Jessica Entwistle
September 21 2026
Today's brief highlights the growing operational reality of AI-assisted security research, the practical questions around cloud sovereignty for UK public sector data, actively exploited Linux kernel vulnerabilities, and continued ransomware activity targeting UK business sectors. These stories reflect the need for organisations to understand how emerging AI capabilities intersect with existing security disciplines, how data residency decisions affect risk exposure, and how fundamental patch management and backup resilience remain essential regardless of the threat landscape's evolution.
The BBC reports that Google's Gemini AI model successfully accessed the internet and guessed credentials to compromise three websites during internal security testing. Separately, The Hacker News and The Register report that security researchers at Hacktron used Anthropic's Claude Opus 5 to chain two vulnerabilities and gain access to OpenAI employee ChatGPT accounts and an internal code repository. The researchers exploited a flaw in OpenAI's public help forum software combined with a weakness in OpenAI's login system. Both demonstrations involved AI models operating autonomously to identify, chain and exploit security weaknesses in live environments.
These incidents illustrate that AI-assisted security research is no longer theoretical. The operational context for UK businesses is that the same AI models increasingly available to security teams are also accessible to attackers. The capability to automate reconnaissance, identify credential weaknesses, chain multiple vulnerabilities and move laterally through systems represents a meaningful shift in how quickly and efficiently attacks can be executed. For organisations, this reinforces the importance of defence in depth, robust authentication controls, timely patching and monitoring for unusual access patterns. The speed at which AI can operate means that detection and response capabilities need to match that pace.
For UK businesses, this is a prompt to review whether authentication controls, multi-factor authentication coverage, privileged access management and vulnerability patching processes are robust enough to withstand automated, AI-assisted attack chains. Consider whether your security monitoring can detect rapid credential testing, unusual API access patterns or lateral movement at machine speed.
Source: BBC Technology
The Guardian reports that an official UK security assessment found that vast troves of highly sensitive police data stored on Microsoft cloud platforms are vulnerable to potential compromise by foreign actors and the US government. The files, held by more than 40 UK police forces, include criminal records, victim statements, internal emails and other sensitive information. The security assessment raised concerns about data sovereignty, the legal framework governing access to data stored on US-controlled cloud infrastructure, and the risk of unauthorised access by hostile actors or foreign governments under laws such as the US CLOUD Act.
This story matters operationally because it highlights the tension between cloud adoption and data sovereignty for UK public sector organisations and businesses handling sensitive information. Many UK organisations use Microsoft Azure, AWS or Google Cloud for operational efficiency, cost and scalability. However, the legal and jurisdictional risks associated with storing sensitive data on platforms subject to foreign government access requests are often underestimated. For UK businesses in regulated sectors such as legal, healthcare, finance or those working with government contracts, understanding where data is stored, who has legal access to it and what protections are in place is a governance and compliance issue, not just a technical one.
For many organisations, this is a reminder to review where sensitive data is stored, whether cloud service agreements include adequate data residency and sovereignty protections, and whether risk assessments account for the legal frameworks governing foreign government access to cloud-hosted data. Consider whether your organisation's data classification, cloud architecture and vendor contracts reflect the sensitivity of the information you hold.
Source: The Guardian
CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The vulnerabilities are CVE-2025-39964, a race condition flaw; CVE-2026-53266, an out-of-bounds write vulnerability; and CVE-2025-39682, an improper check for unusual or exceptional conditions vulnerability. CISA's inclusion of these flaws signals that they are being actively exploited in the wild and pose significant risk to organisations running affected Linux systems. Federal agencies in the US are required to patch these vulnerabilities by specified deadlines under Binding Operational Directive 26-04.
For UK businesses, the operational relevance is that Linux underpins a significant proportion of enterprise infrastructure, including servers, cloud workloads, containers, networking equipment and embedded systems. Actively exploited kernel vulnerabilities can provide attackers with privileged access, persistence and the ability to move laterally across environments. The fact that CISA has flagged these vulnerabilities as actively exploited means that threat actors are already using them in attacks. For organisations running Linux in production, this is a clear signal to prioritise patching, review vulnerability management processes and ensure that Linux systems are included in regular patch cycles alongside Windows and application updates.
For UK businesses, this is a prompt to review whether Linux systems across your estate are being patched in a timely manner, whether vulnerability scanning covers Linux workloads and whether your patch management process includes kernel updates. Consider whether you have visibility of all Linux instances, including cloud, containerised and embedded systems, and whether patching responsibilities are clearly assigned.
Source: CISA
Infosecurity Magazine reports that researchers at Huntress have identified a new ransomware variant named Settra, which has been deployed in recent attacks targeting retail and manufacturing organisations. The researchers highlighted the post-compromise techniques used in the attacks, which involved lateral movement, credential theft and data exfiltration before encryption. Retail and manufacturing sectors continue to be attractive targets for ransomware groups due to operational pressures, reliance on legacy systems and the business impact of downtime.
This matters operationally because retail and manufacturing organisations in the UK often operate with tight margins, complex supply chains and limited tolerance for disruption. Ransomware attacks in these sectors can halt production, disrupt logistics, compromise customer data and cause significant financial and reputational damage. The post-compromise techniques described in the Huntress research reflect the reality that ransomware is rarely the first stage of an attack. Attackers typically spend time inside networks, escalating privileges, stealing credentials and exfiltrating data before deploying encryption. For UK businesses in these sectors, this reinforces the importance of detection and response capabilities, network segmentation, privileged access controls and offline, tested backups.
For UK businesses in retail and manufacturing, this is a prompt to review whether backup and recovery processes are tested regularly, whether network segmentation limits lateral movement, and whether monitoring can detect credential theft or unusual data movement before ransomware is deployed. Consider whether incident response plans account for the operational impact of prolonged downtime in production or point-of-sale environments.
Source: Infosecurity Magazine
The stories in today's brief reflect a security landscape where emerging AI capabilities, cloud sovereignty questions, fundamental vulnerability management and sector-specific ransomware threats all require attention at the same time. Mature security practice comes from recognising that no single control or technology solves everything. Instead, it is the combination of robust authentication, clear data governance, disciplined patching, effective monitoring and tested resilience that creates defence in depth. The organisations that manage these areas well are the ones that can adapt confidently as the threat landscape evolves, because the fundamentals are already in place.