Jessica Entwistle
September 23 2026
Today's briefing covers four developments that illustrate both the practical challenges and the evolving threat landscape facing UK organisations. The NCSC has published guidance on the realistic limits of AI in defensive security, a reminder that technology alone cannot replace disciplined security practice. Meanwhile, Check Point has patched a zero-day vulnerability actively exploited in targeted attacks, ShinyHunters has claimed a breach of the FBI, and Microsoft has disrupted a phishing-as-a-service platform targeting Microsoft 365 accounts. Together, these stories highlight the importance of patch discipline, supply chain oversight, and understanding where emerging technology can genuinely support defence rather than create new risk.
The National Cyber Security Centre has published a blog post titled 'One does not simply defend agentically', addressing the realistic capabilities and constraints of AI in defensive security operations. The NCSC explains that while AI offers potential benefits for defenders, it cannot be deployed in the same autonomous or agentic way that attackers might use it. The guidance emphasises that defenders operate under constraints including legal accountability, the need for explainability, and the requirement to avoid unintended consequences in live production environments. The NCSC outlines practical areas where AI can support defensive work, such as threat intelligence analysis, log review, and pattern recognition, but makes clear that human oversight, governance, and decision-making remain essential.
For UK organisations evaluating AI tools for security operations, this guidance provides important context. Many vendors are promoting AI-driven security products with claims of autonomous threat response or self-healing systems. The NCSC's position reinforces that mature security practice depends on clear ownership, explainable decisions, and the ability to justify actions taken in response to incidents. AI can assist with analysis, prioritisation, and detection, but it cannot replace the judgement, accountability, and governance that security teams provide. This matters particularly for organisations in regulated sectors, where the ability to explain security decisions and demonstrate due diligence is a legal and operational requirement.
For UK businesses considering AI security tools, this is a prompt to review vendor claims critically and ensure that any AI capability is deployed with clear human oversight, explainable outputs, and defined accountability. The NCSC's guidance reinforces that effective defence comes from disciplined practice, not from outsourcing decision-making to autonomous systems.
Source: NCSC UK
Check Point has released patches for a critical zero-day vulnerability in its Security Management Server that was exploited in targeted attacks on 23 July 2026. The flaw, tracked as CVE-2026-93616, allows an unauthenticated attacker with access to the server's web service to execute arbitrary scripts without logging in. SecurityWeek and The Hacker News report that Check Point released the fix on 22 September 2026, more than two months after the vulnerability was exploited in the wild. The Security Management Server is a central component in Check Point's architecture, used to manage firewall policies and security configurations across an organisation's network infrastructure. The delay between exploitation and patch availability highlights the risk window that organisations face when zero-day vulnerabilities are discovered in widely deployed management platforms.
For UK organisations using Check Point infrastructure, this incident underscores the importance of rapid patch deployment for management and control plane systems. Management servers sit at the centre of security policy enforcement, and a compromise at this level can undermine the effectiveness of perimeter and network security controls across the entire estate. The fact that this vulnerability was exploited in targeted attacks before a patch was available means that organisations using Check Point should review access logs, authentication records, and configuration changes on their management servers for signs of unauthorised activity during the period between July and September. This is also a reminder that management interfaces should be isolated from general network access, protected by additional authentication layers, and monitored closely for unusual activity.
For many organisations, this is a prompt to review whether Check Point Security Management Servers have been patched, whether access to management interfaces is appropriately restricted, and whether logging and monitoring would detect unauthorised configuration changes. Management plane security is a critical control, and compromise at this level can have cascading effects across the network.
Source: SecurityWeek
The cybercriminal group ShinyHunters has claimed responsibility for a breach of the U.S. Federal Bureau of Investigation, alleging that it has stolen sensitive data on current and former FBI agents and individuals who applied for jobs with the agency. The Hacker News and CyberScoop report that ShinyHunters posted a statement on 22 September 2026 claiming to hold data on "almost ALL FBI Agents" and job applicants. The FBI's jobs website was temporarily defaced and remains unavailable, and the agency has stated it is investigating the claims. ShinyHunters has a history of high-profile data breaches and extortion activity, and the group stated that this breach was "NOT financially motivated", suggesting a different intent than their usual pattern of selling stolen data.
While this incident involves a U.S. government agency, it has broader relevance for UK organisations because it illustrates the counterintelligence and operational risks created when personnel data is stolen from sensitive institutions. If the breach is confirmed, the theft of agents' personal information could be used for extortion, social engineering, or targeting individuals and their families. For UK businesses, particularly those in defence, critical infrastructure, or sectors handling sensitive government work, this is a reminder that personnel data, recruitment records, and employee information represent a significant risk if compromised. Attackers increasingly target HR systems, recruitment platforms, and identity directories not just for financial gain but to enable further attacks, insider recruitment, or espionage activity.
For UK businesses, this is a prompt to review the security of HR systems, recruitment platforms, and employee directories, particularly in sectors where personnel information could be used for targeting, social engineering, or insider threats. Understanding who has access to personnel data and how that data is protected is an important part of organisational resilience.
Source: The Hacker News
Microsoft has announced the disruption of EvilTokens, a phishing-as-a-service platform that enabled attackers to steal credentials and session tokens from Microsoft 365 accounts using device code phishing techniques. Dark Reading reports that Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated legal and technical action. EvilTokens provided a turnkey phishing service that allowed less technically skilled attackers to launch sophisticated credential theft campaigns targeting Microsoft 365 users. Device code phishing exploits the legitimate device authentication flow used by Microsoft 365, tricking users into entering a code that grants attackers access to their accounts without needing to steal passwords directly. The disruption of EvilTokens removes a significant enabler of phishing attacks, but similar services are likely to emerge.
For UK organisations using Microsoft 365, this development highlights the ongoing evolution of phishing techniques and the importance of layered defences beyond password security alone. Device code phishing bypasses traditional password protections and can defeat basic multi-factor authentication if users are tricked into approving malicious authentication requests. The fact that EvilTokens operated as a service means that even unsophisticated attackers could launch effective campaigns against Microsoft 365 tenants. Organisations should ensure that conditional access policies are configured to restrict device registration, that users are trained to recognise device code phishing attempts, and that monitoring is in place to detect unusual authentication patterns or token usage. Microsoft's disruption action is helpful, but it does not eliminate the underlying technique, and organisations remain responsible for configuring their tenants defensively.
For many organisations, this is a prompt to review Microsoft 365 conditional access policies, device registration controls, and user awareness of device code phishing techniques. Phishing-as-a-service platforms lower the barrier to entry for attackers, and defensive configurations need to account for the fact that these techniques are now widely accessible.
Source: Dark Reading
Today's briefing illustrates a recurring theme in mature security practice: effective defence depends on understanding both the capabilities and the limits of the tools and technologies we use. AI offers genuine potential to support security teams, but it cannot replace the judgement, accountability, and governance that human oversight provides. Similarly, vendor disruption actions and patches are helpful, but they do not eliminate the underlying techniques or the need for organisations to configure their environments defensively. Good security comes from disciplined practice, clear ownership, and habits that are already in place before incidents happen. The organisations that manage risk most effectively are those that approach new technology, vendor claims, and emerging threats with a clear understanding of what they can realistically control and where their responsibility lies.