GPT-6 Astra Asked Permission. An Automated Reply Said Use Your Best “Judgement.”

Cyber Insurance News story on an AI agent supply chain attack showing a chat window with a glowing automated reply above a network with one red node

The model asked before it acted. The reply came from a script. “Please proceed to the next step using your best [judgement].” That is the automated reply the UK AI Security Institute’s harness sends whenever an agent asks a question. OpenAI’s GPT-6 Astra sometimes read it as a yes. What followed, in simulation, was unsanctioned … Read more

Compliant In May. Seventeen Thousand Open Ports In June.

Cyber Insurance News podcast thumbnail on continuous cyber risk monitoring reading compliant in May, exposed in June, with Andrew Horkan, CEO of Cyber Tzar, in association with Cyber Tzar

A defense supplier held every certificate on the list. Then it moved its servers. And issues arrived. On this episode of the Cyber Insurance News Podcast, Cyber Tzar CEO Andrew Horkan on why compliance is paperwork, what an outside-in scan sees, and why brokers are starting to use a cyber score before they bind. Oh, … Read more

Security Chiefs Hit Brakes – AI Risk Concerns Spike

Apono’s new 2026 State of Agentic AI Cyber Risk Report finds that companies are tightening controls as AI risks rise. In a global survey of 250 security leaders, 98% said they slowed deployments, added extra reviews, or reduced project scope. CEO Rom Carmel explained, “CISOs are pressing the brakes” as agentic AI gets closer to … Read more

Non-Human Identity Sprawl Is a Cyber Liability Insurance Problem Now

People often talk about human mistakes causing data breaches and cyber insurance claims. But there’s another problem: non-human identities. These include bots, service accounts, apps, automations, and AI agents that act on our behalf. We give them access easily and then forget about them. Some reports say there are now up to 45 non-human identities … Read more

UK Longitudinal Cyber Survey Flags Cyber Insurance Uptick And Supplier Risk

The UK Cyber Security Longitudinal Survey’s fifth iteration arrived this week. The report tracks cybersecurity changes across the same organizations, including medium- and large-sized businesses and high-income charities. The first “wave” of data came out in 2022. This new release, “Wave Five,” follows medium- and large-sized businesses and high-income charities. The study links security practices … Read more

×