All issues
Tech & Security Intelligence ● Issue 018 · 28 Sep 2026

The Weekly
Brief

The NCSC’s annual threat report lands with a blunt message for business leaders: AI is coming for the attack side first. Medium-sized firms are now the ones getting hit. A WordPress hole was being probed within hours of its fix. And Microsoft wants Copilot to stop answering questions and start doing the work.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 8 min read

In this issue

01 NZ Threat Report

369 serious incidents, and the NCSC’s message to every business leader: prepare for AI now

On 24 September the National Cyber Security Centre released its Cyber Threat Report 2026, covering July 2025 to June 2026. It handled 369 incidents of potential national significance — the serious end, not the everyday phishing email. 86 of them had suspected links to state-sponsored actors, and the NCSC named the People’s Republic of China as the most persistent and capable state actor operating in New Zealand, alongside activity linked to Russia, Iran and North Korea. The targets it listed are worth reading slowly: government agencies, health and education organisations, and IT managed-service providers — the companies that hold the keys to everyone else. China’s foreign ministry rejected the finding.

The criminal side grew too. 162 incidents were tied to criminal or financially motivated actors, up 18% on the year before, and four were rated “highly significant” — as many as in the previous ten years combined. The report also calls out North Korean IT workers landing remote jobs with New Zealand businesses under false identities to earn money for the regime. But the headline the NCSC chose was about AI. Its warning is that the next generation of frontier AI models could automate attacks, find vulnerabilities and personalise targeting, and that those capabilities may be widely in attackers’ hands by early 2027. Readers of Issue 017 have already seen what that looks like: an AI agent swarm through 440 print servers in days.

02 Small Business

Three in four NZ businesses with 20–49 staff were hit in six months

Three days before the threat report, on 21 September, the NCSC published its SME Cyber Security Behaviour Tracker 2026, and the number that stands out is about medium-sized firms. 76% of businesses with 20 to 49 employees said they had experienced a cyber threat or attack in the previous six months, against 53% of SMEs overall. Of the medium-sized businesses that were hit, 44% reported moderate to severe impacts — money lost, devices damaged, a lot of stress. Owners have noticed: 43% of SMEs now say they feel vulnerable to cyber attack, up from 34% in 2025, rising to 59% among firms with 20–49 staff.

The gaps are familiar. 32% of SMEs take no action at all to train staff in cyber security. Among businesses that faced a threat, 32% did not report it to anyone, mostly because they judged it insignificant (58%) or saw no value in reporting (51%). And AI-enabled threats — AI-written scams and deepfakes — have climbed to the fourth most top-of-mind concern. The NCSC’s acting deputy director-general, Kevin Moar, pointed back to the fundamentals: keep software up to date, use multi-factor authentication, back up important data, and make sure staff can recognise a threat when it arrives.

03 Patch Now

A critical WordPress flaw was under attack within hours of the fix

WordPress, which runs a large share of small-business websites in New Zealand, shipped a security release, version 7.1.2, on 22 September, with patched versions for every branch back to 4.7. It fixes CVE-2026-87902, rated 9.2 on the CVSS 4.0 scale: an unauthenticated path traversal in get_page_template(), the function that chooses which theme file draws a page. In plain terms, an attacker with no login can trick WordPress into running a PHP file of their choosing that is already on the server, and in the right conditions that becomes full remote code execution — control of the site. Everything from 4.7.0 to 7.1.1 is affected.

There are conditions. The active theme (or its parent) has to contain a top-level folder whose name begins with page-, such as page-templates — WordPress itself lists the old Twenty Twelve and Twenty Fourteen themes and popular third-party themes including Neve, Hestia and Sydney as examples — and the server needs a suitable PHP file lying around to abuse. Attackers did not wait to find out who qualified. Security firms recorded exploitation attempts within hours of disclosure, trying to write malicious PHP files onto servers; Patchstack confirmed the traffic had moved from reconnaissance to active exploitation. New Zealand’s NCSC issued an alert on 24 September, and the US agency CISA added the flaw to its Known Exploited Vulnerabilities list the next day.

04 AI & Microsoft 365

Microsoft’s new Copilot wants to be a colleague, not a chat box

On 25 September Microsoft announced what it calls its biggest Copilot update yet, with Satya Nadella pitching Copilot as a “new OS for work”. There are four parts. Home merges the quick-question Chat with Cowork, where longer jobs are handed off, into one starting screen. Office puts Word, Excel and PowerPoint inside Copilot, so documents are created and edited there. Code lets people with no development background build small apps, trackers, dashboards and automations by describing them in plain language, using the same technology as GitHub Copilot and running in a sandbox hosted inside the organisation’s own tenant.

The part that changes the conversation is Autopilot: a persistent agent with its own identity, memory and workspace that takes on recurring tasks and long-running projects, following up on threads and picking work back up days later without being prompted again. Microsoft’s pitch is that you give it a name, a role and a goal. None of this is in most tenants yet. Home and Code start in Microsoft’s Frontier early-access programme, with broader availability promised in the coming weeks, and Autopilot is expanding to a private preview. Microsoft mentions per-user licences for everyday AI and usage-based billing for agent work, plus admin controls for cost and for which AI models different groups can use, but has not yet said which Microsoft 365 plans will include what.

Tip of the week

A fifteen-minute scam briefing for your team — this week

A third of New Zealand SMEs do no cyber training at all, and it does not need to be a course. Put fifteen minutes on the agenda at your next team meeting and cover three scams, one rule and one habit. The three scams: the tax-refund or toll text pretending to be IRD or NZTA (Inland Revenue does not send links to log in to myIR); the “our bank details have changed” email from a supplier, which is how most business money is actually lost; and the urgent favour from the boss — gift cards, a quick payment, “I’m in a meeting, just do it” — which now sometimes arrives as a convincing voice message. The rule: any change to bank details, and any unusual payment request, is confirmed by phone on a number you already had — never the number in the email. Say out loud that nobody gets in trouble for checking, including checking with the boss. The habit: if something feels off, forward it and ask, and make it obvious who to ask. Close by asking the room whether anyone has had something odd lately; you will almost always hear about one. Those are the incidents that never get reported, and they are how you learn what is actually aimed at your business. Managed clients: forward anything suspicious to us and we will take a look.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup