On 4 August the UK NCSC answered a run of frontier AI-agent incidents, urging stronger safeguards and real-time oversight as NIST works on agent identity and authorization.Nobody is asking whether the agent has an identity. They're asking who issued it.
Fastly's research finds AI-first organizations took almost seven months to recover from an incident, around 80 days longer, with breach costs 135% higher.The interesting number is not the 135%. It is the 30%.
CISA has confirmed that CVE-2026-45659, a critical flaw in on-premises Microsoft SharePoint Server, is being exploited in ransomware attacks.Patching is vulnerability management. Finding out whether it already happened is a different meeting.
OpenAI has expanded its Daybreak cybersecurity initiative with GPT-5.6-Cyber, a model for authorized vulnerability research and security testing.Time-to-detect was never your problem. Time-to-decide-who-owns-it is.
71% of CISOs spend 10+ hours preparing each board report. Only 12.5% are very confident the board understands the true state of security.The other 87.5% presumably have another slide.
Unauthenticated command injection in Progress (Kemp) LoadMaster, now on CISA's KEV catalog amid active exploitation. ~300 instances remain exposed.Three days is the deadline. Exploitation, apparently, didn't need one.
The EU Cyber Resilience Act reporting duty starts 11 September 2026: 24-hour and 72-hour vulnerability notifications for products with digital elements.The vulnerability doesn't need to wait for the regulation.