Daily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript. TranscriptToday’s cyber and AI risk landscape is defined by a convergence of escalating software vulnerabilities, rapid AI adoption, and evolving governance challenges. We’re seeing a perfect storm: critical vulnerabilities are surfacing at a record pace, AI systems are being integrated into every layer of business, and both regulators and attackers are moving faster than ever. For security leaders, the practical implications are clear—accelerated patch management, proactive AI governance, and enhanced supply chain vigilance are no longer optional. Let’s break down the top developments shaping the risk environment right now, and what they mean for organizations navigating this complex terrain. Let’s start with software vulnerabilities, where urgency is the name of the game. The US Cybersecurity and Infrastructure Security Agency, or CISA, has just imposed its shortest-ever patching deadline: three days. This unprecedented mandate comes in response to a newly disclosed Oracle vulnerability, rated a “perfect-10” on the CVSS scale. For context, a CVSS score of 10 means the flaw is as severe as it gets—an open door for remote code execution, potentially allowing attackers to take full control of affected systems from anywhere in the world. What’s significant here isn’t just the technical risk, but the regulatory shift. CISA’s three-day deadline signals a new era of accelerated vulnerability management, where organizations can expect tighter timelines and closer scrutiny from regulators. For CISOs and IT teams, this means immediate triage: identify affected Oracle systems, deploy patches without delay, and verify remediation. Delayed action isn’t just a technical risk—it’s a compliance risk, with potential for regulatory penalties and reputational damage. This sets a precedent, and we can expect similar expectations for future critical flaws. The message is clear: patch management needs to be both proactive and agile. Moving from traditional software to the evolving world of AI, the UK’s National Cyber Security Centre has released new guidance focused on what’s known as “agentic AI.” These are AI systems capable of autonomous action—think of AI agents that can make decisions, execute tasks, and interact with other systems without direct human oversight. The NCSC’s guidance addresses several key areas: threat modeling for AI-specific risks, managing supply chain dependencies, and the need for continuous monitoring of AI behaviors. Why does this matter? As organizations accelerate AI adoption, these agentic systems introduce new risk dimensions. They can act in unpredictable ways, interact with sensitive data, and even make decisions that impact business operations or customer trust. Integrating AI-specific controls into existing risk management frameworks is now essential. That means not just securing the AI models themselves, but also the data pipelines, APIs, and third-party dependencies that support them. For security leaders, this is a call to action: AI governance needs to be built into your cyber risk strategy from the ground up. Supply chain risk is another area where the stakes are rising. A new report highlights that 91 recently disclosed Spring Framework vulnerabilities—CVEs—impact more than 209,000 software components across the supply chain. The Spring Framework is widely used in enterprise applications, and attackers are increasingly targeting these open-source dependencies as a way to compromise organizations at scale. This amplifies the importance of comprehensive Software Bill of Materials, or SBOM, management. Knowing exactly which components you’re running, where they come from, and how they’re maintained is critical. Rapid patching is essential, but so is coordination with vendors and third-party partners to mitigate cascading vulnerabilities. The supply chain is only as strong as its weakest link, and attackers know it. For organizations, this means investing in tools and processes to track, assess, and remediate vulnerabilities across the entire software ecosystem. Identity and access management is also under the microscope, following the disclosure of a critical vulnerability in Keycloak. This flaw allows attackers to hijack any account by bypassing the password reset process—a direct route to unauthorized access and potential data breaches. Keycloak is a popular open-source identity solution, relied on by organizations worldwide to manage authentication and authorization. The practical takeaway here is straightforward: patch Keycloak immediately, and review your authentication workflows for any signs of compromise. But the broader implication is that identity platforms are high-value targets, and attackers are constantly probing for weaknesses. Regular audits, strong monitoring, and layered defenses around identity infrastructure are now table stakes. Email infrastructure is facing its own set of threats. Unpatched Zimbra servers are currently being targeted by attackers exploiting CVE-2026-73570. Zimbra is a widely used email and collaboration platform, and the vulnerability allows unauthorized access with potential for lateral movement inside affected environments. The lesson here is familiar: patch quickly, monitor for indicators of compromise, and review your email infrastructure for any lingering vulnerabilities. Email remains a critical attack vector, and unpatched systems are low-hanging fruit for threat actors. Let’s turn to the evolving tactics of cybercriminals. The WeedHack malware campaign is a case in point. Despite disruptions to its command-and-control infrastructure, WeedHack continues to spread through SEO-poisoned Minecraft-related websites. This campaign targets gaming and youth-oriented platforms, using malicious downloads to compromise unsuspecting users. What stands out is the resilience and adaptability of threat actors. Even when infrastructure is disrupted, they find new ways to reach victims—often by exploiting popular search terms and trusted community sites. For organizations, this underscores the importance of user awareness training, especially for younger or less security-savvy audiences. Web filtering controls and proactive monitoring of web traffic can help reduce exposure to these types of campaigns. Third-party risk is also in the spotlight, following reports that the threat group ShinyHunters has allegedly breached ReliaQuest and leaked screenshots of an Okta dashboard as proof. While details are still emerging, this incident highlights the risks associated with identity providers and the potential for downstream compromise. Okta is a widely used identity platform, and a breach can have ripple effects across multiple organizations. For CISOs, this is a reminder to review third-party access controls, monitor for suspicious activity in identity platforms, and maintain strong incident response plans. The interconnected nature of modern IT environments means that a compromise in one provider can quickly escalate into a broader security incident. Vigilance and proactive management of third-party relationships are essential. Critical infrastructure is facing heightened threats as well. A recent wave of cyberattacks has impacted major organizations including Shell, GE, and Philips, prompting federal agencies to issue warnings about vulnerabilities in Siemens programmable logic controllers, or PLCs. These devices are foundational to operational technology environments—think manufacturing plants, energy grids, and transportation systems. The attacks underscore the persistent threat to critical infrastructure and the need for robust OT security controls. Unlike traditional IT systems, OT environments often have unique constraints—legacy devices, limited patch windows, and a high tolerance for uptime. Security teams need to balance operational requirements with the imperative to patch and secure vulnerable systems. Network segmentation, continuous monitoring, and specialized OT security solutions are key components of a resilient defense. On the industry front, we’re seeing major players join forces to tackle the scale and complexity of AI and cyber threats. NTT DATA and Palo Alto Networks have announced a global alliance targeting $1 billion in AI security solutions. The partnership aims to deliver integrated, AI-driven security platforms that can scale with enterprise needs. This reflects a broader trend: as threats become more sophisticated and AI adoption accelerates, no single organization can go it alone. Strategic alliances and advanced security tooling are becoming essential. For security leaders, it’s worth evaluating the potential benefits of these partnerships—whether that means access to cutting-edge technology, shared threat intelligence, or streamlined integration across security domains. As organizations scale their AI initiatives, the limitations of traditional security tools are coming into focus. Experts are warning that conventional SBOMs—Software Bills of Materials—are no longer sufficient for managing risks in AI-driven environments. AI models introduce new dependencies, often with opaque or dynamic supply chains that are hard to track using legacy methods. Enhanced transparency and dynamic SBOMs are recommended to address the complexity of AI software stacks. This means not just listing static components, but also tracking model versions, training data sources, and third-party services that feed into AI workflows. For organizations, this is a call to invest in tools and processes that can keep pace with the evolving nature of AI software. On the tooling front, a review of leading AI safety solutions highlights a range of options for model monitoring, bias detection,