Visualização normal

Antes de ontemCybersecurity News
  • ✇Firewall Daily – The Cyber Express
  • AI Cyber Attacks Emerge as Biggest Threat to Indian Banking: RBI Samiksha Jain
    The Reserve Bank of India (RBI) has identified AI Cyber Attacks as the biggest near-term cybersecurity threat facing the Indian banking system, according to the June 2026 edition of its Financial Stability Report (FSR). The central bank's latest assessment highlights that while banks and financial institutions have strengthened cyber risk management practices, rapid advances in artificial intelligence are making cyber threats more difficult to counter. The findings are based on a survey condu
     

AI Cyber Attacks Emerge as Biggest Threat to Indian Banking: RBI

AI Cyber Attacks

The Reserve Bank of India (RBI) has identified AI Cyber Attacks as the biggest near-term cybersecurity threat facing the Indian banking system, according to the June 2026 edition of its Financial Stability Report (FSR). The central bank's latest assessment highlights that while banks and financial institutions have strengthened cyber risk management practices, rapid advances in artificial intelligence are making cyber threats more difficult to counter. The findings are based on a survey conducted by the RBI to assess the preparedness of major banks and non-banking financial companies (NBFCs) against evolving cyber risks. The survey found that institutions have established robust cybersecurity practices, particularly in vulnerability assessment and penetration testing of critical systems. However, AI Cyber Attacks emerged as the most significant challenge expected over the next 12 months.

AI Cyber Attacks Lead RBI's Cyber Risk Assessment

According to the RBI Financial Stability Report, AI-enabled cyber threats can increase the speed, scale and sophistication of attacks targeting financial infrastructure. Survey responses showed that most financial institutions are still in the developing or intermediate stages of integrating AI-specific threat preparedness into their existing cybersecurity frameworks, while only a smaller number reported mature capabilities. The report states that continued improvements in threat monitoring, detection, response mechanisms, employee awareness and cyber resilience will remain critical as AI-powered attacks continue to evolve.

Cybersecurity Practices Improve, But Gaps Remain

The RBI noted that financial institutions have made significant progress in cyber risk management. Regulatory reporting processes and board-level reporting of major cyber incidents have also matured. However, the report identified employee cybersecurity awareness and training as areas requiring further improvement, noting that human behaviour remains one of the most exploited entry points for cyberattacks. It also highlighted the need to strengthen forensic preparedness to improve incident response, preserve digital evidence and support regulatory and law enforcement investigations following sophisticated cyber incidents. The survey further revealed that around 67 percent of respondents increased IT and cybersecurity staffing between March 2025 and March 2026. Additionally, 71 percent reported higher cybersecurity spending as a share of overall IT expenditure during the last three financial years.

Third-Party Risk Emerges as Second Biggest Concern

Beyond AI Cyber Attacks, the RBI ranked third-party risk and supply chain dependencies as the second most important cybersecurity challenge for the financial sector. The survey found that 93 percent of respondents rely partially or substantially on external vendors for cybersecurity functions such as security operations centre monitoring, cloud security, incident response, threat intelligence and vulnerability assessments. Three-fourths of respondents also reported moderate to very high dependence on third-party technology providers for critical applications. According to the RBI, a major cyber incident affecting a common service provider could rapidly disrupt multiple regulated entities and create broader financial stability risks.

Growing Digital Transactions Increase Cyber Risk

The report noted that cyber risk has become a major financial stability concern as India's financial ecosystem becomes increasingly digital and interconnected. About 79 percent of surveyed institutions said more than three-fourths of their customer transactions are now conducted through digital financial services. Although 98 percent of respondents rated their current cyber risk exposure as very low to moderate and reported minimal disruption to customer services during 2025-26, nearly one-third indicated that cyber risk had increased compared with the previous year. The RBI also observed that geopolitical uncertainty is contributing to the evolving threat landscape, with 42 percent of surveyed institutions believing it has increased the likelihood of cyberattacks.

Financial Sector Cybersecurity Strategy Advances

The report said the proposed Financial Sector Cybersecurity Strategy is at an advanced stage of formulation. Developed by an Inter-Ministerial Group under the Financial Stability and Development Council, the strategy aims to establish governance frameworks, regulatory harmonisation and implementation timelines across the financial sector. The RBI said the strategy will address cybersecurity risks associated with artificial intelligence, cloud computing, quantum technologies, third-party dependencies, consumer protection and cross-sector critical infrastructure, strengthening the resilience of India's financial system against emerging cyber threats.
  • ✇Firewall Daily – The Cyber Express
  • NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands Samiksha Jain
    The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases,
     

NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

Agentic AI Deployment

The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases, limiting system privileges, and maintaining strong human oversight throughout deployment. The advisory comes as organizations increasingly experiment with AI systems capable of making decisions, accessing tools, and carrying out actions with limited human involvement.

What Is Agentic AI?

Unlike traditional generative AI systems that primarily create text, images, or predictions, agentic AI systems are designed to independently pursue goals. These systems can access data sources, remember context, make decisions, interact with software tools, and even create sub-agents to complete tasks. According to the NCSC, this added autonomy is what makes agentic AI useful for areas such as cyber defense, workflow automation, and operational efficiency. However, it also introduces a wider attack surface and increases the difficulty of monitoring system behavior. The agency noted that many security risks linked to AI are not entirely new. Concerns around access control, supply chain security, monitoring, and incident response already exist in traditional IT systems. Agentic AI systems also inherit existing large language model risks, including prompt injection and jailbreaking attacks. However, the NCSC warned that the autonomy of agentic AI systems could amplify these issues, especially if organizations deploy them without proper safeguards.

Why Agentic AI Raises Security Risks

The guidance outlines several risks tied to agentic AI deployments. One of the main concerns is broader access to systems and sensitive data. AI agents may interact with external tools, APIs, or databases in ways that traditional AI applications do not. The NCSC also highlighted the possibility of unpredictable behavior. Since AI agents interpret goals autonomously, they may take actions that differ from human expectations or exceed their intended scope. Another challenge involves visibility and oversight. Autonomous systems can operate at speeds that make meaningful human review difficult, particularly in enterprise environments where multiple systems and workflows are interconnected. The guidance further noted that explaining the behavior of agentic AI systems can be more difficult than understanding conventional AI models. The combination of decision-making, tool usage, and autonomous actions creates additional complexity during incident investigations or compliance reviews.

NCSC Calls for Incremental Agentic AI Deployment

To reduce risks, the NCSC urged organizations to adopt agentic AI gradually instead of deploying it across critical systems from the outset. The guidance recommends tightly controlled pilot deployments focused on clearly defined, low-risk tasks. Organizations are also encouraged to assess whether AI is genuinely necessary before integrating autonomous agents into existing workflows. “If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment,” the guidance stated. The agency stressed that organizations should never grant unrestricted access to sensitive data or critical infrastructure. Maintaining visibility into AI system behavior and preserving meaningful human control were identified as key requirements for safe deployment.

Human Accountability Remains Essential

Despite the growing capabilities of autonomous AI systems, the NCSC emphasized that humans remain fully accountable for how these technologies are used. The guidance states that organizations should clearly define who is responsible for approving AI access, monitoring system behavior, reviewing incidents, and shutting systems down when necessary. Security teams were also advised to integrate agentic AI risk management into existing cybersecurity and governance frameworks instead of treating AI security as a separate process. Recommended practices include applying least-privilege access controls, limiting system scope, avoiding long-lived credentials, monitoring unusual behavior, and planning for incidents involving AI misuse or loss of control.

Path Forward

While warning about the risks, the NCSC acknowledged that agentic AI could deliver significant operational benefits, particularly for repetitive and low-risk tasks. The agency said organizations should focus on responsible and scalable adoption strategies built around existing cybersecurity practices and strong governance controls. The guidance ultimately encourages businesses to move carefully, test systems incrementally, and prepare for potential failures before expanding the role of autonomous AI systems across enterprise environments.

UAE Cyber Security Council Warns 1 in 4 Public Files Contain Sensitive Personal Data

UAE Cyber Security Council

The UAE Cyber Security Council has raised concerns over widespread data exposure, revealing that nearly 25 percent of publicly accessible files contain sensitive personal data. The warning comes as part of its ongoing awareness efforts, urging individuals and organisations to strengthen basic cybersecurity practices. In its latest advisory under the “Cyber Pulse” campaign, the Council highlighted that poor file-sharing habits continue to expose users to avoidable cyber risks. The findings point to a growing gap between the use of cloud platforms and the understanding of how to secure shared data.

Public Files and Sensitive Personal Data at Risk

The Council’s findings show that a significant portion of files shared openly online contain sensitive personal data such as identification details, financial records, or login information. This raises concerns about how easily such data can be accessed by unintended users. The issue is not limited to publicly shared files. According to the Council, between 68 percent and 77 percent of privately shared files may also be accessible to unintended recipients due to weak access controls or misconfigured sharing settings. This highlights a broader problem where users assume that private sharing automatically ensures security. In many cases, improper permissions or link-based access can lead to unintentional exposure of sensitive personal data.

Cyber Security Council Highlights Encryption as Critical Safeguard

The UAE Cyber Security Council emphasized that encryption remains one of the most effective ways to protect sensitive personal data. Files that are encrypted before being shared or stored online are significantly less vulnerable to unauthorized access. The advisory noted that cloud storage platforms do not guarantee automatic protection of data. Without encryption, sensitive files remain exposed if access controls are bypassed or misconfigured. Alongside encryption, secure account management plays a key role in reducing risk. Weak passwords, reused credentials, and lack of authentication measures continue to be major contributors to data exposure incidents.

Key Cybersecurity Practices Recommended

To address the risks associated with exposed sensitive personal data, the Cyber Security Council outlined several essential cybersecurity practices. Users are advised to use strong and regularly updated passwords and enable two-factor authentication across all accounts. Avoiding public links when sharing sensitive files is also critical, as these links can be easily forwarded or accessed without proper restrictions. The Council stressed the importance of reviewing privacy settings and managing access permissions carefully. Monitoring file usage and access logs can help identify unusual activity and prevent misuse. Additional measures include deleting unused files and inactive sharing links, securing Wi-Fi networks, and keeping devices and software up to date. Users are also encouraged to review application permissions and limit access to only necessary services. When accessing files over public networks, the use of virtual private networks can provide an added layer of security. Regular data backups and secure database management on cloud platforms are also recommended to prevent data loss and unauthorized access.

Awareness Remains Key to Reducing Exposure

The Cyber Security Council noted that many cases involving sensitive personal data exposure are the result of simple, preventable mistakes. Lack of awareness around basic cybersecurity practices continues to be a major factor. The “Cyber Pulse” campaign, now in its second year, aims to address this gap by promoting safer digital behaviour among individuals and organisations. The initiative forms part of broader national efforts to build a secure and resilient digital environment. By encouraging users to adopt stronger security measures and understand the risks of improper file sharing, the Council aims to reduce the exposure of sensitive personal data and improve overall cybersecurity hygiene. The latest findings serve as a reminder that while technology platforms continue to evolve, the responsibility to secure data often lies with users. Simple steps such as enabling encryption, managing access, and reviewing shared content can significantly reduce the risk of data exposure.
❌
❌