- Cybersecurity Docket
- Posts
- Five Cybersecurity Agencies Globally Publish Guidance on How to Safely Deploy AI Agents
Five Cybersecurity Agencies Globally Publish Guidance on How to Safely Deploy AI Agents
Plus., U.S. Treasury warns of AI-driven cyber threats to bank accounts

SPONSORED BY
Good morning! Here’s what’s up.

People
Usman Wahid has joined Three Points Law as partner. Usman joins the tech-enabled law firm from KPMG Law, where he was a partner and head of its technology and data legal team. At Three Points, his practice will focus on financial technology, as well as digital transformation and complex outsourcing projects.

Clips ✂️
US government, allies publish guidance on how to safely deploy AI agents
Cybersecurity agencies from the United States, Australia, Canada, New Zealand and the United Kingdom jointly published guidance Friday urging organizations to treat autonomous artificial intelligence systems as a core cybersecurity concern, warning that the technology is already being deployed in critical infrastructure and defense sectors with insufficient safeguards.
The guidance focuses on agentic AI — software built on large language models that can plan, make decisions and take actions autonomously. In order for this software to function it needs to connect to external tools, databases, memory stores and automated workflows, allowing it to execute multi-step tasks without human review at each stage.
…
The agencies’ central message is that agentic AI does not require an entirely new security discipline. Organizations should fold these systems into the cybersecurity frameworks and governance structures they already maintain, applying established principles such as zero trust, defense-in-depth and least-privilege access.
US Treasury Warns of AI-Driven Cyber Threats to Bank Accounts
Treasury Secretary Scott Bessent has raised the alarm on escalating cybersecurity risks, warning that artificial intelligence could be weaponized to hack into bank accounts across the US financial system. Speaking on Fox News’ Sunday Morning Futures, Bessent emphasized that both financial and technology companies are actively bolstering their defenses against these emerging threats.
The urgency of the issue came into sharp focus during short-notice discussions held in Washington in April. Bessent, alongside Federal Reserve Chair Jerome Powell, convened with Wall Street leaders to address specific concerns tied to Anthropic’s latest AI model. The fear is that this technology could usher in an era of heightened cyber risk, potentially exposing vulnerabilities in banking infrastructure.
Bessent’s public statements underscore a broader push to safeguard the financial sector. “We’re going to make sure that things stay safe,” he assured viewers, signaling a proactive stance from the Treasury as AI capabilities continue to advance at a rapid pace.
Bizarre moment at Berkshire's annual meeting spotlights cyber risk
Berkshire Hathaway’s annual shareholder meeting was destined to be interesting as the first without its now-retired CEO, Warren Buffett, MC’ing the event.
But Buffett, who remains chairman of Berkshire’s board, made a few cameos. One of them was pretty eerie.
Kicking off the Q&A on Saturday morning, the spotlight went to a video where “Warren from Omaha” asked the first question:
Hi. My name is Warren from Omaha. I’ve recently undergone, let’s call it, a significant change in role. And I have, well, let’s just say, a not insignificant portion of my net worth tied up in Berkshire stock. … And I want to know, just so I have something to tell my fellow shareholders: Why should they hold their Berkshire shares for the long term?
The fun moment quickly turned serious when CEO Greg Abel informed the audience that it wasn’t Warren Buffett.
Spotting third-party cyber risk before attackers do
In this Help Net Security video, Jeffrey Wheatman, SVP and Cyber Strategist at Black Kite, discusses how organizations can identify and manage third-party cyber exposures before attackers exploit them.
He argues that businesses should move beyond a data-loss mindset toward one centered on resilience, meaning keeping operations running when vendors or partners get hit.
Wheatman walks through practical steps: engaging business stakeholders early, scoping which third parties are business critical, retiring outdated questionnaire-based assessments, and running quick pre-assessments tied to data sensitivity and breach history. He covers concentration risk, cascading exposures from fourth and fifth parties, and governance gaps that leave key decisions unowned.
Over 40,000 Servers Compromised in Ongoing cPanel Exploitation
More than 40,000 servers have likely been compromised as attackers ramp up exploitation of a recently patched cPanel zero-day.
As part of the ongoing campaign, non-profit organization The Shadowserver Foundation says threat actors are exploiting CVE-2026-41940, a critical authentication-bypass vulnerability in cPanel & WebHost Manager (WHM), a server and site management platform.
Disclosed on April 28, the security defect provides unauthenticated attackers with administrative access to cPanel, allowing them to take over the host system and compromise all configurations, databases, and websites the platform manages.
The issue can be exploited via special characters in authorization headers to write parameters to a session file, then trigger a reload of the session file to authenticate using the injected administrative credentials.
CVE-2026-41940 was likely exploited as a zero-day since late February, with activity spiking after the public disclosure and after the threat intelligence firm WatchTowr published technical details.
Instructure confirms data breach, ShinyHunters claims attack
Educational tech giant Instructure has confirmed that data was stolen in a cyberattack, with the ShinyHunters extortion gang claiming responsibility.
Instructure is a U.S.-based education technology company best known for developing Canvas, a widely used learning management system that helps schools, universities, and organizations manage coursework, assignments, and online learning.
On Friday, Instructure disclosed that it suffered a cybersecurity incident and is working with third-party cybersecurity experts and law enforcement to investigate it.
On Saturday, the company issued an update stating that the personal information of users was exposed in the breach.
"While we continue actively investigating, thus far, indications are that the information involved consists of certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages among users," reads the updated statement.

SPONSORED BY

Incident Response Forum London 2026 is set for Thursday, June 4, 2026, at the Four Seasons Hotel London at Park Lane!
Incident Response Forum London (and its U.S. counterparts in D.C. and L.A.) are the only conferences of their kind, bringing together hundreds of cybersecurity and incident response attorneys, in-house counsel and compliance executives, and other top professionals in the field. This event focuses solely on the field of Incident Response – the work that begins after a data breach that has quickly become the fastest growing practice area at law firms and consulting firms – and is geared specifically for the legal and compliance professionals who have emerged as critical players during the aftermath of a data security incident.
Incident Response Forum London will feature over 30 leaders in the incident response field serving on eight panels.
🚨This week only we are giving away five free tickets to Incident Response Forum London! 🚨
If you are in London or if you can make it there on June 4, please hit reply to this email (it will go directly to me) and let me if you would like to attend!