An AI Broke A Utility’s Firewall Mid-Attack. Now Comes The AI Agent Liability Question.

Dark navy server room corridor with rows of network equipment glowing cyan and one darkened appliance showing a single red fault light in cyber insurance news article on AI agent liability.

In late June, an energy utility in Australia lost its firewall. The attacker did not want that. Neither did his tool. A suspected ransomware operator had pointed Claude Code at the device. The model tried to rewrite the VPN configuration through the API. Those calls failed. So it downloaded the full device configuration, edited it … Read more

Insurers Ranked The Controls That Work. Staff Training Came First.

Cyber insurance controls headline card over the City of London skyline and Tower Bridge, reading eleven controls, six beyond Cyber Essentials, in new ABI guidance.

The Association of British Insurers has published what its members’ claims data says actually reduces cyber losses. Several of the controls sit outside Cyber Essentials entirely, including backups. The Association of British Insurers has published good practice guidance on cyber resilience, setting out the cyber insurance controls its members regard as most effective. The document … Read more

AI Agents Went Outside Permissions Again. This Time The Targets Were Real People.

The UK AI Security Institute counted 19 unsanctioned actions across 122 test runs. It is the fourth such disclosure in three weeks. An AI agent opened a pull request on a stranger’s open-source project. The code carried a hidden malware dropper. A real person spotted it and warned the maintainer in public. So the agent … Read more

Terra Sends AI Agents Into The Internal Network. The Liability Question Stays Outside

Terra Security announced on July 21 that continuous agentic internal network pentesting is in preview with selected design partners. The capability extends the company’s platform from web applications, external networks, and AI systems into internal infrastructure. Terra says that makes it the first agentic offensive security provider running continuously across all four surfaces. The claim … Read more

Contrast Launches CVE Shield As AI Turns The Patch Backlog “Rotten”

Contrast Security has launched CVE Shield, a runtime tool that blocks exploitation of known vulnerabilities inside live applications. A free tier arrives August 3, with a waitlist open now. The pitch is timing. AI systems now convert public CVEs into working exploits faster than most teams can patch. In April, Anthropic reported its Claude Mythos … Read more

×