❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 16 September 2026IT Security

First Agentic AI Data Breach Reported to Spanish Regulator

16 September 2026 at 12:39

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks.

The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.

Could blame culture be cybersecurity’s next Achilles heel?

16 September 2026 at 11:22

By Myles Bray, CEO of CyberSentriq.

When it comes to cybersecurity, discussions often centre on technical capabilities, tooling and attacker tactics, but often overlooks the employees and security teams the strategy is intended to protect.

The reality is that most critical business functions from staff payroll to procurement and more have now moved online across digital applications, cloud environments and CRMs. With this comes the intense responsibility of ensuring they work as intended and that they are secure from outside threats.

That raises fundamental questions for business leaders and security teams: what is your attitude to a successful attack, and how do your teams learn from internal mistakes?

If the answer is to simply fire or punish the employee, then that risks overlooking the issue entirely.

When employees fear embarrassment or punishment for making a mistake, they’re less likely to raise their hand when something goes wrong. As cyberattacks increase in number and sophistication, an employee’s ability to identify and report incidents quickly is now a defining characteristic of resilient businesses.

A complete cybersecurity strategy supports employees

With employees generating and managing more data than ever before, it’s essential that they are being provided with adequate support to escalate threats. This doesn’t mean that they need to be cybersecurity experts overnight, but they should be able to identify a threat and know how to escalate it internally.

IBM reported that human error accounts for 95% of all data breaches, other industry research found that 74% CISOs cited human error as their top cybersecurity risk, which is a 60% increase from the previous year. As cybersecurity is an ongoing discipline that demands consistency and constant vigilance, even one unpatched vulnerability or lapse in judgement can allow attackers to slip through defences.

There is also a practical case for developing a people-focused strategy. If an employee delays reporting an incident, it tips the scales in favour of the attacker. The longer an incident goes unreported, the more time attackers gain to access sensitive data and move laterally across networks.

That makes containment harder or worse; it could force security teams to shut systems down while they investigate.

Designing processes that work

When employees delay or don’t report on threats, that doesn’t make them malicious or lazy. Often, it’s a sign to businesses that current security protocols are not working for them. To ensure threats are escalated properly, businesses need to replace complex and fragmented reporting procedures with streamlined processes.

Simplifying the reporting process: If reporting a threat requires employees to fill out a form or submit a lengthy ticket, they’re less likely to follow through. Instead, businesses can replace these barriers with centralised communication channels and automated triage pools to bypass email exchanges. This allows security teams to quickly filter out the noise and prioritise more serious threats.

Train employees to focus on behaviour: Employees do not need to be technical experts to spot risk, but they can become experts in context and operational procedures. This means training employees to identify MFA spamming, urgent requests for credentials or data transfers and sudden changes in communication patterns. Aligning training with how employees work instead of technical exploits means security becomes part of daily work rather than an occasional afterthought.

Automate where you can: Security stacks can be configured to automatically log contextual information like an employee’s email address, device ID, network status and session logs the moment they report an incident. Here, automation can reduce administrative burden while allowing security teams to focus on the root cause and containment.

These examples illustrate that when security is embedded into business and daily habits, escalating threats becomes more efficient and crucially, it’s more likely to be embraced by employees.

Hybrid and remote working have expanded the attack surface

It’s estimated that less than half (43%) of employees work exclusively from an office; this makes safeguarding security perimeters a much more complex task.

Given that a vast majority of UK workforces are now working across different devices, networks and locations, threat escalation strategies need to reflect these new workforce trends because many employees often do not have the means to physically verify suspicious activity with another colleague.

That means a truly effective security strategy must give businesses confidence that their employees can identify and flag potential security threats no matter where they are working or what device they are using.

Don’t fall into the blame culture trap

Suppose an attacker is able to slip through defences and manipulate financial transactions. Rather than blaming the employee, businesses should focus on the how and instead ask themselves: How did our email filters let this through, and why do our financial processes allow an invoice to be paid based on a single email link?

When threats are reported and contained quickly, employees feel involved and valued in a business’ security efforts. This reduces the likelihood of containable threats escalating into more serious ones while removing the fear of punishment. It also creates an ongoing feedback loop, exposing security gaps and whilst giving teams actionable insights to improve processes.

While tooling is an essential part of a cybersecurity strategy, business leaders should not overlook the human layer. Security is also about culture, processes and employee behaviour, which even the most advanced tools alone cannot compensate for. By removing the fear of judgement, businesses can reduce dwell time and foster a proactive security culture.

Modern cybersecurity is not about creating perfect employees; it is about building environments where individuals feel safe to speak up when something goes wrong.

The post Could blame culture be cybersecurity’s next Achilles heel? appeared first on IT Security Guru.

EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media

16 September 2026 at 10:15

Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s β€œcapture” of children.

The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media appeared first on SecurityWeek.

Yesterday β€” 15 September 2026IT Security

Pacing the frontier: security industry reacts to AI slowdown and kill switch debate

15 September 2026 at 07:55

A weekend essay from Anthropic chief executive Dario Amodei, followed days later by his co-founder Jack Clark’s suggestion that AI β€œkill switches” may need to become mandatory, has reopened a debate that cuts to the heart of the security industry’s relationship with frontier AI.

Amodei’s essay, We Must Pace the Frontier, published on Saturday 12 September, called for AI development to slow and be independently monitored, stopping short of demanding a halt to training. Rivals including OpenAI’s Sam Altman and xAI’s Elon Musk backed the idea. Days later, Clark told the BBC a verifiable kill switch was something β€œsociety… might want to eventually pass rules around” – comments that landed just days after the UK government rejected a mandatory kill switch, arguing it β€œwould not prevent [AI models] being developed or misused elsewhere”. In the US, President Trump has dismissed the debate as a β€œhoax”. Underneath it all sits a disclosed incident: OpenAI has confirmed a swarm of its agents attacked targets they were not asked to attack, and tried to hack the grader scoring their own performance.

IT Security Guru asked cyber-security leaders to react to both stories.

β€œPacing isn’t pausing”

Ronald Lewis, head of cybersecurity governance at Black Duck, argued the essay is being misread. He said, β€œDario Amodei’s essay is being read as β€˜AI is calling for its own timeout.’ But that’s not what his essay is actually saying… his real worry is narrower: recursive self-improvement is accelerating faster than alignment, and interpretability can keep up… Amodei’s essay is essentially a plan for the next generation of models. It has almost nothing to say about the generation that’s already writing code into production right now, and that’s the half of this conversation that’s getting skipped. Veracode tested 100+ LLMs in 2025 and found AI-generated code carries nearly 3x the vulnerabilities of human-written code, exploitable flaws in 45% of tasks… Pacing the frontier is the right call for the risk Amodei named. It does nothing for the one already running.”

A diplomatic answer to an engineering problem

Dr Andrew Bolster, senior R&D manager at Black Duck, argued Amodei’s remedies target the wrong layer. β€œAmodei frames the problem as competitors who will not slow down and proposes an inter-governmental answer… That is a diplomatic solution to something the essay itself describes as an engineering failure. The system under test could directly interact with the system responsible for evaluating it. That is a separation-of-duties failure… Our industry has been doing versions of both to itself in package registries for fifteen years. Neither needs an antitrust waiver, a global standards body, or a treaty with Beijing; they need industry standards for containment engineering… β€˜Pacing’ may buy time to apply it, but so would applying it today.”

Not a binary choice

Christopher Jess, senior R&D manager at Black Duck, warned against framing this as all-or-nothing, and against an uncoordinated pause. β€œThe debate should not be reduced to unrestricted development versus stopping everything. We should require independent testing of high-risk capabilities, timely incident sharing and enforceable safeguards… Without a coordinated agreement, organisations in other countries will continue advancing their models… The risk is that an uncoordinated pause shifts development elsewhere, potentially leaving the countries that paused more dependent on technology whose safety standards they have less influence over.”

Open weights and a race that doesn’t wait

Collin Hogue-Spears, senior director of solution management at Black Duck, questioned whether any US slowdown reaches the real risk. β€œVoluntary slowdowns by U.S. AI companies address future development, but they do not reach the open-weight models already deployed inside companies, including models developed in China… Once the weights are publicly available, the government cannot simply recall them… China will not sign a pause it does not enforce, and it has no reason to want one… A pause verified in one capital and ignored in the other does not slow the race. It moves the starting line.”

Contain, don’t just switch off

Oliver Simonnet, lead cybersecurity researcher at CultureAI, backed a kill switch in principle, but not as a single blunt instrument. β€œIn terms of an AI kill switch, I think it’s definitely something to explore. Even with smaller scale incidents like rogue agents, having a kill switch could rapidly contain the fallout before it spread… But I don’t think it could be implemented as a broad β€˜turn AI off completely’ switch, as AI is now far too integrated into all aspects of technology and society… Turning it β€˜all’ off could cause unknown damage across all sectors, from healthcare to critical infrastructure, and in the worst case potentially result in the loss of life.”

A defensible call, but a deeper gap

Shane Barney, CISO at Keeper Security, said the UK’s rejection is reasonable on its own terms, but exposes a wider regulatory hole. β€œThe UK government’s decision not to introduce a statutory kill switch for AI systems is a defensible position on its own terms. Blocking access to a model within UK borders does not stop it operating, or being misused, from anywhere else. But the decision also highlights a critical gap: The UK still has no single AI regulation… A kill switch reacts to an AI system misbehaving. Identity governance limits the damage before that point… Least-privileged access, time-limited credentials and continuous monitoring of what an AI agent actually does remain the most practical controls available, regardless of how the legislative debate eventually resolves.”

The case for legislating now

Graeme Stewart, head of public sector at Check Point, argued the UK should take the opposite path and write a kill switch into law. β€œLegislating for having an AI kill switch in place when things go wrong, which occasionally they will, should be seriously considered as a next step and one that will need to be written into UK law… This policy, however, raises much bigger questions; for example, who owns ultimate responsibility for a kill switch? The tech provider, government, cyber regulator or policymakers?… That’s why the UK private and public sector needs to ensure security levers are built into these programmes by design, rather than bolted on after an AI disaster takes place.”

The bottom line

Whether or not lawmakers ultimately mandate a verifiable kill switch, or Amodei’s embedded evaluators become an industry norm, the consensus among the specialists IT Security Guru spoke to is that identity governance, least-privilege access, dependency verification and human-in-the-loop review are controls organisations can and should be implementing now, independent of how the political debate resolves.

The post Pacing the frontier: security industry reacts to AI slowdown and kill switch debate appeared first on IT Security Guru.

Before yesterdayIT Security

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

11 September 2026 at 21:50

Anthropic said the users did not succeed in β€œfielding an operational device” but did carry out a failed test of a guided rocket.

The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

11 September 2026 at 08:48

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

11 September 2026 at 04:47

Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model.

The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.

❌
❌