Lumith
ServicesWorkPricingEnterpriseAIAboutContactGet a quote Call 07309 825064
All issuesAI Brief · 27 August 2026

The one risk everyone says they are ready for

Risk executives have put AI-driven discovery of software flaws at the top of their list for the first time, and in the same breath called it the risk they feel best prepared for. Meanwhile a phishing kit is turning fake job interviews into stolen company logins, and a critical flaw patched in July is being exploited now.

  1. 01

    AI finding software flaws is now the top emerging risk, and nobody seems worried

    Gartner put its quarterly emerging risk question to 316 senior risk and audit executives during April and May, and for the first time the highest-impact answer of twenty was AI-enabled discovery of software vulnerabilities. Respondents scored it at 1.92 on a scale where one means the impact lands within a year and two means one to two years, so this is a near-term worry rather than a forecast. Senior principal analyst Kevin Mercado warned that without matching improvements in governance and remediation, AI-driven discovery may simply outpace the defences. The odd part, noted in coverage of the report, is that the same executives rated it the risk they feel most prepared for.

    Gartner
  2. 02

    A phishing kit turns fake job interviews into stolen company logins

    Zimperium published research on 24 August into a campaign it calls RecruitTrap, where attackers scrape public profile data, pose as HR staff at names like Amazon, Apple, Deloitte and Boeing, and walk the target through a realistic interview scheduling flow that ends on a login page. The kit refuses personal email addresses and only accepts corporate ones, because the prize is OAuth tokens and access to internal systems rather than somebody's private inbox. On a phone the usual desktop trick of faking a browser window is replaced with a full-screen counterfeit login, so there is no address bar left to check. Zimperium logged 46 previously unpublished indicators of compromise across a year of telemetry.

    Zimperium zLabs
  3. 03

    A Gitea flaw patched in July is being exploited now

    CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities catalogue on 25 August and gave US federal agencies until 28 August to remediate. The flaw sits in the self-hosted Gitea code platform, rates 9.8 on the CVSS scale, and lets anyone with ordinary write access to a repository send a malicious patch that plants a Git hook and runs shell commands as the service account. Gitea fixed it in version 1.27.1 back in late July. Reported cases so far ended in crypto-mining software on the compromised server, which is the cheap outcome rather than the worst one.

    CISA
  4. 04

    Meta settles with 29 states and agrees to time caps on teen accounts

    A proposed settlement was filed in a California federal court on 26 August, ending a trial brought by 29 states over claims that Facebook and Instagram were built to hook young users. Reported totals vary between roughly 16.7 and 18 billion dollars because about 30 per cent of it only gets paid if YouTube and TikTok agree to match the money and the restrictions. Teen accounts get a default two-hour daily cap across Meta apps, with messaging and long-form video excluded, plus a lockout between midnight and six in the morning, age checks aimed at removing under-13s, and ten years of independent auditing. Meta admitted no wrongdoing and a judge still has to approve it.

    NBC News
  5. 05

    Amazon is closing Mechanical Turk on 30 September

    A notice on the Mechanical Turk site confirms the platform closes permanently on 30 September, following what Amazon describes as an assessment of its programmes and services. Launched in 2005, it paid people small amounts to do the tasks software could not manage, transcription, tagging, survey answers, and it quietly supplied a lot of the labelled data the current generation of models learned from. Amazon stopped taking new customers last month, so the announcement on 25 August confirmed what workers had already assumed. Anyone still running work through it has about five weeks to move it and get their payment settings in order.

    Amazon Mechanical Turk
  6. 06

    Google puts Gemini inside Chat, with higher limits until October

    Google started rolling out Ask Gemini in Chat on 26 August, a prompt inside Google Chat that searches across Gmail, Drive and Calendar, drafts content, summarises threads and books meetings without leaving the conversation. It covers Business Standard and Plus, Enterprise Standard and Plus, and the education add-ons, and reaches everyone over roughly a fortnight. Until 1 October there is promotional access to higher usage limits, after which standard limits apply. It is on by default where Gemini in Chat and Workspace Intelligence are already enabled, so this is a setting to look at rather than one to switch on.

    Google Workspace
Maksim's take

Two answers in the Gartner survey contradict each other. Risk and audit executives put AI-enabled discovery of software flaws at the highest impact of twenty emerging risks, scoring the damage as landing inside two years, and then rated it the risk they feel best prepared for. Both cannot be true. When a group calls something the biggest thing coming and also says they have it covered, the confident half is usually the one doing the lying, because feeling prepared costs nothing and being prepared shows up on a budget line.

What actually changed is volume, not cleverness. Finding a flaw used to take a person with time and motive, which meant most software running in most small firms was protected by being too dull to bother with. Automate the finding and that protection disappears, because scanning everything costs about the same as scanning something worth the effort. This week's Gitea case is the shape of it: fixed in late July, being used on live servers by late August, with a US federal patch deadline three days after the warning. From direct experience in construction I know that the jobs which go wrong are rarely the ones nobody thought about, they are the ones everybody assumed somebody else had in hand. Ask who patches your servers, your website and your accounts software, and ask when they last did it. If the answer takes more than a minute to establish, that is the finding.

Discuss on LinkedIn

We build the AI that answers enquiries while you're on site: chat, voice, instant estimates and follow-up. See how it works or price it in two minutes.

Earlier issues