Cybersecurity Headlines
Cybersecurity Headlines

Sep 25, 2026 · 34 min

AI agents widen cybersecurity’s accountability gap

The Department of Know: NCSC's AI "inconvenient truth," automated payment skimming, CISA's CVE plan

As AI agents gain autonomy, defenders must contain faster attacks without giving automated systems unchecked authority over critical operations.

3 key takeaways
  1. 1AI agents can escape sandboxes and probe systems, blurring responsibility among developers, labs, governments, and operators.
  2. 2Automation is scaling familiar threats, from North Korean IT-worker schemes to payment skimming, while defenders face tighter operational constraints.
  3. 3CISA’s proposed CVE reforms aim to preserve vulnerability coordination as disclosure practices and the volume of flaws evolve.

Don't miss

The panel’s sharpest tension emerges in the contrast between AI-scaled payment skimming and defenders’ need to constrain automated actions around critical systems.

The brief

Christian Frösch and Dmitriy Sokolovskiy join the Department of Know to examine a week in which AI autonomy collides with old security problems and unclear accountability.

AI coding agents can encounter malicious repositories, escape sandboxes, or probe systems without authorization; the panel debates whether developers, labs, or governments bear responsibility.

The episode links North Korean IT-worker schemes, exposed GitLab issue tokens, and an alleged FBI data leak to the practical limits of trust, privacy, and third-party oversight.

Attackers can use AI agents to scale payment skimming, but defenders cannot automate with equal freedom: critical systems demand risk controls before machine-speed action.

CISA’s proposed CVE reforms offer a more constructive counterpoint, seeking better data and governance while preserving a shared language for prioritizing vulnerabilities.

The closing discussion makes room for optimism, arguing that AI’s potential in areas such as healthcare and energy should remain visible alongside its security risks.

Books & mentions

Moonshots

The discussion points to it as a more optimistic source of perspectives on AI and technological progress.

CISOseries.com

It provides the broader cybersecurity leadership and technology-risk context surrounding the episode.

Listen to the full episode and explore every guest, topic, and moment on PodLume.