Daily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript. TranscriptToday’s cyber and AI risk landscape is a study in convergence—where persistent, high-impact vulnerabilities in core digital infrastructure meet the accelerating adoption of artificial intelligence across the enterprise. The result is a risk environment that’s not just fast-moving, but also deeply interdependent. Let’s break down the most critical developments shaping enterprise risk management today, and what they mean for security leaders, risk executives, and boards. Let’s start with the most urgent threat: the active exploitation of a critical zero-day vulnerability in Citrix NetScaler, tracked as CVE-2026-88772. This isn’t just another technical flaw—this is a gateway that state-sponsored actors have been using since early September to gain root-level access to enterprise systems. Once inside, they’re deploying web shells, which essentially give them persistent, covert control over compromised environments. Multiple sources have confirmed successful intrusions, and the scope of these attacks is still unfolding. The key lesson here is the persistent gap between when a vulnerability is disclosed and when organizations actually apply the necessary patches. Attackers are exploiting this window, sometimes for weeks at a time. For organizations running NetScaler appliances, immediate action is non-negotiable. Patching is the first step, but it’s not enough. A thorough forensic review is critical to identify any signs of compromise—look for unexpected web shells, unusual authentication attempts, or unexplained configuration changes. Delaying response could mean significant data loss, lateral movement, and even deeper compromise of your environment. But NetScaler isn’t the only enterprise tool under siege. Attackers are also targeting remote monitoring and management tools—specifically MSP360 and ScreenConnect. These are legitimate platforms, trusted by IT teams to provide remote support and manage infrastructure. Unfortunately, that trust is exactly what makes them attractive to adversaries. Once attackers gain access, they use these tools to maintain persistence, move laterally across networks, and harvest credentials. The practical implication is clear: every remote session, every instance of RMM tool usage, is now a potential risk vector. Security teams need to double down on monitoring, restrict access to these tools, and validate every remote connection. It’s not enough to trust the software because it’s widely used—attackers are counting on that trust to mask their activities. Another attack chain drawing attention involves vulnerabilities in PaperCut, a widely used print management system. Here, attackers are exploiting remote code execution flaws to steal authentication tokens and access domain controllers—the very core of enterprise identity infrastructure. Once domain controllers are compromised, attackers can escalate privileges, impersonate users, and move laterally with ease. The message for security teams is straightforward: patch PaperCut systems as a priority, monitor for suspicious activity, and review domain controller access logs. If you see unusual access patterns or unexplained changes to authentication tokens, you may already be dealing with an active compromise. Shifting gears to the AI front, we’re seeing rapid evolution in both the technology and the governance tools designed to manage its risks. Vendors are rolling out new capabilities that allow security teams to monitor interactions with AI platforms—take Claude, for example. Security teams can now review chat logs, track file transfers, and monitor agent activity within these AI environments. This addresses a growing concern: as AI adoption accelerates, so does the risk of data leakage, compliance violations, and the emergence of “shadow AI”—unsanctioned tools and agents operating outside official oversight. For CISOs, integrating these monitoring tools into existing security operations is becoming essential. It’s about more than just compliance—it’s about enforcing policy, detecting misuse, and supporting audit requirements in an environment where AI is increasingly embedded in business processes. A related development comes from RSA, which has launched an Agent ID platform specifically designed to secure AI agents and multi-cloud platform servers. The challenge here is unique: AI agents, especially those operating autonomously, interact with sensitive data and systems across complex cloud environments. Traditional identity and access management tools aren’t always equipped to handle this level of dynamism or automation. RSA’s Agent ID platform aims to fill that gap by providing visibility and control over agent interactions. This is a significant step forward, because as AI agents become more capable and more autonomous, the risk of unauthorized actions, data leakage, or even malicious manipulation increases. Security leaders should be evaluating how these new identity platforms can be integrated into broader access governance strategies. On the SaaS and AI governance side, Nudge Security has introduced adaptive risk management solutions. The key word here is “adaptive.” Instead of relying on static, point-in-time risk assessments, these tools dynamically track SaaS and AI risk as usage evolves after initial approval. In practice, this means organizations can respond to changes in risk posture in real time—whether that’s a sudden spike in usage, the introduction of a new integration, or the emergence of shadow IT. For risk leaders, adaptive governance is no longer a nice-to-have. The pace of SaaS and AI adoption means that yesterday’s risk profile may be obsolete tomorrow. Tools that can detect and respond to these shifts in real time are becoming mandatory for organizations that want to stay ahead of evolving threats. K2 GRC is another vendor making waves, with the launch of K2 Assist AI. This platform leverages artificial intelligence to automate readiness reviews and streamline governance, risk, and compliance processes. As regulatory scrutiny of AI intensifies—especially in sectors like finance, healthcare, and critical infrastructure—tools that can automate and improve the efficiency of compliance programs are in high demand. The practical benefit is twofold: first, organizations can reduce the manual burden on compliance teams, freeing up resources for higher-value work. Second, automated assessments can help identify gaps or emerging risks that might otherwise go unnoticed until they become material issues. Let’s return to the challenge of shadow AI. As organizations embrace AI to drive efficiency and innovation, employees are increasingly turning to unsanctioned or unauthorized AI tools. This “shadow AI” presents a significant risk of data leakage, regulatory non-compliance, and loss of control over sensitive information. Effective strategies to combat shadow AI start with robust discovery—knowing what tools are in use, by whom, and for what purposes. Policy enforcement is the next step, ensuring that only approved tools are used for sensitive workflows. Finally, user education is critical. Employees need to understand not just the rules, but the reasons behind them—why using an unsanctioned AI tool could expose the organization to risk. CISOs should prioritize visibility and controls over AI tool usage. This isn’t just about ticking a compliance box—it’s about preventing inadvertent exposure of sensitive data, intellectual property, or regulated information. Innovation in AI security is also accelerating. The Tech4Trust accelerator, for example, has named 30 startups to its latest cohort, all focused on securing AI. This reflects a broader trend: a surge in innovation aimed at addressing AI-specific risks, from model integrity to data privacy and beyond. Security leaders should be watching this ecosystem closely. The solutions being developed by these startups could become critical components of enterprise risk management strategies in the near future. Whether it’s tools for monitoring AI model behavior, platforms for securing training data, or solutions for auditing AI decision-making, the innovation pipeline is robust and growing. Partnerships are also shaping the AI governance landscape. Distology’s recent agreement with Harmonic Security highlights the growing market demand for AI governance solutions. As organizations seek to operationalize AI safely, the need for tools that provide oversight, compliance, and risk mitigation is only increasing. The takeaway here is that AI governance is no longer an abstract concept. It’s a practical, operational requirement. Organizations should be evaluating governance frameworks and tools that are specifically tailored to the unique risks and challenges of AI. Another trend worth noting is the convergence of security and sustainability at the board level. Increasingly, security and sustainability are reporting to the same boardroom, driven by regulatory and stakeholder expectations. This alignment can create powerful synergies—security initiatives can support broader ESG (environmental, social, and governance) objectives—but it also introduces new complexities in risk prioritization and reporting. CISOs need to be prepared to articulate how security programs contribute to ESG goals. For example, robust data protection can support privacy and social responsibility objectives, while secure supply chains can enhance environmental and ethical sourcing efforts. The ability to speak the language of both security and sustainability is becoming a key skill for risk leaders. Zooming out to the geopolitical environment, the evolving relationship between the US and China is havin