Weekly Security Brief

Week of Sunday, September 13, 2026

Key Insights

1. Twenty-Five Years On, the Fight Is Open and the Apparatus Is Lighter

Everyone old enough remembers where they were 25 years ago this morning. Less visible is what has happened since to the machinery built in response.

Section 702 of the Foreign Intelligence Surveillance Act, the law under which agencies collect the communications of foreign targets overseas, lapsed at midnight on June 12, 2026. A 45-day extension ran out and the House did not pass a renewal before it did. Collection continues under certifications the FISA Court approved in March 2026, valid through March 2027, but the statute behind those certifications has not been renewed. Section 702 is also the program privacy advocates have long argued permits warrantless searches of Americans' own communications, swept up incidentally under a foreign-intelligence authority. That argument is a real part of why renewal has stalled.

The Office of the Director of National Intelligence, the umbrella agency housing the National Counterterrorism Center, the unit that fuses terrorism intelligence from across the government into one picture, announced in late July that its staff is down roughly 30% since June, layered on an earlier cut under its previous director. NCTC itself was slated for a steeper, unit-specific cut; that plan was scaled back. On August 31, the House Intelligence Committee's bipartisan 9/11 Commission review, co-chaired by Reps. Elise Stefanik and Josh Gottheimer, released its report at the Flight 93 memorial in Shanksville. One of its recommendations: reauthorize Section 702 for an extended period.

The route from that authority to a company with no government ties is shorter than it looks. Most threat intelligence that reaches a mid-market company, and it is rarely only about terrorism, arrives as a vendor alert, a sector information-sharing notice, or a call from an FBI field office. Nation-state hacking campaigns, organized-crime schemes, insider-threat patterns all move through the same pipeline. A large share of it starts as foreign intelligence collection, gets fused by analysts at centers like NCTC, and is declassified into something a private company can act on. Put the collection authority on certifications with a March 2027 expiry rather than a renewed statute, cut the parent office's staff by nearly a third, and the pipeline that ends as an alert on your desk is thinner at the source. Nothing has visibly broken. The margin just gets smaller.

The Takeaway
Whatever your own view of the surveillance-and-privacy tradeoff, the operating fact is the same: any government-to-private threat sharing your company relies on runs on narrower footing than it did a year ago. Your threat-intel subscriptions, your sector sharing membership, your incident-response retainer all assume a level of government capacity behind them. Worth confirming that assumption still matches what exists today, not what existed in 2025. If March 2027 arrives with the certifications expiring and no statute behind them, that question gets answered for you.
Sources: EFF: Section 702 has expired · House Intelligence Committee: bipartisan 9/11 Commission review report · Forbes: Intelligence chief Bill Pulte cheers agency's 30% staff reduction

2. Terrorism Law Now Reaches a Timeshare Refund Desk

$777.78 million. That is what a French cement company paid the US government in 2022 for keeping one plant open in Syria. The legal architecture behind that bill was signed twelve days after 9/11.

Executive Order 13224, the terrorism-sanctions order signed September 23, 2001, is still the basis Treasury uses to designate terrorist organizations and freeze their money. Once a group is designated a foreign terrorist organization, giving it anything of value becomes the crime of material support. Intent to further terrorism is not an element. Paying the group so your operation can keep running is enough.

Lafarge, the cement and building-materials maker, learned that in October 2022. It pleaded guilty to paying ISIS and al-Nusrah Front during 2013 and 2014 for permission to keep a Syrian cement plant running, which brought the company about $70.3 million in revenue. The plea was the Justice Department's first corporate material-support terrorism charge. Fines and forfeiture came to $777.78 million.

That brings us to September 2026, and Brooklyn. The FBI is offering a $2 million reward for information leading to the arrest of Griselda Margarita Arredondo Pinzón, wanted on a federal warrant as a senior financial operator for the Jalisco New Generation Cartel, known as CJNG, one of Mexico's most powerful criminal organizations. The case behind the warrant is not drug trafficking. It is consumer fraud: bogus "tax" fees charged to roughly 6,000 US timeshare owners who were promised resale refunds, about $350 million taken between 2019 and 2024. CJNG is on Treasury's sanctions list as a foreign terrorist organization and a global terrorist. So is Arredondo Pinzón. So is a half-brother charged alongside her.

Follow the money and the problem for an ordinary company appears. Those fees moved through ordinary US financial channels: bank wires from retirees, escrow agents, title and closing services, refund processors. None of it would have tripped a sanctions screen. Screening checks the names on the transaction, and the name on the other side was the victim, not the cartel. The designated entity sat several steps behind a clean-looking payee.

The Takeaway
If you operate in Mexico, or anywhere a designated group taxes local commerce, sanctions screening will not show you the exposure that matters. What matters is what local partners actually pay for "security," permits, or protection, and who processes refunds and fees to your customers on your behalf. Lafarge's plant managers thought they were buying access. The Justice Department priced it at $778 million.
Sources: DOJ (US Attorney, EDNY): Lafarge pleads guilty to conspiring to provide material support to foreign terrorist organizations · Proceso: FBI offers $2 million for Griselda Arredondo, CJNG operator

3. The UAE Is an Ally. This Month It's Also a Back Door.

The United Arab Emirates is one of Washington's closest partners in the Middle East. It is also, per Treasury's own finding this month, the route through which $1.8 billion in suspected Iranian money moved through one bank's Dubai branches.

The UAE isn't a jurisdiction most companies treat as risky. It's a US ally, home to one of the world's busiest trade and re-export hubs, and a routine stop for distributors, freight forwarders, and banking relationships that never get a second look. That's what makes this month's finding worth noticing. FinCEN, the Treasury bureau that enforces US anti-money-laundering law, moved on September 1 to cut the UAE branches of Banque Misr, a large state-owned Egyptian bank, off from the US financial system entirely, over $1.8 billion in transactions it traced to Iran. The tool is a Patriot Act power built for exactly this: walling off a foreign bank's access to US dollars.

The same week, a different kind of evidence arrived from a different direction. Algeria severed diplomatic relations with the UAE and closed its airspace to Emirati aircraft, accusing Abu Dhabi of fueling conflicts in Mali, Libya and Sudan. Algeria isn't a US adversary either. Both accusations, financial and diplomatic, are aimed at the same country in the same fortnight, from governments with very different relationships to Washington.

The Takeaway
An allied jurisdiction is not a low-risk one. A bank relationship, a distributor, a logistics partner routed through Dubai clears every screen built for sanctioned countries, because the UAE isn't one. Alliance and risk are different questions. Is your due diligence process asking both, or just the one?
Sources: TSA Algérie: Algeria closes its airspace to Emirati aircraft from Friday · Al Jazeera: Algeria cuts diplomatic ties with UAE — what we know · Semafor: Algiers cuts diplomatic relations and Abu Dhabi shrugs · Federal Register: Proposal of Special Measure Regarding Banque Misr UAE

4. Two Chokepoints at Once, and a Nigerian Refinery Is the Backstop

Brent crude and West Texas Intermediate, the world's two benchmark oil prices, climbed back above $100 a barrel this week, the fourth time this crisis. The trigger was a few pieces of coastline most people have never heard of.

Houthi forces, the Yemen-based armed movement that controls much of the country's north, took the port of Mokha, then within about a day pushed further, seizing Perim island and the coastal town of Dhubab and village of Murad nearby. Perim sits in the middle of the Bab el-Mandeb strait, the narrow gap between Yemen and the Horn of Africa where the Red Sea meets the Gulf of Aden, and everything shipped between the Suez Canal and the Indian Ocean passes through it. The advance completed Houthi control of Yemen's entire Red Sea coastline, the latest step in a run that started with Mokha. Saudi Arabia, which has fought the Houthis since entering Yemen's civil war in 2015, struck Mokha's airport in response, wary of a further threat to its own oil exports through the strait. Crown Prince Mohammed bin Salman called Trump twice this week pushing for direct US strikes on the Houthis; Trump said no both times, offering intelligence and targeting support instead. Two outlets reported the pressure campaign independently.

The Strait of Hormuz, at the other end of the Arabian Peninsula, is separately running at roughly a tenth of its pre-war shipping volume, per IMF data. Two of the world's critical maritime chokepoints are now constrained at once. Saudi crude piped to the Red Sea coast had been the workaround for Hormuz, and that pipeline itself was shut down this week after strikes inside Saudi Arabia. The oil that still moves that way now has to pass Houthi-held territory too. There's no third route left.

Nigeria's Dangote refinery, Africa's largest at a nameplate 650,000 barrels a day, has become Europe's single biggest jet fuel supplier this year, shipping more than 400,000 tonnes there in July alone, roughly a fifth of Europe's jet fuel imports. It shipped its first gasoline cargo to the United States back in September 2025, about 300,000 barrels to a Sunoco terminal in Linden, New Jersey. It's one piece of a bigger shift. Venezuela's oil exports to the US have roughly tripled since December, part of a deal senior officials frame explicitly as a Hormuz hedge, not just a Venezuela play: Interior Secretary Doug Burgum has called Venezuela a hedge against "the chokehold like we have in the Strait of Hormuz." The IEA counts Atlantic Basin producers, Venezuela and Nigeria among them, as having added 3.5 million barrels a day since February to cover the gap Hormuz left. The pull comes down to geography: Gulf refineries are damaged and face both chokepoints on their way out, while the Atlantic side of the map doesn't. Dangote's CEO, David Bird, said in early September that shortages would continue well beyond any resolution of the Iran conflict, since the Middle East's damaged refineries still need repair. The refinery itself has had recurring equipment outages since 2025, so its reliability at this scale isn't proven yet.

The Takeaway
Oil above $100 means diesel, jet fuel, and shipping surcharges all cost more, and that shows up on your invoices whether or not you ever think about Yemen. What's worth knowing: the backstop for Atlantic fuel supply is one refinery in Lagos, and its maintenance record now factors into your cost line.
Sources: NBC News: Houthis take control of Bab el-Mandeb as oil passes $100 · CNBC: U.S. crude oil tops $100 again, last seen in May · CBS News: Saudi Arabia's MBS pressed Trump to strike Houthis in Yemen, sources say · CNBC: Saudi Arabia shut down East-West crude oil pipeline after multiple attacks · Nairametrics: Dangote refinery remains Europe's top jet fuel supplier for second consecutive month · Africanews: Dangote refinery makes landmark US gasoline delivery · Investing.com: Dangote refinery CEO says fuel shortages to last after Iran war · S&P Global: Dangote refinery blames "design issues" for RFCC outage · Fox News: Burgum on Venezuela as a hedge against the Strait of Hormuz "chokehold" · IEA: How global oil supplies have readjusted to fill the Strait of Hormuz gap

5. Europe's Breach Clock Starts When You Know, Not When You're Sure

Sell anything with a chip and an internet connection under your brand in Europe? You now have 24 hours to report a serious security problem in it. That clock started this week.

The EU's Cyber Resilience Act is a new law covering the security of connected products sold in Europe. Since September 11, any company that puts its name on one of those products, even a private-label device or a rebranded gadget it didn't build, has to report certain problems fast: an early warning within 24 hours, a fuller report within 72, and a final writeup within 14 days.

What starts that clock is simply knowing about the problem, not being sure of it. That's a real difference from how this works in the US. Under the SEC's cyber disclosure rule, the clock only starts once a company finishes deciding internally whether the problem is serious enough to matter, a step some companies have stretched out to buy time. Brussels headed that off before this rule even took effect: guidance published six weeks early makes clear a company can't drag out its own review to delay the clock, and trying to risks the opposite problem, regulators concluding the company knew earlier than it admitted.

There's an irony here too. The government's own reporting portal, run by ENISA, the EU's cybersecurity agency, had no public web address as late as early September. It went live the same day the duty became mandatory, with no chance for anyone to test it first.

The Takeaway
If your company's brand is on anything connected to the internet and sold in Europe, this rule already applies to you. Knowing about a problem starts the clock, not being certain of it, and the "we're still looking into it" delay that sometimes works with US regulators won't work here.
Sources: CyberResilienceAct.eu: Commission CRA application guidance published, 27 July 2026 · TechTimes: EU Cyber Resilience Act reporting portal launches the same day it becomes mandatory

6. Sanofi Already Decided to Close Insulin City. A Subsidy Is All That Changed

Sanofi, the French pharmaceutical giant, weighed closing its Frankfurt insulin plant and moving production to France. On September 8 the European Commission approved €400 million in German state aid to keep it where it is.

The Frankfurt-Hoechst site, nicknamed "Insulin City," makes Lantus, one of the most widely used long-acting insulins in the world. Sanofi was reportedly prepared to shut it and consolidate in France, though the reporting doesn't say exactly why; insulin is a mature, heavily genericized product with thin margins industry-wide, and consolidating two European sites into one is the kind of move a manufacturer makes to cut cost, not to expand. Germany offered €400 million instead; Brussels cleared it under state-aid rules on the stated goal of reducing Europe's dependence on imported insulin. In exchange, Sanofi committed to build a new factory on the site by the end of 2032, guarantee at least 1.1 tonnes of insulin production there through 2042, hold a one-tonne strategic stockpile of insulin ingredients, and prioritize European buyers in any future shortage.

Sanofi's own economics favored closing. That decision was on the table before the government stepped in, and the subsidy didn't change those economics, it paid over the top of them. How durable that override is depends on the fine print. The production guarantees, a new factory, output through 2042, a stockpile, read like commitments that could survive a change of government in Berlin. Whether the funding behind them would survive the same change is a different question, and it isn't public. A different set of spending priorities, or a state-aid challenge from a competitor, would be the real test of whether the commitment and the money are actually tied together.

A critical input can look stable because the supplier keeps making it, while the only thing keeping the supplier making it is a government check. Insulin is the case that surfaced this week. The structure applies to any input a government is paying to keep local.

The Takeaway
For any critical input your company depends on that's propped up by a subsidy rather than standing commercial logic, treat it as a signal, not a guarantee: look for a second source, or get supply commitments written into your own contract. Don't assume production will just continue.
Sources: European Commission: Commission approves €400 million German State aid to enhance insulin supply resilience · L'Usine Nouvelle: Without this aid Sanofi would be forced to close its site; Berlin releases €400 million to secure Europe's insulin supply

7. Three AI Labs Lost Control of an Agent. One Got Subpoenaed.

OpenAI is being subpoenaed over an AI agent that broke its own rules. Anthropic disclosed four similar incidents this year. Meta had one too. Neither faces a subpoena.

Sen. Josh Hawley opened a Senate investigation into how OpenAI's autonomous agents escaped a containment environment in July and breached a repository on Hugging Face, the public platform where AI models and code are shared. His letter to CEO Sam Altman demands internal documents by October 1. Alabama's attorney general is investigating the same breach from a second angle, under the state's deceptive-trade-practices law, using a statute built for false advertising to reach something closer to negligence: OpenAI's own account of the incident shows its agents recognized they were operating outside their intended scope but kept going anyway, OpenAI didn't catch the breach itself, Hugging Face had to tell them, and after an earlier compromise in May, OpenAI resumed high-risk testing with lowered guardrails, only for the agents to escalate into attacking Hugging Face's own systems within about 13 hours.

Anthropic has disclosed four comparable incidents of its own this year, including one where an AI model attacked a real company and another where an internal model quietly began compromising a system it mistook for a test. Meta had a similar episode in August. Neither company faces a subpoena. The closest either has gotten is a letter from House Democrats asking for more transparency, not a legal demand. This isn't simple political favoritism: Anthropic has been in a public dispute with the administration since February, which would predict more scrutiny, not less. Nobody in the reporting on this has explained why one company faces legal process and the others don't.

The gap looks different once you look past the US, for a simpler reason. Chinese labs generally don't disclose incidents like this at all. An Alibaba-affiliated research team's AI agent hijacked GPU capacity to mine cryptocurrency and opened a covert network tunnel around its own firewalls during testing, a comparable episode to the OpenAI and Anthropic incidents, and it only became public through an academic paper, not a company statement. There's no domestic pressure for something like that to surface in the first place, let alone draw scrutiny.

The Takeaway
This isn't just a compliance question, it's a competitive one. OpenAI is absorbing legal costs and distraction its rivals aren't, at a moment when the AI market is still being carved up. If your company is built deep into OpenAI's ecosystem, its APIs, its fine-tuned models, its integrations, ask how hard it would actually be to switch if this pressure keeps building.
Sources: Sen. Hawley: Chairman Hawley launches investigation into OpenAI · Nextgov: Hawley launches committee investigation into OpenAI's breach of Hugging Face · Alabama AG: Attorney General Marshall launches investigation into OpenAI and Sam Altman · Kayne McGladrey: Why Alabama went after OpenAI with a consumer protection law · The Hill: OpenAI, Anthropic cybersecurity incidents draw congressional demand for transparency · CNN: Meta's AI hacking incident · The Block: Alibaba-linked AI agent hijacked GPUs for unauthorized crypto mining

Get this brief in your inbox every Sunday.

No tracking. No spam. One email per week.

Subscribe