CISA has confirmed active exploitation of a critical MLflow vulnerability, demanding immediate action from any organisation running AI or machine learning infrastructure. The server-side request forgery flaw allows attackers to access internal systems, and deployment patterns mean the platform often sits outside normal security review cycles. Separately, Citrix has issued an urgent advisory for NetScaler Gateway and ADC vulnerabilities, with language reflecting high exploitation likelihood. The perimeter-facing nature of these widely deployed remote access solutions makes them priority targets. Finally, the Manic Android banking trojan is spreading across Europe with a relay-based exfiltration capability that partially defeats network controls, raising BYOD security questions for UK small businesses. The NCSC has also published new guidance on managing agentic AI cyber risk, connecting to broader concerns about autonomous systems acting on behalf of users without adequate security review.