Infosec stories
Most firms are deploying AI agents without proper oversight, leaving non-human identities exposed as security teams race to catch up.
The findings add pressure on ministers to modernise the 1990 Computer Misuse Act as breaches hit 43% of UK businesses and 28% of charities.
Phishing, supplier risks and weak staff training are still leaving UK firms exposed, experts warn after the latest government survey.
QR code phishing climbed sharply in the quarter, exposing email users to more mobile-led credential theft despite disruption of major infrastructure.
Businesses can now run supplier, tax and sanctions checks through AI tools, as apexanalytix opens access to more than 280 million records.
Security chiefs say AI agents and credential theft are making password-only defences too risky as World Password Day returns.
Broader attacker activity is increasingly moving beyond stolen credentials, even as identity still accounted for 58.7% of incidents in Q1 2026.
Only about 10% of APAC organisations say their identity systems can fully secure AI agents, bots and service accounts.
A flaw in a widely watched Microsoft repository could have let attackers run code and steal secrets through GitHub Actions, Tenable said.
Its general release gives IT teams a single place to monitor and secure AI agents as shadow deployments spread across workplace software and cloud tools.
Threats are spreading beyond inboxes as phishing shifts into Teams, calendars and other collaboration tools, raising the risk for hybrid workers.
Attackers are exploiting help functions to reset credentials and bypass defences, putting entire networks at risk through a single call.
Businesses are racing to upgrade defences as Yubico says quantum computers could expose banking, health data and other records within years.
Security teams can now trace AI-led attacks before phishing begins, as Outtake targets lookalike domains, bot networks and fake accounts.
Ransomware activity stayed elevated in March, with NCC Group saying Qilin alone was linked to 136 attacks and drove a 43% monthly rise.
Security teams can now validate scanner findings in minutes as Intruder rolls out AI agents to cut false positives and speed remediation.
A misconfigured database left 86,859 images and private chats from a prominent European celebrity’s device open to anyone online.
It aims to curb staff data leaks into public AI tools by giving Australian employers visibility and controls over what workers share.
Local firms in regulated sectors can now keep identity security data onshore as scrutiny over machine and AI access intensifies.
Public sector buyers in New Zealand gain a marketplace option for tighter email controls as phishing and impersonation keep driving cyber risk.