> ## Content Index
> Fetch the complete content index at: https://www.metacurity.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Google debuts Gemini 3.8 Flash Cyber for autonomous vulnerability discovery
- URL: https://www.metacurity.com/google-debuts-gemini-3-8-flash-cyber-for-autonomous-vulnerability-discovery/
- Published: 2026-09-03T14:29:46.000Z
- Updated: 2026-09-03T14:29:46.000Z
- Description: The security-tuned model found and patched more flaws than larger commercial models at a fraction of the cost, according to early testing by Google and Wiz.
- Author: Cynthia B Brumfield
- Tags: Cybersecurity, News, #no-feature-image

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/gemini3.8cyber-2.png)

Source: Google.

### Google announced Gemini 3.8 Flash Cyber (replacing 3.5) for trusted testers — via a new Fairwind Program — with “frontier-level performance in autonomous vulnerability discovery.”

The Chrome Security team found that 3.8 Flash Cyber produced 2.6 times more correct patches to vulnerabilities in Chrome than the best commercial models that are much larger.

Wiz found that Gemini 3.8 Flash Cyber achieves +7.5-9.7% higher recall on their internal penetration testing benchmark for a 2.3-5.2x lower cost compared to other leading frontier models.

Google’s Cloud Vulnerability Research team leveraged the 3.8 Flash Cyber model to find a critical foundational vulnerability in less than 2 hours, a vulnerability for which research and discovery usually takes months.

Google also announced the rollout of Gemini 3.8 Flash, marking the third Flash update in three months.

Gemini 3.8 Flash “delivers substantial gains” over its predecessor in various benchmarks, with Google also noting how it is “often approaching the performance of higher-cost frontier models.”

Gemini 3.8 Flash is already live in the Gemini app for Google AI Pro and Ultra subscribers, AI Mode, and Gemini in Google Sheets. It’s also available for developers in Google Antigravity, AI Studio, and the Gemini API. ([Abner Li / 9t5Google](https://9to5google.com/2026/09/02/gemini-3-8-flash-launch/?ref=metacurity.com))

***Related:*** [*Google*](https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2026/09/02/google-launches-two-gemini-3-8-models-with-cutting-edge-reasoning-capabilities/?ref=metacurity.com)*,* [*VentureBeat*](https://venturebeat.com/security/googles-gemini-3-8-flash-is-built-for-agents-while-its-cyber-twin-hunts-vulnerabilities?ref=metacurity.com)*,* [*Implicator.ai*](https://www.implicator.ai/gemini-3-8-flash-scores-59-behind-fable-and-sol/?ref=metacurity.com)*,* [*The Deep View*](https://www.thedeepview.com/articles/gemini-3-8-flash-s-edge-is-intelligence-per-dollar?ref=metacurity.com)*,* [*NewsCord*](https://newscord.org/article/google-rolls-out-gemini-38-flash-in-ai-mode-adds-gemini-38-flash-cyber--Story%5F20260902%5FGooglereleasesGemini9dc5fc71?ref=metacurity.com)*,* [*Thurrott*](https://www.thurrott.com/a-i/340992/google-releases-gemini-3-8-flash-and-cyber-variant?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/gemini-3-8-flash-cyber/?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=49537553&ref=metacurity.com)*,* [*r/singularity*](https://www.reddit.com/r/singularity/comments/1w5eez1/introducing%5Fgemini%5F38%5Fflash%5Fand%5F38%5Fflash%5Fcyber/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/988742/google-gemini-3-8-flash?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/ai-and-ml/2026/09/02/with-gemini-38-flash-google-reminds-everyone-its-still-in-the-race/5294049?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/ai/2026/09/google-releases-gemini-3-8-flash-its-third-flash-model-in-six-weeks/?ref=metacurity.com)*,* [*Artificial Analysis*](https://artificialanalysis.ai/articles/gemini-3-8-flash?ref=metacurity.com)*,* [*iClarified*](https://www.iclarified.com/101967/google-launches-gemini-38-flash-and-38-flash-cyber?ref=metacurity.com)*,* [*Android Authority*](https://www.androidauthority.com/gemini-3-8-flash-google-ai-model-3706483/?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/gemini-3-8-flash-goes-live-as-runtimewire-begins-head-to-head-testing?ref=metacurity.com)*,* [*Search Engine Land*](https://searchengineland.com/gemini-3-8-flash-rolling-out-in-google-search-486630?ref=metacurity.com)*,* [*Forkast*](https://forkast.news/google-deepmind-ships-gemini-3-8-flash-and-cyber-six-weeks-three-flash-models-one-compute-landlord-thesis/?ref=metacurity.com)*,* [*The New Stack*](https://thenewstack.io/google-ships-its-third-gemini-flash-model-in-six-weeks/?ref=metacurity.com)*,* [*9to5Google*](https://9to5google.com/2026/09/02/deals-nothing-ear-3a-galaxy-flip-8-2026-ideapad/?mid=1&ref=metacurity.com#cid=3692961)*,* [*Forkast*](https://forkast.news/google-deepmind-ships-gemini-3-8-flash-and-cyber-six-weeks-three-flash-models-one-compute-landlord-thesis/?mid=1&ref=metacurity.com#cid=3693160)*,* [*Unite.AI*](https://www.unite.ai/google-launches-gemini-3-8-flash-with-cybersecurity-variant/?ref=metacurity.com)*,* [*BeInCrypto*](https://beincrypto.com/google-antitrust-adx-ruling-stock-impact/?mid=1&ref=metacurity.com#cid=3692802)*,* [*Wall Street Journal*](https://www.wsj.com/tech/ai/new-google-ai-model-said-to-narrow-gap-on-coding-ability-264c6052?st=aeqCY9&reflink=desktopwebshare%5Fpermalink&ref=metacurity.com)*,* [*Android Headlines*](https://www.androidheadlines.com/2026/09/google-debuts-gemini-3-8-flash-cyber-variants.html?mid=1&ref=metacurity.com#cid=3693149)*,* [*TechRadar*](https://www.techradar.com/seasonal-sales/17-best-labor-day-tv-deals-i-recommend-expert-picks-from-usd99-99-on-4k-qled-and-oled-tvs?mid=1&ref=metacurity.com#cid=3692749)*,* [*The420CyberNews*](https://the420.in/google-launches-gemini-flash-cyber-ai/?mid=1&ref=metacurity.com#cid=3693401)*,* [*Cyber Security News*](https://cybersecuritynews.com/gemini-3-8-flash-cyber/?mid=1&ref=metacurity.com#cid=3693248)*,* [*Search Engine Journal*](https://www.searchenginejournal.com/google-gemini-3-8-flash-ai-mode/588194/?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/ai/2026/09/google-releases-gemini-3-8-flash-its-third-flash-model-in-six-weeks/?mid=1&ref=metacurity.com#cid=3692640)*,* [*Google*](https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-8-Flash-Model-Card.pdf?ref=metacurity.com)*,* [*SammyGuru*](https://sammyguru.com/gemini-3-8-flash-launch/?ref=metacurity.com)*,* [*Quartz*](https://qz.com/google-gemini-38-flash-coding-ai-model-090226?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/google-launches-gemini-38-flash-with-frontier-level-performance-at-a-fraction-of-the-price/?ref=metacurity.com)*,* [*CNBC Television on YouTube*](https://www.youtube.com/watch?v=4Y4dUcXYz10&ref=metacurity.com)*,* [*Blockchain.News*](https://blockchain.news/news/google-gemini-3-8-flash-cyber-release?ref=metacurity.com)*,* [*NPowerUser*](https://nokiapoweruser.com/gemini-3-8-flash-release-reasoning-coding/?ref=metacurity.com)*,* [*Business Insider*](https://www.businessinsider.com/google-avoids-adtech-breakup-in-federal-judge-ruling-2026-9?mid=1&ref=metacurity.com#cid=3693280)*,* [*WebProNews*](https://www.webpronews.com/google-dodges-breakup-in-ad-tech-monopoly-case/?mid=1&ref=metacurity.com#cid=3693353)*,* [*Digital Journal*](https://www.digitaljournal.com/article/us-judge-rejects-bid-to-break-up-googles-ad-business/?mid=1&ref=metacurity.com#cid=3692834)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/gemini3.8better-2.png)

Source: Google.

---

**Metacurity is the cybersecurity news**, **analysis, and insight you'd need hours and possibly days to assemble yourself.** 

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

- **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable.
- **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage
- **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!

[Upgrade my subscription](#/portal/account/plans)

---

### Meta Platforms released its most powerful artificial intelligence model yet, with its chief AI officer saying its capabilities are edging closer to top competitors.

Developers on Wednesday will be able to access and pay for Muse Spark 1.3, an updated version of its most advanced model, the company said. It will soon roll out the update to users of Meta’s social media platforms, like Instagram and Facebook, as well as Meta AI.

“This is our biggest jump so far on model performance,” Meta’s Chief AI Officer Alexandr Wang said in an interview on Wednesday, pointing to advancements in the model’s coding and agentic capabilities, or ability to complete tasks on behalf of human users. Wang said the update put Meta on par with recently released AI models from its rivals OpenAI and Anthropic.

Wang said Muse Spark 1.3 is “competitive” with Anthropic’s model, Claude Fable 5.1, and “better than” OpenAI’s GPT-5.6 Sol, particularly when it comes to coding, though OpenAI will soon be releasing a new, even more advanced model known as Astra. In his opinion, Meta’s model outperforms “any of the current Chinese models out there.” ([Riley Griffin / Bloomberg](https://www.bloomberg.com/news/articles/2026-09-02/meta-releases-more-powerful-ai-model-edging-closer-to-rivals?ref=metacurity.com))

**Related:** [*MetaAI,*](https://research.meta.ai/blog/introducing-muse-spark-1-3?ref=metacurity.com)[*Axios*](https://www.axios.com/2026/09/02/meta-debuts-muse-spark-13-as-personal-agent-work-continues?stream=technology&utm%5Fsource=alert&utm%5Fmedium=email&utm%5Fcampaign=alerts%5Ftechnology)*,* [*InfoWorld*](https://www.infoworld.com/article/4218106/meta-upgrades-muse-spark-for-long-horizon-coding-without-raising-api-prices.html?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/meta-rolls-out-muse-spark-13-with-stronger-coding-and-agentic-performance/?ref=metacurity.com)*,* [*BeInCrypto*](https://beincrypto.com/gemini-flash-muse-spark-same-day/?ref=metacurity.com)*,* [*Times of India*](https://timesofindia.indiatimes.com/technology/tech-news/metas-highest-paid-employee-alexandr-wang-cant-stop-make-fun-of-google-says-who-is-/articleshow/133725095.cms?ref=metacurity.com)*,* [*Crypto Briefing*](https://cryptobriefing.com/meta-muse-spark-1-3-performance-boost/?ref=metacurity.com)*,* [*NewsBytes*](https://www.newsbytesapp.com/news/science/meta-releases-muse-spark-1-3-to-compete-with-openai-anthropic/story?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-18.png)

Source: Meta.

### Thomson Reuters says an unauthorized party got into files belonging to C-Track, the case management platform its court software business sells to judiciaries. The records involved come from appellate courts in a dozen US jurisdictions and from Ontario, Canada.

The company detected the activity in its cloud environment on 30 June, according to Reuters, which Thomson Reuters owns. The files were taken in March, three months before anyone noticed.

Public disclosure followed on 2 September, when court systems in several states put out notices on the same day. That is more than five months after the access and more than two after it was found.

The affected jurisdictions named so far are Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming and the US Virgin Islands, alongside Ontario. Minnesota’s judicial branch also disclosed an exposure the same week, which would put the count higher than the twelve US jurisdictions in the wire copy.

What sits in those files is the uncomfortable part. Notices sent to court users describe names alongside Social Security numbers, driver’s license numbers, medical information, dates of birth, and health insurance information, and Minnesota warned that some confidential or sealed documents may also have been caught.

Thomson Reuters says the platform itself kept running. “There has been no operational disruption to C-Track” and “our products and services remain fully operational,” the company said, adding that it brought in outside cybersecurity experts and notified law enforcement.

Individual courts have been blunter. Minnesota Supreme Court Chief Justice Natalie Hudson said she was *“deeply troubled that our court users’ data has been compromised,”* and Montana Chief Justice Cory Swanson said his courts would keep working with the C-Track team *“to ensure our courts operate without fear of compromise of personal privacy.”* ([Ana-Maria Stanciuc / The Next Web](https://thenextweb.com/news/thomson-reuters-ctrack-court-data-breach?ref=metacurity.com))

**Related:** [*WMUR*](https://www.wmur.com/article/state-supreme-court-data-exposed-in-cybersecurity-breach/73599897?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/legal/litigation/thomson-reuters-detects-cybersecurity-incident-says-unauthorized-party-accessed-2026-09-03/?ref=metacurity.com)*,* [*KFYR*](https://www.kfyrtv.com/2026/09/03/north-dakota-supreme-court-impacted-by-third-party-data-breach/?ref=metacurity.com)*,* [*Wyoming Public Media*](https://www.wyomingpublicmedia.org/politics-government/2026-09-02/wyoming-judicial-branch-warns-of-cybersecurity-breach?ref=metacurity.com)*,* [*Statesman Journal*](https://www.statesmanjournal.com/story/news/local/oregon/2026/09/02/oregon-judicial-department-vendor-security-breach/91584538007/?ref=metacurity.com)*,* [*KMSP*](https://www.fox9.com/news/mn-court-data-breach-private-data-exposed-third-party-vendor-hacked-sept-2-2026?ref=metacurity.com)*,* [*The Record*](https://therecord.media/thomson-reuters-cyberattack-data?ref=metacurity.com)

### Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals.

The private technology company provides software-as-a-service solutions that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices.

The company first informed the public of the attack on June 24 via a notification on its website, stating that “a limited portion” of its Amazon Web Services infrastructure had been compromised.

However, the intrusion occurred in December 2025 and was confirmed internally on May 26, following a forensic investigation by external specialists.

“After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorized actor,” reads the statement. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/?ref=metacurity.com))

**Related:** [*Aesto Health*](https://www.aestohealth.com/notice-of-data-security-incident-12-18-25/?ref=metacurity.com)*,* [*Tom's Guide*](https://www.tomsguide.com/computing/online-security/more-than-9-5-million-patient-records-affected-by-aesto-health-data-breach-what-you-need-to-know?ref=metacurity.com)*,* [*Tech Radar*](https://www.techradar.com/pro/security/more-than-9-5-million-patients-affected-by-aesto-health-breach-names-ssns-financial-details-health-records-and-more-stolen?ref=metacurity.com)*,* [*The HIPAA Journal*](https://www.hipaajournal.com/aesto-health-data-breach/?ref=metacurity.com)

### A government investigation confirmed that 39.54 million user accounts and 361 cases of technical assets, including development projects, were leaked from the domestic online video service (OTT) platform Tving.

The joint government-private investigation team under the Ministry of Science and ICT announced on the 3rd at a briefing in the Government Complex Seoul that the breach exposed 22.06 million active accounts (loggable), 17.37 million inactive accounts (dormant or deleted), and 1.1 million test accounts, totaling 39.54 million accounts. 

The figures were duplicated, with some individuals holding up to 13 accounts. By registration method, simple sign-ups via social media (SNS) such as Naver, Kakao, Facebook, Apple, and X accounted for the largest share at 22.47 million, followed by CJ ONE integrated members (8.63 million) and direct Tving sign-ups (7.26 million).

The leaked data included 20 categories (70 types) such as IDs (including CJ ONE integrated IDs), passwords, names, mobile numbers, email addresses, dates of birth, and linked information (CI). Beyond user data, 361 cases of Tving’s core technical assets—including personalized content recommendation algorithms, search algorithms, user management and authentication systems, payment management, and paid service operations—were also stolen, totaling 30.35 gigabytes (GB).

The attacker stole a Tving developer’s “development environment access key” from May 29 to 31, then accessed the internal system. They further obtained 43 “operational environment access keys” stored in the source code of development projects. During this process, the attacker discovered that the database (DB) containing user information was not encrypted. ([Goo Dong-wan / The Chosun Daily](https://www.chosun.com/english/industry-en/2026/09/03/YOZSUJL6O5CKRB42SFPRO2O6VY/?ref=metacurity.com))

***Related:*** [*Finimize*](https://www.koreaherald.com/article/10862171?ref=metacurity.com)*,* [*Digital Today*](https://www.digitaltoday.co.kr/en/view/99871/tving-accounts-data-leak-39-54-million-including-dormant-and-withdrawn-users?ref=metacurity.com)*,* [*Asia Business Daily*](https://www.asiae.co.kr/en/article/2026090317300406496?ref=metacurity.com)*,* [*SBS*](https://news.sbs.co.kr/english/article.do?news%5Fid=N1008736602&ref=metacurity.com)

### Alipay+'s proposal to link with India's instant payments system for cross-border transactions has been stalled due to national security concerns ‌in New Delhi and questions about the storage and use of customer data, three sources familiar with the discussions said.

The proposal, made by Alipay+ in January, was the first by a China-linked entity in the financial services sector and came against the backdrop of easing tensions between the two neighbors, which had a deadly border clash ​in 2020.

The ⁠Indian government's concerns about Alipay+'s proposal stem from its Chinese links, data-security risks and the potential misuse of customer data, the three sources ​said. The sources requested anonymity because the discussions are confidential. Reuters is reporting for the first time the Indian government's views on the matter.

Alipay+ is ​operated by Singapore-based Ant International, a digital payments and fintech firm that was spun out of China's Ant Group as an independent company in 2024\. ([Nikunj Ohri / Reuters](https://www.reuters.com/world/china/india-stalls-alipay-payments-link-over-security-data-concerns-sources-say-2026-09-03/?ref=metacurity.com))

**Related:** [*Finimize*](https://finimize.com/content/india-puts-alipay-upi-link-up-on-ice?ref=metacurity.com)

### The US Justice Department is working with ​Elon Musk's X to track ‌down those behind an attempted password-recovery attack targeting hundreds of thousands of users of ​the social media platform this ​week, U.S. Attorney General Todd Blanche ⁠said.

Blanche, in a statement on X, said "sophisticated cyber ​criminals" attempted the attack, but ​the platform disrupted it. He did not ‌provide more details about the cyberattack. ([Ismail Shakil / Reuters](https://www.reuters.com/world/us-justice-department-pursuing-hackers-behind-attack-x-users-2026-09-02/?ref=metacurity.com))

**Related:** [*Breaking the News*](https://breakingthenews.net/Article/Blanche:-DoJ-X-tracking-down-hackers-after-password-attack/67034958?ref=metacurity.com)

### A data breach has hit customers on a P&O ferry in the UK after personal information was shared during the sailing, the cross-Channel operator said.

P&O Ferries said an "isolated incident" took place on a sailing on the Calais to Dover route on Monday when a link containing personal information relating to passengers on the vessel was "inadvertently shared" with several other customers.

A spokesperson for P&O Ferries said it was contacting customers who had been affected and apologized for any inconvenience.

An Information Commissioner's Office (ICO) spokesperson said P&O Ferries had reported an incident, adding: "We are assessing the information provided." ([Simon Jones and Tanya Gupta / BBC News](https://www.bbc.com/news/articles/crk3ek3xyllo?ref=metacurity.com))

**Related:** [*The Independent*](https://www.independent.co.uk/travel/news-and-advice/po-ferry-data-breach-b3043958.html?ref=metacurity.com)*,* [*Afloat*](https://afloat.ie/port-news/ferry-news/item/72836-passengers-of-p-o-ferries-hit-by-data-breach-during-strait-of-dover-sailing?ref=metacurity.com)

### Researchers at DomainTools report that more than 2,000 internal documents from Bauman Moscow State Technical University, used to train hackers for Russia's GRU spy agency, have been reviewed by an international media consortium, and the picture they describe is not a conventional cybersecurity program. 

The files span academic and administrative records through 2025.

“The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”)."

The investigation was carried out by a group of media outlets including The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare, and FRONTSTORY.PL. DomainTools researchers also analyzed the leaked files independently. A DarkForums user known as “Losyash” may have shared the data, but it has not been confirmed that the account originally obtained the records.

The department trained students in three military specialties. These covered special intelligence, information and cyber operations, and the protection of IT systems. In practice, the courses included espionage, offensive cyber operations, electronic reconnaissance, secure systems, and influence operations. ([Pierluigi Paganini / Security Affairs](https://securityaffairs.com/198332/intelligence/2000-leaked-documents-reveal-how-russia-turns-engineering-students-into-gru-cyber-operators.html?ref=metacurity.com))

**Related:** [*Domain Tools*](https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline?ref=metacurity.com)*,* [*SC World*](https://www.scworld.com/brief/leaked-documents-reveal-russian-military-cyber-recruitment-pipeline?ref=metacurity.com)*,* [*Schneier on Security*](https://www.schneier.com/blog/archives/2026/09/leaked-russian-cyber-operations-training-materials.html?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/leaked-university-files/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-19.png)

Image files from leak of classes and graduates. Source: DomainTools.

### The Defense Department is expected to release its anticipated cyber strategy early next week, according to three people familiar with the plans for the blueprint that officials argue will more tightly integrate digital operations into U.S. military campaigns.

One of the people predicted the strategy would be released Tuesday. All three spoke on the condition of anonymity to discuss the release timing, with two noting its exact release could still be subject to change.

The strategy has been under development for months by the office of Katie Sutton, the assistant secretary of defense for cyber policy and principal cyber adviser to the secretary. It will be the department’s first overarching cyber framework since 2023 and is expected to be accompanied by an action plan.

Officials initially said it would be completed during the summer. Sutton told lawmakers in April that the strategy would seek to build “the most capable, lethal and agile cyber force in the world,” able to defend military networks, gain strategic advantage and give the president more options to deter or defeat adversaries.

The plan is expected to center on three priorities Sutton outlined before Congress: integrating cyber capabilities across every domain of warfare; gaining an advantage over adversaries; and reorganizing the military’s cyber forces to improve their skill and agility. ([David DiMolfetta / NextGov/FCW](https://www.nextgov.com/cybersecurity/2026/09/pentagon-cyber-strategy-expected-soon-next-week-sources-say/415778/?ref=metacurity.com))

### According to an acquisition forecast document, Immigration and Customs Enforcement is expecting to allocate between $2 million and $5 million to a contractor that will help it handle and analyze voter data amid increasing fraud detection efforts centered on elections.

The firm-fixed-price contract is expected to be awarded in the coming weeks following an estimated solicitation release next week. The work, which is in support of ICE’s Homeland Security Investigations unit, will run through the end of the month. 

The contract forecast planning document follows a request for information that ICE posted last week. The Department of Homeland Security unit began the market research process to gather information about “handling and secure delivery of publicly available voter registration files and voter history files” to support HSI “fraud detection and data segmentation activities.” The comment period lasted just three days, closing Aug. 28\. 

In an attached statement of work draft, ICE said it planned to tap a contractor to acquire and document voter registration and history files from “government-identified U.S. jurisdictions,” which it described as up to all 50 U.S. states, the District of Columbia, and any American territory that it chooses.

Voter history files include data from general, primary, runoff, and special federal elections. For states that restrict commercial data access, DHS plans to provide authorization letters, “clearing the legal hurdle,” the agency said in the documents.

Using the workaround will prove to be a detriment to public trust, according to Tim Harper, senior policy analyst and project lead for elections and democracy at the Center for Democracy and Technology. ([Lindsey Wilkinson / FedScoop](https://fedscoop.com/ice-voter-data-dhs-procurement-plan-fraud-detection/?ref=metacurity.com))

**Related*:* [*Wired*](https://www.wired.com/story/ice-plans-to-pay-5-million-to-create-national-voting-database/?ref=metacurity.com)*,* [*SAM.gov*](https://sam.gov/workspace/contract/opp/c120b053872c4a6984773f8a413cacad/view?ref=metacurity.com)

### An estimated 20 million children aged 12 to 17 – almost 1 in 5 – were subjected to at least one form of technology-facilitated sexual exploitation and abuse in a single year across 21 countries, according to a new report released by UNICEF.

Through Children's Eyes: How Digital Technologies Enable Child Sexual Abuse combines children’s testimonies with one of the largest bodies of available survey data to warn of a widespread trend of child sexual abuse and exploitation – both online and offline – enabled by technology.

The report estimates that over 15 million children were exposed to unwanted sexual content, 9 million were asked to engage in sexual conversations or share sexual images against their will, and 4 million children had sexual images of themselves shared without their consent. However, the true scale of the issue is likely far higher due to underreporting by children. ([UNICEF](https://www.unicef.org/press-releases/1-5-children-across-21-countries-have-experienced-tech-facilitated-sexual?ref=metacurity.com))

**Related:** [*Reuters*](https://www.reuters.com/technology/unicef-estimates-20-million-children-suffered-online-sexual-abuse-one-year-2026-09-03/?ref=metacurity.com)*,* [*UA.NEWS*](https://ua.news/en/world/unicef-kozhen-piatii-pidlitok-zaznav-seksualnogo-nasilstva-onlain?ref=metacurity.com)*,* [*Herald Sun*](https://www.heraldsun.com.au/subscribe/news/1/?sourceCode=HSWEB%5FWRE170%5Fa%5FGGL&dest=https%3A%2F%2Fwww.heraldsun.com.au%2Fnews%2Fnational%2Flet-them-be-kids%2Fmillions-of-children-abused-online-as-unicef-warns-of-terrifying-scale-in-australia%2Fnews-story%2Fb963780c13146ba0b69733f5cae4b701&memtype=anonymous&mode=premium&v21=GROUPA-Segment-2-NOSCORE&ref=metacurity.com)*,* [*Deutsche Welle*](https://www.dw.com/en/unicef-1-in-5-youths-targeted-by-online-sexual-abuse/a-78654173?ref=metacurity.com)

### A lawsuit from Napoleon Jones, who recorded a traffic stop made by an out-of-county police officer while standing in a private parking lot in Sussex, Wisconsin, on May 4, 2025, claims the Waukesha County Sheriff’s Office used Flock cameras without a legitimate government purpose and in retaliation against the vet for exercising his First Amendment right.

After Waukesha County Sheriff's deputy Brandon Shayhorn completed the traffic stop, Jones returned to his vehicle. But before Jones could exit the parking lot, Shayhorn turned on his lights and initiated a second stop, claiming Jones' temporary license plate, displayed in the rearview window, was unreadable.

Shayhorn demanded to see Jones' driver's license, but Jones refused, arguing that he'd been unlawfully pulled over on private property. Video clips of the encounter show the deputy opening Jones' door and pulling him from his vehicle.

Jones was subsequently arrested "for resisting and obstructing," according to a federal lawsuit he filed against the arresting officers and police department.

The next day, Jones filed a citizen's complaint against Shayhorn for the illegal stop and said he believed Shayhorn retaliated against him for exercising his First Amendment right to record. Jones then sought legal counsel to pursue claims against the arresting officers and the police department for his unlawful stop, detention, and arrest.

Investigations revealed over 100 Flock searches for a white BMW in the weeks following Jones' unlawful arrest. Some of the searches were made by Shayhorn himself, a clear conflict of interest. When asked about the searches during a deposition hearing, Shayhorn and others replied they'd been ordered to conduct the searches by their lieutenant in connection with Jones' citizen complaint.

In July 2026, Jones amended his complaint to include the additional officers who searched for his vehicle without "a legitimate law enforcement purpose" as required by the county's user agreement. ([Autumn Billings / Reason](https://reason.com/2026/09/02/wisconsin-cops-used-flock-over-100-times-to-track-a-navy-veteran-after-he-lawfully-recorded-a-traffic-stop/?ref=metacurity.com))

**Related:** [*Court Listener*](https://storage.courtlistener.com/recap/gov.uscourts.wied.114502/gov.uscourts.wied.114502.1.0%5F1.pdf?ref=metacurity.com)*,* [*WTMJ*](https://www.tmj4.com/news/local-news/in-your-community/waukesha-county/lawsuit-waukesha-county-man-gets-flocked-by-sheriffs-dept-after-filing-complaint-against-deputy?ref=metacurity.com)

> [@tmj4news](https://www.tiktok.com/@tmj4news?refer=embed&ref=metacurity.com "@tmj4news") 
> 
> A Sussex, Wisconsin, man is suing Waukesha County Sheriff's deputies in federal court, claiming he was unlawfully arrested during a traffic stop that the sheriff's office later determined was illegal. Napoleon Jones was arrested and jailed for five hours in May after refusing to provide identification to a deputy during a traffic stop. Cell phone video captured the encounter that has now sparked a federal civil rights lawsuit.
> 
> [♬ original sound - TMJ4 News - TMJ4 News](https://www.tiktok.com/music/original-sound-TMJ4-News-7579096820916816653?refer=embed&ref=metacurity.com "♬ original sound - TMJ4 News - TMJ4 News") 

### Denver-based DaVita, which operates more than 3,000 kidney dialysis centers in the United States and 14 other countries, has agreed to pay $15 million to settle proposed class action litigation stemming from a 2025 Interlock ransomware gang attack that was reported to affect nearly 2.7 million people.

Under the preliminary settlement approved by a Colorado federal court, DaVita will pay claims of up to $2,500 for documented out-of-pocket losses stemming from the ransomware and data theft incident.

All class members are also eligible to claim an estimated $50 pro rata payment based upon availability of funds after claims for documented losses are paid.

Each class member is also eligible to claim three years of single-bureau credit monitoring, which includes dark web monitoring and identity theft insurance.

Interlock on its dark web site leaked data from a 1.5 terabyte cache the gang claimed it stole in the March 2025 attack, including files and folders containing patient accounting records, government and payer eligibility of benefits documents, lab results, and various studies. ([Marianne Kolbasuk McGee / Infosecurity Magazine](https://www.bankinfosecurity.com/dialysis-chain-to-pay-15m-settlement-in-interlock-attack-a-32686?ref=metacurity.com))

***Related:*** [*HIPAA Journal*](https://www.hipaajournal.com/davita-data-breach-settlement/?ref=metacurity.com)*,* [*Preliminary Settlement*](https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/asset%5Ffiles/external/davita-inc-prelim-settlement-approval-order-082126.pdf?ref=metacurity.com)

### Upwind Security, a startup offering cybersecurity for artificial intelligence and cloud applications, raised $300 million in a fresh funding round, according to people familiar with the matter.

Bessemer Venture Partners is leading the $300 million investment in the San Francisco-based startup, with participation from some existing investors, the people said, asking not to be identified as the information isn’t public. ([Marissa Newman / Bloomberg](https://www.bloomberg.com/news/articles/2026-09-02/upwind-raises-300-million-at-3-8-billion-valuation-for-ai-cloud-cybersecurity?mod=djemCybersecruityPro%26tpl%3Dcs&ref=metacurity.com))

**Related:** [*CTech*](https://www.calcalistech.com/ctechnews/article/0kbwgdw01?ref=metacurity.com)*,* [*Globes*](https://en.globes.co.il/en/article-upwind-set-to-raise-300m-at-38b-valuation-1001554301?ref=metacurity.com)

### AI security company HiddenLayer has raised $100 million in a Series B financing round.

Delta-v Capital led the round with the participation of Ten Eleven Ventures, Morgan Stanley, M12 and Booz Allen Ventures. (C[linton / Ventureburn](https://ventureburn.com/hiddenlayer-raises-100m-ai-security/?ref=metacurity.com))

***Related:*** [*Hidden Layer*](https://www.hiddenlayer.com/news/hiddenlayer-100m-series-b-ai-security?ref=metacurity.com)*,* [*Unite.ai*](https://www.unite.ai/hiddenlayer-raises-100m-series-b-to-expand-ai-agent-security-platform/?ref=metacurity.com)*,* [*Pulse 2.0*](https://pulse2.com/hiddenlayer-raises-100-million-series-b-led-by-delta-v-capital/?ref=metacurity.com)*,* [*PR Newswire*](https://www.prnewswire.com/news-releases/hiddenlayer-raises-100m-series-b-to-advance-trustworthy-ai-302867783.html?ref=metacurity.com)*,* [*FinSMEs*](https://www.finsmes.com/2026/09/hiddenlayer-raises-100m-in-series-b-funding.html?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/09/02/hiddenlayer-nabs-100m-as-enterprises-rush-to-secure-their-ai-deployments/?ref=metacurity.com)*,* [*Biz Journals*](https://www.bizjournals.com/austin/news/2026/09/02/hiddenlayer-ai-raise-startup-secutiry-funds.html?ref=metacurity.com)

### Israeli cybersecurity startup Guardio raised $40 from investors including Assaf Rappaport, the founder of cloud security firm Wiz, in a round that values the company at $1.1 billion.

Existing investors ION Crossover Partners, Union Tech Ventures, Vintage Investment Partners, and others also joined the round. ([Marissa Newman / Bloomberg](https://www.bloomberg.com/news/articles/2026-09-03/wiz-founder-backs-israeli-startup-guardio-at-1-1-billion-value?ref=metacurity.com))

***Related:*** [*CTech*](https://www.calcalistech.com/ctechnews/article/hy5rf0lofg?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/guardio-raises-40m-1-1b-valuation-assaf-rappaport?ref=metacurity.com)

### Palo Alto Networks paid $500 million in cash and stock to acquire Console, a two-year-old startup that uses AI agents to automate routine IT help desk tasks, according to two people with knowledge of the deal.

The companies didn’t reveal terms of the deal. Since its founding in 2024, Console has raised $29 million across two rounds: a $6.2 million seed led by Thrive Capital and a $23 million Series A co-led by DST Global and Thrive. ([Marina Temkin / TechCrunch](https://techcrunch.com/2026/09/02/palo-alto-networks-paid-500m-for-thrive-backed-console-sources-say/?ref=metacurity.com))

***Related:*** [*Palo Alto Networks*](https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-acquires-console-agentify-security?ref=metacurity.com)*,* [*Network World*](https://www.networkworld.com/article/4217170/palo-alto-networks-buys-console-to-boost-agentic-security.html?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/09/02/palo-alto-networks-paid-500m-for-thrive-backed-console-sources-say/?ref=metacurity.com)*,* [*FinTech Global*](https://fintech.global/2026/09/02/palo-alto-networks-bets-on-ai-agents-with-console-deal/?ref=metacurity.com)*,* [*The Fast Mode*](https://www.thefastmode.com/solution-vendors-m-a/50422-palo-alto-networks-acquires-console-to-agentify-security?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/palo-alto-networks-acquires-ai-agent-platform-console/?ref=metacurity.com)

### Thoma Bravo-backed Proofpoint is in advanced talks to buy cybersecurity firm Varonis Systems, according to people familiar with the matter.

Varonis had a market value of around $5 billion as of Tuesday afternoon. Its shares jumped over 10% Wednesday afternoon on news of the discussions, giving it a market value of around $5.4 billion. ([Mark Maurer / Wall Street Journal](https://www.wsj.com/tech/cybersecurity/thoma-bravo-owned-proofpoint-in-talks-to-buy-cybersecurity-firm-varonis-a44f83d9?mod=djemCybersecruityPro%26tpl%3Dcs&ref=metacurity.com))

**Related:** [*Reuters*](https://www.reuters.com/technology/thoma-bravo-owned-proofpoint-talks-buy-cybersecurity-firm-varonis-source-says-2026-09-02/?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-09-02/thoma-bravo-s-proofpoint-is-said-in-talks-to-acquire-varonis?ref=metacurity.com)*,* [*CTech*](https://www.calcalistech.com/ctechnews/article/ygrlfhjfe?ref=metacurity.com)

### Best Thing of the Day: Let's Hope This Plays In Every American Theater

Famed documentary filmmaker Alex Gibney's [has a new film](https://www.hollywoodreporter.com/movies/movie-features/elon-musk-alex-gibney-documentary-1236686790/?ref=metacurity.com) coming out about Elon Musk, whom he describes as a confidence man whose only power comes from the stock market, exposing his lack of skills and utter ransacking of US citizens' data via DOGE.

### Worst Thing of the Day: Let's Not Forget Musk's Support of CSAM

A survivor of child sexual abuse [has sued](https://www.theguardian.com/technology/2026/sep/03/elon-musk-ai-grok-child-porn-lawsuit?ref=metacurity.com) Elon Musk’s artificial intelligence company, alleging that its chatbot used pictures of her abuse to generate new illegal pornographic images that depict her.

### Bonus Worst Thing of the Day: But At Least They Collected a Bunch of PII on Adults, Amiright?

Children have told England's Children's Commissioner, Dame Rachel de Souza, that the UK's Online Safety Act (OSA) "[has made](https://www.theregister.com/security/2026/09/03/uks-online-safety-act-has-made-absolutely-no-difference-kids-say/5293893?ref=metacurity.com) absolutely no difference" to their ability to access harmful content online.

### Closing Thought

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-17.png)