decrypted · 8 july 2026 · uk policy and law · ai and llm security
The UK builds an AI shield while attackers already have one
This week the NCSC set out its clearest vision yet for defending the UK with autonomous AI, in the same week that researchers documented a ransomware attack run almost entirely by one. Sysdig's account of the JadePuffer intrusion and the NCSC's new Cyber Shield blueprint make an unplanned but instructive pair: one shows what an AI agent can already do to a business once a single authentication check is missing, the other shows what government now thinks defenders need to keep pace. Layered underneath, a Microsoft SharePoint flaw patched in May is being actively exploited two months on, a reminder that most breaches still need nothing cleverer than a missed update.
A national AI shield, built carefully
The NCSC and the Department for Science, Innovation and Technology used a blog this week to sketch Cyber Shield, a blueprint for national-scale "agentic" cyber defence. The idea, first trailed by GCHQ director Anne Keast-Butler in May, is a network of AI "red" and "blue" agents: red agents hunting for weaknesses across UK infrastructure at machine speed, blue agents detecting and containing intrusions in real time, all operating under the authority of the organisations that own the systems rather than a central government kill switch. The NCSC is explicit that this sits on top of the basics, not instead of them, pointing organisations back to secure by design principles and its Software Security Code of Practice as the foundation any AI layer has to be built on. That is the right instinct. An autonomous defence agent bolted onto a legacy estate full of unpatched, badly segmented systems does not make that estate secure, it just makes the alerts arrive faster. The blueprint is still a consultation, not a product, and the NCSC is inviting industry and academia to help shape it. UK organisations, especially in critical infrastructure, should expect to be asked to take part rather than simply be told the outcome.
The attacker got there first
The urgency behind Cyber Shield is easier to understand next to Sysdig's write-up of JadePuffer, what the firm assesses to be the first ransomware operation conducted end-to-end by an AI agent rather than a human operator. The entry point was mundane: an internet-facing Langflow server, an open-source tool for building AI workflows, running with a code execution endpoint that had no authentication check at all. Once in, the agent harvested cloud credentials, enumerated storage buckets, wrote its own reasoning into its payloads as it went, and pivoted to a production database server. When one of its own backdoor attempts failed, it diagnosed the fault and shipped a working fix 31 seconds later. It ultimately encrypted 1,342 configuration records and demanded a ransom for a key that, tellingly, had never left the victim's own infrastructure and could not have been recovered regardless of payment. The Secure by Design lesson here has nothing to do with AI and everything to do with defaults: authentication on an admin or code-execution endpoint should never be optional configuration. Whatever else changes as attacks get faster, the fix for this specific intrusion was a checkbox that should have been ticked before the server ever faced the internet.
Patch clocks are not a suggestion
CISA added a SharePoint Server deserialisation flaw, CVE-2026-45659, to its exploited vulnerabilities catalogue this month, giving US federal agencies days to patch. Microsoft fixed it in an out-of-band update in late May, meaning organisations have had over a month to act before attackers caught up. Deserialisation bugs are a known bad pattern: they let an application be tricked into rebuilding attacker-supplied data into live code, and they turn up again and again in enterprise software because the underlying design, trusting a data structure to say what it is, is inherently fragile. CISA's remediation deadlines have no legal force in the UK, but they are a useful proxy for real-world attacker interest: if a flaw is serious enough to earn a KEV listing, it is serious enough to jump the patch queue here too. Any UK organisation running on-premises SharePoint should treat this as done, not pending.
Sources
- Cyber Shield: The path to an agentic AI future for cyber defence
- JADEPUFFER: Agentic ransomware for automated database extortion
- JadePuffer ransomware used AI agent to automate entire attack
- CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
- Known Exploited Vulnerabilities Catalog
- NCSC Touts National Scale, AI-Powered "Cyber Shield" for Defense
Thinking through what agentic AI, on either side of the fence, means for your own systems? Get in touch.
More like this
- A crafted email is all it takes to root Cisco's mail gateway 15 september 2026
- Revolut handed over customer data because an email looked official 15 september 2026
- The AI test that broke into a real company because it couldn't stop 11 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.