Skip to main content
☕ Zero to cyber hero
To:Brew Readers
How to turn help desk talent into a cybersecurity pro.
September 23, 2026View Online | Sign Up | Shop
Newsletter Logo

Presented By

Sponsor Logo: F5

Wonderful Wednesday! We hope no one taps you on your shoulder and says, “Can you take a look at this?” while you’re reading this email.

In today’s edition:

🖥️ Helping the help desk

❌ Acting brand new

🗣 All you had to do was ask

—Billy Hurley, Brianna Monsanto

IT STRATEGY

Shadowing IT

Accounting pipeline

Getty Images

Jim Sherlock found one of his best pen testers—the offensive-minded security pros who break down tech vulnerabilities—at the help desk.

Sherlock’s company at the time, the online learning-assessment platform Pearson, had to prepare for its busiest period of the year: school finals. Sherlock managed Pearson’s product operations before serving as director of information security, compliance, and tech innovation between 2015 and 2021.

While Pearson prepped for its academic equivalent of the Super Bowl, Sherlock noticed a help desk employee with a knack for capturing user traffic between students’ testing devices and Pearson’s system. That employee was adept at building scripts that replayed that activity, allowing the company to simulate hundreds of thousands of students logging in to take tests.

Understanding an application through the information it exchanges, beyond what appears in its interface, is valuable for both load testing and security testing. Sherlock noted the employee’s skill and steered him to the security side of the house.

Guiding help desk talent into a cybersecurity career.—BH

Sponsored By F5

Too much, but not enough

Sponsor: F5

There’s a lot of pressure to aggressively deploy AI. But with all those isolated and mismatched tools, you’re left with visibility gaps and operational overhead. Securing complex workflows with a fragmented patchwork of point products just doesn’t cut it.

Attackers use frontier AI to weaponize zero days in just hours. And waiting to patch after discovery isn’t enough anymore. Security needs to live inline, where the traffic flows.

F5 delivers a unified platform that spans the entire enterprise AI footprint, without requiring developer code changes. With one platform you can:

  • Discover every model, agent, and third-party integration running across your enterprise.
  • Inspect prompts and responses inline with 98.4% security efficacy, blocking jailbreaks and redacting sensitive data.
  • Attribute token spend by team and lower it by up to 60% with smart routing.

See what one platform can cover.

CLOUD

Agents gone rogue

Robotic hand shifting a mouse around the canvas in a circular motion

Francis Scialabba

Like the cookie tin that now houses sewing supplies at Nana’s house, most enterprises are witnessing agents do things outside of their original purpose.

According to an August report from Enterprise Management Associates for Cequence Security, 65% of companies said they’ve had an AI agent perform actions outside of its intended scope. Of those companies, 29.2% said these occurrences had a measurable impact (e.g., data exposure, financial loss, etc.) on their business. The findings are based on a survey of 202 global IT and security leaders at organizations deploying or evaluating agentic AI.

The governance problem. Cequence CISO Randolph Barr told IT Brew the high rate of unintended-action performing agents are a byproduct of governance and technical failures within organizations.

“A lot of organizations adopt AI quickly. They sometimes don’t have the proper controls in place to detect what these agents are doing, and on top of that, [are] assigning general access to these agents, not going through a review process and making sure that what the intention of an agent is…doing what it’s supposed to do,” Barr said.

The gaps holding organizations back.—BM

CYBERSECURITY

Ask away!

Computer with mouse arrows on a square grid

Francis Scialabba

Closed mouths don’t get fed—but open ones do, whether they are malicious or not.

A Noma Security researcher has discovered an AI workflow attack vector that enables cybercriminals to obtain sensitive information just by asking for it.

How it works. The vector, which was detailed in a Sept. 9 Noma Labs blog post, is known as “workflow identity hijacking,” and occurs when malicious actors send seemingly ordinary requests for sensitive information to unauthenticated entry points (think web forms or support inboxes) that generate a response via AI. In a workflow identity hijacking, an attacker, for example, may use an organization’s public support email to request and receive sensitive information from a finance director’s most recent email.

Sasi Levi, security research lead at Noma Labs, told IT Brew the security gap is a result of the AI workflow using privileges the attacker does not possess.

How it differs from prompt injections.—BM

Ransomware response game

Block the breach: an IT Brew interactive game

Morning Brew Design

Play through a live ransomware attack and make the calls real IT leaders face—negotiate, disclose, or dig in? An interactive breach simulator, not just another explainer.

Check it out

patch notes

Picture of data with

Francis Scialabba

Today’s top IT reads.

Stat: 3. That’s how many companies Google said its Gemini model hacked during a May security test. (Ars Technica)

Quote: “At this point, we can assume that all threat actors are using AI in some capacity, and their operations have benefited.”—John Hultquist, chief analyst at Google Threat Intelligence Group, in a statement on the current threat landscape (Cybersecurity Dive)

Read: Got a problem with your agent coworker? Take it up with robot relations. (CNBC)

AI, meet the light: You can’t govern what you can’t see. F5 discovers every model, agent, and integration across your enterprise. It secures everything inline on one platform. Scale without sacrificing protection. And let’s be real—C-suite will be satisfied.*

*A message from our sponsor.

Twitter Facebook LinkedIn Instagram YouTube TikTok

Written by Billy Hurley and Brianna Monsanto

Was this email forwarded to you? Sign up here.

Get smarter in just 5 minutes

Take The Brew to work

Interested in podcasts?

  • Check out ours here.
ADVERTISE//CAREERS//SHOP//FAQ

Update your email preferences or unsubscribe here.
View our privacy policy here.

Copyright © 2026 Morning Brew Inc. All rights reserved.
22 W 19th St, 4th Floor, New York, NY 10011

From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.

A mobile phone scrolling a newsletter issue of IT Brew