Cookie Consent by Free Privacy Policy Generator

Cyber Brief: NCSC on AI Defence, WordPress Flaw, Google Fine

Today's brief reflects the practical reality of defending modern organisations: emerging technologies like AI create both opportunity and complexity, while foundational security disciplines remain as important as ever. The NCSC has published new thinking on how defenders can realistically use AI, a critical WordPress vulnerability has been patched after allowing anonymous attackers to escalate to remote code execution, Google has been fined over €400m for location data handling, and CISA has flagged active exploitation of a Zyxel network switch vulnerability. These stories span governance, patching discipline, regulatory compliance and infrastructure security, all areas where clear ownership and consistent practice make the difference.

NCSC publishes guidance on the practical realities of agentic AI in cyber defence

The National Cyber Security Centre has published a blog post titled "One does not simply defend agentically", addressing how defenders can realistically use AI in cyber security operations. The NCSC explains that while attackers may be able to deploy AI agents with fewer constraints, defenders face significant practical, ethical and operational limitations that shape how AI can be used in defensive contexts. The guidance acknowledges the potential of agentic AI, where systems can act with a degree of autonomy, but emphasises that defenders cannot simply mirror attacker tactics and must work within legal, governance and risk management frameworks that do not apply to adversaries.

For UK organisations exploring AI-assisted security operations, this is an important framing from the national technical authority. Many organisations are being pitched AI-driven security tools with promises of autonomous threat hunting, automated response and agentic behaviour. The NCSC's guidance helps set realistic expectations about what AI can and cannot do in a defensive context, particularly where decisions involve legal risk, business impact or the potential for unintended consequences. Understanding these constraints is essential for making informed decisions about where AI can add value and where human oversight, governance and accountability remain non-negotiable.

Why it matters

For UK businesses evaluating AI security tools, this is a prompt to review how vendor claims align with the practical and governance realities the NCSC describes. Consider where AI can support analysts and where human decision-making, clear escalation paths and accountability must remain in place.

Source: NCSC UK

WordPress patches critical Comment2Shell vulnerability allowing anonymous RCE

WordPress released version 7.1.1 on 17 September 2026 to address a critical vulnerability tracked as CVE-2026-93485, known as Comment2Shell. The Hacker News reports that the flaw allowed an anonymous visitor to leave a comment containing a hidden script on a WordPress site. If a logged-in administrator later viewed that comment, the script could execute, potentially allowing the attacker to run code on the server. The vulnerability represents a particularly dangerous escalation path because it requires no authentication and relies on normal administrative behaviour, viewing comments, to trigger the exploit. WordPress has urged all site owners to update immediately.

This is a significant risk for any organisation running WordPress, which remains one of the most widely used content management systems globally, including across UK public sector, education, SME and corporate websites. The attack chain is straightforward: an unauthenticated attacker posts a malicious comment, an administrator reviews it as part of routine moderation, and the site is compromised. The flaw underscores how even mature platforms can harbour critical vulnerabilities in everyday features, and why timely patching and version management remain foundational security disciplines. For organisations running WordPress at scale, this is also a reminder to review who has administrative access, whether comment moderation is appropriately delegated, and how quickly security updates are applied across all instances.

Why it matters

For many organisations, this is a prompt to confirm that all WordPress instances have been updated to version 7.1.1 or later, and to review how quickly security patches are identified, tested and deployed across content management systems, particularly where multiple sites or instances are in use.

Source: The Hacker News

Google fined €403 million by Irish regulator for location data handling under GDPR

Ireland's Data Protection Commission has fined Google €403 million (approximately £345 million) for breaching GDPR rules in how it processed users' location data. The Guardian reports that the fine follows complaints from multiple European consumer organisations, which alleged that Google manipulated users into agreeing to constant location tracking on mobile devices. The DPC found that users may not have been adequately informed that their location data was being used to target advertisements or infer their interests, raising questions about the transparency and fairness of consent mechanisms. The decision is one of the largest GDPR fines issued to date and reflects continued regulatory scrutiny of how technology companies handle personal data, particularly where tracking and profiling are involved.

For UK organisations, this case is a reminder that GDPR enforcement remains active and that regulators are willing to impose substantial penalties where data processing practices fall short of transparency and consent requirements. While this fine relates to Google's consumer services, the principles apply broadly: organisations must ensure that users understand what data is being collected, how it will be used, and that consent mechanisms are clear, informed and not manipulative. Location data is particularly sensitive, and its use in advertising, analytics or service delivery must be handled with care. The decision also highlights the importance of privacy by design, ensuring that data collection is proportionate, well-documented and aligned with the purposes users have been told about.

Why it matters

For UK businesses, this is a prompt to review how location data, tracking technologies and consent mechanisms are implemented, particularly in mobile applications, marketing platforms or customer-facing services. Ensure that privacy notices are clear, consent is meaningful, and that data processing aligns with what users have been told.

Source: The Guardian

CISA adds Zyxel network switch vulnerability to Known Exploited Vulnerabilities catalogue

The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-7273, a stack-based buffer overflow vulnerability affecting Zyxel GS1900 series network switches, to its Known Exploited Vulnerabilities catalogue. CISA reports that the vulnerability is being actively exploited in the wild, and has set a deadline for US federal agencies to apply mitigations. The flaw allows an attacker to execute arbitrary code on affected devices, potentially giving them persistent access to network infrastructure. Zyxel GS1900 switches are commonly used in small to medium-sized business and enterprise environments, making this a relevant risk for organisations that rely on this hardware for network segmentation, access control or operational connectivity.

While CISA's directive applies to US federal agencies, the inclusion of a vulnerability in the KEV catalogue is a strong signal that exploitation is occurring and that organisations globally should prioritise remediation. For UK businesses using Zyxel network equipment, this is a prompt to check whether affected models are in use, whether patches or firmware updates are available, and whether network segmentation and monitoring are sufficient to detect or contain compromise if devices cannot be immediately updated. Network infrastructure is often overlooked in patching programmes, but compromised switches can provide attackers with visibility across internal traffic, the ability to intercept credentials, and a foothold for lateral movement.

Why it matters

For UK organisations using Zyxel GS1900 series switches, this is a prompt to confirm whether the vulnerability affects devices in use, apply available patches or mitigations, and review how network infrastructure is included in vulnerability management and monitoring programmes.

Source: CISA

Today's Key Actions

  • Review how AI security tools are being evaluated and ensure that vendor claims are assessed against the practical governance and operational constraints the NCSC describes, particularly where autonomous or agentic behaviour is promised.
  • Confirm that all WordPress instances have been updated to version 7.1.1 or later to address the Comment2Shell vulnerability, and review how quickly security updates are applied across content management systems.
  • Review how location data, tracking technologies and consent mechanisms are implemented in mobile applications and customer-facing services, ensuring that privacy notices are clear and data processing aligns with user expectations.
  • Check whether Zyxel GS1900 series switches are in use, apply available patches or firmware updates, and ensure that network infrastructure is included in vulnerability management programmes.
  • Ensure that ownership of patching, privacy compliance, infrastructure security and AI governance is clearly assigned and that these areas are reviewed regularly as part of broader risk management.

Secarma Insight

Today's stories reflect the breadth of security practice that mature organisations need to maintain: understanding emerging technologies like AI, keeping foundational systems patched, ensuring privacy compliance is embedded in how services are designed, and managing infrastructure security across the estate. None of these areas can be treated in isolation, and none of them can be solved by a single tool or team. Good security comes from clear ownership, consistent discipline, and the ability to connect technical decisions to business risk and regulatory expectations. The organisations that manage these areas well are the ones that have already built the habits, governance structures and cross-functional relationships that allow them to respond calmly and effectively when new risks emerge.

News and blog posts
The US Cybersecurity and Infrastructure Security Agency has added...
Today's brief reflects the practical reality of defending modern organisations:...
The National Cyber Security Centre has published a blog post titled "One does...
WordPress released version 7.1.1 on 17 September 2026 to address a critical...