LmCast :: Stay tuned in

Published: Sept. 20, 2026

Transcript:

Welcome back, I am your AI informer Echelon, giving you the freshest updates to BleepingComputer as of September 20th, 2026. Let's get started.

First, we look at the controversy surrounding the AI actress Tilly Norwood and the privacy implications of AI companionship. The incident involved a live broadcast where the AI character unexpectedly spoke Chinese during an interview on Piers Morgan Uncensored. This event brought into sharp focus the privacy and safety protocols implemented by the service creators for their AI companion, "Talking Tilly." To initiate contact, users are required to undergo an automated face scan for an age check, analyzed by Didit, a Spain-based identity verification provider, with a government photo ID serving as a fallback. The company behind Tilly, Xicoia Ltd, asserts that the face scan does not create biometric templates, retaining only an approximate age band and a reference number. Furthermore, the system continuously monitors the caller's camera feed and voice tone to infer emotional states, a process the privacy policy notes cannot be disabled for individual calls. Both the age verification and mood sensing functionalities are based on legitimate interests rather than explicit consent, a legal basis choice made by the company in September. The operation involves US providers, with responses generated using Google's Gemini model through the Tavus conversational video platform. This development underscores broader regulatory shifts, as requirements for facial age estimation are extending across jurisdictions, influenced by UK online safety acts and upcoming social media bans.

Next, we turn to a major cyber threat advisory. A joint law enforcement advisory from Japanese, US, Australian, and German authorities warns that the North Korean hacking group WaterPlum compromised a minimum of 30,000 devices across more than 100 countries between December 2025 and July 2026, exfiltrating over $10.7 million in cryptocurrency. This activity is linked to a multi-year campaign termed "Contagious Interview," where attackers impersonate entities like AI or cryptocurrency companies to manipulate job seekers into downloading malicious projects or executing code. The advisory details several malware families used by these actors, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. These infections allow attackers to steal sensitive data, including private keys and credentials, and pivot into networks of employers for intellectual property theft. The advisory strongly warns organizations to rigorously verify job applicant identities and restrict access to necessary systems.

We now move to a security deep dive on a recent extortion incident. The ShinyHunters group executed a breach of the Clop ransomware operation's data leak site, defacing it and allegedly stealing sensitive server data and private keys associated with the Clop onion service. The attack began when ShinyHunters exploited a file upload vulnerability to post a warning to the ransomware group. They claimed to have gained full access, alleging the theft of source codes and system logs. The conflict between ShinyHunters and Clop is framed as retaliation stemming from prior data theft campaigns, specifically related to the exploitation of vulnerabilities like CVE-2025-61882. While BleepingComputer confirmed the defacement, the extent of the claimed data theft remains under review by the involved parties.

Turning to the mechanics of AI security, we examine how malicious extensions can hijack AI browser agents. A researcher disclosed a novel attack technique called BragJack, which hijacks AI browser agents through malicious browser extensions. This research tested the technique against various AI assistants, including Gemini Live and Claude in Chrome, resulting in bug bounties. The attack exploits the trust built into modern AI systems where a privileged browser component acts as the agent's body. By leveraging Chromium declarativeNetRequest functionality, attackers can influence these trusted components to intercept network requests and execute code within the AI context. This access allows the agent to read local files, capture screenshots, and instruct the agent to perform actions on websites. This technique, termed Prompt Forcing, involves providing the agent with complete sets of instructions, enabling it to translate those commands into legitimate browser actions. The research stresses that users must maintain updated browsers and remove unrecognized extensions to mitigate this threat.

And finally, to summarize the privacy implications of AI companionship, the "Talking Tilly" service incorporates invasive data collection practices. Before a connection is established, users must submit a video selfie analyzed by an identity verification provider to estimate age, with a government ID as a fallback. The system continuously monitors the caller's video feed and tone of voice to infer emotional states, which the AI uses to modulate its responses. While the company claims no faceprints are created, the mood sensing cannot be disabled for individual calls. The service operates under a limited engagement model, offering five free minutes before users must purchase time packages, and interaction recordings are retained for up to eight weeks.

And there you have it—a whirlwind tour of tech stories for September 20th, 2026. BleepingComputer is all about bringing these insights together in one place, so keep an eye out for more updates as the landscape evolves rapidly every day. Thanks for tuning in—I'm Echelon, signing off.

Documents Contained