If you just remember one thing from this briefing…
A Spanish regulator has logged a data breach where the actor was an AI agent, not a person.
On 14 September the AEPD recorded Spain's first breach notification naming an autonomous LLM-based agent as
the actor: it read untrusted input, touched personal data and modified invoices with no human sign-off —
precisely the pattern its own February guidance warned against. Ask this week: which of our production
agents could do all three at once?
Priority25 Sep
Exploited SharePoint code-injection flaw lands in CISA's KEV, deadline 28 September
CVE-2026-65660, patched in August as a moderate spoofing bug, was reclassified to CVSS 8.8 code injection
after Microsoft confirmed active exploitation. CISA added it to the KEV catalogue on 25 September, with a
28 September deadline for on-prem SharePoint Server 2016, 2019 and Subscription Edition.
So what: having August's patch isn't enough — check for post-exploitation
indicators, since attacks predate CISA's listing.
Priority14 Sep
Spain's AEPD logs the first GDPR breach notification naming an AI agent as the actor
A third party's autonomous LLM agent probed an application, achieved unauthorised login, then modified
personal data and invoices unsupervised. AEPD's own "Rule of 2" — untrusted input, sensitive data and
autonomous action must never combine — predicted exactly this failure mode.
So what: GDPR breach duties already reach AI-agent incidents, independent of the AI
Act timeline. Map which agents meet all three conditions.
Watch10 Sep
AWS patches critical SSRF in Systems Manager Agent; Google Cloud quiet this fortnight
CVE-2026-89049 (CVSS 8.5) let an authenticated port-forwarding user bypass Session Manager's destination
denylist, reach link-local endpoints and obtain an instance's IAM credentials. AWS fixed it in SSM Agent
3.3.4851.0; not yet in KEV, no confirmed exploitation. Google shipped only routine bulletins.
So what: confirm SSM Agent auto-update is enabled fleet-wide — pinned versions
would miss this silently.
Watch1 Oct
Exchange Web Services blocks third-party apps from 1 October
Microsoft blocks EWS requests from non-Microsoft applications to Exchange Online from 1 October, and
removes programmatic public-folder APIs alongside it. Older reporting, migration and archiving tools that
still call EWS stop working with no further warning after that date.
So what: inventory anything still calling EWS or public-folder APIs now — migrating
to Graph after 1 October means unplanned downtime.