BARR Advisory Senior Consultant Sean Estrada has picked out top security and compliance headlines from the past month that you need to know. Take a look to find out what our consulting team has been reading this September—plus, scroll to see Sean’s CISO Pick of the Month for a must-read new resource on FedRAMP 20x.
OpenAI CEO Sam Altman said this week that he would welcome “a federal framework that sets consistent safety requirements for frontier AI.” Altman warned of catastrophic scenarios where humanity loses control of the future to AI or power becomes overly concentrated within a single entity. His comments come after Anthropic CEO Dario Amodei also recently called for an industry-wide effort to pace AI development. To mitigate these dangers, both OpenAI and Anthropic have committed to giving independent evaluators access to audit advanced models.
Microsoft is warning of campaigns that use passkey- and MFA-themed social engineering to hijack Microsoft cloud accounts, establish attacker-controlled authentication methods, and exfiltrate data from SharePoint, OneDrive, and Exchange. Attackers are combining voice phishing, convincing fake Microsoft sign-in pages, and device-code authentication flows to bypass traditional MFA protections and turn short-lived compromises into persistent access.
A Twitch browser extension with nearly 31,000 users was found routing users’ live OAuth session tokens through operator-controlled proxy infrastructure, potentially exposing credentials capable of accessing chats, private messages, and account settings. The incident highlights how seemingly legitimate third-party extensions can create serious credential-handling risks.
A new op-ed warns that the concept of “security through obscurity” is officially obsolete now that AI tools can easily surface decades-old vulnerabilities across legacy code and operational technology (OT) systems. While adversaries use AI to quickly reverse-engineer patches and lower the bar for complex exploits, defensive AI-generated patching still fails more than half the time. The lesson? Don’t rely on endlessly patching individual bugs—instead, focus on identifying root-cause process failures and deploying systemic prevention measures early.
OpenAI is pledging $1 billion in subsidized access and training to help under-resourced security teams protect critical infrastructure like water utilities, energy, and healthcare. Dubbed the “Daybreak for Frontline Defenders” initiative, the program aims to help public sector teams search for software vulnerabilities and hunt for suspicious stack activity. The effort comes as threat actors are increasingly leveraging AI to automate cyberattacks.

Sean Estrada
Senior Consultant, Cybersecurity Consulting
What’s New with FedRAMP 20x? 🚀
FedRAMP 20x is more than a documentation overhaul—it’s changing how cloud service providers (CSPs) demonstrate security.
In a new article, BARR’s Practice Leader of Cybersecurity Consulting Aaron Hamlin explains how FedRAMP 20x has evolved, what’s coming next, and what CSPs should be doing now to stay ahead of the changes. If you’re looking to grow your business in the public sector, it’s a must-read.
Take a look. 👀
Want to get these insights straight to your inbox? Subscribe to Take5, our monthly newsletter featuring top security and compliance headlines, events, and resources—brought to you by CISOs from BARR’s cybersecurity consulting team.