Access Expands. Accountability Must Keep Pace
Cyber This Week Edition 109 explores OAuth consent abuse, identity weaknesses, social engineering, aviation cyber losses, agentic SOCs, AI governance, AI-driven security operations, agent security, capability gaps, and ransomware’s human impact.
Cybersecurity risk is increasingly shifting from simply protecting accounts and systems to governing who—or what—can act inside them. This edition of Cyber This Week examines OAuth consent abuse, persistent identity weaknesses, social-engineering failures, agentic SOCs, AI-driven security operations, and the growing challenge of controlling autonomous agents with legitimate access. At the same time, accountability must extend beyond security teams. Legal, procurement, compliance, leadership, and human resilience all matter as AI adoption expands and ransomware continues to affect both systems and people. Stronger governance, clearer ownership, constrained automation, better skills, and human oversight are becoming essential to keeping access from turning into uncontrolled risk.

This Week's Articles
- 01Dark Reading
MFA Won't Save You from OAuth Consent Abuse
MFA does not prevent users from authorising malicious or excessively privileged OAuth applications through legitimate consent screens. Such permissions can provide persistent API-based access to email, files, cloud environments, and business applications without stealing passwords or deploying malware. Organisations should restrict user consent, enforce least-privilege scopes, require admin approval for high-risk applications, monitor grants, and revoke suspicious tokens quickly.
Why it mattersMFA protects authentication, but it does not stop a user from granting dangerous permissions to a malicious application. OAuth consent therefore needs its own governance, monitoring, and revocation controls.
- 02Cybersecurity Dive
Manufacturers Make Patching Progress, but Identity Management Still Major Weakness
Black Kite research finds that manufacturers have improved patching but remain exposed through identity, credential, remote-access, and configuration weaknesses. The findings highlight the need to combine patching with stronger IAM, exposed-service reduction, credential protection, and supplier-risk controls.
Why it mattersImproved patching does not eliminate risk when identity, credentials, remote access, and configuration remain weak. Manufacturing security requires broader exposure reduction, not patching alone.
- 03The Wall Street Journal
Europe’s Most Valuable Startup Gave Data to a Scammer. Now It Faces a Shakedown.
The article reports that Revolut disclosed customer data to a person allegedly impersonating a government agency, followed by an extortion demand. The incident shows that sensitive-data exposure can result from social engineering and weak verification, not only technical compromise. Stronger authentication of official requests, dual approval, data minimisation, and audit trails are important safeguards.
Why it mattersSensitive data can be exposed through a convincing request even when systems are not technically compromised. Verification, dual approval, minimised disclosure, and auditable processes are essential.
- 04SecurityInfoWatch
Aviation Organizations Report $1.4M Average Loss From Cybersecurity Breaches
A Bridewell survey reports average cyber losses of $1.4 million among aviation organisations in the past year. Phishing, malware, credential theft, and DDoS incidents were widespread, while concerns were especially high around airport operations and suppliers. The findings reinforce the need for stronger identity protection, third-party assurance, and aviation-specific cyber capability.
Why it mattersAviation depends on interconnected operators, suppliers, identities, and operational systems. Cyber losses can therefore extend beyond a single organisation and disrupt a wider ecosystem.
- 05CPO Magazine
The Agentic SOC Won’t Win on Automation Alone
Agentic SOCs can use AI agents to enrich alerts, gather evidence, investigate activity, and perform multi-step security tasks. However, successful automation also requires reliable data, tightly controlled access, clear escalation thresholds, human accountability, and measurable outcomes. Organisations should begin with constrained tasks before allowing agents to perform high-impact actions.
Why it mattersAgentic security operations need more than automation. Reliable data, least privilege, escalation rules, measurable outcomes, and accountable human oversight are necessary before agents are trusted with higher-impact actions.
- 06Lexology
AI Cyber Risk: Why Legal Teams Need to Look Beyond Attackers
AI introduces cyber risk through external AI-enabled attacks, unsafe internal use, and third-party AI suppliers. The article argues that legal, security, privacy, procurement, and compliance teams must manage AI as a cross-functional risk, supported by AI inventories, vendor due diligence, contractual controls, and clear incident-response obligations.
Why it mattersAI risk crosses legal, security, privacy, procurement, and compliance boundaries. Effective governance therefore needs shared ownership, inventories, vendor controls, contracts, and clear incident obligations.
- 07CSO Online
AI Made Software Development Unrecognizable. Is Cybersecurity Next?
The article explores how AI could reshape cyber defence through automated triage, vulnerability prioritisation, faster containment, and smaller teams focused on judgement and oversight. It recommends starting with bounded, repeatable tasks while maintaining least-privilege access, human escalation, agent inventories, and continuous monitoring.
Why it mattersAI can accelerate security operations, but safe adoption requires bounded tasks, least privilege, human escalation, agent inventories, and continuous oversight rather than unrestricted automation.
- 08The Register
Agentic Security Is the Billion-Dollar Challenge for Some Clever Startup to Solve
The article argues that enterprises are adopting AI agents faster than they are securing them. Key gaps include agent discovery, identity, permissions, behavioural boundaries, monitoring, and auditability. The immediate need is for governance systems that can continuously control what AI agents access, decide, and execute.
Why it mattersOrganisations cannot govern agents they cannot discover or identify. Agent identity, permissions, behaviour, monitoring, and auditability are becoming foundational security requirements.
- 09InformationWeek
The Cybersecurity Skills Gap Is About More Than Head Count
The article argues that cybersecurity risk is increasingly driven by capability gaps, not just staffing shortages. It highlights security culture, internal talent development, specialist expertise, and AI literacy, while noting that skilled professionals remain essential to validate AI outputs, understand business context, and make accountable risk decisions.
Why it mattersClosing the cybersecurity skills gap is not simply about hiring more people. Organisations need the right capabilities, culture, specialist expertise, AI literacy, and professionals able to make accountable decisions.
- 10Security Magazine
Ransomware Doesn’t Just Break Systems. It Breaks People.
The article highlights the human consequences of ransomware, including prolonged stress, burnout, fear, reputational anxiety, and pressure on incident-response teams, leaders, customers, and communities. Cyber-resilience programmes should therefore include crisis communications, employee support, clear leadership roles, and recovery-team wellbeing alongside technical response plans.
Why it mattersCyber resilience must account for people as well as technology. Crisis communication, leadership clarity, employee support, and recovery-team wellbeing can materially affect an organisation’s ability to recover.
