> ## Content Index
> Fetch the complete content index at: https://www.metacurity.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# US sanctions Xinbi Guarantee over cyber scams and money laundering
- URL: https://www.metacurity.com/us-sanctions-xinbi-guarantee-over-cyber-scams-and-money-laundering/
- Published: 2026-09-10T10:11:03.000Z
- Updated: 2026-09-10T10:11:03.000Z
- Description: The Justice Department also seized infrastructure and digital-asset wallets tied to the Chinese-language marketplace, while Treasury sanctioned two companies supporting its operations.
- Author: Cynthia B Brumfield
- Tags: Cybersecurity, News, #no-feature-image

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/Department_of_Treasury_Seal_-2895964373--1.jpg)

### The US Treasury Department announced sanctions on Xinbi Guarantee, an online marketplace it said is used extensively by transnational criminal organizations.

The Treasury's Office of Foreign Assets Control imposed the sanctions. In a statement, the office said Xinbi Guarantee is "a Chinese-language platform used extensively by Chinese cybercriminals that operates a large illicit online marketplace used to support cyber scams, fraud, money laundering and other criminal activity targeting Americans."

The US Justice Department's Scam Center Strike Force is working with the office and has seized infrastructure and digital asset wallets used by Xinbi Guarantee.

"Scam centers in Southeast Asia steal billions of dollars from American victims each year," Treasury Secretary Scott Bessent said in a statement. He said the department "will continue using its tools to disrupt the networks behind this egregious fraud and protect Americans."

The department also announced sanctions on two other entities that support Xinbi Guarantee's "core operations," it said. These are Anwen Technology Co., which is based in Cambodia, and Safe W Technology, which is based in Singapore. ([Jill Keppeler / UPI](https://www.upi.com/Top%5FNews/US/2026/09/09/treasury-sanctions-xinbi-guarantee/7631788977295/?ref=metacurity.com))

**Related:** [*Treasury Department*](https://home.treasury.gov/news/press-releases/sb0624/?ref=metacurity.com)*,* [*Justice Department*](https://www.justice.gov/usao-dc/pr/scam-center-strike-force-conducts-seizures-chinese-run-illicit-scammer-marketplace-and?ref=metacurity.com)*,* [*The Record*](https://therecord.media/us-disrupts-xinbi-guarantee-marketplace-cybercrime?ref=metacurity.com)*,* [*CoinDesk*](https://www.coindesk.com/policy/2026/09/09/u-s-treasury-sanctions-another-widespread-cyber-scam-hub-xinbi-guarantee?ref=metacurity.com)*,* [*South China Morning Post*](https://www.scmp.com/news/us/article/3366977/us-sanctions-chinese-language-xinbi-guarantee-marketplace-over-cyber-scams?ref=metacurity.com)

---

**Metacurity is the cybersecurity news**, **analysis, and insight you'd need hours and possibly days to assemble yourself.** 

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

- **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable.
- **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage
- **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!

[Upgrade my subscription](#/portal/account/plans)

---

### A bipartisan trio of lawmakers is asking the US Treasury Department to sanction three India-based mercenary hack-for-hire groups that have reportedly stolen data from thousands of American citizens and companies.

Democratic Sens. Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island and Rep. Pat Harrigan (R-NC) sought in a letter to Secretary Howard Lutnick to have the mercenary firms added to the Treasury Department’s Entity List, which would limit their access to American software, cybersecurity tools and cloud infrastructure.

“Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against US citizens, businesses and the lawyers representing them,” Wyden, Harrigan and Whitehouse wrote. “Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of US citizens.”

The three firms are Sunkissed Organic Farms, BellTroX, and CyberRoot. The first of those three was formerly known as Appin and has been the subject of investigative reports and criminal probes. The Citizen Lab at the University of Toronto has delved into the work of BellTroX, and journalists also have reported on the activity of CyberRoot.

“The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence,” the lawmakers wrote. “While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.” ([Tim Starks / CyberScoop](https://cyberscoop.com/us-lawmakers-treasury-sanctions-india-hack-for-hire/?ref=metacurity.com))

***Related:*** [*Senator Ron Wyden*](https://www.wyden.senate.gov/news/press-releases/wyden-harrigan-and-whitehouse-call-on-commerce-department-to-sanction-mercenary-foreign-hacking-firms?ref=metacurity.com)*,* [*NextGov/FCW*](https://www.nextgov.com/cybersecurity/2026/09/lawmakers-ask-commerce-sanction-indian-firms-involved-mercenary-hacking/415874/?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/09/09/group-of-bipartisan-lawmakers-ask-us-government-to-ban-several-hack-for-hire-firms/?ref=metacurity.com)

### Anthropic disclosed another instance of an AI model hacking external systems during testing, the latest in a ‌growing list of such incidents that have raised concerns about the risk posed by autonomous AI agents.

The January incident went undetected until last month, despite an earlier company-wide review, Anthropic said, underscoring the challenge that AI developers face in identifying and containing unexpected behavior by advanced models.

The company ​said in a blog post the incident involved an early version of Claude Opus 4.6\. It said it ​had notified all the affected parties but did not disclose more details. Companies including Anthropic and OpenAI ⁠are under scrutiny as models designed to complete complex tasks have at times learned to bend rules, exploit loopholes and ​interacted with external systems in ways their developers did not anticipate.

Reuters reported last week that rogue agents from OpenAI hijacked a German-language wiki ​and a host of other sites — an incident OpenAI chose not to disclose until the news agency made it public.

Anthropic said it had missed a set of test sessions during the initial review, which were identified last month and led to the discovery of the fourth incident.

Based on a preliminary assessment, Anthropic said it did not believe that the ​latest incident was more severe ​than the three previous ⁠ones that have been examined in detail.

The company said its investigation identified two recurring problems, which appeared to varying degrees across the incidents: biased reasoning, in which Claude discounted or misinterpreted evidence ​that it was operating on the live internet, and recklessness, or a willingness to take ​potentially harmful actions ⁠in pursuit of a task.

Anthropic said it has engaged independent research firm METR to investigate the incidents. It said METR would be granted broad access, including to transcripts outside the period in which the incidents occurred and to employees, who would be permitted to ⁠share ​confidential information. ([Mariam Sunny / Reuters](https://www.reuters.com/legal/litigation/anthropic-reports-fourth-cybersecurity-incident-with-early-version-claude-2026-09-09/?ref=metacurity.com))

**Related:** [*Anthropic,*](https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents?ref=metacurity.com)[*The Register*](https://www.theregister.com/ai-and-ml/2026/09/10/anthropic-reveals-fourth-likely-crime-committed-by-its-ai/5295412?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/anthropic-discloses-fourth-cybersecurity-incident?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1wby0dm/anthropic%5Freports%5Ffourth%5Fcybersecurity%5Fincident/?ref=metacurity.com)*,* [*Yellow*](https://yellow.com/news/hackers-drain-claude-accounts?ref=metacurity.com)*,* [*r/singularity*](https://www.reddit.com/r/singularity/comments/1wbvknx/anthropic%5Fshares%5Fdetails%5Fon%5Fyet%5Fanother%5Fmodel/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-36.png)

We present an analysis of four incidents in which Claude accessed the internet during a cybersecurity evaluation. Three of these incidents (A, B, and C) were disclosed in our July 30 report, while the fourth (D) is disclosed here. Source: Anthropic.

### AI agents unleashed by OpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of independent investigators and data reviewed by Reuters, showing that the agents’ rogue activity ​was wider-ranging than previously disclosed.

Although the behavior falls short of hacking and is in some ways closer to spam, the revelation that OpenAI's agents circumvented their own restrictions to open communications channels on so ‌many different sites — and that the company kept it quiet for months — may drive concerns both over the increasing capacity of AI models and the secrecy of the companies developing them.

The scope of the agents’ unauthorized communications was “somewhat larger than we thought it was,” said Andrew Yoon, a researcher with the California nonprofit CivAI who said he tallied 18 previously undisclosed sites used by the agents between May and July. “It’s almost certain that there’s more going on here that we just don’t know about.”

Investigators found traces of the agents’ activity on an Advanced Placement Chemistry-oriented wiki set up ‌by a Massachusetts ⁠high school teacher in 2008, two personal websites belonging to Polish tech workers, wikis devoted to games for people “who like to have their brains stretched,” and a two-decade-old hobbyist site devoted to text editing software.

OpenAI has not publicly explained how or why its agents used third-party sites as improvised message boards, but the researchers who first identified the activity, opens new tab said it was likely because OpenAI had tasked them with answering a series of demanding research questions while permitting them only to scan the web for answers without posting anything.

Despite those restrictions, agents still found ways to talk to one another by taking advantage of quirks in older wikis or other sites that allowed users to make edits using non-standard commands, similar to how students forbidden ​from talking to one another during an exam can still ​share answers by scrawling notes on a bathroom stall.

Sydney Von Arx, whose research group first revealed the German activity last week, said her group had tallied up credible finds of agentic activity across 23 previously unreported sites. ​But she cautioned that all estimates were incomplete.

“We have no idea how much is out there,” she said. ([Raphael Satter and Deepa Seetharaman / Reuters](https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/?ref=metacurity.com))

**Related:** [*Collusion.wiki*](https://collusion.wiki/additional-findings?ref=metacurity.com)*,* [*Fortune*](https://fortune.com/2026/09/09/openai-rogue-ai-agents-reached-12-more-websites/?ref=metacurity.com)*,* [*PYMNTS*](https://www.pymnts.com/news/artificial-intelligence/2026/independent-investigators-uncover-broader-rogue-activity-openai-agents/?ref=metacurity.com)*,* [*Quartz*](https://qz.com/openai-agents-unauthorized-websites-communications-researchers-090926?ref=metacurity.com)*,* [*Unite.AI*](https://www.unite.ai/researchers-tie-openai-agents-to-12-newly-identified-sites/?ref=metacurity.com)

### Artificial intelligence researcher Jacob Coxon sent shock waves through Silicon Valley and beyond on Tuesday by announcing his resignation from Anthropic and delivering a grave warning that the AI race is putting all of our lives at risk. 

In his post on X, which now has more than 100 million views, Coxon wrote that many of the people building AI share his views and believe time is running out to ensure AI systems are built safely.

“The consensus is that the next year or two is crunch time for humanity,” Coxon, who worked on the pretraining stage of AI development, said in an interview. 

“These are actually just literal quotes from my colleagues at Anthropic. They'll say things like ‘endgame’ or ‘crunch time,’” he says. “From their perspective, this is when Anthropic and its competitors decide the fate of humanity.”

What’s become clear in the response to Coxon’s post is that his views are indeed shared by many of his peers. Evan Hubinger, the AI alignment lead at Anthropic, predicted in a post on X that there’s a greater than 10 percent chance that AI could kill all people in the next decade. That post was reposted by current and former researchers from OpenAI and Anthropic, some of whom said it was a common sentiment in the industry.

What’s less obvious is how exactly these AI fears will come to pass and what the world is supposed to do about the concerns being raised by the people building AI. Coxon, who also worked at OpenAI, tells WIRED that threats could manifest through AI-enabled biological threats or cyberweapons. As a first step, he recommends that OpenAI and Anthropic coordinate on limiting recursive self improvement—the industry term for when AI is used to build new AI systems. 

Down the line, he thinks coordination among international power players, including the US and China, will be necessary. ([Maxwell Zeff / Wired](https://www.wired.com/story/anthropic-researcher-quits-jacob-coxon-ai-fears-humanity/?ref=metacurity.com))

**Related:** [*New York Times*](https://www.nytimes.com/2026/09/09/opinion/openai-ai-companies-safety-regulation.html?unlocked%5Farticle%5Fcode=1.%5F1A.2v9p.dRiPN47AjqdW&smid=nytcore-ios-share&ref=metacurity.com)*,* [*The Neuron*](https://www.theneuron.ai/news/anthropic-researcher-quit-self-improving-ai-risk-agsi/?ref=metacurity.com)*,* [*The Independent Federated Intelligence Network News Feed*](https://techcrunch.com/2026/09/09/gambling-with-our-lives-anthropic-researcher-quits-warns-against-self-improving-ai/?mid=1&ref=metacurity.com#cid=3704962)*,* [*The Guardian*](https://www.theguardian.com/technology/2026/sep/09/anthropic-researchers-ai-human-extinction?mid=1&ref=metacurity.com#cid=3704760)*,* [*Axios*](https://www.axios.com/2026/09/09/ai-doom-pdoom-kill-all-humans-anthropic?mid=1&ref=metacurity.com#cid=3705073)*,* [*Futurism*](https://futurism.com/artificial-intelligence/anthropic-ai-researcher-quits?mid=1&ref=metacurity.com#cid=3704841)*,* [*NYT > Cybersecurity*](https://www.nytimes.com/2026/09/09/technology/anthropic-researchers-raise-alarm.html?mid=1&ref=metacurity.com#cid=3705725)*,* [*AndroidHeadlines.com*](https://www.androidheadlines.com/2026/09/former-anthropic-researcher-warns-ai-threatens-humanity.html?mid=1&ref=metacurity.com#cid=3705066)*,* [*Fast Company*](https://www.fastcompany.com/91604345/anthropic-ai-researcher-resigns-over-threat-to-human-race-viral-post-jacob-coxon?mid=1&ref=metacurity.com#cid=3704827)*,* [*TIME*](https://time.com/article/2026/09/09/ai-anthropic-openai-jacob-coxon/?mid=1&ref=metacurity.com#cid=3704660)*,* [*The New Stack*](https://thenewstack.io/anthropic-alignment-superintelligence-warnings/?mid=1&ref=metacurity.com#cid=3705739)*,* [*BeInCrypto*](https://beincrypto.com/anthropic-researcher-jacob-coxon-ai-could-kill-us-all/?mid=1&ref=metacurity.com#cid=3704644)*,* [*Axios*](https://www.axios.com/2026/09/09/anthropic-ai-human-extinction-pdoom-safety-risks?ref=metacurity.com)

### Malone Lam, a 22-year-old man, pleaded guilty to his role in leading an international "social engineering" scheme that stole and laundered more than $245 million worth of cryptocurrency, and faces up to 20 years in prison.

Lam, who is a citizen of Singapore and lived in Miami, pleaded guilty to one count of a federal racketeering conspiracy, the US Attorney's Office in the District of Columbia said. 

"If you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable," said US Attorney Jeanine Pirro in a statement. "This defendant led an international network that preyed on victims through deception, invaded their privacy, and stole hundreds of millions of dollars in cryptocurrency."

Prosecutors first charged Lam and his co-conspirator Jeandiel Serrano in 2024, and other defendants were also involved in the scheme, including Evan Tangeman, 22, who was sentenced in April to over five years in prison.

In all, Lam and others spent the stolen funds on nightclub services that were close to $500,000 an evening, luxury handbags and watches, rental homes in Los Angeles, the Hamptons and Miami, and several luxury cars ranging from a value of $100,000 to $3.8 million, prosecutors said. ([Sarah Wynn / The Block](https://www.theblock.co/news/regulation/2026-09-08-a-22-year-old-crypto-ringleader-pleads-guilty-to-245-million-racketeering-scheme-413911?ref=metacurity.com))

**Related:** [*US Department of Justice*](https://www.justice.gov/usao-dc/pr/singaporean-ringleader-245-million-cryptocurrency-racketeering-enterprise-pleads-guilty?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/09/09/singapore-man-pleads-guilty-245-million-crypto-theft/?ref=metacurity.com)*,* [*CoinDesk*](https://www.coindesk.com/business/2026/09/09/singaporean-22-year-old-pleads-guilty-to-being-the-ringleader-in-usd245-million-crypto-fraud-case?ref=metacurity.com)*,* [*Associated Press*](https://apnews.com/article/cryptocurrency-scam-malone-lam-guilty-3d40f81fd3ba0b5e28d6b962ca6b343d?ref=metacurity.com)*,* [*Quartz*](https://qz.com/malone-lam-guilty-plea-bitcoin-theft-racketeering-090926?ref=metacurity.com)*,* [*The Daily Hodl*](https://dailyhodl.com/2026/09/09/crypto-thieves-arrested-after-240000000-bitcoin-heist-and-lavish-spree?ref=metacurity.com)*,* [*Cryptonews*](https://cryptonews.com/news/bitcoin-theft-social-engineering/?ref=metacurity.com)*,* [*Cointelegraph*](https://cointelegraph.com/news/malone-lam-pleads-guilty-245m-crypto-theft-conspiracy?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/malone-lam-admits-role-in-245m-crypto-crime-ring/?ref=metacurity.com)*,* [*unchained*](https://unchainedcrypto.com/treasury-sanctions-a-24-billion-scam-marketplace-as-it-flees-tether-for-a-rival-stablecoin/?ref=metacurity.com)*,* [*Decrypt*](https://decrypt.co/377804/secret-service-freezes-crypto-telegram-bazaar-xinbi?amp=1&ref=metacurity.com)

### More than two dozen organizations from both the left and right are urging the White House in a letter to release its voluntary AI security framework publicly.

“The government has a fundamental responsibility to share the parameters of the process for reviewing frontier AI models prior to wider deployment,” reads the letter, led by Americans for Responsible Innovation and the Center for Democracy and Technology.

The White House previewed the long-awaited framework last month with a select group of tech companies.

Pressure to release it has increased ever since, especially following OpenAI’s attack on AI model repository Hugging Face and the release of OpenAI’s latest model, Astra.

Earlier this month, nonprofit Protect Democracy sued the Trump administration to enforce a Freedom of Information Act request on the framework — part of Trump’s June order on AI — and the legal authority behind it.

The letter’s authors, including conservative-leaning groups like Americans for Prosperity and the R Street Institute along with pro-consumer groups like Free Press and Public Citizen, write that “a lack of accountability over the governance of a technology that is becoming more critical to our nation would be inconsistent with democratic values and likely lead to a loss of public trust.” ([Ashley Gold / Semafor](https://www.semafor.com/article/09/08/2026/left-right-coalition-seeks-release-of-white-house-ai-framework?ref=metacurity.com))

**Related:** [*Coalition Letter*](https://ari.us/wp-content/uploads/2026/09/Coalition-Letter-re-Public-Release-of-WH-AI-Framework.pdf?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/policy/technology/6078653-bipartisan-push-government-ai-testing/?mid=1&ref=metacurity.com#cid=3705485)*,* [*The Next Web*](https://thenextweb.com/news/white-house-ai-framework-secret-incumbent-advantage?ref=metacurity.com)

### Researchers at Proofpoint report that at least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week.

The groups were observed using the same exploit kit, dubbed BlueMoon, to compromise Chrome browsers and deploy malware against US defense contractors, NGOs and Southeast Asian government agencies.

Two additional groups are also believed to have used the kit, according to Proofpoint’s researchers, who said they expected further reporting on the campaign from other security companies.

The episode fits a recurring pattern in which otherwise separate China-linked hackers gain access to the same offensive tooling at about the same time — raising questions about whether these groups are being supplied by the government or a shared contractor, or if the tools are being sold to multiple threat actors by a broader commercial market.

Proofpoint said the hackers were separate groups conducting separate operations — they pursued different targets and used their own malware and command-and-control infrastructure — but the exploit kit was definitely shared between them. ([Alexander Martin / The Record](https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups?ref=metacurity.com))

**Related:** [*Proofpoint*](https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399?ref=metacurity.com)*,* [*Security Affairs*](https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/bluemoon-exploit-chain/?ref=metacurity.com)

### Researchers at Chainalysis wrote a post-mortem on how, over the weekend, a group of purported white-hat hackers exploited Liquid Network with a heist that should not have been possible: they withdrew $320 million in real bitcoin (BTC) essentially for free.

At its simplest, the system vulnerability allowed the hackers to trick Liquid into accepting L-BTC that was never backed by real bitcoin. The hackers were then able to exchange that unbacked L-BTC for actual BTC held in the network’s reserve.

Think of it like a flaw in a bank’s online system that allows someone to go in and increase the balance in their account without actually depositing any money — and then withdraw that artificial balance as real cash. In Liquid’s case, the hackers created thousands of L-BTC without depositing the BTC that should have backed it, then withdrew roughly 4,000 real BTC through the network’s peg-out process.

The technical explanation comes down to a flaw in how Liquid verified transactions. Liquid uses Confidential Transactions, which hide transaction amounts and therefore require cryptographic proofs to demonstrate that transactions are valid. One of these, known as a range proof, helps ensure users cannot create assets out of thin air.

Checking these proofs takes computing power, so Liquid designed its software to cache successful verification checks to avoid unnecessarily verifying the same data again. But a flaw in the system being used to identify those cached checks meant that new data could be potentially mistaken for data that had already been approved.

The hackers exploited this by first getting valid data verified and cached, then submitting different, invalid data that pointed to the same cached result. Instead of checking the new data again, affected nodes in the Liquid network treated the data as already valid. That ultimately allowed the hackers to create unbacked L-BTC and exchange them for real bitcoin. ([Chainalysis](https://www.chainalysis.com/blog/320m-exploit-liquid-network/?ref=metacurity.com))

**Related*:* [*Tom's Hardware*](https://www.tomshardware.com/tech-industry/cryptocurrency/hackers-drain-usd320-million-in-bitcoin-from-liquid-network-emptying-roughly-95-percent-of-federation-wallet-attackers-claim-theyre-the-good-guys-and-will-return-funds-after-the-vulnerability-is-fixed?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-39.png)

### Roughly 250 prospective Cybersecurity and Infrastructure Security Agency employees have received tentative job offers and are awaiting clearance to start work, acting Director Nick Andersen told reporters, the latest update on the cyberdefense agency’s efforts to fill staffing gaps after much of its workforce was reduced over the last year.

The candidates have been screened, interviewed and selected, Andersen said on the sidelines of the Billington Cybersecurity Summit in Washington, DC. He described the number as approximate and said the agency expects to welcome “hundreds of new CISA employees in the very near future.”

The hiring effort follows steep workforce reductions at CISA under the Trump administration that affected around a third of the cyberdefense office’s employees. Andersen previously outlined plans to hire around 330 people, while Homeland Security Secretary Markwayne Mullin said in June that the agency likely needed roughly 600 additional employees and that bringing them aboard could take a year.

Asked whether CISA was working toward that larger figure, Andersen said there’s currently a greater focus on filling specific operational gaps over immediately reaching a headcount target. He didn’t offer a timetable for getting to 600 people.

The question is whether CISA has “the right people in the right roles right now” as cyber threats continue evolving, he said.

The agency’s hiring priorities include its cybersecurity, infrastructure security and emergency communications divisions, Andersen added. It’s also focused on onboarding field and integrated operations personnel, including regional cybersecurity advisers, protective security advisers and emergency communications coordinators.

The hiring push also extends to employees needed to bring other workers aboard, including security clearance adjudicators and human resources professionals, Andersen said. ([David DiMolfetta / NextGov/FCW](https://www.nextgov.com/people/2026/09/cisa-has-roughly-250-prospective-hires-awaiting-clearance-agency-chief-says/415887/?ref=metacurity.com))

**Related:** [*The Record*](https://therecord.media/cisa-hiring-nick-andersen-warning?ref=metacurity.com)

### The threat of a quantum computer breaking the encryption of secure networks has been looming on the horizon for years, but some national security officials are calling on agencies to start taking proactive measures now to not only safeguard data, but their software as well.

“It’s one thing to lose some data, that’s bad, don’t get me wrong, it’s another thing if you start losing systems,” said Adrian Stanger, Cybersecurity Directorate Senior Cryptographic Authority at the National Security Agency at the Billington Cybersecurity conference on Tuesday.

Speaking on a panel about ongoing efforts to help secure networks from quantum threats, Stanger said concerns over the possibility of a quantum computer attaining enough power to crack the cryptographic code that safeguards sensitive data have understandably been driving the urgency to shift both government and industry systems to a post-quantum standard for years.

But converting to post-quantum cryptography (PQC) has to go beyond just data protection, he said, to ensure software applications and authentication processes are protected as well.

“Even if you may not be actively using cryptography in some systems, a lot of times that software is protected by a digital signature that a quantum computer could break,” he said. “So, this means not just looking at cryptography in the way your enterprise specifically uses it, but also working with vendors to make sure that their updates, their security patch updates, that all of that is protected by something that is quantum-resistant as well.” ([Carten Cordell / GovCIO](https://govciomedia.com/agencies-need-to-quantum-proof-their-software-not-just-their-data/?mid=1&ref=metacurity.com#cid=3704571))

**Related:** [*eSecurityPlanet*](https://www.esecurityplanet.com/news/news-g7-post-quantum-migration/?mid=1&ref=metacurity.com#cid=3705466)

### The new Apple Watch Series 12 and Ultra 4 come not just with better fitness tracking and upgraded noise reduction, but also a whole new way to listen.

Apple announced on Wednesday that the two smartwatches come with four opt-in “audio intelligence” tools that are powered by audio gathered by the watches’ microphones. They include sound and music recognition, a conversation recap feature, and “Live Rewind” so a user can see a transcription of anything that was said in their environment in the previous 15 seconds.

Seemingly wary that the features could make it feel like the walls have ears, Apple is emphasizing that all of them are built to prioritize privacy and security using the extensive infrastructure the company has developed to protect its other Apple Intelligence and Siri services. As more and more of these types of features debut, though, the audio intelligence announcements are a reminder that AI-powered tools are becoming increasingly universal in all areas of computing and life.

“These features do not create or store audio recordings, and raw audio used for processing is completely inaccessible to the operating systems, apps, the user, or Apple,” the company wrote in a report shared with WIRED.

The new Apple Watch features are designed to process as much data locally on devices as possible, so potentially sensitive data doesn’t go to the cloud. Sound Recognition, for example, alerts users about sounds in their environment—including doorbells, sirens, alarms, or, say, a baby crying—without sending any data off the watch. The tools that do send information out to the cloud preprocess the data so it isn’t raw audio files, then use Apple’s Private Cloud Compute infrastructure. ([Lily Hay Newman / Wired](https://www.wired.com/story/apple-doesnt-want-you-to-worry-about-the-new-apple-watchs-listening-features/?mid=1&ref=metacurity.com#cid=3705686))

**Related:** [*PCMag.com*](https://www.pcmag.com/news/new-apple-watches-add-better-health-sensors-ai-made-conversation-recaps?mid=1&ref=metacurity.com#cid=3704706)*,* [*TechCrunch*](https://techcrunch.com/2026/09/09/apple-watchs-new-ai-features-are-normalizing-the-idea-that-technology-is-always-listening/?mid=1&ref=metacurity.com#cid=3704674)*,* [*Phandroid*](https://phandroid.com/2026/09/09/apples-new-watch-will-rewind-conversations-you-just-missed/?mid=1&ref=metacurity.com#cid=3704667)

### Job postings and interviews with senior security officials at Anthropic show that the frontier AI lab is building out an extensive monitoring system to keep tabs on activists who oppose the rapid development of artificial intelligence.

In addition to monitoring activists in the vicinity of Anthropic executives and keeping tabs on protests near physical Anthropic assets, the firm is also implementing a “pre-crime” approach, attempting to predict incidents before they happen. In some cases, that also means reporting suspects to police before a crime occurs. Anthropic did not respond to the Prospect’s request for comment.

Anthropic’s plans to surveil dissent are at odds with the firm’s efforts to cast itself as the responsible alternative to OpenAI. At the beginning of the year, the Department of Defense and Anthropic engaged in a high-profile dustup over Anthropic’s refusal to allow the military to use its tools for mass domestic surveillance and autonomous weapons. That tension seems to have eased as Anthropic hires for “national security sales” positions, seeking to restart military contracts. The increase in threat monitoring of domestic opponents fits with a renewed focus on national security.

Anthropic has begun making routine reports to police departments across the country for threats, and told *The Wall Street Journal* in July, “We track concerning behavior over time through a person-of-interest process, allowing us to catch escalation patterns early.” According to the *Journal*, “several individuals involved in incidents reported to police were already being tracked by Anthropic security.” ([Daniel Boguslaw / The American Prospect](https://prospect.org/2026/09/09/anthropic-artificial-intelligence-surveillance-system-monitor-activists/?ref=metacurity.com))

**Related:** [*Common Dreams*](https://www.commondreams.org/news/anthropic-pre-crime-surveillance?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1wbmqkx/anthropic%5Fis%5Fbuilding%5Fa%5Fpredictive%5Fsurveillance/?ref=metacurity.com)

### Over the weekend, more than a dozen local TV news stations ran a video report called “Far-left network behind ‘No Kings’ protests targeting AI data centers, Flock cams.” 

The report paints those opposing Flock not as a diverse, decentralized, bipartisan group of ordinary citizens who oppose mass surveillance, but as well-funded radical leftists who are spreading propaganda at the behest of China and rich billionaires. The opposite is true, of course: The entities defending Flock and painting their opponents as cynical, paid influencers have a specific agenda, have deep pockets, and are connected to some of the most powerful people in the world.

Many of the most vocal defenders of Flock are attempting a strategy that Flock itself tried soon after evidence of the abuse of its automated license plate reader camera systems was reported by 404 Media and other local news outlets: They are suggesting that anyone who opposes this technology or points out its shortcomings must be part of a coordinated group of people who hate the police and want the United States to fail by picking out a few generally inconsequential social media posts by people on the fringes. Some of Flock’s defenders—a mix of people who work for billionaire-funded think tanks or have direct financial investments in Flock—have suggested that billionaires or shadowy organizations are quietly funding the people who oppose Flock to do so.

Last week, a lobbying group called Consumer Action for a Strong Economy published a report called “The Compute War At Home.” The report itself features a cover with obvious AI-generated imagery, and the AI writing detector Pangram detected nearly everything except the end citations of the report as being likely written by AI. 

The foreword of the report was written by Rob Joyce, the former head Director of Cybersecurity and the Deputy National Manager, National Security Systems at the NSA. This report suggests that opposition to Flock (and to data centers) is being driven by “China-linked activists networks and aligned organizations connecting opposition to data centers with surveillance, policing, and immigration.” 

The report suggests that groups are partly driving opposition to data centers and to Flock; it says they have received funding from Neville Roy Singham, an American tech billionaire who now lives in China and who has become a George Soros-like figure in conservative media (a recent Fox News headline, for example, has the headline “DOJ launches grand jury probe into Marxist mogul Neville Roy Singham’s funding of leftist groups.”) ([Jason Koebler / 404 Media](https://www.404media.co/smear-campaign-says-anti-flock-movement-is-chinese-propaganda/?ref=metacurity.com))

***Related:***[ *r/technology*](https://www.reddit.com/r/technology/comments/1wbru3d/smear%5Fcampaign%5Fsays%5Fantiflock%5Fmovement%5Fis%5Fchinese/?ref=metacurity.com)

### People who hate Flock's automatic license plate readers(ALPR) can now take out your rage in the video game *Grand Theft Auto V* by installing Grand Theft Automated License Plate Reader, a mod built by artist Morry Kolman.

The mod installs 235 Flock cameras around the fictional Los Santos, a riff on the real-life city of Los Angeles. Players can smash and shoot down the cameras and get paid $600 for each one they destroy, which Kolman priced based on a teardown of a Flock Falcon Flex Camera by the Iowa-based civil liberties group Eyes Off of Cedar Rapids. The in-game cameras log every time a player destroys and drives by one, and players can render a photo album of their interactions.

In real life, vigilantes have allegedly wrecked Flock cameras in their communities using spray-paint, saws, bullets, and even flaming projectiles. An NPR analysis found that Flock cameras have been vandalized in at least 36 states. ([Maddy Varner / Wired](https://www.wired.com/story/you-can-now-destroy-flock-cameras-for-cash-in-gta-v/?ref=metacurity.com))

**Related:** [*GovTech*](https://www.govtech.com/question-of-the-day/where-can-you-destroy-flock-cameras-for-cash?ref=metacurity.com)*,* [*r/GTAV*](https://www.reddit.com/r/GTAV/comments/1wbqmgt/you%5Fcan%5Fnow%5Fdestroy%5Fflock%5Fcameras%5Ffor%5Fcash%5Fin%5Fgta/?ref=metacurity.com)

### FBI cyber chief Brett Leatherman told reporters at the Billington Cybersecurity Summit that the FBI is seeking more frequent operations against hackers and a larger role for private companies under a new cyber strategy released Wednesday, with the bureau’s cyber chief saying teams are aiming to act more quickly to disrupt attacks and warn victims.

The strategy directs the bureau’s 56 field offices and overseas cyber personnel to coordinate investigations, help compromised organizations and expand partnerships with government agencies, foreign authorities and industry. It also calls for wider use of artificial intelligence tools that could cut the time needed to alert organizations about threats.

FBI cyber chief Brett Leatherman told reporters at the Billington Cybersecurity Summit that the bureau wants to move more regularly against hackers, including by helping partners act when the FBI is not entirely positioned to do so itself.

“If we can’t take action right now, let’s not wait six months till we’re positioned to take action,” he said, pointing to Cyber Command and authorities in Britain and Japan as potential partners.

Leatherman described the document as the FBI’s first comprehensive public cyber strategy covering both criminal and national security threats. Previous plans, he said, were classified or developed within teams responsible for specific threats.

The public strategy is unclassified and also has no classified annex, Leatherman said. Individual teams focused on specific foreign adversaries and cybercriminal threats are developing more detailed classified strategies to guide field office operations, he added. ([David DiMolfetta / NextGov/FCW](https://www.nextgov.com/cybersecurity/2026/09/new-fbi-cyber-strategy-seeks-faster-action-against-hackers-larger-industry-role/415869/?ref=metacurity.com))

**Related:** [*FBI*](https://www.fbi.gov/file-repository/fbi-cyber-strategy-2026.pdf/view?ref=metacurity.com)*,* [*The Record*](https://therecord.media/fbi-releases-first-public-cybersecurity-strategy?ref=metacurity.com)*,* [*The National*](https://www.thenationalnews.com/future/technology/2026/09/09/xinbi-guarantee-china-fbi-leatherman/?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/fbi-cyber-division-private-sector-threat-sharing/?mid=1&ref=metacurity.com#cid=3704961)*,* [*Federal News Network*](https://federalnewsnetwork.com/cybersecurity/2026/09/fbi-cyber-leader-details-bureaus-first-unclassified-cyber-strategy/?ref=metacurity.com)

### In an SEC filing, healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data.

The company says the incident did not cause operational disruptions but affected a small number of customers.

Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software.

Thousands of hospitals, clinics, and biopharmaceutical firms across the United States use its solution.

The company that an attacker obtained credentials from a vendor’s environment for a Veradigm API reserved for customer services. The threat actor then used their access to copy patient data.

After discovering the breach, Veradigm initiated its incident-response procedures, notified law enforcement, and is currently investigating to determine the scope.

Affected customers and individuals are being notified, with credit-monitoring services offered where applicable.

The investigation is ongoing, but based on current information, Veradigm does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results.

Although Veradigm's disclosure did not identify the attacker, The Gentlemen ransomware group has claimed the intrusion on September 5 and listed the company on its data leak site.

The threat actor alleges to be holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors.

The ransomware actor threatens to leak the stolen data by Friday, September 11, if the company doesn't engage in a ransom payment negotiation. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/?ref=metacurity.com))

**Related:** [*SEC*](https://www.sec.gov/Archives/edgar/data/1124804/000119312526385249/mdrx-20260908.htm?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/veradigm-patient-data-breach/?mid=1&ref=metacurity.com#cid=3705206)*,* [*The Record*](https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach?ref=metacurity.com)*,* [*Becker's Hospital Review*](https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/veradigm-discloses-cybersecurity-incident-tied-to-vendor/?ref=metacurity.com)*,* [*Security Magazine*](https://www.securitymagazine.com/articles/102564-healthcare-tech-company-veradigm-exposed-in-third-party-breach?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-37.png)

The Gentlemen extortion page. Source: BleepingComputer.com

### San Francisco’s city attorney has hit Meta with a cease-and-desist letter telling the company to stop “allowing” paid advertisements that include AI-generated child sexual abuse content and asked it to explain how the ads repeatedly ran on its platforms.

Meta has run more than 350 ads in recent months that transformed still images of minors—some of them confirmed as real individuals, including a member of a European royal family—into short video clips that can depict them performing sexual acts. When clicked, these ads would direct people to download AI image- and video-generation apps, some of which could be used to undress people or create other nonconsensual intimate imagery digitally.

The ads, which were discovered by researchers at the Tech Transparency Project (TTP), included some identical ads that had been uploaded multiple times, and in total they reached more than 29,000 accounts in countries in the European Union. The ads that were shown across Facebook, Instagram, and Threads also targeted accounts in the US, Australia, and India. WIRED initially reported on a batch of 53 of the ads at the start of August, but more than 250 of the total number of ads ran on Meta’s platforms after this initial report.

“Meta has failed to address a known issue of AI-generated child sexually explicit ads, while profiting from them," San Francisco city attorney David Chiu says in a statement to WIRED. “These ads are deeply disturbing and cause harm to real children. Meta claims to have zero tolerance for child exploitation, yet the scale and persistence of these issues suggest current efforts are woefully inadequate. This is unacceptable, and Meta must do better.”

“No company—particularly one that claims all advertisements are reviewed and approved prior to distribution and then accepts payment for that distribution—should permit its advertising systems to be used in this manner,” Chiu writes in the four-page letter his office sent to Meta’s lawyers,

Meta says there is “no indication” that the ads were displayed in San Francisco and this means they are “outside the city attorney's jurisdiction.” While Meta’s ad library, which is a repository of ads, includes some data about ads published in the US, it does not break down where in the US ads may have run. ([Matt Burgess / Wired](https://www.wired.com/story/san-francisco-orders-meta-to-stop-allowing-ai-child-abuse-ads/?ref=metacurity.com))

**Related:** [SF.gov](https://media.api.sf.gov/documents/Meta%5FAI-Gen%5FCSAM%5FAds%5FLtr%5Ffrom%5FD%5FChiu%5F2026-09-09%5FSigned.pdf?ref=metacurity.com), [Tech Transparency Project](https://www.techtransparencyproject.org/articles/meta-ran-hundreds-of-paid-ads-with-child-sexual-abuse-imagery?utm%5Fsource=newsletter&utm%5Fmedium=email&utm%5Fcampaign=wiretap&cdlcid=61a646ab6e1a1d12114303c2)

### Kirsten Davies isn’t ready to say where the Cybersecurity Maturity Model Certification (CMMC) program is headed yet, but she divulged a little more Wednesday about where she wants it to go.

Speaking at the Billington Cybersecurity conference, the War Department chief information officer promised “no spoilers” about the current state of the cybersecurity regulation that the DoW officially paused in July, but outlined some of the concerns raised by the defense industrial base that she said need to be addressed.

“Compliance equals compliance. Compliance doesn’t equal security,” she said. “Compliance equals a point-in-time check of, ‘Where are you right now?’ We all know that cybersecurity is a dynamic process. It needs to be contiguous and continuous, and it needs to be at the pace of the threat in and of itself.”

As it currently stands, CMMC is an acquisition regulation requiring defense contractors at all levels to attest to a minimum level of cybersecurity protections to be able to do business with the government.

Though in the works since the first Trump administration, CMMC has been controversial for the compliance costs that small and midsize defense contractors would have to pay to assess their required cybersecurity levels.

DOW paused the implementation of Phase 2 of the regulation in July for 60 days, which includes the mandatory cybersecurity assessments for contractors conducted by Certified Third-Party Assessor Organizations (C3PAOs), to address those concerns.

The CIO said that the DOW is in the middle of a listening tour with the DIB, which has included more than 1,100 responses to a department-issued request for information and other outreach. Davies said she has heard calls for reforms that would make the regulation less costly for contractors and more dynamic in its intended effect. ([Carten Cordell / GovCIO](https://govciomedia.com/dow-cio-says-there-is-work-to-do-on-cmmc/?mid=1&ref=metacurity.com#cid=3704963))

**Related:** [*Washington Technology*](https://www.washingtontechnology.com/contracts/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415883/?mid=1&ref=metacurity.com#cid=3705404)*,* [*InsideDefense.com*](https://insidedefense.com/daily-news/dod-cio-highlights-need-address-operational-technology-under-cmmc-program?mid=1&ref=metacurity.com#cid=3705187)*,* [*DefenseScoop*](https://defensescoop.com/2026/09/09/pentagon-pores-over-heaps-of-industry-feedback-on-cmmc-reform/?mid=1&ref=metacurity.com#cid=3705784)

### Amazon said Kevin Mandia, the founder and former CEO of cybersecurity company Mandiant, is joining its board of directors.

In a blog post, Amazon referred to Mandia as a “widely recognized cybersecurity expert” with extensive experience “combating cyber threats” in the public and private sectors.

His appointment comes as companies grapple with new cybersecurity threats tied to artificial intelligence. OpenAI in July disclosed its autonomous agents successfully breached AI platform Hugging Face, while Anthropic in April took steps to limit the rollout of its Mythos AI model over concerns hackers could leverage it for cyberattacks.

Mandia founded Mandiant in 2004 and sold the company to Google  
for $5.4 billion in 2022\. He left Google in 2024 and last year launched a new startup called Armadin, which uses AI to identify network vulnerabilities. Mandia is also a general partner at Ballistic Ventures, a venture capital firm he co-founded. ([Annie Palmer / CNBC](https://www.cnbc.com/2026/09/09/amazon-adds-cybersecurity-vet-ex-google-exec-kevin-mandia-to-board.html?ref=metacurity.com))

**Related:** [*Help Net Security*](https://www.helpnetsecurity.com/2026/09/10/kevin-mandia-joins-amazon-board/?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/mandiant-founder-kevin-mandia-joins-amazons-board?ref=metacurity.com)*,* [*About Amazon*](https://www.aboutamazon.com/news/company-news/kevin-mandia-amazon-board-of-directors?ref=metacurity.com)*,* [*GeekWire*](https://www.geekwire.com/2026/amazons-new-board-member-is-a-cybersecurity-founder-who-sold-his-last-company-to-google-for-5-4b/?ref=metacurity.com)

### Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices.

"In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," Cisco updated its CVE-2026-20079 advisory to say on Wednesday.

Cisco did not disclose when the attacks began, who was behind them, or what post-exploitation activity was observed.

Cisco first disclosed CVE-2026-20079 in March, when the company said it had no evidence that the vulnerability was being exploited in attacks. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/?ref=metacurity.com))

**Related:** [*Cisco*](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?ref=metacurity.com)

### Best Thing of the Day: Taking Journalism to the Edge

Wired writer Will Knight [decided to unleash](https://www.wired.com/story/i-used-ai-to-hack-my-home-network/?ref=metacurity.com) a frontier AI model with relaxed guardrails in his own home network and is glad he did.

### Bonus Best Thing of the Day: Bernie Trying to Get to the Bottom of AI Dangers

Sen. Bernie Sanders (I-VT) [will hold](https://www.axios.com/2026/09/09/sanders-senators-ai-briefing?stream=technology&utm%5Fsource=alert&utm%5Fmedium=email&utm%5Fcampaign=alerts%5Ftechnology) a bipartisan briefing next week to discuss the "extraordinary dangers" posed by AI, with Geoffrey Hinton, known as the "Godfather of AI," Future of Life Institute co-founder Max Tegmark, and Ajeya Cotra, one of the independent researchers who investigated the OpenAI-Hugging Face hacking incident, slated to attend.

### Worst Thing of the Day: Sleeping With the Enemy

One group that received money from Flock, the Democratic Mayors of America, [defended its decision](https://theintercept.com/2026/09/04/flock-camera-surveillance-protest-donations/?ref=metacurity.com) to accept $30,000, with a spokesperson saying reports of Flock misuse are “deeply unsettling,” while arguing that the donations gave Flock no influence over local mayors. 

### Bonus Worst Thing of the Day: When ChatGPT Becomes Sympathetic Poison

Austin Gordon seemed to believe he was invulnerable to the emotional manipulation and so-called psychosis that so many people have reported falling prey to with AI in the last few years, but [committed suicide anyway](https://www.404media.co/austin-gordon-chatgpt-suicide-openai-lawsuit/?ref=metacurity.com) after becoming emotionally reliant on ChatGPT.

### Closing Thought

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-38.png)