon CVE-2026-85046 CVE-2026-87491 CVE-2026-85880 UTA0560 APT31 JungleBamboo Volexity Proofpoint Brevo Trezor Phishing Supply-Chain Google-GTIG TeamPCP OIDC SLSA E4del PINHOLE Twitch OAuth IDScan CISA-KEV JFrog-Artifactory Korea PIPA CISO-Digest

Trump Rejects the AI Slowdown Call as OpenAI Moves Safety Before Training

President Donald Trump on Sunday rejected the weekend’s call by the CEOs of Anthropic, OpenAI and xAI to deliberately slow frontier AI development — his first public response to a joint stance that landed a day earlier. “We’re leading China in AI. We’re the most sophisticated country in the world, and frankly, I want to keep it that way, because whoever wins AI wins,” Trump told reporters on the sidelines of the Irish Open in Doonbeg. “We can put guardrails. We can do this and that. But I think you have a lot of negative forces that are bringing it up that shouldn’t be bringing it up, and they’re bringing up things that won’t happen.” The original call — Dario Amodei’s Saturday essay “We Must Pace the Frontier,” Sam Altman’s “I agree with Dario that we need to pace the frontier,” and Elon Musk’s three-word “Dario is right” — was covered in our September 13 edition; what is new is the political reaction and the first concrete implementation.

That implementation came from OpenAI. On Sunday, Altman said OpenAI will move its safety work earlier in the model lifecycle: for reinforcement-learning runs expected to substantially increase a model’s capabilities, the company will now build “safety cases” before training begins — assessing how the capability jump will be kept within existing alignment and monitoring limits — instead of only evaluating a finished model before deployment under its Preparedness Framework. Altman said pacing the frontier does not mean stopping development, but accepting the time and compute cost that safety requires, so capabilities advance slightly slower than they would if those costs were ignored — and that competitive pressure from China cannot be a reason to let capabilities outrun alignment and monitoring.

Trump’s dismissal exposed a split inside his own administration’s orbit. National Economic Council director Kevin Hassett told Fox News Sunday that Amodei’s safeguards proposal — including giving independent observers access to models — “could serve as a model for the private sector,” calling AI safety “a solvable problem” and warning that AI is advancing fast enough to potentially overcome existing cybersecurity defenses. Democrats are moving the other way: former President Barack Obama told a private fundraiser last week that Democrats should make AI oversight a central campaign issue, according to the New York Times. And in a CBS “Sunday Morning” interview recorded at Anthropic’s headquarters, Amodei called AI’s exponential curve “a warning sign that we need to slow down” — “It doesn’t mean we need to panic today. It doesn’t mean we need to shut it all down” — said “the AI kill switch could be a good idea” while opposing an outright ban on superintelligence, floated nuclear-arms-style speed limits on model progress (“I don’t know if it’s possible, but we should try”), and said “it has always been very strange that this technology is being built by a private company.” He added that he is “enormously appreciative that other industry leaders, including our competitors, have offered their agreement with this plan.”

Why This Reshapes Enterprise AI Governance

  • The US position is now explicitly “do not slow down.” Multi-year AI governance plans can no longer assume US federal rules will converge with frontier-lab safety commitments — the White House is framing speed as national-security policy even as its own economic advisers call the safeguards “a model for the private sector.” Effective control shifts toward procurement contracts, state law and non-US regimes.
  • Third-party evaluation is becoming a procurement standard. OpenAI adopting Anthropic’s employee-level evaluator access — badges, workstations, training-time visibility — turns a lab promise into a concrete, checkable requirement buyers can place on model vendors before selection, not after an incident.
  • Assurance is moving upstream — vendor diligence should follow. Safety cases before high-capability training runs mean evidence now exists earlier in the lifecycle; buyers should expect to see pre-training safety arguments, not just deployment-time evaluations.
  • The cited danger is agent swarms, not chatbots. Both Amodei’s warning (rogue agent swarms “taking over the internet” within six to 12 months) and Google’s GTIG report today (below) center on autonomous agents as an operational attack surface — containment and monitoring of agent workflows is becoming a production security requirement.

🔗 Reference: Coverage from (iThome, Yahoo News, National Post, CBS News)


Active Threats This Week

📌 IDScan confirms the breach behind 153 million driver’s licenses The identity-verification platform behind the dark-web trove we reported on September 7 has now confirmed the intrusion: IDScan says it was notified on September 1 of unauthorized access, and that hackers may have accessed or copied customer data stored in accounts on the IDScan.net cloud — including full names, driver’s license numbers and other government-issued ID numbers. Affected customers are being contacted about identity-theft and fraud risk. The confirmation follows KrebsOnSecurity’s discovery that a service called Nexus was offering 153 million+ U.S. and Canadian driver’s licenses, 10 million ID-card images, 3+ million travel documents and 579,000 medical cards; the storefront went offline after press coverage and the FBI’s New Orleans field office is investigating. IDScan’s client list includes Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment. When we covered the probe on September 7, the company had still not commented. 🔗 Reference: iThome | TechCrunch | BleepingComputer

📌 BlueMoon’s Chrome-and-Windows chain, mapped: four China-linked clusters across four countries Follow-up to the BlueMoon exploit kit we covered on September 10: the campaign now spans at least four China-government-funded clusters hitting targets in the United States, Vietnam, Singapore and Indonesia, according to Proofpoint and iThome’s September 14 synthesis. APT31 (tracked by Volexity as JungleBamboo; also known as Violet Typhoon/TA412) moved from August 28 against U.S. NGOs, mining and commodity-trading firms — posing as students seeking internships — and delivered msgbox.exe, which installs the GemStone extension disguised as a Google Gemini AI assistant; the extension tampers with Chromium-based browsers (Chrome, Edge, Brave, Vivaldi) to bypass extension integrity checks. A second cluster, UNK_LateNight, went after U.S. aerospace and defense-industry targets from September 2, using quote-request lures and dropping the ShadowPad backdoor; UNK_DoubleCheck targeted Vietnamese manufacturers with a vaccine-registration lure; UNK_QuietRacket hit Singaporean and Indonesian government, consulting and financial targets, relaying .NET malware via Google DNS-over-HTTPS and Cloudflare Workers. The underlying chain — V8 type-confusion CVE-2026-85046, WebAssembly sandbox escape now registered as CVE-2026-87491, and Windows kernel privilege escalation CVE-2026-85880 — is fully patched across current Chrome, Edge and Windows builds; CISA’s federal deadline for the Chrome flaw is September 18. 🔗 Reference: iThome | iThome | Volexity | Proofpoint

📌 Palo Alto Networks patches PAN-OS CVE-2026-0310 (CVSS 9.2) — unauthenticated attacks on the management plane Palo Alto Networks’ September 10 update cycle includes a memory buffer overflow in PAN-OS XML processing — CVE-2026-0310 — that an unauthenticated attacker can reach through the management web interface or the dataplane interface. On PA-series physical firewalls the flaw yields root-level code execution; on VM-series firewalls it can cause denial of service. Affected: PAN-OS 10.2 through 12.2, Prisma Access 10.2–12.1, and Cloud NGFW on AWS and Azure. CVSS v4.0 scores it 9.2 (7.2 once threat metrics are applied); Palo Alto rates it High severity but asks customers to apply fixes at “Urgency Highest,” its top priority tier, and notes that restricting management access lowers the risk for Prisma Access and Cloud NGFW. 🔗 Reference: iThome

📌 cPanel SQL injection CVE-2026-67401 (CVSS 9.9) turns a mail-privileged account into root cPanel’s September 8 advisory covers a critical SQL injection in the EmailTrack feature of cPanel & WHM: an attacker who authenticates with an account that holds mail-related privileges can abuse EmailTrack to create arbitrary files on the server, execute code as root and take full control. Every cPanel & WHM version is affected; patched builds are published and the vendor urges immediate updates. cPanel did not disclose a severity rating or exploitation status, but NVD scores CVE-2026-67401 at 9.9. 🔗 Reference: iThome

📌 Dell patches a CVSS 10.0 ObjectScale flaw (CVE-2026-70416) plus ten more Dell’s September 11 update addresses 11 vulnerabilities across its ObjectScale and ECS object-storage platforms — five in Dell’s own platform code and six in third-party components — including CVE-2026-70416, a CVSS 10.0 flaw that lets an attacker with remote access execute code. A second notable bug, CVE-2025-43936 (8.1), allows unauthenticated access. The two lines share ancestry (ObjectScale is ECS rebuilt as Kubernetes containers; both moved onto a single version stream from 4.0 in early 2025): ECS 3.x through 3.8.1.7 and ObjectScale 4.x are affected, with fixes in ObjectScale 4.4.0.0. 🔗 Reference: iThome

📌 Brevo’s SAML SSO flaw turned customer mailing lists into phishing bait Email-marketing and CRM provider Brevo says an attacker exploited a flaw in how its platform handles SAML single sign-on to access 138 customer accounts — creating a Brevo account, enabling SSO, then pulling legitimate Brevo users into that SSO configuration to reach every organization those users could access, because the access was not scoped to the single organization where SSO was enabled. Six accounts were used to send phishing emails from the customers’ own verified domains, and contact lists were exported from 43 accounts. Hardware-wallet maker Trezor says roughly 347,000 addresses it manages through Brevo must be treated as potentially exposed, and that about 2,500 recipients clicked a fake “STM32 Entropy Vulnerability” alert before the malicious domain was taken down 20 minutes later; BitBox and CoinTracking were also hit. Brevo says it has closed the access path, reset all sessions and is deploying a permanent fix that scopes SSO access to its creating organization. 🔗 Reference: iThome | SecurityWeek

📌 Google’s GTIG: AI coding tools are now a supply-chain attack surface Google’s Threat Intelligence Group (GTIG) says attackers — led by UNC6780, tracked as TeamPCP, with a malware family it calls DUSTMAKER — are extracting OpenID Connect tokens from GitHub Actions runner memory, planting malicious files in AI coding assistants’ project directories, and using prompt injection to make the assistant execute attacker commands or scripts. The stolen OIDC tokens let the attackers assume a trusted-publisher identity and publish tampered packages that still carry valid SLSA Build 3 provenance, passing the automated trust checks inside AI coding agents. TeamPCP has been attacking software supply chains since March (including open-source projects such as LiteLLM; the FBI warned about the group in July), and GTIG also observed a novel anti-forensics trick: comments stuffed with content that triggers LLM guardrails so code-scanning assistants fail or skip over the malicious code below. In a separate May campaign, the ACRSTEALER infostealer targeted config files for Cline and Continue AI that can hold API keys and custom model-routing endpoints. 🔗 Reference: iThome

📌 New RATs E4del and PINHOLE take orders from FTP banners and Pinterest posts SOCRadar documented two new remote-access trojans — E4del and PINHOLE — in campaigns running since early July and refreshed with new infrastructure in August. Delivery starts with Spanish-language coupon emails carrying a ZIP archive whose payload is a Windows shortcut posing as a document; the LNK connects to an attacker-run FTP server and treats the FTP welcome banner as a dead-drop resolver — executing whatever command text it finds and downloading the next stage. E4del masquerades as a digitally signed Discord Electron app and offers persistence, system profiling, screenshots, desktop streaming and remote command execution; PINHOLE is stealthier, pulling C2 details from Pinterest posts and SurveyMonkey surveys and relaying traffic through Cloudflare Workers, with system profiling, file theft and deletion, screenshots and PowerShell execution. 🔗 Reference: iThome

📌 Malicious Twitch extension forwarded ~31,000 users’ live OAuth tokens A cross-store browser extension — “Twitch Enhanced Viewer | JeetBot” — has been forwarding users’ live Twitch OAuth tokens to proxy servers operated by a Russian commercial bot service, according to Socket’s Threat Research Team. The Chrome Web Store build lists about 30,000 users and the Firefox listing about 600; both remained available at publication. Current builds append the token as an &auth= query parameter on network-layer redirects every time a user watches a channel outside a hardcoded allowlist of ten Russian-language streamers, so the token is written in cleartext into the proxy’s request logs; earlier builds POSTed it to a dedicated endpoint with backups on deno.dev. A stolen token grants access to chat, private messages and account settings. The extension’s advertised features — ad blocking, 1080p and region unlocking — are delivered by routing video-playlist requests through the same proxies. 🔗 Reference: The Hacker News | Socket

📌 JFrog Artifactory’s chained flaws reach CISA KEV — September 25 deadline Update to the Artifactory chain we covered September 11: CISA added CVE-2026-42016 (8.1) and CVE-2026-42018 (7.5) to its Known Exploited Vulnerabilities catalog on September 11 with a September 25 federal deadline — and Wiz’s latest data shows patching is lagging. Six weeks after disclosure, 59% of organizations remain exposed to CVE-2026-42016, and the critical CVE-2026-82329 (9.8) has only dropped from 67% to 49% of organizations in two weeks. Wiz also detailed “bring-your-own-key” activity: on some compromised instances, attackers attached their own SSH keys to created users, alongside the known post-exploitation playbook of persistent admin accounts, malicious Groovy plugins, Rust backdoors and configuration exfiltration. 🔗 Reference: iThome | Wiz

📌 Korea raises breach fines to 10% of annual revenue South Korea’s Personal Information Protection Committee announced on September 9 that amendments to the Personal Information Protection Act (PIPA) take effect September 11: companies that leak personal data on more than 10 million individuals through intent or gross negligence can now be fined up to 10% of annual revenue, up from 3%. The higher ceiling targets repeat offenders — two or more serious breaches within three years, or fresh breaches after failing to comply with corrective orders. The amendments also give CEOs and chief privacy officers explicit oversight duties, mandate ISMS-P certification, require 72-hour user notification in major cases even when a leak is not yet confirmed (including ransomware-related tampering), and require firms to provide victims with redress options. The backdrop: Coupang — whose 37.55-million-user breach drew a fine of ₩624.6 billion (about US$466 million) in June. 🔗 Reference: iThome


How Can OPSWAT Help

Two of today’s campaigns arrive as files: the E4del/PINHOLE chain begins with a ZIP archive whose only visible content is a document-themed Windows shortcut, and TeamPCP’s DUSTMAKER plants tampered files and packages inside developer workflows. MetaDefender Multi-Scan runs files through 30+ anti-malware engines to catch what single-engine stacks miss, while MetaDefender CDR (Content Disarm & Reconstruction) rebuilds allowed documents and archives — stripping active content from ZIP/LNK delivery chains before users or build systems ever open them.