Daily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript. TranscriptToday’s cyber and AI risk landscape is evolving at a pace—and scale—that’s challenging even the most mature security programs. We’re witnessing a convergence of two major forces: the rapid proliferation of AI technologies and a new generation of advanced cyber threats. Both are testing the resilience and adaptability of organizations worldwide. In this environment, the imperative for security and risk leaders is to adapt quickly, investing in agility, automation, and trust as core strategic assets. Let’s start with one of the most significant shifts: the rise of autonomous, AI-powered cyberattacks. Chinese-speaking threat actors have begun using DeepSeek-powered agents to launch attacks that are not only automated, but also capable of operating independently—without direct human oversight. These AI agents are being deployed for reconnaissance, exploitation, and lateral movement, targeting exposed servers with remarkable speed and adaptability. What’s different here is the scale and velocity of these attacks. Traditional dwell times—where attackers linger undetected in networks for days or weeks—are shrinking. These AI agents can scan, exploit, and pivot across environments in minutes, not days. For defenders, this means that the window for detection and response is closing fast. Automated attack patterns are no longer a theoretical risk; they’re a present reality. Security teams need to invest in AI-driven defense mechanisms—solutions that can detect, analyze, and respond to threats at machine speed. Monitoring for automated behaviors, rather than just known signatures, is quickly becoming table stakes. This brings us to a persistent weakness that’s only being exacerbated by this new threat landscape: patch management. Recent analysis shows that attackers are able to exploit one out of every four vulnerabilities before organizations can apply patches. Think about that: for every four vulnerabilities disclosed, adversaries are successfully exploiting at least one before it’s closed. This so-called “patch gap” is a critical exposure, especially as zero-day exploits and automated attack tools become more widespread and easier to use. The operational impact is clear. Delays in patching not only increase the likelihood of a breach, but also the potential damage, as attackers are often able to move laterally and escalate privileges before detection. The solution isn’t just to patch faster—it’s to automate vulnerability management, invest in real-time asset discovery, and streamline patch deployment processes. Security teams should be asking: How quickly can we identify new vulnerabilities across our environment? How rapidly can we deploy patches or mitigations? And, crucially, how do we prioritize what matters most, given limited resources? This need for speed is underscored by recent incidents, such as the active exploitation of a critical zero-day vulnerability in Cisco Secure Firewall Management Center—CVE-2026-20316. This flaw allows remote attackers to gain unauthorized access or disrupt firewall management operations. Given Cisco’s widespread use in enterprise environments, this isn’t a niche concern. Organizations should prioritize immediate patching and monitor for indicators of compromise. The lesson here is that zero-days in core security infrastructure are not rare events—they’re a persistent risk that requires constant vigilance and rapid response. But the challenges aren’t limited to external attackers. Inside organizations, the growth of AI is creating new, often invisible, risk vectors. One of the most pressing issues is the rise of “shadow AI”—the unsanctioned use of AI tools by employees. As AI becomes embedded in daily workflows, employees are increasingly leveraging generative AI, automation platforms, and other tools outside the formal oversight of IT or security. This creates significant governance and security blind spots. The risks are multifaceted. There’s the potential for data leakage, as sensitive information is fed into external AI models. There are compliance violations, as regulatory requirements around data handling, privacy, and AI usage tighten. And there’s the challenge of unmonitored model usage, where employees might inadvertently introduce bias, errors, or security vulnerabilities into business processes. The solution isn’t to clamp down on innovation, but to adopt a governance-first approach—establishing clear policies, monitoring usage, and integrating AI risk into broader enterprise risk management frameworks. This dovetails with another trend: the democratization of AI has turned every employee into a potential “builder.” Employees are integrating AI tools into business processes, often bypassing traditional IT and security controls. While this can drive efficiency and innovation, it also opens up new security gaps that many organizations aren’t monitoring. Security teams need to proactively engage with business units—to understand how AI is being used, where sensitive data is flowing, and where controls need to be strengthened. This requires a shift from a purely technical mindset to one that’s cross-functional and collaborative. As regulatory milestones approach—most notably, the EU AI Act—governance is moving from a compliance checkbox to a core operating discipline. Enterprises are being urged to treat AI governance not as a one-off project, but as an ongoing process embedded in the fabric of business operations. This means assessing governance maturity, preparing for increased scrutiny from regulators, customers, and partners, and embedding responsible AI practices into every stage of the AI lifecycle. Trust is emerging as the new security battleground in the AI age. As AI systems become integral to business operations, trust—encompassing transparency, explainability, and ethical use—has become a key differentiator and risk factor. Organizations that fail to build and maintain trust in their AI systems may face reputational damage, regulatory penalties, and loss of customer confidence. Security leaders should champion responsible AI practices and transparent risk communication, ensuring that both internal and external stakeholders understand how AI is being used, what risks are present, and how those risks are being managed. Identity and cloud security are also in the spotlight, with notable M&A activity and product innovation reflecting the evolving threat landscape. Okta’s intent to acquire Permiso Security signals a strategic push into identity threat detection and response for cloud environments. Identity remains a primary attack vector, and the need for integrated solutions that span on-premises and cloud assets is only growing. Security leaders should evaluate their identity threat detection capabilities and anticipate increased vendor consolidation in this space. On the innovation front, Snowflake has introduced the Cortex AI Gateway and other AI security features, aiming to provide enhanced governance, monitoring, and protection for AI workloads in the cloud. As data and model usage proliferate across business units, centralized oversight becomes critical. Security leaders should assess the maturity of their AI security controls and consider leveraging such platforms to manage AI risk at scale. Let’s turn to some additional technical threats that have surfaced. PHP, a widely used programming language for web applications, has patched three critical vulnerabilities enabling SQL injection, memory corruption, and server crashes. Meanwhile, SolarWinds Web Help Desk is vulnerable to a memory-based denial-of-service attack. Both products are common in enterprise environments, and unpatched systems could be targeted for initial access or operational disruption. Prioritizing patching and monitoring for exploitation attempts is essential. Attackers are also evolving their tactics when it comes to malware distribution and initial access. The Astaroth banking trojan, for example, has added a WhatsApp Web spambot module to propagate malware across Brazil. By leveraging trusted communication channels and social engineering, attackers are increasing the likelihood of successful infection. This highlights the importance of updating user awareness training and monitoring for unusual messaging activity—not just email, but across all channels where employees interact. Another noteworthy trend is the rise of recon-only SSH attacks. In these cases, attackers conduct reconnaissance without deploying malware—likely as a precursor to more damaging second-stage intrusions. This stealthy approach can evade traditional detection methods, as there’s no malware to flag. Instead, defenders need to enhance monitoring of authentication logs and look for anomalous access patterns—such as unusual login times, source locations, or command usage. The goal is to catch attackers early, before they escalate privileges or deploy payloads. So, what are the strategic implications of all these developments? First, AI-driven autonomous attacks are accelerating the threat landscape. Defenders need to invest in AI-enabled defense and detection to keep pace. This isn’t about replacing humans, but about augmenting security teams with tools that can operate at machine speed—analyzing vast amounts of data, identifying patterns, and executing responses in real time. Second, patch management remains a critical weakness. Automation and prioritization are essential to close the exploit window. Organizations should be looking at solutions that can automatically identify, prioritize, and deploy patches across diverse environments, reducing manual effort and minimizing the time attackers have to exploit known vulnerabilities. Thi