Jessica Entwistle
September 22 2026
Today's brief reflects the practical reality of defending modern organisations: emerging technologies like AI create both opportunity and complexity, while foundational security disciplines remain as important as ever. The NCSC has published new thinking on how defenders can realistically use AI, a critical WordPress vulnerability has been patched after allowing anonymous attackers to escalate to remote code execution, Google has been fined over €400m for location data handling, and CISA has flagged active exploitation of a Zyxel network switch vulnerability. These stories span governance, patching discipline, regulatory compliance and infrastructure security, all areas where clear ownership and consistent practice make the difference.
The National Cyber Security Centre has published a blog post titled "One does not simply defend agentically", addressing how defenders can realistically use AI in cyber security operations. The NCSC explains that while attackers may be able to deploy AI agents with fewer constraints, defenders face significant practical, ethical and operational limitations that shape how AI can be used in defensive contexts. The guidance acknowledges the potential of agentic AI, where systems can act with a degree of autonomy, but emphasises that defenders cannot simply mirror attacker tactics and must work within legal, governance and risk management frameworks that do not apply to adversaries.
For UK organisations exploring AI-assisted security operations, this is an important framing from the national technical authority. Many organisations are being pitched AI-driven security tools with promises of autonomous threat hunting, automated response and agentic behaviour. The NCSC's guidance helps set realistic expectations about what AI can and cannot do in a defensive context, particularly where decisions involve legal risk, business impact or the potential for unintended consequences. Understanding these constraints is essential for making informed decisions about where AI can add value and where human oversight, governance and accountability remain non-negotiable.
For UK businesses evaluating AI security tools, this is a prompt to review how vendor claims align with the practical and governance realities the NCSC describes. Consider where AI can support analysts and where human decision-making, clear escalation paths and accountability must remain in place.
Source: NCSC UK
WordPress released version 7.1.1 on 17 September 2026 to address a critical vulnerability tracked as CVE-2026-93485, known as Comment2Shell. The Hacker News reports that the flaw allowed an anonymous visitor to leave a comment containing a hidden script on a WordPress site. If a logged-in administrator later viewed that comment, the script could execute, potentially allowing the attacker to run code on the server. The vulnerability represents a particularly dangerous escalation path because it requires no authentication and relies on normal administrative behaviour, viewing comments, to trigger the exploit. WordPress has urged all site owners to update immediately.
This is a significant risk for any organisation running WordPress, which remains one of the most widely used content management systems globally, including across UK public sector, education, SME and corporate websites. The attack chain is straightforward: an unauthenticated attacker posts a malicious comment, an administrator reviews it as part of routine moderation, and the site is compromised. The flaw underscores how even mature platforms can harbour critical vulnerabilities in everyday features, and why timely patching and version management remain foundational security disciplines. For organisations running WordPress at scale, this is also a reminder to review who has administrative access, whether comment moderation is appropriately delegated, and how quickly security updates are applied across all instances.
For many organisations, this is a prompt to confirm that all WordPress instances have been updated to version 7.1.1 or later, and to review how quickly security patches are identified, tested and deployed across content management systems, particularly where multiple sites or instances are in use.
Source: The Hacker News
Ireland's Data Protection Commission has fined Google €403 million (approximately £345 million) for breaching GDPR rules in how it processed users' location data. The Guardian reports that the fine follows complaints from multiple European consumer organisations, which alleged that Google manipulated users into agreeing to constant location tracking on mobile devices. The DPC found that users may not have been adequately informed that their location data was being used to target advertisements or infer their interests, raising questions about the transparency and fairness of consent mechanisms. The decision is one of the largest GDPR fines issued to date and reflects continued regulatory scrutiny of how technology companies handle personal data, particularly where tracking and profiling are involved.
For UK organisations, this case is a reminder that GDPR enforcement remains active and that regulators are willing to impose substantial penalties where data processing practices fall short of transparency and consent requirements. While this fine relates to Google's consumer services, the principles apply broadly: organisations must ensure that users understand what data is being collected, how it will be used, and that consent mechanisms are clear, informed and not manipulative. Location data is particularly sensitive, and its use in advertising, analytics or service delivery must be handled with care. The decision also highlights the importance of privacy by design, ensuring that data collection is proportionate, well-documented and aligned with the purposes users have been told about.
For UK businesses, this is a prompt to review how location data, tracking technologies and consent mechanisms are implemented, particularly in mobile applications, marketing platforms or customer-facing services. Ensure that privacy notices are clear, consent is meaningful, and that data processing aligns with what users have been told.
Source: The Guardian
The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-7273, a stack-based buffer overflow vulnerability affecting Zyxel GS1900 series network switches, to its Known Exploited Vulnerabilities catalogue. CISA reports that the vulnerability is being actively exploited in the wild, and has set a deadline for US federal agencies to apply mitigations. The flaw allows an attacker to execute arbitrary code on affected devices, potentially giving them persistent access to network infrastructure. Zyxel GS1900 switches are commonly used in small to medium-sized business and enterprise environments, making this a relevant risk for organisations that rely on this hardware for network segmentation, access control or operational connectivity.
While CISA's directive applies to US federal agencies, the inclusion of a vulnerability in the KEV catalogue is a strong signal that exploitation is occurring and that organisations globally should prioritise remediation. For UK businesses using Zyxel network equipment, this is a prompt to check whether affected models are in use, whether patches or firmware updates are available, and whether network segmentation and monitoring are sufficient to detect or contain compromise if devices cannot be immediately updated. Network infrastructure is often overlooked in patching programmes, but compromised switches can provide attackers with visibility across internal traffic, the ability to intercept credentials, and a foothold for lateral movement.
For UK organisations using Zyxel GS1900 series switches, this is a prompt to confirm whether the vulnerability affects devices in use, apply available patches or mitigations, and review how network infrastructure is included in vulnerability management and monitoring programmes.
Source: CISA
Today's stories reflect the breadth of security practice that mature organisations need to maintain: understanding emerging technologies like AI, keeping foundational systems patched, ensuring privacy compliance is embedded in how services are designed, and managing infrastructure security across the estate. None of these areas can be treated in isolation, and none of them can be solved by a single tool or team. Good security comes from clear ownership, consistent discipline, and the ability to connect technical decisions to business risk and regulatory expectations. The organisations that manage these areas well are the ones that have already built the habits, governance structures and cross-functional relationships that allow them to respond calmly and effectively when new risks emerge.