Plus: Coding agents exposed internal data on GitHub ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
Zero Trust Weekly

This week in Zero Trust

Policy is only as strong as the controls enforcing it

Estimated reading time: 5 minutes

 

In this issue:

  • The EU AI Act is here. What should security teams do now?
  • Policy says what should happen. Controls enforce it
  • How a workstation becomes a file server problem
  • Threats: Coding agents expose internal company data and malicious Custom GPTs used in ClickFix campaign
View in browser

Manage preferences

From the CEO

Connecting IT and OT needs to be strictly monitored

 

"Organizations should focus on maintaining clear security boundaries as these environments become increasingly connected: segmenting networks, limiting communications between systems, ensuring applications can only perform approved actions, and applying least privilege consistently across both operational and corporate environments. Physical systems may now share data with cloud services and AI platforms, but they shouldn’t automatically share trust. " - Danny Jenkins

From the ThreatLocker blog

 

What the EU AI Act means for your security team

High-risk AI systems face new cybersecurity requirements

 

The EU AI Act introduces cybersecurity requirements that vary based on how AI is used and an organization's role. For high-risk systems, requirements include risk management, access controls, logging and traceability, human oversight, monitoring, and incident response, and rules begin applying December 2027. The Act applies to deployers located in the EU and where the system's output is used in the EU.

 

Don't wait for the deadline. Inventory your AI systems, map their permissions, control what they can access and execute, and make sure you can prove those safeguards work.

 

See the EU AI Act requirements

Turning governance rules into technical controls

Policy defines what should happen—controls determine what is actually allowed

 

Policies do not enforce themselves, and vague rules such as "use AI responsibly" give security teams little to technically enforce. To close the gap between policy and execution, organizations need to translate expectations into specific, enforceable controls. 

 

Effective policies should specify the system, data, user, action, and conditions involved. This way, they can be tested, monitored, and enforced while preventing AI tools from operating outside their intended boundaries.

Turn AI policy into control

The problem with always-on access

Ransomware does not need unlimited power if the environment gives it unlimited access

 

Remote encryption is often a workstation issue that becomes a file server problem. If a compromised workstation can reach a share and write to the files, ransomware may be able to encrypt them remotely. Write access can be enough to cause a problem. 

 

Access should come with an expiration date. Instead of leaving access continuously available, organizations should limit when devices can reach sensitive files and remove access when it is no longer needed.

Three steps to reduce remote encryption risk
Zero Trust World 2027 · Say no to malicious activity. Learn control at 2027's premier Zero Trust event · Register now

Webinars

 

Oct 27 · Privilege escalation: The attack path most security tools overlook

 

How attackers expand access and how to stop them with new ThreatLocker elevation control features.

 

Register now

 

On demand · Debunking the cybersecurity myths that leave you exposed

 

Will the AI kill switch work how we think? Do more controls equal stronger security? And are longer, more complex passwords enhancing account security?

 

Watch now

Threats you need to know

 

AI coding agents exposed internal company data on GitHub

More than 13,000 images from 300+ organizations were reportedly exposed

  • What's happening: Researchers found that AI coding agents asked to share code changes for review uploaded internal company images to public GitHub repositories, including screenshots of unreleased features and customer billing records. Most images appeared under developers' personal accounts, putting them outside their organization's visibility. 

  • What defenders need to know: Don't rely on individual developers to configure AI agents safely. Centrally control what agents can publish externally, and require human approval before an agent creates a public repository or changes a private repository to public.

Attackers abuse custom GPTs to deliver RAT via ClickFix lures

Victims reportedly interacted with attacker-created Custom GPT

  • What's happening: Researchers observed users interacting with a malicious custom GPT hosted on the legitimate ChaptGPT website. The GPT was reportedly programmed to respond to prompts with a Google Sites link that initiated a ClickFix-style attack and ultimately delivered a remote access trojan (RAT).

  • What defenders need to know: The attack reportedly began with sponsored search results for "chatgpt" on Google. Users should avoid sponsored links when accessing AI tools and use caution when given instructions asking them to copy, paste, or run commands. Consider restricting command interpreters and scripting tools to users and applications that actually need them.

Upcoming events

 

Meet the ThreatLocker team next week in:

 

Munich · Barcelona · Charlotte · San Diego · Buenos Aires · Atlanta

 

See all upcoming events
ThreatLocker: Zero Trust Platform | Zero Trust Weekly

ThreatLocker, 1901 Summit Tower Blvd, Orlando, Florida 32810, United States

Manage preferences

Connect with us

                             

©2026 ThreatLocker Inc., All Rights Reserved