AI Agents & Security Risks

⚠️ Some links on this site are affiliate links. If you buy through them, we earn a small commission at no extra cost to you. This never influences our reviews.

Welcome back to the itpick weekly roundup — your no-nonsense guide to what’s actually happening in tech and why it matters if you run a small business or just want to keep your home setup safe. Grab a brew; here’s what caught our eye this week.

AI Agents Are Getting a Bit Too Big for Their Boots

There’s been a lot of excitement about AI agents — software that doesn’t just answer questions but actually goes off and does things on your behalf, booking meetings, running reports, firing off emails. Sounds brilliant. The catch? A new survey of enterprise tech teams has found that roughly one in five large organisations has no way to stop an AI agent from racking up costs in real time if it goes rogue. That’s a lot of trust to hand over to something that can spend your budget faster than an intern with a company card.

Separate research backs this up. The companies actually getting good results from AI agents aren’t the ones giving them the most freedom — they’re the ones putting sensible guardrails in place and keeping humans in the loop for anything that matters. Less “fully autonomous AI overlord”, more “very capable assistant who still needs sign-off on the big stuff.”

If you’re using AI productivity tools like Notion or Grammarly to help run your business, you’re probably fine — these are assistants, not autonomous agents. But if you’re eyeing up more powerful agentic tools, it’s worth thinking carefully about what permissions you hand over and whether you can pull the plug quickly if something goes sideways.

What this means for you: Don’t give any AI tool more access to your accounts, files, or payment methods than it absolutely needs — treat it like a new member of staff on probation.

A Trojan Hiding in Handy-Looking Code Packages

This one’s more technical but worth knowing about, especially if anyone in your team writes code or uses developer tools. Security researchers uncovered fourteen malicious packages hiding in npm — a hugely popular library of reusable code that developers pull into their projects every day. These packages looked like legitimate calendar and productivity utilities, but once installed, they quietly dropped a backdoor onto the host machine.

What makes this particularly nasty is that the backdoor — dubbed RedC2 4.0 — uses AI to help manage its communications with the attackers, making it harder to detect with traditional security tools. It targets Linux systems, so Windows and Mac home users aren’t directly in the firing line here, but the broader lesson stands: supply chain attacks (where the bad stuff hides inside tools you trust) are becoming more sophisticated.

If your small business relies on any open-source or third-party software, keeping everything updated and running decent endpoint security is non-negotiable. Mac users in particular might want to look at something like Intego, which is built specifically to catch threats targeting Apple systems.

What this means for you: Be cautious about where your software comes from, and make sure your security tools are up to date — even “boring” developer utilities can carry nasty surprises.

Microsoft Defender’s Own Driver Turned Against It

Here’s an uncomfortable one. Researchers at Check Point discovered a technique that uses a legitimate, Microsoft-signed component of Windows Defender — a driver that normally helps clean up malware at boot time — to delete security software and registry entries at the kernel level. No dodgy third-party drivers needed. It works across Windows versions all the way back to Windows 7.

To be clear, an attacker would need to already have admin-level access to your machine to pull this off, so it’s not something that happens out of nowhere. But it does highlight a worrying trend of attackers turning your own security tools against you. Microsoft has been notified and is working on a fix, but there’s no patch available yet.

In the meantime, the usual advice applies: don’t run your day-to-day computer as an administrator, keep Windows Update switched on, and consider whether a VPN like NordVPN or Surfshark is adding an extra layer of protection against the kind of remote intrusions that could give an attacker that initial foothold.

What this means for you: Keep Windows fully updated, avoid working in administrator mode unless you have to, and don’t assume your built-in security tools are bulletproof.

That’s Your Week in IT

A theme is emerging: the tools we rely on to protect and help us — AI agents, trusted code libraries, even Windows Defender itself — can be turned against us if we’re not paying attention. None of this is cause for panic, but it is a good reminder to keep your software updated, stay sceptical about permissions, and keep humans in the loop wherever it counts. See you next week.


Further Reading

AI agents cybersecurity npm Microsoft Defender small business