The AI Safety Net is Full of Holes: What 2026 Taught Us So Far

The conversation around AI Safety Net is Full of Holes has reached a critical point. Look, I’m not here to be the fun-police. I love AI as much as the next bloke. But we’ve hit a point in 2026 where the hype has officially outrun the brakes, and the brakes weren’t even attached to begin with.

I was reading through the latest Experian and White & Case reports this morning, and the numbers are bloody terrifying. We’re talking over 8,000 major data breaches in just the first half of last year, with 345 million records floating around in the wild. If you think the “big guys” have this under control, you’re dreaming. In fact, 69% of people don’t believe banks or retailers are ready for what’s coming.

The shift we’re seeing right now isn’t just about a clever hacker in a hoodie. It’s about Autonomous AI Agents. These things are self-operating bots that can execute complex attacks without a human even lifting a finger. It’s like leaving the front door unlocked and finding out the burglar is an invisible robot that can pick locks at light speed.

Here’s the reality: your data is being used as training material for the very tools that will eventually be used to scam you. We’ve seen a massive spike in “Synthetic Identities” – AI-created profiles that look so real they can bypass most standard verification checks. One in four millennials has already been hit by identity theft this past year. That isn’t a statistic; it’s a crisis.

Also, regulators are finally waking up, but they’re creating a patchy mess. From the DOJ bulk data rules to Missouri and Maryland passing their own “Online Data Privacy Acts,” businesses are drowning in compliance while the hackers are just getting more efficient. If you’re a business owner, you can’t just tick a box and hope for the best anymore.

So, what should you actually do?

First, stop feeding the beast. If your staff are using AI tools without a clear policy, they’re likely leaking your trade secrets and customer data into a public model.

Second, get serious about “Privacy-Enhancing Technologies.” If you aren’t looking at quantum-resistant encryption yet, you’re already behind. The attackers are already using AI to find vulnerabilities in current standards.

Third, verify everything. If a video call from your “boss” asks for a transfer or sensitive files, call them back on a different number. Deepfakes aren’t just for viral TikToks anymore; they’re the new phishing.

We’re in an era where cyberattacks aren’t just about stealing your credit card; they’re about manipulating digital reality itself. Don’t be the low-hanging fruit.

> “AI is evolving at breakneck speed, and cybercriminals are the early adopters. If you isn’t using AI to defend your data, you’re bringing a knife to a gunfight.”

### Related Reading
* [Your Staff are Feeding AI Tools 18,000 Terabytes of Company Data](https://philiphall.com/your-staff-are-feeding-ai-tools-18000-terabytes-of-company-data-most-bosses-have-no-idea/)
* [The NSA’s Warning on AI Agent Security](https://philiphall.com/nsa-mcp-ai-agent-security-warning-2026/)
* [Why Stolen Passwords are Still King](https://philiphall.com/ai-dethroned-stolen-passwords-hackers-verizon-2026/)

AI-Generated Political Attack Videos Are Now Mainstream. Heres Why That Terrifies Security Pros

AI-Generated Political Attack Videos Are is a topic I have been following closely, and the developments keep coming. This week, a 22-second AI-generated video showed something that should make every cybersecurity professional stop and think. The clip, posted on Truth Social, depicts a prominent figure grabbing a late-night talk show host and physically throwing him into a dumpster on stage. The crowd cheers. The figure dances. The video is convincing enough to make you look twice.

It was created with generative AI. However, it went viral within hours.

Now, set aside the politics for a moment. What matters here is not who posted it or who the target was. What matters is that a synthetic media clip depicting a real person in a physically impossible scenario was produced, distributed, and consumed by millions without any kind of warning label, content provenance marker, or verification mechanism baked into the distribution chain. That is a watershed moment for AI-generated misinformation.

The Intelligence Community Saw This Coming

Avril Haines, the US Director of National Intelligence, has been warning for months that AI can generate “seemingly authentic” deepfake content capable of influencing audiences and spreading false narratives at scale. This video is a textbook demonstration of exactly that capability.

The technology behind these clips is not cutting-edge. It is openly available. The same tools that can make a convincing deepfake of a CEO’s voice for a business email compromise attack can generate a video of a political figure doing something they never did. The same diffusion models that power creative applications can be repurposed for targeted attacks against individuals.

Why This Is a Security Problem, Not Just a Political One

From a cybersecurity standpoint, the proliferation of AI-generated video content creates several urgent problems:

Synthetic media undermines trust in all digital evidence. When a convincing deepfake of any public figure can be created in minutes, the default position shifts from “seeing is believing” to “nothing is real.” This erosion of trust is exactly what threat actors exploit in disinformation campaigns.

Detection is still playing catch-up. Deepfake detection tools exist but they are not deployed at the distribution layer. Social media platforms, messaging apps, and news sites have no consistent requirement for AI-generated content labelling. The technology to detect synthetic media exists, but the infrastructure to apply it at scale does not.

The barrier to entry keeps dropping. The video that went viral this week was not produced by a state-level actor with unlimited resources. It was produced with consumer-grade AI tools. As the cost of generating convincing synthetic video approaches zero, the volume of this content will explode.

What This Means for Australian Organisations

Australian businesses and government agencies are not immune to this trend. Deepfake technology is already being used in Australian contexts, from voice cloning scams targeting executives to fabricated evidence in social engineering campaigns. The same tools that produce viral political content are being repurposed for targeted attacks against Australian organisations.

The Australian Signals Directorate and the Cyber Security Centre have flagged synthetic media as an emerging threat vector. If your organisation has not yet updated its incident response plan to account for AI-generated disinformation, this week’s events should be a wake-up call.

The Path Forward

Content provenance standards like C2PA (Coalition for Content Provenance and Authenticity) are gaining traction, but adoption is voluntary and uneven. Regulation is being discussed in multiple jurisdictions but has not materialised in any meaningful form. Detection technology continues to improve but faces an asymmetric battle against generative models that improve even faster.

For now, the best defence is scepticism and verification. Treat any video or audio clip that confirms your existing biases with extra scrutiny. Verify through multiple independent channels before acting on synthetic media content. However, push the platforms you use to implement mandatory AI content labelling.

The era where a video could be taken as proof is over. We are now in the era where every piece of digital media must be treated as potentially synthetic until proven otherwise. Security professionals who adapt to this reality will protect their organisations from what comes next.

Related Reading

The NSA Just Issued Its First Formal Warning About AI Agent Technology. Your IT Team Needs to Read It.

Every time I think I have seen it all with NSA Just Issued Its, something new emerges. I’ve been watching AI agent technology move from developer toy to corporate backbone over the past 18 months, and the security conversation has been almost entirely missing. This week, the NSA made that conversation unavoidable.

On May 22, the US National Security Agency published its first formal cybersecurity guidance specifically targeting Model Context Protocol (MCP), the underlying technology that lets AI assistants like Copilot, Claude, and ChatGPT connect to your files, calendars, databases, and business systems. The NSA’s conclusion is blunt: organisations are deploying this technology faster than they understand what they’re handing it access to.

What MCP Actually Is

Most people using AI tools at work have no idea MCP exists. It’s the plumbing. When your AI assistant books a meeting, reads a contract, queries your CRM, or writes code that runs against a live database, MCP is what connects the AI model to those systems. Anthropic created it, and it’s now embedded in production workflows at financial institutions, law firms, and software companies globally.

The NSA describes MCP as “the de facto standard” for AI-driven services. That’s actually the problem. A protocol that connects AI models to everything has become standard before anyone built a security model for it.

What the NSA Found

The advisory lists six categories of risk, and none of them are theoretical. Weak or missing authentication. Poor approval workflows. Insecure data handling. Missing audit logs. Session hijacking vulnerabilities. Prompt injection attacks that let malicious content hijack what the AI does on your behalf.

The NSA notes that real-world exploits have already been documented: “poorly secured MCP tools used to access private information or run harmful commands.” This is not a warning about what might happen. It’s a warning about what is already happening.

Research published by Noma Security earlier this month found that one in four MCP servers exposes AI agents to arbitrary code execution risk. A typical enterprise now runs over 100 high-risk tools connected to its agents. Most of those connections have no version pinning, meaning a silent update to a malicious version could run in production before anyone notices.

The Speed Problem

The core issue isn’t that MCP is fundamentally broken. It’s that the adoption timeline has compressed what should have been a multi-year security maturation process into a matter of months. The NSA’s own words: MCP’s rapid adoption has “outpaced the development of its security model.”

Companies wanted the productivity gains. The AI tools delivered them. The security conversation got deferred. Now the NSA is the one having it, which means the deferral period is over.

I’ve seen this pattern before. A useful technology gets adopted at speed. The security infrastructure builds slowly behind it. The gap between the two is where attackers live. With AI agents, that gap is enormous because the tools are highly capable, deeply connected, and often running with admin-level permissions that nobody explicitly approved.

The Shadow AI Multiplier

This gets worse when you factor in shadow AI. The Verizon DBIR published last week found that employee use of unapproved AI tools tripled in a single year, jumping from 15% to 45%. Most of those tools connect via MCP or similar protocols. Most of those connections aren’t in any IT inventory. Most of the data flowing through them isn’t being logged.

The NSA is warning about sanctioned MCP deployments. The real exposure is the unsanctioned ones that nobody is watching at all.

What to Actually Do About It

The NSA’s recommendations are practical and worth implementing now, regardless of how your AI tools are deployed:

  • Audit what your AI tools connect to. Most organisations can’t answer this question. Start there.
  • Apply least privilege. If an AI assistant needs to read emails, it doesn’t need write access to your database. Scope the permissions.
  • Separate sensitive systems. High-risk data environments should have extra barriers before any AI automation touches them.
  • Log everything. AI agent activity needs audit trails. If you can’t see what the agent did, you can’t detect when it was misused.
  • Validate tool inputs. Prompt injection is a real attack class. Systems that ingest untrusted content into AI workflows need filtering.
  • Pin MCP server versions. Silent updates from a poisoned package are a documented attack vector. Don’t rely on whatever the latest version happens to be.

The NSA is not saying stop using MCP. They’re saying stop treating it as invisible infrastructure that doesn’t need the same scrutiny you’d apply to any other system that touches sensitive data. That’s a reasonable ask.

The Broader Shift

We’re at an inflection point where AI tools have graduated from being interesting experiments to being core operational infrastructure. The security conversation needs to make the same jump. Governance frameworks that were written before agentic AI existed don’t cover this. Procurement processes that check a security questionnaire box but never ask what MCP servers the AI connects to don’t cover this either.

The NSA publishing a formal advisory is a signal that the intelligence community considers this a live, active risk surface. That should carry weight with every CISO and every board that has signed off on AI tooling without asking hard questions about what it’s connected to.

The most dangerous thing about AI agents isn’t what they can do. It’s that nobody in most organisations knows what they’re doing right now.

Related Reading

One VS Code Extension. One Developer. 3,800 GitHub Repositories Gone.

Every time I think I have seen it all with One VS Code Extension. One, something new emerges. I’ve been saying for years that the biggest security risk in most organisations isn’t the firewall or the servers. It’s the developer’s laptop. This week, GitHub proved me right in the most spectacular way possible.

On May 20, Microsoft-owned GitHub confirmed that a hacking group called TeamPCP had stolen data from roughly 3,800 of its internal repositories. The attack vector? A single employee installed a poisoned VS Code extension. That’s it. One bad plugin on one machine, and suddenly a hacking crew is rifling through thousands of GitHub’s own code repositories and offering the stolen data for sale on a cybercrime forum with a starting price of $50,000.

GitHub says there’s no evidence of customer data being impacted, and I’m inclined to believe them on that narrow point. But let’s not lose sight of what actually happened here. The company that hosts the world’s software got hacked through the exact same supply chain weakness that’s been exploited repeatedly in 2026, and they had zero visibility into what extensions their developers were running.

TeamPCP Have Been Busy

Here’s what makes this more alarming than a one-off incident. TeamPCP isn’t some new crew stumbling onto a technique. In 2026 alone they’ve compromised Trivy, Checkmarx, Bitwarden CLI, TanStack, and now GitHub. All through developer tooling. All using the same basic playbook: get malware onto a developer’s machine via a trusted tool, then use that foothold to reach further into the network.

Mackenzie Jackson from Aikido Security put it plainly: “Developer workstations are the number one target in supply chain attacks right now. Most security teams still have zero visibility into what extensions or packages are on their developers’ machines, or how recently they were published. That’s the blind spot these attacks keep walking through.”

That’s the real story here. Not just GitHub. The blind spot is everywhere, in every company with developers using VS Code, which is basically all of them.

Why VS Code Extensions Are a Genuine Crisis

VS Code extensions aren’t sandboxed. They have full access to everything on the machine they run on: credentials, SSH keys, cloud API keys, environment files, tokens sitting in memory. A developer’s laptop is essentially a master key to your entire infrastructure, and VS Code extensions get handed a copy of that key the moment they’re installed.

The VS Code marketplace has hundreds of thousands of extensions. Microsoft does review them, but the review process has never been designed to catch sophisticated supply chain attacks where a legitimate extension is later poisoned via a compromised publisher account or a dependency update. The attacker doesn’t need to create a new malicious extension from scratch. They just need to get access to one that developers already trust.

GitHub hasn’t named the specific extension involved. That omission matters. Without that information, every developer using VS Code right now has no idea whether they’ve been exposed to the same poisoned tool.

What You Actually Need to Do

If you’re responsible for a team of developers, or you are a developer, here’s what this week’s GitHub breach tells you to action:

  • Audit every VS Code extension across your developer machines. You need to know what’s installed, who published it, when it was last updated, and whether the publisher account shows any signs of compromise.
  • Treat developer machines as high-value targets in your threat model, not just endpoints. The credentials and tokens sitting on a developer’s laptop can give an attacker more access than a successful phishing attack on an executive.
  • Rotate credentials and secrets regularly, and treat any secret that has lived on a developer machine as potentially compromised if that machine is breached. GitHub rotated critical secrets immediately after detection, which is good practice, but reactive rotation is always worse than proactive rotation.
  • Consider restricting VS Code extension installs via policy to an approved list. Yes, developers will complain. That’s fine. The alternative is what happened to GitHub.

GitHub is investigating and has promised a full incident report. When that comes out, the specific extension name should be disclosed. Until then, treat your VS Code extension inventory as an open security question.

The Supply Chain Is the Attack Surface Now

What TeamPCP is doing in 2026 is the logical evolution of supply chain attacks. Rather than targeting one organisation directly, they’re targeting the tools that developers at hundreds of organisations use every day. Compromise Trivy (used for container vulnerability scanning) and you potentially have access to every CI/CD pipeline that runs it. Compromise a VS Code extension with millions of installs and you have a foothold on millions of developer machines simultaneously.

We wrote recently about a worm that hit 160+ npm packages including OpenAI. That was the same group, the same technique. The GitHub breach isn’t a surprise. It’s a continuation.

The security perimeter isn’t your network edge anymore. It’s your software supply chain, and most companies have no idea what’s in it.

“A single VS Code extension on one employee’s machine was enough to get access to 3,800 internal GitHub repositories. Most security teams still have zero visibility into what extensions or packages are on their developers’ machines. That’s the blind spot these attacks keep walking through.” – Mackenzie Jackson, Aikido Security

Related Reading

Your Staff Are Feeding AI Tools 18,000 Terabytes of Company Data. Most Bosses Have No Idea.

Few topics in technology right now are as important as Your Staff Are Feeding AI. I had a conversation with a CFO last week who was proud of his company’s AI policy. “We’ve banned ChatGPT,” he told me. I asked him if his team used Grammarly. He said yes, of course, everyone does.

That’s the problem right there.

New data from Zscaler’s ThreatLabz 2026 AI Security Report makes for uncomfortable reading if you run any kind of business. Researchers analysed 989.3 billion AI and machine learning transactions across enterprise networks in 2025, and what they found should be on every board agenda this week.

Employees at enterprise companies transferred 18,033 terabytes of data to AI apps last year. That’s a 93% jump in a single year. The biggest recipient wasn’t ChatGPT. It was Grammarly, with 3,615 terabytes of corporate text flowing into its systems. ChatGPT came in second at 2,021 terabytes. Those 410 million Data Loss Prevention violations tied to ChatGPT alone included attempts to share social security numbers, source code and medical records.

Let that sink in. 410 million violations. In one year. From one tool.

The tools your people are using every day have quietly become, as the Zscaler report puts it, “the world’s most concentrated repositories of corporate intelligence.” Grammarly reads your emails, your proposals, your legal documents, your client strategies. Every time someone pastes text into it and hits “improve,” that text goes somewhere.

This isn’t a criticism of Grammarly or ChatGPT specifically. The problem is the governance gap, or rather, the total absence of one. Enterprise AI usage grew 91% year-on-year across more than 3,400 applications. Engineering teams account for nearly half of all AI usage (48.9%). IT teams handle another 31.8%. These are the people touching your most sensitive systems and codebases.

Meanwhile, separate research from Hadrian, drawn from data across 300-plus organisations, found that 99.5% of security alerts are false positives. Security teams are drowning in noise, unable to find the 0.47% of genuinely exploitable issues buried in thousands of irrelevant notifications. The average time to remediate a critical vulnerability is four days. Some stay open for four months. Not because nobody noticed. Because teams couldn’t distinguish the real threats from the background static.

So here’s where we are: AI adoption is accelerating at machine speed, governance is moving at human speed, and security teams can barely see what’s real. Attackers, by contrast, are using AI for reconnaissance, for exploit chaining, for automated lateral movement. They know exactly where to strike. Defenders are still reading tickets.

What you should actually do about this

Start with a simple audit. List every AI tool your team uses, including the ones embedded in existing software (AI writing assistants baked into Microsoft 365, for instance, or AI features inside your CRM). You probably don’t have a complete list. That’s the point.

Second, implement Data Loss Prevention policies before your employees paste something they shouldn’t. Most enterprise security platforms support DLP rules for common AI endpoints. It’s not a perfect solution but it closes the most obvious doors.

Third, if you’re in finance, healthcare, legal, or any regulated industry, you need to categorise what data is allowed to touch external AI systems. Source code, client contracts, financial projections and patient records should have explicit policies attached. “We don’t use AI with sensitive data” is not a policy. It’s a wish.

Finally, ask your security team how they’re handling alert triage. If the answer is “manually,” you have a problem. The math doesn’t work when you’re looking at thousands of alerts per day and 99.5% of them are noise. Automation and prioritisation tools aren’t optional extras anymore.

The Zscaler report notes that AI governance “has transitioned from a policy discussion to an immediate operational necessity.” The simpler version: your staff are feeding your business intelligence into AI systems you didn’t approve, at a scale you probably haven’t measured, and most of those systems have been found to contain critical vulnerabilities. Every single enterprise AI system in the Zscaler research had at least one. Every one.

That’s not a technology problem. It’s a leadership problem.

“The biggest risk going into 2026 isn’t that organisations lack security tools. It’s that they no longer know which threats are real while attackers know exactly where to strike.”

Rogier Fischer, CEO, Hadrian

Related Reading

AI Just Dethroned Stolen Passwords as the Number One Way Hackers Break In

Let me tell you about AI Just Dethroned Stolen Passwords and why it matters right now. Something just happened in cybersecurity that should make every CISO in Australia sit up and pay attention. For the first time in the history of Verizon’s annual Data Breach Investigations Report, vulnerability exploitation has overtaken stolen credentials as the number one way attackers break into organisations.

And it’s not a small shift. The 2026 DBIR, released this week, reviewed over 31,000 incidents and found that 31% of all breaches now start with vulnerability exploitation. Stolen credentials, which held the top spot for years, have been pushed into second place. The reason? Artificial intelligence.

AI Is Shrinking Your Patching Window to Hours

Here’s what should really worry you. Verizon says AI is accelerating the time to exploit known vulnerabilities, shrinking the window for defence from months to mere hours. That means the patch you deployed last Tuesday might already be too late. Attackers are using AI to scan for unpatched systems, identify the most valuable targets, and craft custom exploits at machine speed.

This isn’t theoretical. The report found that AI is being used at every stage of the attack chain, from initial reconnaissance to malware development. Threat actors are automating the boring parts of hacking, which means they can spend more time on the creative, damaging stuff.

Shadow AI Is Your Biggest Insider Threat

There’s a twist in this report that should terrify anyone running a business. Shadow AI, the use of unauthorized AI tools by employees, is now the third most common non-malicious insider action in data loss incidents.

Think about that for a second. Your marketing team is feeding customer data into unapproved AI tools. Your developers are pasting source code into free coding assistants. Your finance people are uploading spreadsheets to AI analysis tools. Every single one of those actions is a potential breach waiting to happen.

The Verizon report specifically calls out employees submitting source code and structured data via images and other formats. They don’t even realise they’re creating a vulnerability.

The Numbers Don’t Lie

Let’s put some hard numbers on this. CrowdStrike reported earlier in 2025 that AI-enabled adversaries increased their attacks by 89% year-over-year. Combine that with Verizon’s finding that AI is automating attack techniques at scale, and you’ve got a threat landscape that looks nothing like it did two years ago.

Verizon’s Chief Information Security Officer Nasrin Rezai put it bluntly: “We need to fight AI with AI. We need to incorporate them into our practices at a scale that we have never done before.” That’s not marketing speak. That’s a warning.

The Mythos Question

Here’s something the report doesn’t cover, but probably should. Verizon’s DBIR data doesn’t include the impact of Anthropic’s Mythos model, which has raised serious cybersecurity concerns due to its advanced coding and vulnerability-identification capabilities. Verizon is part of a controlled initiative called “Project Glasswing” that allows select organisations to use Mythos for defensive purposes. But the offensive capabilities are already out there.

What You Need to Do Right Now

Stop thinking about cybersecurity as a patching problem. It’s now an AI problem. Here’s where to start:

Audit your Shadow AI usage. You need to know exactly which AI tools your team is using, authorized or not. If you don’t have an AI governance policy, write one this week. Not next month. This week.

Cut your patching cycle to days, not weeks. If your mean time to patch is measured in weeks, you’re already behind. AI-powered attackers will find and exploit your unpatched systems before your next maintenance window.

Deploy AI-powered detection. If you’re still relying on signature-based detection, you’re bringing a knife to a gunfight. You need security tools that can recognise AI-generated attacks and respond in real time.

Train your people on AI risks. Your employees don’t know they’re creating vulnerabilities. Make sure they do. Regular training on what data can and cannot go into AI tools is non-negotiable.

The gap between attackers using AI and defenders using AI is widening. The organisations that survive the next twelve months will be the ones that stop treating AI security as a future problem and start treating it as today’s emergency.

Related Reading:

Microsoft Defender Has Two Zero-Days Being Exploited Right Now. Patch Immediately.

0

Another week, another development in the world of Microsoft Defender Has Two Zero-Days. When the agency responsible for US cyber security issues an emergency directive telling every federal agency to patch within two weeks, you pay attention.

On May 20, CISA added two Microsoft Defender zero-day vulnerabilities to their Known Exploited Vulnerabilities catalogue. Both are being actively exploited in the wild. Both have patches available. The clock is ticking.

What’s Actually Vulnerable

The first flaw, CVE-2026-41091, is a privilege escalation bug in the Microsoft Malware Protection Engine. Versions 1.1.26030.3008 and earlier are affected. If exploited, an attacker gains SYSTEM privileges on your machine. That’s the highest level of access possible on a Windows system. The root cause is an improper link resolution weakness, essentially a link following flaw that lets an attacker trick the engine into loading malicious content with elevated permissions.

The fix is straightforward: update to version 1.1.26040.8.

The second flaw, CVE-2026-45498, is a denial-of-service vulnerability in the Microsoft Defender Antimalware Platform. This affects versions 4.18.26030.3011 and earlier, which is the platform used by System Center Endpoint Protection and Security Essentials among others. An attacker can trigger a DoS state on unpatched devices, potentially disabling your defences at the worst possible moment.

Update to version 4.18.26040.7.

The CISA Mandate

CISA has invoked Binding Operational Directive 22-01, which means this isn’t a suggestion. All Federal Civilian Executive Branch agencies must secure their systems by June 3, 2026. That’s two weeks from the order date.

Their guidance is blunt: apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

For those of us outside the federal government, the message is the same. If CISA considers these vulnerabilities serious enough to mandate a two-week patch cycle across all federal agencies, you should treat them with similar urgency.

How to Check If You’re Protected

Even with automatic updates enabled, you should verify. Here’s how:

  1. Open Windows Security
  2. Go to Virus and threat protection
  3. Click Protection updates and select Check for updates
  4. Navigate to Settings > About
  5. Check the Antimalware Client Version number

Make sure your version meets or exceeds the patched versions listed above. If it doesn’t, force the update manually.

Microsoft has stated that the default configuration in their antimalware software keeps definitions and the platform up to date automatically. That’s true for most users. But “most users” isn’t the same as “all users,” and the organisations most likely to be running outdated versions are exactly the ones that can least afford a breach.

The Bigger Picture

There’s something deeply uncomfortable about vulnerabilities in your security software. You install an antivirus to protect yourself. When that same software becomes the attack vector, it undermines the entire trust model.

These aren’t theoretical risks. CISA says both vulnerabilities are being actively exploited. That means someone, somewhere, is using these flaws against real targets right now.

The privilege escalation bug is particularly concerning. Gaining SYSTEM-level access through your security software gives an attacker everything they need to install persistent backdoors, exfiltrate data, or move laterally across your network. However, they’d be doing it through a process that’s trusted by default by every security tool on your system.

What You Should Do

  • Check your version now. Don’t assume automatic updates have you covered.
  • Force an update if your version is behind.
  • Notify your IT team if you’re in an enterprise environment.
  • Monitor your logs for unusual activity from the Defender process.
  • Consider the timeline. If these are being exploited now and patches are available, the window between disclosure and mass exploitation is shrinking fast.

Microsoft’s Defender team does solid work under enormous pressure. But when the product designed to catch threats becomes one, the entire industry needs to take notice.

Patch now. Check your version. Don’t be the organisation that gets caught waiting.

Related Reading

Cloudflare Just Taught an AI to Chain Security Bugs Into Real Exploits

I keep coming back to Cloudflare Just Taught an AI because it affects every part of digital life. I’ve spent years watching AI vendors promise that their models will revolutionise cyber security. Most of the time, the reality falls short. Finding bugs is one thing. Proving they matter is another.

Cloudflare just showed me something different.

They partnered with Anthropic on Project Glasswing, pitting a new security-focused language model called Mythos Preview against their own codebase of over 50 repositories. The results are worth paying attention to.

The Big Leap: Exploit Chain Construction

Previous frontier models could find individual vulnerabilities. They’d spot a use-after-free bug, flag a buffer overflow, report a logic error. But they couldn’t connect the dots. They’d hand you a list of low-severity findings and call it a day.

Mythos Preview does something different. It takes those same low-severity bugs, the ones that would normally sit invisible in a backlog for months, and chains them into a single, working exploit. It can turn a memory corruption bug into full system control through return-oriented programming chains. It writes proof-of-concept code, compiles it, runs it, and iterates until it has working proof or a confirmed dead end.

“What changed with Mythos Preview is that a model can now take those low-severity bugs and chain them into a single, more severe exploit.”

Cloudflare described the model’s reasoning as resembling “the work of a senior researcher.” That’s not marketing fluff. When a model can independently construct exploit chains, it’s operating at a level we haven’t seen before.

The Harness: How to Scale AI Security Research

Here’s where it gets practical. Cloudflare didn’t just throw the model at their code and hope for the best. They built a staged pipeline, what they call a harness, to leverage Mythos Preview’s strengths while managing its weaknesses.

The key lessons:

  • Narrow scope beats broad prompts. Telling an AI “find all the bugs” is useless. Telling it “examine this specific function for trust boundary violations” produces results.
  • Ask separate questions. “Is this code buggy?” and “Can an attacker actually reach this bug?” are fundamentally different questions. The model performs better when you split them.
  • Run parallel narrow tasks. Instead of one agent trying to cover everything, run 50 focused hunters simultaneously, then deduplicate findings.
  • Use adversarial review. A second agent with different prompts catches the noise the first one generates.

The pipeline runs through recon, hunting, validation, gap-filling, deduplication, reachability tracing, and structured reporting. It’s methodical. It’s boring. It works.

The Refusal Problem

One finding that caught my attention: Mythos Preview exhibits organic refusals on certain security requests, but they’re inconsistent. Same task, different framing, opposite results. Sometimes it’ll help with an exploit chain. Sometimes it won’t.

This matters because it tells us that model guardrails built into the weights alone aren’t reliable. If you’re building security tools on top of these models, you need additional safeguards. The model’s own judgement about what it should and shouldn’t help with is too unpredictable for production use.

The Signal-to-Noise Challenge

False positives remain the biggest headache in AI-assisted vulnerability research. Memory-unsafe languages like C and C++ generate more false positives than memory-safe languages like Rust. Models tend to over-report hedged findings, words like “possibly” and “potentially.”

Mythos Preview improves on this. It produces clearer reproduction steps and working proofs, which reduces the triage burden on human researchers. When the model can prove a bug exists by triggering it, you don’t waste time debating whether the finding is real.

Why This Matters for the Rest of Us

Cloudflare is one of the few companies with the resources and expertise to do this kind of research properly. The fact that they’re sharing their approach publicly is significant.

The implications are straightforward:

  • If AI can chain low-severity bugs into critical exploits, your attack surface just got bigger. Bugs that were “low priority” yesterday are tomorrow’s incident.
  • Generic coding agents won’t cut it for security work. The context mismatch between “write features” and “find vulnerabilities” is too large.
  • The organisations that benefit most will be the ones that build proper harnesses, not the ones that just point a model at their code and hope.

Cloudflare also flagged a dual-use concern. The same capabilities that let an AI defend your code can be turned against someone else’s. There’s no sugar-coating that reality.

My Take

I’ve been sceptical of AI-powered security tools for a while. Most of what I’ve seen is glorified static analysis with a chatbot wrapper. Project Glasswing is different. It demonstrates genuine reasoning about vulnerability exploitation, not just pattern matching.

The staged harness approach is the real takeaway here. AI security research isn’t about finding a magic model. It’s about building the right infrastructure around a capable model. Narrow tasks, parallel execution, adversarial review, and structured reporting. Boring engineering, not flashy demos.

For security teams watching this space: start thinking about how you’d build a harness for your own codebase. The models are getting capable enough that the bottleneck is shifting from “can AI find bugs?” to “can we operationalise the findings?”

Cloudflare plans to share more about how these architectural principles protect their customers. I’ll be watching.

Related Reading

AI Just Broke the 19-Year Record. Here’s What It Means for Your Business.

AI-powered cybersecurity attack concept with digital shield cracking under pressure

Few topics in technology right now are as important as AI Just Broke the 19-Year. I’ve been writing about cybersecurity for years, and every time Verizon drops its annual Data Breach Investigations Report, I sit up and pay attention. This year’s report, released yesterday, contains a finding that should make every business owner in Australia stop what they’re doing and listen.

For the first time in the report’s 19-year history, software vulnerabilities have overtaken stolen credentials as the number one way attackers get into your systems. However, AI is the reason why.

The Numbers That Should Scare You

The 2026 DBIR analyzed over 31,000 security incidents and 22,000 confirmed breaches across 145 countries. The headline finding: vulnerability exploitation was the initial attack method in 31% of all breaches. That’s a massive shift. For nearly two decades, stolen passwords and credentials were the top way in. Not anymore.

Here’s why. AI has compressed the time between discovering a vulnerability and weaponizing it from months to just hours. What used to require a team of skilled researchers now takes a single attacker with a large language model and a few spare hours. The economics have fundamentally changed.

As Trey Ford from Bugcrowd put it: “The DBIR’s 19-year credential streak ending is not primarily a credential story. It is an economics story. AI is making vulnerability discovery and weaponization so fast and cheap that attackers no longer need a stolen password.”

Shadow AI: Your Biggest Internal Threat

But here’s the part that really got me. The report found that employee use of unapproved AI tools tripled in just one year, from 15% to 45% of the workforce. That means nearly half your staff are uploading company data, source code, and confidential information to external AI models you don’t control.

This isn’t a hypothetical risk. This is happening right now, in your organisation, whether you know it or not. Every time someone pastes a client email into ChatGPT, or uploads a spreadsheet to an AI tool without IT approval, they’re creating a data exposure risk that traditional security tools can’t see.

The report calls this “shadow AI” and it represents what experts are calling a massive internal coverage gap that most enterprises remain completely blind to.

The Patching Problem Is Getting Worse

The volume of vulnerabilities is exploding. Security researchers found 48,000+ vulnerabilities last year, an 18% increase. The dataset grew from 68.7 million records in 2022 to 527.3 million in 2025. That’s an eightfold increase in just three years.

And organisations are falling further behind. Only 26% of critical vulnerabilities were fully remediated in 2025, down from 38% the year before. The average time to patch critical vulnerabilities increased to 43 days, up from 32. Even the best-performing organisations can only patch 30-40% of critical vulnerabilities in the first week.

What You Should Do Right Now

Here’s my practical advice, based on what the report recommends:

First, audit your shadow AI usage. You need to know what AI tools your team is using. Run a network audit, check browser histories, and have the conversation with your staff. This isn’t about banning AI, it’s about understanding your exposure.

Second, prioritise patching based on active exploitation, not severity scores alone. The report shows that the probability of exploitation drops after 30 days, 90 days, and about 9 months. If something is being actively exploited in the wild, patch it today, regardless of what CVSS score it has.

Third, invest in automated vulnerability management. The human bottleneck is real. You need tools that can detect, contextualise, prioritise, and remediate without waiting for a human to approve every step. As one expert put it, the defenders who close the gap will be the ones who use AI agentially, not as a co-pilot, but as autonomous workflows.

Fourth, review your supply chain. Supply chain attacks surged 60%, with vendor vulnerabilities now accounting for 48% of all breaches. Every third-party tool, every SaaS platform, every cloud service is a potential entry point.

The Bigger Picture

What strikes me about this report is how it confirms what I’ve been saying for months. AI is a double-edged sword. It’s making us more productive, but it’s also making attackers faster, cheaper, and more effective. The organisations that will survive are the ones that stop treating cybersecurity as an IT problem and start treating it as a business survival issue.

The 48% ransomware figure is also worth noting. Nearly half of all breaches now involve some form of ransomware action, up from 44% the prior year. However, 50% of ransomware breach victims showed signs of an infostealer event within 95 days of intrusion. The attack chain is getting longer and more sophisticated.

The cybersecurity landscape has fundamentally shifted. AI hasn’t just changed the tools attackers use, it’s changed the economics of attack. When vulnerability exploitation becomes cheaper and faster than stealing credentials, every unpatched system becomes a sitting duck. The question isn’t whether you’ll be targeted, it’s whether you’ll be ready.

Related Reading

80% of Organisations Are Worried About AI Data Leaks. Most Aren’t Doing Anything About It.

If you care about 80% of Organisations Are Worried, this is the story you need to read today. Something’s gone wrong with how we’re handling AI security, and the numbers are staring us in the face.

I was reading through Mimecast’s State of Human Risk 2026 report this morning, and there’s a stat that stopped me cold: 80% of organisations are concerned about sensitive data leaking through generative AI tools. Eighty percent. That’s almost everyone.

Now here’s the kicker. Only 40% report being fully prepared with specific strategies for AI-driven threats. That’s a 40-point gap between knowing there’s a problem and actually doing something about it. It’s like knowing your house is on fire but only half the residents have bothered to buy a fire extinguisher.

The report surveyed 2,500 IT security and decision-makers across nine countries, and the findings are brutal. 69% of security leaders say AI-powered attacks are inevitable within the next 12 months. Yet 60% are not fully prepared. We can see the train coming, but nobody’s getting off the tracks.

When Theory Meets Reality

If you think this is just numbers on a page, consider what happened at NYC Health + Hospitals last week. The largest public healthcare system in the United States disclosed a breach affecting 1.8 million people. Hackers had access for three months, from November 2025 to February 2026, and they walked away with medical records, Social Security numbers, and here’s the scary part, fingerprints and palm prints.

Think about that for a second. You can change your password. You can cancel a credit card. But you cannot change your fingerprints. Those 1.8 million people will carry that exposure for the rest of their lives.

The breach came through a third-party vendor, which is exactly the kind of supply chain vulnerability that AI tools are making easier to exploit. When you’re rushing to deploy AI across your organisation, every integration point becomes a potential attack vector.

The AI Vulnerability Explosion

It’s not just Mimecast sounding the alarm. Cycode’s research shows that publicly reported AI security incidents increased by 56.4% from 2023 to 2024, and the trend hasn’t slowed. Their analysis of the top AI security vulnerabilities in 2026 paints a worrying picture:

  • Prompt injection remains the number one attack vector, with a critical CVE (CVSS 9.6) enabling remote code execution through hidden prompts in GitHub Copilot.
  • 81% of security teams lack visibility into how AI is used in their own codebases. You can’t protect what you can’t see.
  • 45% of AI-generated code contains vulnerabilities. That’s nearly half the code being pushed by tools developers trust.
  • Shadow AI (unauthorised AI tool usage) affects 76% of organisations and adds an average of $670,000 to breach costs.

What This Means for You

If you’re running a business, here’s what you need to do right now:

1. Inventory your AI tools. Find out what’s being used across your organisation, including the unofficial stuff. If your team is using ChatGPT on personal accounts for work tasks, that’s Shadow AI, and it’s a data leak waiting to happen.

2. Audit your AI-generated code. If your developers are using Copilot, Claude, or any AI coding assistant, you need a review process. That 45% vulnerability rate isn’t a theoretical risk, it’s a code review backlog.

3. Review your vendor access. NYC Health + Hospitals got hit through a third-party vendor. Every external tool and service that touches your systems is a potential entry point.

4. Implement least-privilege access for AI agents. If you’ve deployed AI agents (and according to Gartner, 40% of enterprise apps will have them by end of 2026), make sure they can only do what they absolutely need to do. 80% of IT workers have already witnessed unauthorised agent actions.

5. Train your people. The report found that only 28% of organisations combine security awareness training with continuous monitoring. Training alone isn’t enough. Monitoring alone isn’t enough. You need both.

The Bottom Line

We’re in a weird moment where everyone can see the problem but almost nobody is moving fast enough to fix it. AI is simultaneously the biggest security risk and the most promising security tool. The organisations that figure out how to manage that paradox are going to be fine. The rest are going to end up in next quarter’s breach statistics.

The gap between knowing you have a security problem and actually fixing it is where attackers live. Right now, that gap is 40 percentage points wide, and it’s growing. Stop reading about it and start doing something about it.


Related Reading