Jessica Entwistle
September 8 2026
Today's brief reflects a recurring theme across several areas of security practice: the gap between what organisations have formally approved and what is actually happening across their estate. The NCSC has published new guidance on shadow AI use, Microsoft 365 environments are being targeted through help desk impersonation, N-able customers are managing back-to-back critical vulnerabilities, and Instagram users are falling victim to fake copyright claims that bypass platform protections. Each story highlights where visibility, user behaviour and operational discipline intersect with real security risk.
The National Cyber Security Centre has published new guidance explaining the security challenges created when staff use unapproved AI tools in the workplace. The NCSC blog post, published on 7 September, explains that employees often turn to consumer AI services because they are faster, easier to use or more capable than the tools their organisation has formally approved. The guidance highlights that this creates data leakage risk, introduces unvetted third-party processing, and makes it difficult for security teams to understand where sensitive information is being shared or stored.
For UK organisations, this reflects a familiar challenge that has existed with consumer file sharing, messaging apps and collaboration tools for years, now extended into generative AI. The operational difficulty is that blocking access rarely works in practice if the underlying business need remains unmet. Staff will find workarounds, use personal devices or simply work less efficiently. The NCSC's guidance emphasises understanding why people are using unapproved tools in the first place, then addressing those gaps through clearer policy, better-supported alternatives and proportionate controls that balance productivity with data protection.
This is a prompt to review whether your organisation has a clear and realistic position on AI tool use, and whether that position is actually being followed in practice. For many UK businesses, the first step is simply understanding what is already being used across the organisation, then working out whether the tools you have approved are genuinely meeting the needs that are driving people towards consumer alternatives.
Source: NCSC UK
Threat intelligence researchers have published details of a widespread campaign targeting Microsoft 365 users through fake IT help desk calls, credential theft and session hijacking. The Hacker News reports that attackers are specifically targeting directors, vice presidents and other senior staff, using vishing calls that impersonate internal IT support to convince victims to approve multi-factor authentication prompts or provide access codes. Once initial access is gained, attackers use adversary-in-the-middle techniques to steal session tokens, then connect through residential proxy networks to make their access appear legitimate. The goal is data theft and extortion, with attackers exfiltrating email, files and other sensitive information before demanding payment.
This reflects a broader shift in how Microsoft 365 environments are being compromised. Traditional phishing emails are increasingly being supplemented or replaced by direct voice calls that feel more urgent and convincing, particularly when the caller has already gathered enough information about the target to sound credible. The use of residential proxies makes it harder for conditional access policies to detect suspicious sign-ins, because the attacker's connection appears to come from a normal home or business internet connection rather than a data centre or VPN. For UK organisations, this highlights the importance of making sure that help desk verification processes work in both directions, that users know how to verify who is calling them, and that session token protections and monitoring are in place.
For UK businesses, this is a reminder to review how your organisation verifies identity during support calls, particularly when those calls involve password resets, MFA approvals or access changes. Consider whether your conditional access policies account for session token theft, and whether monitoring is in place to detect unusual data access or exfiltration patterns even when sign-ins appear geographically normal.
Source: The Hacker News
Managed service provider software vendor N-able has released an emergency hotfix for a critical remote code execution vulnerability affecting its N-central remote monitoring and management platform. Infosecurity Magazine reports that the flaw, tracked as CVE-2026-86218, has been assigned a maximum severity rating by N-able itself, and allows an unauthenticated attacker to execute code remotely on an N-central server. The disclosure comes just one day after N-able issued patches for two other vulnerabilities in the same platform, meaning administrators are now managing back-to-back patching cycles for critical flaws in a tool that typically has privileged access across customer environments.
Remote monitoring and management platforms are high-value targets because they are designed to have deep access across multiple customer networks, often with administrative privileges on endpoints, servers and network devices. A compromise of the RMM platform itself can provide an attacker with a direct path into every environment that platform manages. For UK managed service providers and internal IT teams using N-able, this means the patch needs to be prioritised and applied quickly, and it is worth reviewing whether any unusual activity occurred on the platform before the patch was applied. The fact that three critical vulnerabilities have been disclosed in quick succession also raises questions about the security assurance processes around the platform more broadly.
For organisations using N-able N-central, this is a prompt to apply the emergency hotfix immediately and review access logs for any signs of unusual activity before the patch was applied. For those using managed service providers, it is worth confirming that your provider has applied the patch and whether any additional monitoring or review is being carried out as a precaution.
Source: Infosecurity Magazine
The BBC reports that Instagram users are being targeted by scammers who send fake copyright infringement notices, then demand payment to avoid account suspension. The scam works by impersonating Instagram's official copyright reporting process, sending messages that appear to come from Meta and warning that the user's account will be suspended unless they respond quickly. Victims are then directed to fake support channels where they are asked to pay a fee or provide payment details. The BBC reports that users are losing money and in some cases having their accounts suspended anyway, while Meta's systems struggle to identify and remove the scammers quickly enough to prevent harm.
This is a social engineering attack that exploits the fear of losing access to an account that may have significant personal or business value. For UK businesses that use Instagram for marketing, customer engagement or brand presence, the risk is that staff managing those accounts may fall for these scams, leading to financial loss, account compromise or reputational damage. The broader issue is that platform-based scams like this are difficult to defend against through traditional technical controls, because they rely on convincing users to take action outside the normal security boundaries of the organisation. The defence relies on awareness, clear processes for verifying unexpected account warnings, and making sure that staff know how to escalate suspicious messages rather than responding directly.
For UK businesses with Instagram accounts managed by marketing or communications teams, this is a reminder to make sure those teams know how to verify unexpected copyright or account suspension warnings, and that they have a clear route to escalate suspicious messages rather than responding under pressure. Consider whether your organisation has a process for managing social media account security incidents, including who to contact if an account is compromised.
Source: BBC News
The common thread across today's stories is that security risk increasingly sits at the boundary between what organisations have formally defined and what is actually happening in practice. Shadow AI use, help desk impersonation, critical vendor vulnerabilities and platform-based scams all exploit gaps in visibility, user behaviour or operational discipline. Mature security practice recognises that these gaps are normal and inevitable, and builds processes that assume they exist rather than relying on perfect compliance. That means understanding what is really being used, making verification processes practical and two-way, maintaining clear escalation routes, and ensuring that monitoring and review happen continuously rather than only after an incident. The organisations that manage these risks well are the ones that have already built those habits into how they operate every day.