Cyber Essentials — Issue #45 (07 Sep 2026)
AI agents, bug bounties and Langflow RCE put cyber risk back in the boardroom: push for AI-ready governance, budget control and Langflow exposure cleanup now
AI agents, bug bounties and Langflow RCE put cyber risk back in the boardroom: push for AI-ready governance, budget control and Langflow exposure cleanup now
A practical AI due diligence checklist for SaaS buyers. Thirteen questions you can realistically get answered, with the reasoning behind each one.
This week’s AI security and compliance brief for boards and security leaders: cheap Chinese chips, slow regulation, shifting cyber cover and rising infra risk.
A plain-English guide to what AI governance means, why it matters now, the core principles, and how organisations can put it into practice.
The NIS2 Directive raises the EU's cybersecurity baseline across 18 sectors, makes senior management personally accountable, and puts hard clocks on incident reporting. Here is what it requires, who it applies to, and how to prepare.
Shadow AI is quietly eroding AI security, compliance, and data governance. This article breaks down what it really is, why it’s worse than shadow IT, and how CISOs can take back control.
Ox Alpha appeared on OpenRouter on August 20, 2026. No flashy launch. No big tech logo. Just a ‘reasoning model for coding, long-horizon agentic work, and production workloads.
This issue connects a stealth new LLM, messy enterprise AI usage, looming EU transparency rules and fragile agent sandboxes into one pragmatic CISO threat picture.
AI is already in your estate. The only question is whether you discover it in an AI audit or an incident report.
This article breaks down five reasons governance teams are pivoting to self hosted models over ChatGPT style APIs, and two alternatives most overlook: SaaS with BYOK AI backends, and regional providers that satisfy residency requirements.
Swiss banks understood the risks of foreign infrastructure. AI now shows why data sovereignty must cover inference, not just storage.
A practical guide to where ISO 42001 helps, where the EU AI Act bites, and how to use both without building two separate programs.
Malicious LiteLLM releases reached PyPI for about 40 minutes. Here is what the incident reveals about dependency security and detection time.
OpenAI's gated cyber model, GLM-5.3's CyberGym lead, real agent breakouts, EU watermarking rules, and Grok Bot's "coworker" beta—plus what to watch next.
GLM-5.3’s CyberGym result points to faster vulnerability discovery, but we still need human oversight
Two new Apache Struts CVEs show how a bank‑built AI harness for Claude Opus 4.8 can find real, unauthenticated DoS flaws in the legacy Java frameworks powering global banking.
A Cursor coding agent wiped a production database and its backups through a valid API call. Traditional DLP could not catch it.
The EU Cyber Resilience Act mandates 24-hour reporting for actively exploited vulnerabilities from September 2026
From OpenAI's Daybreak to Anthropic's Glasswing: AI Has Accelerated the Wrong Half of Security
How a 60MB .map File Exposed Half a Million Lines of TypeScript — and What Happened Next
In the rush to "go AI," most small and medium-sized enterprises (SMEs) share a common misconception: “We aren’t tech developers, so we don’t need an AI strategy".
Staying Compliant from Outside the Union
AI agents can read your email, browse the web and execute code. Most small teams have no rules around any of it
But Sovereignty Is Still Mostly in American Hands