| IN THIS ISSUE |
AI & INTELLIGENCE Shadow AI becomes an asset class you are now expected to inventory | DATA PLATFORMS Data platforms push identity, lineage and zero-trust ingress into the data plane | APPLICATION PLATFORMS Containers become the sandbox for agents; the supply chain is the soft spot | CLOUD PLATFORMS Misconfiguration is the #1 breach vector of 2026 — 14% of every breach |
CS
Get it in your inbox
Subscribe free — a new edition weekly |
INFRASTRUCTURE Data-center capex tops $1 trillion; the shortage moved from chips to memory | NETWORK Fresh Fortinet flaws demand a patch — as network ops themselves go agentic | IDENTITY & ACCESS Passkeys pass five billion; the race is on to give machines identities too | CYBERSECURITY An RMM bypass is already powering a brand-new ransomware strain |
A 2026 enterprise survey found 88% of organizations reported a confirmed or suspected AI-agent security incident in the past year — while 82% of executives said they believed their existing policies already covered them. That gap is the story of the year, and it sits in one place: the trust boundary. AI agents have moved from reading to acting, and the Model Context Protocol (MCP) that wires them to your tools blends instructions with data, so a poisoned tool description can steer an agent as effectively as a malicious prompt.
This is no longer theoretical. Researchers caught the first malicious MCP server in the wild — a package called postmark-mcp that shipped fifteen clean releases before quietly adding a single line of data-exfiltration code. Separately, CVE-2025-6514 (CVSS 9.6) was disclosed in core MCP infrastructure used by hundreds of thousands of developers. The MCPTox benchmark measured tool-poisoning attack-success rates as high as 72.8% — and more capable models were often more vulnerable, because their stronger instruction-following gets weaponized against them. OWASP still ranks prompt injection the number-one cause of agentic-AI failures in production.
The reason this leads the issue is that it touches every layer of the stack below it. An over-permissioned agent is an identity problem, a data-exfil path is a data and cloud problem, an exposed MCP endpoint is a network problem, an unsandboxed agent is an application-platform problem, and an unlogged, unapproved tool call is a compliance problem. You cannot bolt governance on afterward; the controls have to sit around the agent before it is allowed to act.
| 1 AI & INTELLIGENCE | AI MODELS · ANALYTICS · AUTOMATION |
Why it matters: The intelligence layer's fastest-growing risk is the agents and copilots employees adopt faster than IT can track. A 2026 enterprise survey found 88% of organizations had a confirmed or suspected AI-agent incident in the past year, yet 82% of executives believed existing policy already covered them. Vendors have answered at the control-plane level: Microsoft made Agent 365 generally available on May 1 to discover, inventory and govern both its own and third-party agents — including shadow AI such as Copilot CLI and Claude Code on employee machines — and to track which identities, devices and cloud resources each agent can reach.
Do this now: stand up an agent-and-model inventory before you expand use; require every agent to run under a scoped, catalogued identity; and make "what AI is running, and what can it reach?" a question you can answer on demand, not once a year.
| 2 DATA PLATFORMS | ANALYTICS & DATA MANAGEMENT |
Why it matters: As analytics stacks become the substrate for AI and agents, the data layer is where governance now lives. At Data + AI Summit 2026 (June 15–18) Databricks moved Automatic Identity Management for Microsoft Entra ID to general availability on AWS and GCP (Okta in preview), added context-based, zero-trust ingress to dashboards, Genie and AI apps, and expanded compliance toward HITRUST, ISMAP and FedRAMP-High. Identity and policy are being pushed down into the data plane rather than bolted on at the application.
Do this now: consolidate data access on your identity provider (Entra/Okta) instead of platform-local users; enable context-based, zero-trust ingress on every AI-facing surface; and confirm your lakehouse's compliance certifications match the regimes you actually operate under before you point agents at production data.
| 3 APPLICATION PLATFORMS | CONTAINERS & DEVOPS |
Why it matters: Two things are happening at the application layer at once. First, container platforms are adding agent-grade isolation: Red Hat OpenShift now runs agents as policy-enforced Kubernetes pods with default-deny networking, restricted security-context constraints, Kata-style sandboxing and — in OpenShift 4.20 — initial post-quantum mTLS. Second, the supply chain feeding those platforms is under active attack: the first malicious MCP server in the wild (postmark-mcp) shipped fifteen clean releases before adding one line of exfiltration, and CVE-2025-6514 (CVSS 9.6) hit core MCP infrastructure used by hundreds of thousands of developers.
Do this now: run agents and untrusted workloads in sandboxed, default-deny namespaces rather than on flat cluster networking; enforce signed images and an SBOM in the pipeline; and pin and verify the provenance of AI and developer packages — and any MCP server — before it reaches a build.
| 4 CLOUD PLATFORMS | SCALABLE CLOUD INFRASTRUCTURE |
Why it matters: Analysis aligned with the 2026 DBIR puts cloud misconfiguration at 14% of all global breaches in the first quarter of 2026, up from 9% in 2024 — the single largest technical vector of the year — while Gartner still projects that 99% of cloud-security failures through 2026 are the customer's fault. Public S3 buckets, Azure Blob containers and Google Cloud Storage remain the most common exposure, and automated scanners index them within minutes.
Do this now: turn on CSPM and external attack-surface management so you can answer "what is internet-facing right now?" at any moment; default-deny public storage and enforce account-level public-access blocks; encrypt at rest; enforce least-privilege and just-in-time access and remove standing admin; and scan Infrastructure-as-Code for drift before deploy.
| 5 INFRASTRUCTURE & HYBRID CLOUD | SERVERS & AI HARDWARE |
Why it matters: Dell'Oro puts 2026 data-center capex above $1 trillion, up from roughly $650 billion in 2025; the five largest cloud providers alone committed $600–630 billion, about 75% aimed at AI. Prices have eased — H100 cloud rentals are down about 75% from their 2024 peak to roughly $1.80–3.50 per GPU-hour — but a 3.6-million-unit GPU backlog, 36-to-52-week HBM memory lead times and exhausted CoWoS packaging mean the binding constraint is now capacity and timing, not sticker price.
Do this now: if you are standing up AI infrastructure, reserve GPU and memory capacity early and write lead-time risk into the contract. For most enterprise workloads, rent rather than buy — H100 time runs about $1.38–3.50/hr on marketplace clouds versus $11–12 on hyperscaler on-demand — and put a cost-and-lead-time escalation clause into any build agreement.
| 6 NETWORK & CONNECTIVITY | ENTERPRISE NETWORKING |
Why it matters: The connectivity layer took another hit: two FortiSandbox OS-command-injection flaws (CVE-2026-39808 and CVE-2026-25089, both CVSS 9.1) were added to CISA's exploited-vulnerabilities catalog in July, and Fortinet issued an emergency patch for a FortiClient EMS zero-day (CVE-2026-35616) under active exploitation. Enterprise VPN and edge appliances remain among the most-attacked assets in the estate. At the same time the operating model is shifting: Cisco launched Cloud Control at Cisco Live on June 2, putting network, security and observability under one login shared by people and AI agents.
Do this now: patch FortiSandbox to 4.4.9/5.0.6 and FortiClient EMS immediately, and put phishing-resistant MFA in front of every VPN and management interface. As you evaluate agentic network operations, insist those agents get scoped identities and audited actions — never standing admin.
| 7 IDENTITY & ACCESS | HUMAN & NON-HUMAN IDENTITY |
Why it matters: For humans, the bar moved: the FIDO Alliance reported five billion-plus passkeys and 68% of organizations deploying them, and CISA still rates FIDO2/WebAuthn the only phishing-resistant MFA tier — leaving SMS and app-push as the weak link. For non-humans, identity is the year's biggest security spend: CrowdStrike agreed to buy SGNL ($740M) and Cisco moved on Astrix (~$400M), both to bring API keys, service accounts and AI-agent identities under continuous, revocable access control.
Do this now: move admins, VPN, email and RMM to passkeys/FIDO2 and block SMS OTP and legacy authentication; and start treating machine and agent identities as first-class — inventory service accounts and API keys, issue agents short-lived scoped credentials, and eliminate standing secrets.
| 8 CYBERSECURITY | THREAT PROTECTION & ZERO TRUST |
Why it matters: CISA added CVE-2026-18556, an authentication-bypass flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog. On August 2, 2026 — the same day the related bypass CVE-2026-18577 was disclosed — Microsoft tied the actor Storm-1175 (a former Medusa affiliate) to a previously undocumented C++ ransomware, StormEncryptor, and assessed it may be exploiting that N-able flaw. Remote-monitoring-and-management tooling sits above the whole estate, so one console bypass is a mass-deployment button.
Do this now: patch N-central and rotate agent credentials; restrict the console to VPN or allow-listed IPs behind phishing-resistant MFA; hunt for new admin accounts and unfamiliar scheduled tasks; and schedule the August 12 Patch Tuesday ring now (six critical fixes and a kernel elevation-of-privilege on an emergency reboot).
| MARKET SIGNAL | ACROSS ALL EIGHT LAYERS |
| BACKGROUND SIGNAL | CROSS-CUTTING |
Why it matters: The FBI's 2025 IC3 report logged $3.05 billion in business-email-compromise losses across 24,768 complaints — up about 10% year over year — at an average of $137,000 per incident. BEC is no longer just CEO-spoofing: it now spans vendor impersonation, supplier-invoice fraud, OAuth-consent abuse and mailbox-rule manipulation, where an attacker quietly reads and reroutes your mail before striking. Across the whole IC3 dataset, roughly 85 cents of every fraud dollar went to convincing-someone attacks, not malware.
Do this now: require out-of-band verification on a known-good phone number for any change to bank details; alert on new inbox-forwarding rules and OAuth grants; put dual approval on every payment-change workflow; and train staff to treat "urgent + wire + keep-it-quiet" as an automatic stop — no exceptions for the boss.