Visualização normal

Hoje — 8 de Setembro de 2026Cybersecurity News

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

8 de Setembro de 2026, 08:19

SAP has released its September 2026 Security Patch Day updates, delivering 19 new security notes and one update to a previously issued note.

The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, SAP Commerce Cloud, and other enterprise products.

The most severe issue is CVE-2026-44756, a critical memory corruption vulnerability in SAP Extended Passport Processing, tracked under SAP Note 3747649. It carries a CVSS score of 10.0, the highest possible severity rating.

The flaw affects multiple SAP kernel and Web Dispatcher versions, including KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, and 9.16 through 9.20.

An unauthenticated remote attacker could potentially exploit the memory corruption flaw to compromise confidentiality, integrity, and availability. Organizations using affected SAP kernel components should treat this update as an emergency patching priority.

Another critical vulnerability, CVE-2026-58240, affects SAP NetWeaver Message Server. SAP Note 3759472 addresses a missing authentication check with a CVSS score of 9.8. The issue affects KERNEL versions 9.16, 9.18, 9.19, and 9.20.

Successful exploitation could allow an attacker without valid credentials to access or interact with exposed services, creating a serious risk to SAP environments.

SAP Security Updates September 2026

SAP also fixed CVE-2026-76969, a critical credential disclosure vulnerability in multitenant applications using the SAP Cloud Application Programming Model library sap/cds-mtxs.

The flaw has a CVSS score of 9.4 and affects versions up to 1.18.3, 2.7.6, 3.9.6, and 4.0.2. Developers and cloud administrators should update affected dependencies quickly, especially where they handle tenant data and application credentials.

A fourth critical issue, CVE-2026-66768, impacts SAP GUI for Java in SAP NetWeaver. The improper access control vulnerability, fixed by SAP Note 3781729, has a CVSS score of 9.0. It affects BC-FES-JAV 8.10 and could allow a low-privileged attacker to gain unauthorized access after user interaction.

The September release also includes high-severity fixes, including CVE-2026-76958, an 8.5-rated XXE flaw in SAP Integration Suite Trading Partner Management that could expose sensitive files, enable server-side requests, or disrupt XML processing.

SAP patched insecure deserialization in SAP NetWeaver Business Client, memory corruption in SAP NetWeaver Application Server for ABAP and ABAP Platform, and CRLF injection in SAP Commerce Cloud Search and Navigation.

The company also released an update for CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools originally addressed during the August 2026 Patch Day.

SAP NoteCVEVulnerabilityAffected product/versionsPriority
3747649CVE-2026-44756Memory corruptionSAP Extended Passport (EPP) Processing
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; WEBDISP: 9.16, 9.18, 9.19, 9.20; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
Critical
3759472CVE-2026-58240Missing authentication checkSAP NetWeaver Message Server
KERNEL: 9.16, 9.18, 9.19, 9.20
Critical
3798315CVE-2026-76969Credential disclosure in multitenant CAP applicationsSAP CAP library sap/cds-mtxs
Versions: ≤1.18.3, ≤2.7.6, ≤3.9.6, ≤4.0.2
Critical
3781729CVE-2026-66768Improper access controlSAP NetWeaver SAP GUI for Java
BC-FES-JAV: 8.10
Critical
3772411CVE-2026-58243Privilege escalation — updated August noteSAP ABAP Developer Tools
SAP_BASIS: 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920
High
3792978CVE-2026-76958XML External Entity (XXE)SAP Integration Suite
Cloud Integration – Trading Partner Management V2: 2.9.2; B2B Integration Factory – Cloud Integration – Trading Partner Management: 1.10.0
High
3784138CVE-2026-76967Insecure deserializationSAP NetWeaver Business Client
BC-WD-CLT-BUS: 8.00, 8.10
High
3757002CVE-2026-66767Memory corruptionSAP NetWeaver AS for ABAP and ABAP Platform
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
High
3791068CVE-2026-2332CRLF injection through Jetty componentsSAP Commerce Cloud Search and Navigation
COM_CLOUD: 2211, 2211-JDK21
High
3750721CVE-2026-76968Information disclosureSAP Web Dispatcher, Internet Communication Manager, and SAP Content Server
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53; WEBDISP: 7.22_EXT, 7.53, 7.54, 7.77, 7.93, 9.16; CONTSERV: 7.53, 7.54; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19, 9.20
Medium
3756450CVE-2026-44766SQL injectionSAP S/4HANA Intercompany Matching and Reconciliation
SAPSCORE: 136; S4CORE: 104, 105, 106, 107, 108, 109
Medium
3786489CVE-2026-76971Server-Side Request Forgery (SSRF)SAP Manufacturing Integration and Intelligence
XMII: 15.4, 15.5
Medium
3787345CVE-2026-34477Security misconfiguration due to Apache Log4jSAP Commerce Cloud Search and Navigation
COM_CLOUD: 2211, 2211-JDK21
Medium
3783189CVE-2026-76977ClickjackingSAPUI5 Frame Options Allowlist
SAP_UI: 750, 754, 755, 756, 757, 758, 816; UI_700: 200
Medium
3365276CVE-2026-76960Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
S4CORE: 105, 106, 107
Medium
3371336CVE-2026-76961Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
S4CORE: 108
Medium
3365311CVE-2026-76959Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
UIAPFI70: 800, 900, 901, 902
Medium
3657599CVE-2026-76962Missing authorization checkSAP S/4HANA Manage Bank Chains app
S4CORE: 107, 108, 109
Medium
3772838CVE-2026-76963Missing authorization checkSAP NetWeaver and ABAP Platform
SAP_BASIS: 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758
Medium
3736494CVE-2026-58234Denial of serviceSAP Process Integration SOAP Adapter
MESSAGING: 7.50; SAP_XIAF: 7.50
Low

Medium-severity fixes cover SQL injection, server-side request forgery, clickjacking, cross-site request forgery, information disclosure, authorization bypass, and Apache Log4j-related security misconfiguration issues. SAP also patched a low-severity denial-of-service flaw in the SAP Process Integration SOAP Adapter.

SAP administrators should review all relevant security notes in the SAP Support Portal, map them to deployed product versions, test patches under change-control procedures, and apply the fixes as soon as possible.

Internet-facing SAP services, NetWeaver Message Server instances, cloud application dependencies, and systems processing sensitive business data should receive priority attention.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport appeared first on Cyber Security News.

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • NVIDIA Releases Security Fixes for UFM Enterprise and DGX Spark Do Son
    Critical NVIDIA security updates patch multiple flaws in UFM and DGX Spark systems, addressing CVE-2026-24170 and CVE-2026-24262. Related Posts: CVE-2026-19042: TeamViewer Command Injection Enables Remote Code Execution CVE-2026-72137 (CVSS 9.8): Linux Kernel Flaw Enables Root Privilege Escalation, PoC Public CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler Flaw The post NVIDIA Releases Security Fixes for UFM Enterprise and DGX Spark appeared first on Daily CyberSecurity.
     

OnePlus 10T Is Out of Security Support: Should You Keep Using Yours?

7 de Agosto de 2026, 10:36

OnePlus 10T security support has ended. Here’s how owners can check their patch level, understand the risks, and decide when to replace the phone.

The post OnePlus 10T Is Out of Security Support: Should You Keep Using Yours? appeared first on TechRepublic.

OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades

5 de Agosto de 2026, 12:15

The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app compatibility, device management, and long-term purchasing decisions.

The post OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades appeared first on TechRepublic.

Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices

28 de Julho de 2026, 15:26

Apple’s latest iPhone, iPad and Mac updates patch 194 unique security flaws involving root access, kernel code execution and protected data.

The post Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices appeared first on TechRepublic.

  • ✇Firewall Daily – The Cyber Express
  • Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration Samiksha Jain
    Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research. The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific. The two countries said the Aus
     

Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

Australia-India PACTS

Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research.

The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific.

The two countries said the Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS) builds on two decades of research collaboration, operational coordination, and policy engagement. It also reflects their shared commitment to creating secure digital ecosystems while promoting trusted technology partnerships.

Australia-India PACTS Built on Five Pillars

The Australia-India PACTS is structured around five pillars that will drive collaboration between governments, research institutions, universities, and the private sector. The framework is intended to increase two-way investment in emerging technologies while supporting innovation and the commercialisation of research.

The first pillar focuses on supply chain resilience by strengthening trusted technology supply chains and promoting secure trade. Both countries will establish a bilateral mechanism for trusted vendor frameworks and work together to improve undersea cable security through the Quad Partnership for Cable Connectivity and Resilience. The partnership also includes collaboration on semiconductor research, critical minerals, and trade diversification.

Australia-India PACTS Expands Critical Technology Collaboration

The second pillar focuses on critical technologies, with Australia and India planning to strengthen cooperation in artificial intelligence, telecommunications, biotechnology, advanced materials, and space technologies.

The framework also supports the development of international standards for trustworthy AI and encourages collaboration between academic institutions and industry to promote responsible AI deployment. The two countries will also explore joint research, investment initiatives, and commercial partnerships in emerging technologies to strengthen long-term economic security across the Indo-Pacific.

Australia-India Prioritises Cybersecurity

A major component of the partnership is Australia India cybersecurity cooperation. Under the third pillar, both governments will work together to counter cybercrime, deter malicious cyber activity, strengthen cyber policy coordination, and protect critical infrastructure.

The framework proposes a consolidated bilateral mechanism for cyber and ICT cooperation, expanded engagement in United Nations cyber processes, increased trade opportunities for cybersecurity businesses, and practical workshops involving government agencies and industry stakeholders.

The partnership will also establish a cyber technology skills incubator to promote knowledge exchange and workforce development.

Australia-India PACTS Advances Digital Resilience

The fourth pillar focuses on digital resilience across the Indo-Pacific. Australia and India will collaborate on trusted Digital Public Infrastructure initiatives and promote scalable digital solutions that support connectivity, healthcare, education, renewable energy, critical infrastructure, and digital transformation.

The partnership also seeks to expand pilot projects that help countries across the region build adaptable digital ecosystems while strengthening regional capabilities.

Defence Research and Governance Framework

The fifth pillar strengthens defence science collaboration through joint research, innovation partnerships, and greater engagement between Australia's Defence Science and Technology Group and India's Defence Research and Development Organisation.

Areas of cooperation include maritime surveillance, advanced materials, defence innovation, and stronger links between defence start-up ecosystems.

The Australia-India PACTS will be jointly overseen by the Australian Deputy Secretary of the International and Security Group within the Department of the Prime Minister and Cabinet and the Indian Deputy National Security Advisor. Annual Senior Officials Meetings will review progress, assess emerging cyber and technology risks, and identify future collaborative projects under each pillar.

With the launch of Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS), both countries have outlined a long-term roadmap that brings together cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence cooperation under a single strategic framework aimed at strengthening security and technology collaboration across the Indo-Pacific.

Microsoft Extends Windows 10 Security Updates to 2027

26 de Junho de 2026, 10:46

Microsoft extended Windows 10 security updates for personal devices through Oct. 12, 2027, giving users more time to upgrade.

The post Microsoft Extends Windows 10 Security Updates to 2027 appeared first on TechRepublic.

  • ✇Firewall Daily – The Cyber Express
  • What Ukraine’s Entry Into the EU Cybersecurity Reserve Means Samiksha Jain
    Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities. The decision allows Ukraine to activate support from the EU Cybersecurity Reserve, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity prov
     

What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

Ukraine Joins EU Cybersecurity Reserve

Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities. The decision allows Ukraine to activate support from the EU Cybersecurity Reserve, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity providers. The move reflects ongoing EU-Ukraine cooperation on digital security and resilience amid evolving cyber threats.

Ukraine Joins EU Cybersecurity Reserve Under EU Cyber Solidarity Framework

The EU Cybersecurity Reserve was established under the Cyber Solidarity Act to help participating countries respond to significant cybersecurity incidents. Through the reserve, nations can request specialized assistance when their own incident response resources are overwhelmed. According to the European Commission, Ukraine will now be able to officially seek emergency European support if a cyberattack surpasses the capacity of its domestic response teams. This would allow cybersecurity experts from across the European Union to assist in incident containment and recovery efforts. The Commission described the decision as part of broader efforts to strengthen preparedness, improve rapid response capabilities, and encourage cooperation against growing cyber threats.

EU Highlights Digital Security Cooperation

Commenting on the development, Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, said Ukraine's inclusion strengthens collective cyber defenses and reflects the principle of solidarity at the core of Europe's digital future. The Commission noted that cyberattacks continue to present a persistent challenge and emphasized the importance of coordinated responses and shared expertise among partner nations. Ukraine's inclusion also aligns with the EU's strategic digital partnership agenda, which focuses on strengthening cybersecurity cooperation with neighboring countries.

Moldova Previously Granted Access

Ukraine becomes the second non-EU country to gain access to the reserve. Moldova was granted access in 2024 following an increase in Moscow-linked Cyber Threats and influence operations targeting the country. The Council's authorization for Moldova to use the reserve was described as a major step forward in regional cybersecurity cooperation. The arrangement was implemented under the Cyber Solidarity Act and formed part of broader EU-Moldova efforts to improve digital resilience. The European Commission stated that enhancing cybersecurity cooperation remains a key component of its partnership with Moldova.

Broader EU-Moldova Digital Cooperation Expands

Alongside cybersecurity initiatives, the European Union has expanded digital cooperation with Moldova in several strategic areas. The Commission welcomed a political agreement that will allow Moldova to join the EU Roaming Area under the "Roam Like at Home" framework following formal adoption. Once implemented, Moldovan citizens and EU travelers will be able to call, text, and use mobile data without additional roaming charges. Moldova has also joined the EU Third Countries' Trusted List, enabling easier validation of electronic signatures and seals between EU and Moldovan organizations, businesses, and citizens. To strengthen resilience against Disinformation and foreign interference, a new hub of the European Digital Media Observatory (EDMO) known as FACT has also been established with support from the European Commission.

Cyber Cooperation Advances as EU Membership Talks Progress

The cybersecurity announcement comes shortly after EU member states agreed to launch formal accession negotiations with both Ukraine and Moldova. European Commission President Ursula von der Leyen described the decision as a major milestone, stating that all member states had agreed to open the first accession negotiations cluster with the two countries. She said the move recognizes the reforms undertaken by Ukraine and Moldova despite significant challenges and reinforces the EU's commitment to peace, security, and stability across the region. With access to the EU Cybersecurity Reserve, Ukraine now gains an additional layer of support to strengthen its cyber resilience and coordinate responses to major cybersecurity incidents alongside European partners.
  • ✇Firewall Daily – The Cyber Express
  • UK Social Media Ban for Under-16s Could Take Effect by Spring 2027 Samiksha Jain
    The UK government has announced plans to introduce a UK social media ban for under-16s, preventing children from accessing major platforms such as TikTok, Instagram, Snapchat, Facebook, YouTube and X under a sweeping package of online safety reforms. The measures, expected to be brought before Parliament later this year and enforced from Spring 2027, would make Britain one of the toughest countries in the world when it comes to regulating children's access to social media. The proposal is par
     

UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

UK social media ban

The UK government has announced plans to introduce a UK social media ban for under-16s, preventing children from accessing major platforms such as TikTok, Instagram, Snapchat, Facebook, YouTube and X under a sweeping package of online safety reforms. The measures, expected to be brought before Parliament later this year and enforced from Spring 2027, would make Britain one of the toughest countries in the world when it comes to regulating children's access to social media. The proposal is part of a wider government effort to strengthen online child safety and address growing concerns about the impact of social media algorithms, harmful content and excessive screen time on young users. Prime Minister Keir Starmer described the move as a "line in the sand," arguing that technology companies have failed to do enough to protect children online. "Parents want to keep their kids safe and happy, but the online world has made that harder than ever," Starmer said. "That's why we're going further than any country in the world by banning social media for under-16s and putting wider protections in place to give kids their childhood back." UK Social Media Ban for Under-16s

UK Social Media Ban for Under-16s to Cover Major Platforms

The proposed UK social media ban for under-16s will apply to user-to-user platforms that allow users to interact and share content through algorithm-driven feeds. Platforms expected to fall under the restrictions include TikTok, Instagram, Snapchat, Facebook, YouTube and X. Messaging services such as WhatsApp and Signal are not expected to be included. Alongside the ban, the government plans to introduce new restrictions on features considered particularly risky for young users. These include livestreaming functions and communication between children and strangers across a wider range of digital services, including some gaming platforms. The government is also considering additional safeguards, including overnight access limits and measures designed to interrupt infinite scrolling for users under 18.

AI Chatbots Also Under Scrutiny

The reforms extend beyond social media platforms. Under the proposed rules, AI-powered "romantic companion" chatbots that simulate intimate or sexual relationships will be required to enforce a minimum age of 18. Similar intimate AI functions will also face restrictions for users under the age of 18. Officials say the broader approach reflects how children increasingly encounter online risks across multiple digital services rather than solely through social media platforms.

Global Momentum Builds Behind Social Media Age Restrictions

Britain's announcement comes amid growing international support for tighter social media age restrictions. Earlier this year, Spain announced plans to prohibit social media access for children under 16. Prime Minister Pedro Sanchez described the internet as a "digital Wild West" and said stronger protections were needed to shield young people from online harm. France has also moved in a similar direction. In February, French lawmakers approved legislation banning children under 15 from accessing social media platforms. The measure is expected to take effect at the start of the next school year. French President Emmanuel Macron strongly backed the proposal, stating that children's development should not be dictated by algorithms designed to maximize engagement. The developments have fueled debate over whether age-based restrictions could become a standard approach to child online protection across Europe and beyond.

Australia's Experience Highlights Enforcement Challenges

While support for restrictions is growing, Australia's experience shows that enforcement remains a major challenge. The Australia social media ban, introduced under Prime Minister Anthony Albanese, requires platforms to block users under 16 or face fines of up to AU$32 million. However, recent research suggests many children continue to access restricted platforms despite the rules. A study conducted by the Molly Rose Foundation and YouthInsight found that more than 60% of children aged 12 to 15 who previously used social media still had access to at least one account. The survey of 1,050 young people showed that 53% of former TikTok users, 53% of YouTube users and 52% of Instagram users remained active after the restrictions were introduced. Researchers also found evidence that some children created new accounts after the ban came into effect, raising questions about the effectiveness of current age verification systems.

Age Assurance Measures Key to Enforcement

To improve compliance, the UK government plans to introduce stronger age assurance measures and has tasked Ofcom with conducting a rapid review of age-verification technologies. The regulator will also review its enforcement capabilities, while ministers have pledged additional funding to support implementation of both the proposed regulations and existing provisions under the Online Safety Act. The announcement follows a national consultation that attracted more than 116,000 responses from parents, children and experts. According to government figures, nine in ten parents support a ban on social media access for children under 16. If approved, the reforms will mark one of the most significant changes to Britain's digital safety framework and could further accelerate a global shift toward stricter regulation of children's online experiences.
  • ✇Firewall Daily – The Cyber Express
  • NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands Samiksha Jain
    The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases,
     

NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

Agentic AI Deployment

The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases, limiting system privileges, and maintaining strong human oversight throughout deployment. The advisory comes as organizations increasingly experiment with AI systems capable of making decisions, accessing tools, and carrying out actions with limited human involvement.

What Is Agentic AI?

Unlike traditional generative AI systems that primarily create text, images, or predictions, agentic AI systems are designed to independently pursue goals. These systems can access data sources, remember context, make decisions, interact with software tools, and even create sub-agents to complete tasks. According to the NCSC, this added autonomy is what makes agentic AI useful for areas such as cyber defense, workflow automation, and operational efficiency. However, it also introduces a wider attack surface and increases the difficulty of monitoring system behavior. The agency noted that many security risks linked to AI are not entirely new. Concerns around access control, supply chain security, monitoring, and incident response already exist in traditional IT systems. Agentic AI systems also inherit existing large language model risks, including prompt injection and jailbreaking attacks. However, the NCSC warned that the autonomy of agentic AI systems could amplify these issues, especially if organizations deploy them without proper safeguards.

Why Agentic AI Raises Security Risks

The guidance outlines several risks tied to agentic AI deployments. One of the main concerns is broader access to systems and sensitive data. AI agents may interact with external tools, APIs, or databases in ways that traditional AI applications do not. The NCSC also highlighted the possibility of unpredictable behavior. Since AI agents interpret goals autonomously, they may take actions that differ from human expectations or exceed their intended scope. Another challenge involves visibility and oversight. Autonomous systems can operate at speeds that make meaningful human review difficult, particularly in enterprise environments where multiple systems and workflows are interconnected. The guidance further noted that explaining the behavior of agentic AI systems can be more difficult than understanding conventional AI models. The combination of decision-making, tool usage, and autonomous actions creates additional complexity during incident investigations or compliance reviews.

NCSC Calls for Incremental Agentic AI Deployment

To reduce risks, the NCSC urged organizations to adopt agentic AI gradually instead of deploying it across critical systems from the outset. The guidance recommends tightly controlled pilot deployments focused on clearly defined, low-risk tasks. Organizations are also encouraged to assess whether AI is genuinely necessary before integrating autonomous agents into existing workflows. “If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment,” the guidance stated. The agency stressed that organizations should never grant unrestricted access to sensitive data or critical infrastructure. Maintaining visibility into AI system behavior and preserving meaningful human control were identified as key requirements for safe deployment.

Human Accountability Remains Essential

Despite the growing capabilities of autonomous AI systems, the NCSC emphasized that humans remain fully accountable for how these technologies are used. The guidance states that organizations should clearly define who is responsible for approving AI access, monitoring system behavior, reviewing incidents, and shutting systems down when necessary. Security teams were also advised to integrate agentic AI risk management into existing cybersecurity and governance frameworks instead of treating AI security as a separate process. Recommended practices include applying least-privilege access controls, limiting system scope, avoiding long-lived credentials, monitoring unusual behavior, and planning for incidents involving AI misuse or loss of control.

Path Forward

While warning about the risks, the NCSC acknowledged that agentic AI could deliver significant operational benefits, particularly for repetitive and low-risk tasks. The agency said organizations should focus on responsible and scalable adoption strategies built around existing cybersecurity practices and strong governance controls. The guidance ultimately encourages businesses to move carefully, test systems incrementally, and prepare for potential failures before expanding the role of autonomous AI systems across enterprise environments.
  • ✇Firewall Daily – The Cyber Express
  • EU Faces Criticism Over Surveillance Technology Exports to Rights Violators Samiksha Jain
    The European Union is facing renewed criticism over its failure to stop the export of surveillance technology to governments accused of human rights violations, according to a new report released by Human Rights Watch. The report claims that despite the EU’s landmark Dual-Use Regulation introduced in 2021, EU surveillance technology tool are still reaching countries where they are allegedly used to target journalists, activists, academics, and other critical voices. The 54-page report, titled
     

EU Faces Criticism Over Surveillance Technology Exports to Rights Violators

EU Surveillance Technology

The European Union is facing renewed criticism over its failure to stop the export of surveillance technology to governments accused of human rights violations, according to a new report released by Human Rights Watch. The report claims that despite the EU’s landmark Dual-Use Regulation introduced in 2021, EU surveillance technology tool are still reaching countries where they are allegedly used to target journalists, activists, academics, and other critical voices. The 54-page report, titled “Looking the Other Way: EU Failure to Prevent Surveillance Exports to Rights Violators,” raises concerns about weak oversight, limited transparency, and gaps in enforcement within the EU’s surveillance technology export framework.

EU Surveillance Technology Exports Continue Despite Safeguards

The report highlights that the majority of EU member states host companies involved in the development and export of surveillance technology. These tools include intrusion software and telecommunication interception systems capable of monitoring private communications and tracking individuals. According to Human Rights Watch, the growing global use of commercial spyware and related surveillance technology has become a major human rights concern. Governments in several countries have allegedly used such technologies to suppress dissent, monitor opposition voices, and restrict civic freedoms. The EU’s Dual-Use Regulation was introduced to regulate exports of technologies that could serve both civilian and military purposes. The regulation aimed to strengthen oversight of surveillance technology exports by requiring member states to assess the human rights records of destination countries before approving sales. The law also introduced transparency and reporting obligations requiring EU member states to share export licensing data with the European Commission for inclusion in annual public reports. However, Human Rights Watch argues that the implementation of these measures has fallen short of their intended purpose.

Human Rights Watch Flags Weak Oversight and Transparency

A major focus of the report is the EU’s 2024 implementation guidelines for the Dual-Use Regulation. Human Rights Watch claims the guidelines weakened transparency requirements and limited public access to meaningful information about surveillance technology exports. The organization said the reporting system currently does not provide enough detail to determine whether exports are contributing to human rights abuses. To investigate further, Human Rights Watch submitted freedom of information requests to all 27 EU member states seeking data on surveillance technology licensing and exports. The findings revealed several examples of exports to countries with documented records of surveillance-related rights violations. Among the cases highlighted were exports of surveillance tools from Bulgaria to Azerbaijan in 2022 and telecommunication interception systems exported from Poland to Rwanda in 2023. The report states that these exports included technologies capable of intercepting communications and conducting intrusive digital surveillance. Human Rights Watch also criticized both EU institutions and member states for frequently citing trade secrets, national security, and international relations as reasons for withholding export information from public scrutiny.

Concerns Over Surveillance Technology and Human Rights

The report argues that surveillance technology can directly threaten several fundamental rights, including privacy, freedom of expression, freedom of assembly, and in some cases even the right to life and protection from torture. Human Rights Watch said journalists, activists, humanitarian workers, and anti-corruption investigators are among those most vulnerable to misuse of surveillance tools. The organization warned that digital surveillance can expose confidential sources, restrict independent reporting, and create risks to personal safety. According to the report, the EU remains one of the largest hubs for commercial surveillance technology companies globally. A 2024 report by Google’s Threat Analysis Group reportedly found that nearly all major commercial surveillance companies mentioned in its research were based in the EU.

European Commission Faces Pressure Ahead of 2026 Review

The European Commission is expected to begin a formal evaluation of the Dual-Use Regulation in September 2026. Human Rights Watch is urging the commission, the European Parliament, and EU member states to strengthen the rules governing surveillance technology exports during the review process. The organization is calling for stricter human rights due diligence requirements, stronger export controls, and greater transparency in reporting. It also wants surveillance companies to conduct more detailed assessments of whether their products could be used to facilitate rights abuses. In response to questions raised in the report, the European Commission stated that licensing decisions for dual-use exports are handled by individual EU member states. The commission also defended certain reporting limitations, saying that detailed disclosures could reveal commercially sensitive information or identify companies involved in exports. Still, Human Rights Watch argues that the current framework is failing to provide effective oversight. Zach Campbell, senior surveillance researcher at Human Rights Watch, said the EU needs “real transparency” to ensure that the regulation works as intended and prevents European surveillance technology from enabling abuse worldwide.
  • ✇Firewall Daily – The Cyber Express
  • California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement Samiksha Jain
    California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimizat
     

California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

California Privacy Settlement

California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimization requirements under California privacy law. The case centers on allegations that General Motors shared sensitive driver information, including geolocation data and driving behavior, with data brokers Verisk Analytics and LexisNexis Risk Solutions between 2020 and 2024.

California Privacy Settlement Targets Driver Data Sales

According to the complaint, GM collected data through its OnStar connected vehicle platform, which offers emergency assistance, navigation, and crash response services. Investigators alleged that the company sold names, contact details, precise location information, and driving behavior data of hundreds of thousands of Californians to the two data brokers. Authorities said the data was intended to help create driver-risk scoring products that could be used by insurance companies when setting premiums. The investigation was conducted jointly by the California Department of Justice, the California Privacy Protection Agency (CalPrivacy), and district attorneys from San Francisco, Los Angeles, Napa, and Sonoma counties. Attorney General Rob Bonta said the settlement sends a clear message about consumer control over personal data. “General Motors sold the data of California drivers without their knowledge or consent,” Bonta said in the announcement, adding that the data could reveal sensitive details about consumers’ daily routines and movements.

CCPA Violations and Data Minimization Concerns

A major part of the case focused on alleged violations of the CCPA’s data minimization and purpose limitation requirements, which were added to California law in 2023. Under these provisions, companies are required to collect and retain only the data necessary for a disclosed purpose. Investigators alleged that GM retained driving and location data long after it was needed to operate OnStar services and later sold that retained data to third parties. Authorities also alleged that GM failed to clearly inform consumers about how their information would be used. The complaint stated that GM’s privacy policies suggested driver data would only be used to provide requested OnStar services and even claimed the company did not sell driving or location information. Investigators said the company’s practices contradicted those statements. San Francisco District Attorney Brooke Jenkins described modern vehicles as “rolling data collection machines” and said consumers deserve transparency about what information is collected and how it is shared. Los Angeles County District Attorney Nathan J. Hochman said companies handling consumer data would be held accountable under California privacy laws, regardless of their size.

Connected Vehicle Privacy Under Scrutiny

The settlement follows growing regulatory scrutiny around connected vehicle privacy and automotive data collection practices. In 2023, CalPrivacy launched investigations into connected car manufacturers and their handling of consumer information. Public attention increased further in 2024 after a report by The New York Times highlighted how automakers were sharing driving behavior data with insurance companies. The reporting indicated that some consumers outside California had experienced increased insurance premiums tied to such data-sharing practices. California investigators later determined that California drivers were likely not directly affected through insurance rate increases because state insurance laws prohibit insurers from using driving behavior data to set premiums. However, regulators maintained that the collection, retention, and sale of the data itself violated California privacy requirements.

Settlement Terms for General Motors

Under the proposed California privacy settlement, General Motors must implement several privacy-related measures over the coming years. The company will be required to:
  • Pay $12.75 million in civil penalties.
  • Stop selling driving data to consumer reporting agencies for five years.
  • Delete retained driving data within 180 days unless consumers provide express consent for limited uses.
  • Request the deletion of driver data already shared with LexisNexis and Verisk.
  • Establish and maintain a comprehensive privacy compliance program.
  • Submit privacy assessments and compliance reports to California regulators and prosecutors.
The settlement also reinforces California’s broader push to strengthen consumer control over personal information under the CCPA. CalPrivacy Executive Director Tom Kemp said California privacy laws require businesses to collect only the information they genuinely need and to be transparent about how that data is handled. Alongside the settlement announcement, regulators also highlighted the state’s Delete Request and Opt-out Platform (DROP), which allows Californians to submit requests to delete personal information held by hundreds of registered data brokers.
  • ✇Firewall Daily – The Cyber Express
  • UK’s Online Age Checks Are Failing—Kids are Beating Them with AI, Fake Beards Mihir Bagwe
    When governments introduced stricter online age checks under the UK’s Online Safety Act, the goal was to keep children away from harmful content. But in practice, the system is already showing cracks—and the most telling insight comes from the very users it’s meant to protect. Children aren’t just countering age checks, they’re actively bypassing them—and often with surprising ease. According to a new report from Internet Matters foundation, nearly half of children (46%) believe age verificati
     

UK’s Online Age Checks Are Failing—Kids are Beating Them with AI, Fake Beards

U.S. Government Sues TikTok, TikTok

When governments introduced stricter online age checks under the UK’s Online Safety Act, the goal was to keep children away from harmful content. But in practice, the system is already showing cracks—and the most telling insight comes from the very users it’s meant to protect.

Children aren’t just countering age checks, they’re actively bypassing them—and often with surprising ease.

According to a new report from Internet Matters foundation, nearly half of children (46%) believe age verification systems are easy to get around, while only 17% think they are difficult. That perception isn’t theoretical. It’s grounded in real behavior, shared knowledge, and increasingly creative workarounds.

From simply entering a fake birthdate to using someone else’s ID, children have developed a toolkit to bypass techniques. Some methods are almost trivial—changing a date of birth or borrowing a parent’s login—while others reflect a growing sophistication. Kids reported submitting altered images, using AI-generated faces, or even drawing facial hair on themselves to trick facial recognition systems.

In one striking example, a parent described catching their child using makeup to appear older—successfully fooling the system.

I did catch my son using an eyebrow pencil to draw a moustache on his face, and it verified him as 15 years old. – Mum of boy, 12

But the problem goes deeper than perception. It’s systemic.

Also read: UK Regulator Ofcom Launches Probe into Telegram, Teen Chat Platforms

Bypassing Is the Norm, Not the Exception

The report reveals that nearly one in three children (32%) admitted to bypassing age restrictions in just the past two months. Older children are even more likely to do so, which shows how digital literacy often translates into evasion capability.

The most common methods?

  • Entering a fake birthdate (13%)
  • Using someone else’s login credentials (9%)
  • Accessing platforms via another person’s device (8%)

Despite widespread concerns about VPNs, they play a relatively minor role. Only 7% of children reported using them to bypass restrictions, suggesting that simpler, low-effort tactics remain the preferred route.

In other words, the barrier to entry is not just low—it’s practically optional.

Europe Threat Landscape Q1 2026, Online Age Check Europe’s cyber threat landscape Q1 2026 shows a sharp acceleration in cyber threats across the region. Do you know what's contributing to it?

Check Cyble's full analysis report here!

Even When It Works, It Doesn’t Work

Ironically, even when children attempt to follow the rules, the technology doesn’t always cooperate.

Some reported being incorrectly identified as older—or younger—by facial recognition systems. In cases where they were flagged as underage, enforcement was often inconsistent or temporary. One child described being blocked from going live on a platform for just 10 minutes before being allowed to try again.

This inconsistency creates a loophole where persistence pays. If at first you’re denied, simply try again.

A Risky Side Effect

Perhaps the most concerning finding isn’t that children can bypass age checks—it’s that adults can too.

The report states fears that adults may exploit these same weaknesses to access spaces intended for younger users. In some cases, this involves using images or videos of children to trick verification systems. There are even reports of adults acquiring child-registered accounts to blend into youth platforms.

This flips the entire premise of age verification on its head. Instead of protecting children, flawed systems may inadvertently expose them to greater risk.

Parents, Part of the Problem—or the Solution?

Adding another layer of complexity, parents themselves are sometimes complicit.

About 26% of parents admitted to allowing their children to bypass age checks, with 17% actively helping them do so. The reasoning is often pragmatic. Parents feel they understand the risks and trust their child’s judgment.

I have helped my son get around them. It was to play a game, and I knew the game, and I was happy and confident that I was fine with him playing it. – Mum of non-binary child, 13

But this undermines the consistency of enforcement. If rules vary from household to household, platform-level protections lose their impact.

Interestingly, the data also suggests that communication matters. Children who regularly discuss their online activity with parents are less likely to bypass restrictions than those who don’t.

Why Kids Are Bypassing in the First Place

The motivations aren’t always malicious. In many cases, children are simply trying to access social media (34%), gaming communities (30%), or messaging apps (29%) that their peers are already using.

What this resonate is a fundamental tension where age verification systems are trying to enforce boundaries in environments where social participation is the norm.

Age verification is often positioned as a cornerstone of online safety. But in practice, it’s proving to be more of a speed bump than a safeguard.

Children understand the systems. They share methods. They adapt quickly. And until the technology—and its enforcement—becomes significantly more robust, age checks may offer more reassurance than real protection.

  • ✇Firewall Daily – The Cyber Express
  • NCSC Warns Organisations to Act Fast as Hidden Software Flaws Surface Samiksha Jain
    Organisations worldwide are being urged to prepare for a vulnerability patch wave, as security experts warn that advances in artificial intelligence (AI) could rapidly expose long-standing weaknesses across software systems. The warning comes from National Cyber Security Centre (NCSC), which says businesses must act now to strengthen their environments before a surge of critical updates arrives. In a blog, Chief Technology Officer Ollie Whitehouse highlighted that years of accumulated technic
     

NCSC Warns Organisations to Act Fast as Hidden Software Flaws Surface

vulnerability patch wave

Organisations worldwide are being urged to prepare for a vulnerability patch wave, as security experts warn that advances in artificial intelligence (AI) could rapidly expose long-standing weaknesses across software systems. The warning comes from National Cyber Security Centre (NCSC), which says businesses must act now to strengthen their environments before a surge of critical updates arrives. In a blog, Chief Technology Officer Ollie Whitehouse highlighted that years of accumulated technical debt are now becoming a major cybersecurity risk. Technical debt refers to unresolved flaws and compromises in software that arise when organisations prioritise speed or short-term delivery over long-term resilience. According to Whitehouse, artificial intelligence is accelerating the problem. Skilled attackers are increasingly able to use AI tools to identify and exploit vulnerabilities at scale, forcing what the NCSC describes as a “correction” across the technology ecosystem. This is expected to trigger a vulnerability patch wave, with a high volume of security updates affecting open source, commercial, proprietary, and software-as-a-service platforms.

Prioritising External Attack Surfaces

As part of preparing for the vulnerability patch wave, the NCSC advises organisations to first focus on their external attack surfaces. Internet-facing systems, cloud services, and exposed infrastructure present the highest risk when new vulnerabilities are disclosed. The guidance recommends a perimeter-first approach. Organisations should secure outward-facing technologies before moving deeper into internal systems. This reduces the likelihood that attackers can exploit newly discovered weaknesses during the vulnerability patch wave. Where resources are limited, priority should be given to patching systems that are directly exposed to the internet. Critical security infrastructure should follow next. However, the NCSC cautions that patching alone will not solve every issue. Legacy and end-of-life systems remain a major concern. Many of these technologies no longer receive security updates, leaving organisations vulnerable even during a vulnerability patch wave. In such cases, businesses may need to replace outdated systems or bring them back into supported environments, especially if they are externally accessible.

Preparing for Faster and Large-scale Patching

The expected vulnerability patch wave will require organisations to rethink how they manage updates. The NCSC is urging businesses to prepare for faster, more frequent, and large-scale deployment of security patches, including across supply chains. Several key measures have been recommended:
  • Enable automatic updates wherever possible to reduce operational burden
  • Adopt secure “hot patching” to apply fixes without service disruption
  • Ensure internal processes support rapid and large-scale updates
  • Use risk-based prioritisation models such as Stakeholder Specific Vulnerability Categorisation (SSVC)
Whitehouse noted that organisations must be ready to accelerate patching timelines when critical vulnerabilities are actively exploited, particularly those affecting internet-facing systems. At the core of this approach is an “update by default” policy. This means applying software updates as quickly as possible, ideally through automated processes. While this may not always be feasible for safety-critical or operational technology systems, the NCSC says it should form the foundation of modern vulnerability management strategies.

Beyond Vulnerability Patch Wave: Addressing Systemic Risks

The NCSC emphasises that the vulnerability patch wave is only part of a broader cybersecurity challenge. Patching addresses immediate risks, but it does not eliminate the underlying causes of technical debt. Technology vendors are being encouraged to build more secure systems from the outset. This includes adopting memory safety and containment technologies such as CHERI, which can reduce the likelihood of exploitable vulnerabilities. For organisations operating critical services, strengthening cybersecurity fundamentals is equally important. Frameworks such as Cyber Essentials and sector-specific resilience models can help reduce the impact of breaches and improve overall security posture. Additional guidance has also been issued for high-risk environments, covering areas such as privileged access workstations, cross-domain security architecture, and threat detection through observability and proactive hunting.

Organisations Urged to Act Now

The NCSC has made it clear that preparation cannot be delayed. The anticipated vulnerability patch wave is expected to impact organisations of all sizes and sectors. Businesses are advised to review their vulnerability management processes, assess their exposure, and ensure their supply chains are also ready to respond. Larger organisations, in particular, are encouraged to seek assurance from both commercial and open-source partners. As Whitehouse concluded, readiness for the vulnerability patch wave will depend on proactive planning, strong fundamentals, and the ability to respond quickly at scale.
❌
❌