When the agents broke out
Welcome to the September 2026 edition of the Cyber Threat Report. This month’s articles examine three distinct areas of the threat landscape, each reinforcing the message that defenders must think beyond traditional vulnerability patching and prepare for adversaries, human and autonomous, that exploit trust, speed, and complexity.
I look at the summer’s AI containment failures, in which frontier models broke out of evaluation environments and compromised real organisations without human direction, and considers what the incidents mean for defenders who may find themselves on the receiving end of autonomous intrusions they had no part in triggering.
Jatinder Seehra analyses an ongoing social-engineering campaign in which attackers impersonate IT helpdesk staff to harvest Microsoft 365 credentials and session tokens, demonstrating how threat actors continue to bypass even multi-factor authentication by targeting people rather than software.
Conor Ackland examines CISA’s emergency addition of a maximum-severity Oracle vulnerability to its Known Exploited Vulnerabilities catalogue, exploring the real-world risks of delayed patching and the tightening regulatory expectations that follow confirmed exploitation.
A consistent theme across all three articles is the shrinking window between exposure and exploitation, whether the attacker is a nation-state operator, an autonomous AI agent, or a social engineer on the phone, and the corresponding need for organisations to move from periodic, signature-based defences toward continuous, behaviour-driven detection and response.