| How to turn help desk talent into a cybersecurity pro. |
 Presented By |  |
|
IT STRATEGY Shadowing IT  Getty Images | Jim Sherlock found one of his best pen testers—the offensive-minded security pros who break down tech vulnerabilities—at the help desk. Sherlock’s company at the time, the online learning-assessment platform Pearson, had to prepare for its busiest period of the year: school finals. Sherlock managed Pearson’s product operations before serving as director of information security, compliance, and tech innovation between 2015 and 2021. While Pearson prepped for its academic equivalent of the Super Bowl, Sherlock noticed a help desk employee with a knack for capturing user traffic between students’ testing devices and Pearson’s system. That employee was adept at building scripts that replayed that activity, allowing the company to simulate hundreds of thousands of students logging in to take tests. Understanding an application through the information it exchanges, beyond what appears in its interface, is valuable for both load testing and security testing. Sherlock noted the employee’s skill and steered him to the security side of the house. Guiding help desk talent into a cybersecurity career.—BH |
|
|
Sponsored By F5 Too much, but not enough  | There’s a lot of pressure to aggressively deploy AI. But with all those isolated and mismatched tools, you’re left with visibility gaps and operational overhead. Securing complex workflows with a fragmented patchwork of point products just doesn’t cut it. Attackers use frontier AI to weaponize zero days in just hours. And waiting to patch after discovery isn’t enough anymore. Security needs to live inline, where the traffic flows. F5 delivers a unified platform that spans the entire enterprise AI footprint, without requiring developer code changes. With one platform you can: - Discover every model, agent, and third-party integration running across your enterprise.
- Inspect prompts and responses inline with 98.4% security efficacy, blocking jailbreaks and redacting sensitive data.
- Attribute token spend by team and lower it by up to 60% with smart routing.
See what one platform can cover. |
|
|
CLOUD Agents gone rogue  Francis Scialabba | Like the cookie tin that now houses sewing supplies at Nana’s house, most enterprises are witnessing agents do things outside of their original purpose. According to an August report from Enterprise Management Associates for Cequence Security, 65% of companies said they’ve had an AI agent perform actions outside of its intended scope. Of those companies, 29.2% said these occurrences had a measurable impact (e.g., data exposure, financial loss, etc.) on their business. The findings are based on a survey of 202 global IT and security leaders at organizations deploying or evaluating agentic AI. The governance problem. Cequence CISO Randolph Barr told IT Brew the high rate of unintended-action performing agents are a byproduct of governance and technical failures within organizations. “A lot of organizations adopt AI quickly. They sometimes don’t have the proper controls in place to detect what these agents are doing, and on top of that, [are] assigning general access to these agents, not going through a review process and making sure that what the intention of an agent is…doing what it’s supposed to do,” Barr said. The gaps holding organizations back.—BM |
|
|
CYBERSECURITY Ask away!  Francis Scialabba | Closed mouths don’t get fed—but open ones do, whether they are malicious or not. A Noma Security researcher has discovered an AI workflow attack vector that enables cybercriminals to obtain sensitive information just by asking for it. How it works. The vector, which was detailed in a Sept. 9 Noma Labs blog post, is known as “workflow identity hijacking,” and occurs when malicious actors send seemingly ordinary requests for sensitive information to unauthenticated entry points (think web forms or support inboxes) that generate a response via AI. In a workflow identity hijacking, an attacker, for example, may use an organization’s public support email to request and receive sensitive information from a finance director’s most recent email. Sasi Levi, security research lead at Noma Labs, told IT Brew the security gap is a result of the AI workflow using privileges the attacker does not possess. How it differs from prompt injections.—BM |
|
|
Ransomware response game  Morning Brew Design | Play through a live ransomware attack and make the calls real IT leaders face—negotiate, disclose, or dig in? An interactive breach simulator, not just another explainer. Check it out |
|
|
patch notes  Francis Scialabba | Today’s top IT reads. Stat: 3. That’s how many companies Google said its Gemini model hacked during a May security test. (Ars Technica) Quote: “At this point, we can assume that all threat actors are using AI in some capacity, and their operations have benefited.”—John Hultquist, chief analyst at Google Threat Intelligence Group, in a statement on the current threat landscape (Cybersecurity Dive) Read: Got a problem with your agent coworker? Take it up with robot relations. (CNBC) *A message from our sponsor. |
|
|
Written by Billy Hurley and Brianna Monsanto Was this email forwarded to you? Sign up here. Get smarter in just 5 minutes Take The Brew to work Interested in podcasts? | ADVERTISE//CAREERS//SHOP//FAQ
Update your email preferences or unsubscribe here. View our privacy policy here.
Copyright © 2026 Morning Brew Inc. All rights reserved. 22 W 19th St, 4th Floor, New York, NY 10011 |
|
|