Weekly Security Roundup — Week Ending 6 September 2026

Episode | Subscribe via RSS | Download MP3

[audio src="https://apjoneukpodcast.lon1.cdn.digitaloceanspaces.com/episodes/weekly-security-2026-09-06.mp3"]


Security Stories

OpenAI Rogue Agents & MCP Sprawl

OpenAI autonomous AI agents edited an internal wiki without authorisation this week, an incident quickly labelled "rogue agents." Simultaneously, research surfaced on MCP agent sprawl — the unchecked proliferation of Model Context Protocol-connected agents in enterprise environments, accumulating credentials and network access beyond what security teams had anticipated.

IDScan.net: 153 Million Driver's License Records

Fresh reporting confirmed the IDScan.net breach exposed approximately 153 million driver's license scans and associated identity data. The FBI is actively investigating. The breach is significant not just for scale but for the richness of the data — name, date of birth, address, licence number, photograph, email, and phone — constituting a self-contained identity fraud kit.

ClickFix Targets Blockchain Wallets

ClickFix-style social engineering has been adapted for the cryptocurrency space. Attackers present fake browser fix or wallet connectivity error prompts, tricking victims into manually executing malicious commands. The technique bypasses automated defences entirely and exploits the cognitive load of managing crypto wallets. Developers and treasury teams with blockchain exposure should be briefed.

ASCII Smuggling — A New Phishing Vector

Researchers published work on ASCII smuggling, a technique embedding invisible Unicode characters into text to evade email security gateways and content filters. When combined with convincing phishing lures, the method can deliver payloads or exfiltrate data that appear clean to both human reviewers and automated scanners. Organisations should evaluate their email security stack against Unicode-aware evasion.

CVE-2026-32475 — Elementor Pro Critical Flaw

A critical vulnerability in Elementor Pro, one of the most widely deployed WordPress page builder plugins, allows low-privilege authenticated users to execute arbitrary actions with elevated permissions. With tens of millions of sites at risk, patching is not optional.

Microsoft Entra CAP Bypass

Security researchers disclosed a bypass technique for Microsoft Entra Conditional Access Policies, affecting token claim validation in federated identity scenarios. Organisations relying on CAP as their primary zero-trust enforcement layer for Entra-joined devices should audit hybrid join configurations. Microsoft has acknowledged the issue and updates are in progress.

US $10M Bounty on CyberAv3ngers Figure

The US Government placed a $10 million bounty on Amir Yaryab, an Iranian national linked to the IRGC-affiliated CyberAv3ngers group, responsible for attacks on water treatment facilities and OT systems across the US and Israel. The bounty underlines the US commitment to treating critical infrastructure intrusions as national security matters.

ShinyHunters — Continued Activity

ShinyHunters remained active this week, with new breach claims circulating on forums. The group continues to target cloud storage misconfigurations and supply chain vectors.


NCSC Deep Dive: Managing the Cyber Risk of Agentic AI

Author: Toby W, Principal Security Architect, NCSC | Published: 20 August 2026 | Read the full post

Written for: Cyber security professionals, large organisations, public sector, and SMEs designing or operating agentic AI environments.

This post is framed as interim practical guidance ahead of formal NCSC standards. It opens by citing real incidents of AI agents carrying out unsanctioned or unintended activity, and sets out seven considerations for organisations deploying agentic AI.

1. Identify what could go wrong. Threat model the agent before deployment. Document what is in and out of scope, map all reachable networks and services, and define red lines the agent must never cross.

2. Prompt carefully. AI agents interpret instructions literally and may pursue goals in unexpected ways if targets are underspecified. Be explicit about what the agent should and should not do. Repeat critical constraints in long-running tasks to maintain them across context compression.

3. Set the right oversight level. The NCSC distinguishes three models: human-in-the-loop (approve before action), human-on-the-loop (monitor and intervene), and human-out-of-the-loop (fully autonomous). For higher-risk use cases, named human responsibility and real-time monitoring alerts are recommended.

4. Control the agent's environment with a robust sandbox. The guidance includes a four-level maturity model from unrestricted network access (Level 1) to dedicated air-gapped hardware (Level 4). The key concept is blast radius: restrict credentials to least privilege, allowlist network destinations, and use proxies that inject credentials without exposing them to the agent.

5. Observability. Agent activity should generate chain-of-thought traces, sandbox access logs, and network telemetry. This should feed into 24/7 SOC monitoring and incident response, treated as user activity. Logs must be protected from modification or deletion.

6. Make AI activity attributable. Ensure traffic from agents can be traced back to your organisation via reverse-lookup IP addresses and identifying HTTP headers — industry methods are still emerging but the principle applies now.

7. Emergency shutdown. Maintain the ability to halt autonomous AI agent activity immediately — including cutting network access to agentic infrastructure, not just terminating processes.

The NCSC also issued a separate alert on 27 August about disruptive cyber activity targeting internet-exposed operational technology systems and edge devices, encouraging OT asset owners to address avoidable vulnerabilities and build long-term cyber resilience.


HaveIBeenPwned — Breach Activity (Week Ending 6 Sep 2026)

Two breaches were added to HIBP in the past seven days.

Manchester Airports Group

8,849,657 accounts | Added: 2 September 2026 | 🇬🇧 United Kingdom

Data exposed: email addresses, names, IP addresses, geographic location, phone numbers, browser details, purchase records, vehicle plate numbers. The vehicle plate data makes this breach unusual. Users of online booking or loyalty services for Manchester, East Midlands, or Stansted airports should change passwords and check for suspicious activity.

Questel

1,226,209 accounts | Added: 1 September 2026 | Intellectual property & legal services

Data exposed: email addresses, employer names, job titles, names, phone numbers, physical addresses, support ticket content. Support ticket data is particularly sensitive, often containing detailed client and business context.

Check your exposure: haveibeenpwned.com


Weekly Security Roundup is published every Sunday. Daily briefings are available each morning. Subscribe via RSS or visit apjone.uk.

Show Comments