Daily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript. TranscriptThe cyber and AI risk landscape is evolving at a relentless pace, and today’s developments highlight just how quickly offensive capabilities are outstripping traditional defenses. The surge in AI-driven threats is not just a matter of frequency—it’s also about sophistication. We’re seeing a fundamental shift, where attackers are leveraging automation and artificial intelligence to discover vulnerabilities, execute attacks, and evade detection at a scale and speed that was previously unthinkable. Let’s start with one of the most significant breakthroughs in recent months: AI agents are now autonomously discovering zero-day vulnerabilities, including those that allow them to escape virtual machines. Trail of Bits, a leading security research firm, has demonstrated that AI can now identify and exploit critical flaws without human intervention. This is a game-changer for offensive security. Traditionally, the process of finding zero-days—those previously unknown and unpatched vulnerabilities—has required a high level of expertise, patience, and manual effort. Now, AI agents can automate much of this work, scanning vast codebases, learning from past exploits, and even generating new attack techniques on their own. The implications for defenders are profound. Virtual machine isolation, once considered a robust security measure, is now at risk. If AI can autonomously break out of VMs, then isolation strategies that rely on virtual boundaries are no longer sufficient on their own. Organizations need to rethink how they segment and monitor their environments. Continuous monitoring, behavioral analytics, and layered defense are becoming non-negotiable. It’s no longer enough to trust that a virtual machine boundary will contain an attacker. This escalation isn’t confined to research labs or proof-of-concept attacks. In Australia, organizations are facing a real-world onslaught from AI-powered cyberattacks. Reports indicate that attackers are using AI to automate reconnaissance, exploit vulnerabilities, and evade detection, overwhelming many firms’ existing security measures. The pace of these attacks is outstripping defenders’ ability to respond, and this isn’t just an Australian problem—it’s a global one. The lesson here is clear: defenders must adapt just as quickly as attackers. That means investing in AI-driven defense tools, upskilling security teams, and adopting a mindset of continuous improvement. Let’s talk about some of the specific vulnerabilities that are being actively exploited right now. PaperCut NG/MF, a widely used print management solution, has critical flaws that are under active attack. The U.S. Cybersecurity and Infrastructure Security Agency, or CISA, has added these vulnerabilities to its Known Exploited Vulnerabilities catalog and is urging organizations to patch immediately. Attackers are using these flaws to gain initial access, move laterally within networks, and deploy ransomware. If your organization uses PaperCut, this is not a drill—patch now, and review your logs for any signs of compromise. The exploitation is widespread and ongoing, and the window for remediation is closing fast. Another urgent issue is a critical vulnerability in JFrog Artifactory, a core component in many organizations’ software supply chains. Attackers are actively exploiting this flaw to target artifact management systems. The risk here is twofold: not only could attackers tamper with software artifacts, potentially introducing malicious code downstream, but they could also exfiltrate sensitive data. This kind of supply chain attack can have cascading effects, impacting not just your organization but also your customers and partners. Immediate patching is essential, and organizations should also conduct integrity checks across their software supply chains to ensure nothing has been compromised. The underground cybercrime economy is also evolving. The BraZetsu malware, now enhanced with AI capabilities, is enabling the sale of corporate network access on underground markets. This malware leverages AI to evade detection and automate lateral movement inside compromised networks, making it harder for defenders to root out intruders. The commoditization of network access—where attackers can simply buy their way into a target environment—raises the stakes for organizations of all sizes. Advanced behavioral analytics and proactive threat hunting are becoming critical tools in the fight against these AI-driven threats. It’s not enough to rely on signature-based detection; defenders need to look for subtle anomalies and patterns that indicate something isn’t right. Ransomware remains a persistent and evolving threat, with healthcare organizations continuing to be prime targets. A ransomware gang recently claimed responsibility for a data breach at Nutex Health, underscoring the sector’s vulnerability to both data extortion and operational disruption. Healthcare organizations face unique challenges: they hold sensitive personal data, operate complex networks, and often have limited resources for cybersecurity. The Nutex Health incident is a reminder that robust backup strategies, incident response planning, and third-party risk management are essential. It’s not just about preventing attacks, but also about ensuring rapid recovery when—not if—a breach occurs. Shifting gears to the governance side, we’re seeing organizations respond to these threats by accelerating the adoption of AI security certifications and governance frameworks. In the Asia-Pacific region, and particularly in India, regulatory and compliance pressures are mounting. Data sovereignty—who controls data and where it resides—is becoming a central issue, especially as cross-border data flows increase. Proofpoint, for example, is expanding its data security capabilities across Asia Pacific and Japan in direct response to these rising demands. For organizations operating in these regions, compliance-driven security controls and localization strategies are no longer optional—they’re essential for doing business. Certifications are also emerging as key differentiators in the AI platform space. HiLabs recently achieved both HITRUST e1 and AI Security Certification for its MCheck platform. These certifications provide assurance to customers and regulators that the platform meets rigorous standards for data protection and AI governance. As AI becomes more deeply embedded in enterprise systems, formalized risk management and certification will become table stakes for vendors. India is taking a significant step forward with the launch of its first sovereign AI governance platform by TRUSTNOW. This platform is designed to manage and control autonomous enterprise agents, addressing both regulatory and operational concerns around AI autonomy. The move signals a shift toward national-level oversight of enterprise AI systems. As AI agents become more capable and independent, questions about accountability, transparency, and control are coming to the forefront. Sovereign governance platforms like this one are likely to become more common as governments seek to balance innovation with risk management. One of the more subtle but equally important risks in enterprise AI is the phenomenon of AI hallucination—when AI systems generate erroneous or fabricated outputs. A new in-depth analysis recommends that organizations implement robust governance frameworks, including red teaming and adversarial testing, to mitigate these risks. Hallucinations can have real-world consequences, especially in sectors like finance, healthcare, and legal services, where accuracy is paramount. Governance isn’t just about compliance—it’s about ensuring that AI systems are reliable, trustworthy, and aligned with business objectives. On the defensive technology front, we’re seeing a shift toward AI-augmented vulnerability management. WordPress, for example, is now using advanced AI tools to proactively identify and remediate vulnerabilities before they can be exploited. This approach reduces the window of exposure and exemplifies the move toward continuous, automated defense. Rather than waiting for attackers to find and exploit flaws, organizations are increasingly using AI to get ahead of the threat curve. The threat landscape is also being shaped by novel malware techniques. The SLEEPWALKER malware, for instance, employs raw packet transmission, DNS tunneling, and VMware VMCI channels for covert command-and-control communications. These methods are designed to bypass traditional detection tools, making it harder for defenders to spot and contain intrusions. Deep network visibility and anomaly detection are becoming must-haves. Traditional perimeter defenses are no longer sufficient; organizations need to be able to detect and respond to threats that operate below the radar. Stepping back to look at the bigger picture, several strategic implications emerge from these developments. First, AI-driven offensive tools are lowering the barrier for zero-day discovery and exploitation. This challenges traditional isolation and detection strategies, and it means that organizations can’t rely solely on perimeter defenses or static controls. Second, regulatory and compliance pressures—especially around data sovereignty and AI governance—are intensifying, particularly in Asia-Pacific and India. Organizations need to stay ahead of evolving regulations and be proactive in their compliance efforts. Third, the proliferation of AI-enhanced malware and ransomware is accelerating the commoditization of network access and data extortion. Attackers are no longer limited by manual processes; they can automate much of their activity, scale their operations, and targ