LIVE · cybersecurity feed
Live wire
Critical Zimbra RCE flaw now actively exploited in attacksExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2024-39943 · Operation CameraSwarm Compromised 14,000+ Dahua CamerasCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
ai

Managing the cyber risk of agentic AI

Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.

zeroday.news ·

The National Cyber Security Centre (NCSC) has released interim guidance for organizations deploying agentic AI systems, emphasizing the need for robust safeguards, sandboxing, and active oversight to mitigate risks associated with autonomous AI. This advice comes in response to several recent incidents where AI models and agentic systems performed unsanctioned or unintended activities.

Agentic AI systems, capable of automating complex workflows and enhancing productivity, pose significant risks if they malfunction, access unauthorized information, or act outside their intended scope. The NCSC's guidance is aimed at system designers and operators concerned about AI agents performing unintended actions due to instructions, available tools, or system access.

The NCSC recommends a proportionate approach to implementing controls, based on the level of autonomy an agentic AI system is designed to have. Systems with higher autonomy and potential impact require more stringent controls. Organizations must clearly define the acceptable level of risk to inform the design of these controls.

A critical first step is understanding the built-in safeguards of the AI model, inference service, and harnesses being used. While many AI models include mechanisms to prevent unwanted behavior, these controls should not be considered comprehensive. Model-level safety controls may be bypassed, may not offer adequate protection in high-risk environments, or might be insufficient to manage risks independently.

For applications where the consequences of failure exceed an organization's tolerance, additional safeguards beyond model or harness-level protections are essential. These can include classifiers, deterministic provers, and broader control measures. Regardless of built-in controls, all deployments should incorporate robust observability, operational monitoring, and incident response procedures.

Key considerations for secure deployment include documenting the intended scope of activity and identifying "red lines" that the agentic AI system must not cross. This proactive approach helps determine if an autonomous AI agent is appropriate for a given risk tolerance and what safeguards are necessary to manage associated risks effectively.

The NCSC acknowledges that AI cybersecurity is a rapidly evolving field and that best practices will continue to develop. The current advice is based on ongoing NCSC research and is intended to help organizations make informed decisions about securely deploying agentic AI systems. The NCSC is working with partners to develop more formal guidance, which will eventually supersede this interim advice.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. The post OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses appeared first on SecurityWeek.

malware

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]

security

Police Are Hiding Their Use of Flock Surveillance Cameras

A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy d

vulnerabilitycritical

Critical Zimbra RCE flaw now actively exploited in attacks

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]

phishing

Def Con Attendees Targeted by Persistent Phishing Campaign

Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con

security

US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign

The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute, […]