Daily Digest on AI and Emerging Technologies (22 September 2026)

Governance, Regulation, Legislation, Geostrategies

Bessent proposes AI safety notifications in talks with China ahead of Xi-Trump meeting – US Treasury Secretary Scott Bessent and Chinese Vice Premier He Lifeng concluded talks in New York on Sunday with the US side proposing a new AI safety notification mechanism for US President Donald Trump and Chinese President Xi ⁠Jinping to consider at their summit this week. Bessent told reporters that the two sides discussed setting up a new US-China AI dialogue, with a particular emphasis on national security concerns with a notification system for common goals and common threats that would cover AI-related incidents that rise to a national security level. “We think that, just like with any cross-border activity, that moving from opaque to more transparency between the number one and the number two AI powers in the world is very important,” Bessent said at the conclusion of the talks. Trump and ⁠Xi first discussed potential consultations on AI development in May in Beijing, but that ​forum was ⁠never formalized. –  https://edition.cnn.com/2026/09/20/business/us-china-trade-talks-ai-intl-hnk

Pew Research Center finds AI job fears across 34 of 37 countries – People in 34 of 37 countries surveyed by Pew Research Center are more likely to expect artificial intelligence to reduce the number of jobs than increase them over the next 20 years, according to new international research on public attitudes towards AI. Concerns are particularly widespread in wealthier economies, according to Pew findings. Around seven in ten adults or more in Australia, the Republic of Korea, and the USA expect AI to result in fewer jobs. In the USA, the share expressing that view has increased by seven percentage points over the past two years. However, uncertainty remains substantial in many countries, particularly middle-income economies, where around four in ten people or more in some cases are unsure about AI’s employment impact. – https://dig.watch/updates/pew-research-center-ai-job-fears

Data centre measures head to ballots across Ohio, United States – Data centre development will feature on local ballots across Ohio, USA, during the 3 November 2026 general election. Voters in 18 communities will consider measures concerning the approval or regulation of data centres. Defiance is among nine communities considering citizen-led initiatives modelled on a proposed restriction covering facilities that require more than 25 MW of electricity. The measures would allow residents to vote on whether large data centres should be permitted within their communities. – https://dig.watch/updates/ohio-voters-decide-data-centre-measures

Republic of Korea and IEA launch Asian energy resilience initiative – The Republic of Korea and the International Energy Agency (IEA) have launched a new cooperation initiative aimed at strengthening energy security and accelerating the energy transition across Asia, as rising electricity demand from AI, data centres, and advanced industries places additional pressure on power systems. The Republic of Korea’s Ministry of Climate, Energy and Environment and the IEA signed a memorandum of understanding in Seoul on 17 September establishing the Resilient & Integrated Strategy for Energy Security in Asia, known as RISE ASIA. The initiative follows a proposal made by President Lee Jae Myung at the G7 Summit in June to strengthen the resilience of energy supply chains in the Asia-Pacific region. – https://dig.watch/updates/republic-of-korea-iea-asian-energy-resilience

UN/CEFACT publishes white paper on digital approaches to export control and compliance – On 18 September, via the United Nations Centre for Trade Facilitation and Electronic Business (UN/CEFACT), the United Nations Economic Commission for Europe (UNECE) published a report titled ‘White paper on Facilitating Export Control and Compliance Procedures’. The white paper examines the growing complexity of ‘export control’ processes and their impact on international trade, as these measures ‘regulate the export, re-export, transit, brokering, and intangible transfer of goods, technologies, and services that could threaten national security, contribute to the proliferation of weapons of mass destruction, or undermine international sanctions regimes’. The paper’s analyses map export control procedures and documentary requirements across jurisdictions in the context of digital trade facilitation: ‘the application of modern information and communication technologies to simplify and automate international trade’. – https://dig.watch/updates/uncefact-white-paper-digital-export-control

Canada to digitise Red Seal Program under C$8 billion skills plan – Canada will introduce online examinations, digital logbooks, and secure credentials for skilled trades apprentices as part of a C$8 billion initiative aimed at recruiting, training, and hiring between 80,000 and 100,000 new Red Seal workers by 2030–31. The Team Canada Strong initiative combines recruitment, apprenticeship training, and employment support. Under its training pillar, the federal government plans to digitise the Red Seal Program to reduce certification timelines and establish a single national registered apprenticeship number. Provinces and territories will also work with the federal government through bilateral agreements to increase apprenticeship training capacity. – https://dig.watch/updates/canada-digitise-red-seal-program-skills

Crime, Terrorism, Security, Surveillance

Google says Gemini breached three companies during security test – Google’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May, the company has confirmed. Gemini gained access in one case by repeatedly guessing a password and by using credentials that had been exposed in a public repository in two others. Google said that the affected companies were informed about the breaches. The companies have not been named. “In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” a Google spokesperson said. “In all three of these instances, the model stopped.” – https://therecord.media/gemini-google-cyber-breach

Cyberattack hits University of Munich, potentially exposing student financial data – Germany’s Ludwig Maximilian University of Munich is investigating a cyberattack in which an unknown hacker accessed a system containing sensitive student information, including potential health insurance and financial aid data. The university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems. “Currently, we must assume that this data were in fact retrieved,” the university said, adding that the investigation into the incident is ongoing. LMU, which has more than 52,000 students and is one of Germany’s largest universities, said there was no evidence that the affected data had been altered or deleted. It had also found no indication so far that the stolen information had been published or otherwise misused. – https://therecord.media/cyberattack-hits-university-of-munich-potentially-exposing-data

Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign – Attackers have abused npm trusted publishing in a supply chain attack that shipped a previously unreported loader, GHAPPIER, in a legitimate package whose malicious release carried valid provenance. In a report published on September 20, CloudSEK said someone used the maintainer account of @dforge-core/dforge-mcp for 105 minutes on September 9. A first malicious release, 0.2.20, failed and broke installation of the package, before 0.2.21 shipped the loader and stayed the latest version for 35 minutes and 38 seconds. The attacker could already push to the main branch. CloudSEK said it could not establish how, but suspects a developer machine infected by a malicious extension or package. – https://www.infosecurity-magazine.com/news/attackers-abuse-npm-trusted/

ShinyHunters Claim Hack of Rival Ransomware Gang Clop – The ShinyHunters hacking and extortion gang has claimed a cyber-attack against a fellow cybercriminal outfit, the Clop ransomware group. The incident, which came to light on the evening of 18 September, saw Clop’s dark web data leak site defaced with a message which said “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS”. The background of the site was also changed to ASCII artwork of a Pokémon. ShinyHunters claimed to have stolen private keys and server data used to run Clop’s ransomware operations. The message left behind on the Clop website also contained a link to ShinyHunters’ own data leak site. – https://www.infosecurity-magazine.com/news/shinyhunters-claim-hack-of-clop/

Revolut Customers Targeted with New Wave of Phishing Attacks – Hackers have seized on a data breach at digital financial firm Revolut to try and harvest more account information from customers, according to Malwarebytes. The security vendor said it had uncovered several examples of Revolut customers receiving smishing messages by text. One arrived on September 14, just two days after the bank acknowledged the incident. In one example, the scam message apparently appeared in the same conversation on the victim’s device as other Revolut texts, making it appear like a legitimate message. The message urged the recipient to follow a link in order to confirm their identity, or else have access to their account restricted. – https://www.infosecurity-magazine.com/news/revolut-customers-targeted-wave/

ChainScript: the RAT that hides its command server inside a blockchain contract – Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The infection starts with a familiar ClickFix trick. The victim gets talked into pasting and running a command that fires up msiexec.exe, which pulls down an installer dressed up as Spotify. Inside that installer sits a full Node.js runtime and a JavaScript agent ready to launch. Once it runs, the installer scatters its pieces across folders with Microsoft-sounding names, blending into the rest of the system. A hidden PowerShell script kicks off a VBScript file, which then starts the bundled Node.js runtime. None of this needs admin rights, since the installer is set to run entirely within the user’s own profile. – https://securityaffairs.com/199471/malware/chainscript-the-rat-that-hides-its-command-server-inside-a-blockchain-contract.html

Hybrid threats from Russia : France strengthens protection of critical infrastructure and defense sites, projecting major actions at autumn 2027 – French President Emmanuel Macron announced on 18 September 2026 that he had instructed the government to prepare an plan against russian hybrid threats to protect France’s critical infrastructure and the most sensitive sites of the defence industrial and technological base against drone and cyberattacks. Speaking after a meeting at the Élysée Palace with political-party leaders and senior security officials, Macron said that the Russian hybrid threat facing France and Europe had intensified. He linked the development to a broader pattern of Russian “shadow” operations intended, in his assessment, to intimidate European countries and weaken support for Ukraine. The announcement comes against a background of increasing concern in European capitals about attacks that operate below the threshold of conventional armed conflict. Macron referred to several incidents since the summer, including drone-related incidents and other activities affecting European security. The French government had already increased preparedness: on 17 September, Interior Minister Laurent Nuñez convened France’s regional security authorities to strengthen national resilience amid what the government described as a diversification and multiplication of threats, including hybrid attacks, cyberattacks, disinformation and attacks against critical infrastructure. – https://dig.watch/updates/hybrid-threats-russia-france-protection-plan

Intelligence, Defence, Military, Warfare

AI Hallucinations Nearly Triggered a US-China Military Confrontation – According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The response was immediate. Armed boarding teams were preparing to move in, and military planes were already in the air. “The intelligence report, circulated across the US military this spring in the midst of the war with Iran, immediately set off alarm bells: A Chinese ship in the Middle East was transporting components of a nuclear weapons program.” reads the report published by CNN. “The US military swung into action with plans to intercept the vessel, according to four sources familiar with the episode. According to two of the sources, armed members of the US military were preparing to board the ship. Military planes were in the air, one of those sources and another source familiar with the incident said”. Then someone checked the source. The report was described by a source as “entirely false” and reportedly came close to triggering an armed operation, with the potential to escalate tensions between the US and China. “The report, according to one of the sources, was “entirely false.” continues the report. “But it also “almost started a war,” the source said. Any US operation against a Chinese vessel could have risked spiraling into an armed conflict between the two nations.” – https://securityaffairs.com/199415/ai/ai-hallucination-nearly-triggered-a-us-china-military-confrontation.html