Daily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript. TranscriptToday’s cyber and AI risk landscape is defined by a series of high-impact incidents and persistent governance gaps. As organizations accelerate their adoption of AI and cloud technologies, the challenges of securing data, managing third parties, and maintaining trust are becoming more complex—and more urgent. Let’s break down the key developments shaping risk management today, and explore what they mean for security leaders and organizations navigating this evolving threat environment. To start, we’re seeing a continued surge in high-profile data exposures, with ransomware groups and threat actors targeting critical infrastructure and high-value sectors. Philips and GE, two giants in the healthcare technology space, are currently investigating claims by the Clop ransomware group that sensitive data has been stolen. While the full extent of the breach is still being determined, the incident underscores how ransomware actors are shifting their focus to supply chain partners and critical infrastructure providers. For organizations in healthcare and other regulated sectors, this is a stark reminder: third-party risk management and incident response planning can’t be afterthoughts. These must be core components of your security strategy, especially when you’re handling regulated or life-critical data. Ransomware isn’t the only threat vector making headlines. Misconfigurations in cloud and SaaS environments continue to be a leading cause of large-scale data exposures. A recent incident involving Microsoft Power Pages is a case in point. Due to a misconfiguration, an estimated 27 million records were exposed, potentially to the ExfilSquad threat group. This isn’t an isolated event—it’s part of a broader pattern where simple mistakes in cloud configuration open the door to massive breaches. Security leaders need to prioritize configuration management, conduct regular audits, and implement automated detection for misconfigurations. In the cloud, the speed and scale of deployments mean that small errors can have outsized consequences. Third-party plugins are another area of growing concern. The SafePal order-tracking plugin breach exposed nearly 40,000 customers’ data, putting them at heightened risk for targeted phishing attacks. This incident highlights the downstream impacts that can arise from third-party components. It’s not enough to vet plugins at the point of adoption; organizations need ongoing monitoring and robust governance around all third-party integrations. Customer notification protocols and fraud risk monitoring should be in place, ready to activate the moment a potential breach is detected. We’re also seeing adversaries adapt quickly to new defenses. The ShieldBreak exploit, for example, has been identified as a way to bypass the RoguePlanet patch in Microsoft Defender. This is a classic zero-day scenario: attackers are finding ways around vendor fixes almost as soon as they’re released. The implication for defenders is clear—layered defenses and rapid patch validation are essential. Relying on a single patch or control is no longer sufficient. Security teams need to assume that some controls will fail and have compensating measures in place. One of the most important shifts in thinking comes from the recent analysis of the Microsoft compromise. Rather than framing it as a technical vulnerability, experts are now calling it a breakdown of trust. This reframing is significant. It suggests that effective risk management isn’t just about patching software or fixing bugs—it’s about establishing and maintaining trust across the entire supply chain and identity ecosystem. Continuous trust validation, ongoing monitoring, and secure-by-design principles must be embedded throughout the software lifecycle. The lesson here is that trust is both a technical and organizational challenge, and it requires holistic approaches that go beyond traditional security controls. APIs are another area where risk is escalating rapidly. As organizations pursue digital transformation and integrate AI into their operations, the number of APIs in use is exploding. Softrick has warned that inadequate API security can result in simultaneous, large-scale leaks of sensitive data. The implications are serious: a single weak API can become a conduit for massive data loss, especially when connected to critical systems. To mitigate this risk, organizations need to enforce strong authentication, implement continuous monitoring, and apply data minimization controls. API inventories should be kept up to date, and security teams should be proactive in identifying and addressing potential weaknesses before they can be exploited. Turning to AI, the latest SANS survey reveals a growing gap between the rate of AI adoption and the maturity of governance, validation, and operational controls. Organizations are racing to deploy AI-driven solutions, but the frameworks and oversight needed to manage these technologies safely are lagging behind. This governance gap increases the risk of unintended consequences, model drift, and regulatory non-compliance. For CISOs and risk executives, the message is clear: advocate for AI-specific governance frameworks and cross-disciplinary oversight. AI isn’t just another IT system—it brings unique risks that require tailored approaches to validation, monitoring, and accountability. A cross-industry survey reinforces this point, finding that the gap between AI deployment and effective governance remains wide, with security incidents on the rise as a direct result. Organizations need to formalize AI risk management, establish clear lines of accountability, and develop incident response protocols specifically designed for AI systems. This isn’t just about compliance—it’s about protecting the organization from operational and reputational harm as AI becomes more deeply embedded in business processes. Cloud management is also undergoing significant changes. Cloudflare has introduced new detection capabilities for Managed Control Plane, or MCP, traffic. This advancement makes previously invisible “shadow MCP” activity detectable and blockable. For organizations, this means improved visibility into cloud management activity, and the ability to identify and block unauthorized or risky actions. As cloud environments become more complex, exposure visibility is foundational to effective risk management. Security teams should take advantage of these new capabilities to strengthen their monitoring and response strategies. Research into MCP servers has also highlighted how misconfigured or poorly secured endpoints can leak enterprise secrets. These exposures can compound the risk of supply chain and cloud breaches, especially when attackers are able to pivot from one compromised system to another. Security teams need to inventory all MCP endpoints, harden their configurations, and monitor for anomalous access patterns. The goal is to reduce the attack surface and prevent attackers from exploiting weak points in cloud management infrastructure. Exposure visibility isn’t just a technical issue—it’s an organizational one. A regional analysis of South African organizations found that the core problem isn’t a lack of cybersecurity controls, but insufficient visibility into the exposure and attack surface. This insight is broadly applicable. Asset discovery, continuous monitoring, and risk-based prioritization are critical for organizations everywhere. Without a clear understanding of what’s exposed and where, even the best security controls can fall short. As AI becomes more deeply integrated into enterprise operations, the need for industry context is becoming apparent. Security experts argue that forward deployed engineers—those working on enterprise AI projects—require deep industry knowledge to effectively identify and mitigate risks. This points to the importance of cross-functional collaboration and ongoing education. AI risks aren’t just technical; they’re also operational and contextual. Security teams need to work closely with business units and domain experts to ensure that AI deployments are both effective and secure. Let’s step back and look at the strategic implications of these trends. Ransomware and supply chain attacks are continuing to target high-value sectors, which means enhanced third-party and incident response strategies are more important than ever. Misconfigurations in SaaS and cloud environments remain a leading cause of data exposures, so automated detection and configuration management must be prioritized. The rapid adoption of AI is outpacing governance and validation, increasing the risk of operational, regulatory, and reputational harm. And at the foundation of all of this are trust and visibility—across identity, supply chain, and cloud. So, what should organizations be focusing on today? First, prioritize exposure visibility and asset inventory. This means going beyond traditional vulnerability management and ensuring you have a clear, real-time picture of your attack surface—including shadow IT, third-party integrations, and cloud assets. Second, accelerate the development and implementation of AI governance frameworks. Don’t wait for regulators to set the rules; take a proactive approach to managing AI risk, with clear policies, validation processes, and incident response protocols. Third, strengthen supply chain and third-party risk management, especially if you’re operating in critical infrastructure or healthcare. This includes continuous monitoring, robust due diligence, and clear escalation paths when issues are detected. Let’s take a closer look at some of these points, starting with exposure visibility. In today’s environment, the at