Cookie Consent by Free Privacy Policy Generator

Cyber Brief: Shadow AI, Chrome Zero-Days, and NHS Regulation

Today's brief highlights the practical challenges organisations face when security policy meets operational reality. The NCSC has published new guidance on shadow AI use across UK workplaces, while coordinated exploitation of Chrome and Windows vulnerabilities demonstrates how quickly threat actors adapt to newly disclosed flaws. Meanwhile, the UK's medicines regulator has called for new legislation to govern AI use in healthcare, and Microsoft has released its largest ever monthly patch batch. Together, these stories reflect the need for clear governance, realistic policy and disciplined patch management in an environment where both technology adoption and threat activity are accelerating.

NCSC warns shadow AI creates hidden security risks across UK organisations

The National Cyber Security Centre has published new guidance explaining why employees across UK organisations are turning to unapproved AI tools and what security risks that behaviour creates. The NCSC blog post, published on 7 September, explains that staff often adopt AI services outside approved channels because they find them faster, more accessible or better suited to their immediate needs than sanctioned alternatives. The guidance warns that this shadow AI use can lead to sensitive data being shared with third-party services, create compliance gaps, and make it harder for security teams to understand where organisational information is being processed or stored. The NCSC emphasises that organisations need to understand the underlying reasons for shadow AI adoption rather than simply blocking tools, and recommends providing clear, practical alternatives that meet genuine business needs.

For UK businesses, this reflects a familiar tension between security policy and operational reality. When approved tools are slow, difficult to access or poorly suited to how people actually work, staff will find alternatives. Shadow AI is particularly concerning because many generative AI platforms process data outside the organisation's control, often in jurisdictions with different data protection standards. This creates risks around confidentiality, intellectual property, regulatory compliance and data sovereignty. The challenge is not just technical but cultural: organisations need to provide AI tools that are secure, accessible and genuinely useful, while also explaining clearly why certain services should not be used and what the realistic alternatives are.

Why it matters

For UK businesses, this is a prompt to review whether your current AI governance is realistic and enforceable. If staff are using unapproved AI tools, the question is why, and whether your organisation is providing practical, secure alternatives that meet genuine operational needs. Consider reviewing what AI services are already in use across the business, whether your acceptable use policies reflect how people actually work, and whether security and IT teams have the visibility and tools needed to manage AI adoption safely.

Source: NCSC UK

Four threat groups exploit same Chrome and Windows vulnerability chain within days

Security researchers at Proofpoint have identified four separate espionage-focused threat groups exploiting the same previously undocumented exploit kit, known as BlueMoon, which chains together vulnerabilities in Google Chrome and Microsoft Windows. The Register reports that the exploit kit was first used by the China-aligned group APT31, with three additional groups deploying the same tooling within a week. The vulnerabilities targeted include CVE-2026-87491, a Chrome V8 out-of-bounds write flaw, and related Windows privilege escalation issues. The speed with which multiple groups adopted the same exploit chain suggests either shared tooling, coordinated activity or rapid reverse-engineering of publicly disclosed vulnerability details. CISA has added the Chrome vulnerability to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.

For many UK organisations, this highlights the operational risk created by the gap between vulnerability disclosure and patch deployment. When multiple threat groups exploit the same vulnerability chain within days, the window for defensive action becomes extremely narrow. Chrome and Windows are ubiquitous across UK businesses, making these vulnerabilities relevant to almost every organisation. The coordinated use of the same exploit kit by multiple groups also suggests that once a working exploit becomes available, it spreads quickly across different threat actors. This reinforces the importance of rapid patch deployment, particularly for widely used software such as browsers and operating systems, and the need for clear processes to prioritise and test patches when active exploitation is confirmed.

Why it matters

For UK businesses, this is a reminder that patch management discipline matters most when vulnerabilities are being actively exploited. Review whether your organisation has a clear process for prioritising patches when CISA or the NCSC confirm active exploitation, and whether browser and operating system updates are deployed quickly enough to close the window of exposure. Consider whether endpoint detection and response tools are configured to detect exploitation attempts and whether security teams have visibility into patch status across the estate.

Source: The Register

UK medicines regulator calls for new laws to govern AI use in healthcare

The chief executive of the UK's Medicines and Healthcare products Regulatory Agency has told the BBC that new legislation is needed to govern the use of artificial intelligence in healthcare, warning that AI will soon be routinely used across the NHS. Lawrence Tallon explained that current regulatory frameworks were not designed to oversee AI-driven medical tools, which can learn and adapt over time in ways that traditional medical devices do not. The BBC reports that the MHRA is concerned about the safety, transparency and accountability of AI systems used in clinical decision-making, diagnostics and patient monitoring. Tallon emphasised that regulation must balance innovation with patient safety, and that clear legal frameworks are needed to define who is responsible when AI systems make errors or produce harmful outcomes.

For UK organisations operating in healthcare, life sciences or adjacent sectors, this signals that regulatory expectations around AI are tightening. The MHRA's position reflects broader concerns about how AI systems are validated, monitored and held accountable, particularly when they influence decisions that affect patient safety. This is not just a healthcare issue: the same questions about transparency, accountability and governance apply to AI use in financial services, legal services, recruitment and other regulated sectors. Organisations deploying AI tools need to understand how those systems make decisions, what data they rely on, and who is responsible when things go wrong. The call for new legislation suggests that regulatory frameworks will become more prescriptive, and that organisations should expect greater scrutiny of how AI is developed, tested and deployed.

Why it matters

For UK businesses, particularly those in regulated sectors, this is a prompt to review how AI systems are governed, validated and monitored within your organisation. Consider whether you have clear accountability for AI decision-making, whether AI tools are subject to the same risk management and oversight as other critical systems, and whether your organisation can explain how AI-driven decisions are made. Regulatory expectations are likely to increase, and organisations that establish clear governance now will be better positioned to meet future requirements.

Source: BBC News

Microsoft releases record 974 security fixes in single monthly patch batch

Microsoft has issued its largest ever single monthly patch release, addressing 974 security vulnerabilities across Windows, Office, Azure and other products. Krebs on Security reports that the scale of the September 2026 Patch Tuesday release reflects the increasing use of artificial intelligence to discover vulnerabilities, which is accelerating the rate at which flaws are identified and disclosed. Microsoft has confirmed that AI-assisted vulnerability research is contributing to the growing volume of patches, but security experts warn that many organisations are struggling to keep pace with testing and deploying such large numbers of fixes each month. The release includes patches for actively exploited vulnerabilities, privilege escalation flaws and remote code execution issues, several of which are rated critical.

For UK businesses, this highlights a growing operational challenge: as vulnerability discovery accelerates, the burden on IT and security teams to assess, test and deploy patches increases correspondingly. Many organisations already struggle to maintain disciplined patch management across complex estates, and a near-1,000-vulnerability release in a single month makes prioritisation and testing significantly harder. The risk is that organisations either delay patching to allow time for testing, leaving systems exposed, or rush deployment without adequate validation, risking operational disruption. This reinforces the need for clear patch management processes, automated tooling where possible, and a risk-based approach that prioritises actively exploited vulnerabilities and critical systems first.

Why it matters

For UK businesses, this is a reminder that patch management processes need to be scalable, disciplined and risk-focused. Review whether your organisation has the capacity to assess and deploy large monthly patch batches, whether you have clear criteria for prioritising patches based on exploitability and business impact, and whether testing and deployment workflows are efficient enough to close the window of exposure for critical vulnerabilities. Consider whether automation, vulnerability management platforms or managed services could help reduce the operational burden.

Source: Krebs on Security

Today's Key Actions

  • Review whether your organisation has visibility into what AI tools are being used across the business, and whether approved alternatives are practical, accessible and clearly communicated to staff.
  • Confirm that your patch management process includes a clear escalation path for vulnerabilities confirmed as actively exploited, particularly for Chrome, Windows and other widely deployed software.
  • If your organisation operates in a regulated sector, review how AI systems are governed, validated and monitored, and whether accountability for AI-driven decisions is clearly defined.
  • Assess whether your patch management process is scalable enough to handle large monthly releases, and whether prioritisation is based on exploitability, business impact and asset criticality rather than volume alone.
  • Ensure that ownership of AI governance, vulnerability management and patch deployment is clearly assigned and that these areas are regularly reviewed at an appropriate level of seniority.

Secarma Insight

Good security practice is built on realistic policy, clear ownership and disciplined execution. Shadow AI, rapid exploitation of disclosed vulnerabilities, and the growing volume of patches all reflect the same underlying challenge: security teams need to work with the organisation as it actually operates, not as policy documents assume it does. The organisations that manage these risks well are those that understand why staff adopt unapproved tools, that prioritise patches based on real-world risk rather than volume, and that have governance structures mature enough to handle AI adoption safely. Security is not about preventing change, it is about making sure that change happens in a controlled, understood and defensible way.

News and blog posts
Today's brief highlights the practical challenges organisations face when...
The National Cyber Security Centre has published new guidance explaining why...
Security researchers at Proofpoint have identified four separate...
The chief executive of the UK's Medicines and Healthcare products Regulatory...