| IN THIS ISSUE |
AI & INTELLIGENCE Agents get a language, an ID, and a wallet this month | DATA The data platform becomes the agent’s manager | APPLICATIONS Coding agents take whole assignments now, not lines | CLOUD ~$725B in capex — and ‘when does it pay off?’ |
CS
Get it in your inbox
Subscribe free — a new edition weekly |
INFRASTRUCTURE The shortage was memory; now it’s power | NETWORK A live Cisco VPN zero-day — patch this week | IDENTITY & ACCESS ‘Phishing-resistant’ MFA bypassed; 700 orgs fell | CYBERSECURITY Gunra ransomware and a week of urgent patches |
Three weeks ago, none of this existed. Today an AI agent built on one vendor’s platform can find an agent built on another’s, prove who it is, and pay it for a job. The pieces landed almost on top of each other. On August 20 Google handed its A2A protocol to the Linux Foundation and parked it beside Anthropic’s MCP under a single roof, so agents from rival stacks finally share a language. Snowflake began issuing agents their own cryptographic identities. Cloudflare switched on x402, a way for an agent to pay for a service with no human tapping approve, and more than twenty companies are already using it.
Put those together and you have something most boards have not priced in: a small economy of software actors running inside the business and transacting on its behalf. The upside is obvious. So is the exposure. This same month, attackers lifted one machine credential from a chatbot integration and used it to wander through more than 700 Salesforce tenants. They did not break in. They logged in, as trusted software, because that is exactly what the stolen token said they were. Roughly four in five companies still have no real control over what their agents can see or do.
Our read. The plumbing for the agent economy shipped before the controls did, and that order of operations is the risk in a sentence. Before you let agents transact, give each one an identity you can revoke, a budget it cannot blow past, and a log you can actually read. The companies that treat this as an operating discipline now are the ones that will stay calm the night an agent does something expensive at 2 a.m. One of them eventually will.
| 1 AI & INTELLIGENCE | MODELS · AGENTS · STANDARDS |
OpenAI shipped GPT-5.6 in three sizes. Google folded its Vertex and Agentspace tooling into one Gemini Enterprise platform. AWS made web search generally available inside Bedrock AgentCore, so an agent can pull live, cited answers without data leaving the customer’s account. The standards bodies moved too, with A2A joining MCP under the new Agentic AI Foundation and its 250-plus members. The pile of incompatible pilots is turning into a stack.
Oversight is the piece lagging behind. Deloitte’s latest enterprise survey found only about one company in five has a mature way to supervise autonomous agents, even as usage climbs fast.
Our read. Take the interoperability win, because it lowers lock-in and makes changing vendors a real option instead of a threat. Just build the oversight in the same sprint, not the one after. An agent you cannot inventory is an agent you cannot answer for when the auditor asks who approved it.
| 2 DATA | GOVERNANCE · AGENT IDENTITY |
At this year’s summits, both big lakehouse vendors led with governance instead of burying it. Databricks pitched its Unity AI Gateway as a control layer for the whole AI stack, treating MCP services as assets it can govern rather than models it merely hosts. Snowflake went at identity directly, giving each agent a cryptographic ID with role-based access and dynamic masking. The scale behind this is not a rounding error. Databricks says customers have built more than 100,000 agents on its platform, running through north of a quadrillion tokens a year.
Our read. The right place to enforce what an agent may touch is the data layer, because that is where the sensitive material actually sits. Consolidate agent access on your identity provider, put spend and access limits on every AI-facing surface, and make an agent’s reach something you granted on purpose instead of something it quietly inherited.
| 3 APPLICATIONS | AI CODING · PLATFORMS |
The pattern across the tooling this year is delegation. A developer hands an agent an entire ticket, a migration or a test suite or a refactor, and it works the problem in a loop on its own. Cloudflare leaned in with Kitesurf, a browser built for agents that runs far lighter than Chromium, and with x402 so those agents can pay their own way. The Register said the uncomfortable part out loud, noting that routine software development and IT services are squarely in the cross-hairs as this shifts from novelty to normal.
Our read. Whatever governs your human developers now has to govern the agents working next to them, and the internal platform is where that happens. Golden paths, signed builds, and automated checks stop being nice-to-haves. They become the only practical way to let agents commit code and spend money without a person checking each one by hand.
| 4 CLOUD | CAPEX · FINOPS · ROI |
The four biggest hyperscalers now expect to spend somewhere around $725 billion on capital projects this year, most of it on AI data centers, up better than 70% from last year. Google alone raised its 2026 range to as much as $205 billion. The revenue is real, too. Google Cloud grew 82% last quarter and AWS grew 37%, its fastest in more than four years. And yet Alphabet’s stock slipped after the print, because investors have started asking the question the rest of us are asking: when does all this spending pay for itself.
Our read. That question lands on your desk as well. The cloud bill is now dominated by AI usage that grows with every prompt, so the discipline is knowing which workloads earn their keep. Fund the ones tied to real institutional value and starve the science projects. FinOps is no longer a back-office chore. It is how you keep the AI program defensible when finance comes asking.
| 5 INFRASTRUCTURE & HYBRID CLOUD | MEMORY · POWER · CAPACITY |
High-bandwidth memory is the choke point for AI hardware now, and the supply is already spoken for. SK Hynix has effectively sold its output to Nvidia through the end of the year. The side effects are strange. For the first time in three decades there is no new consumer graphics card, because the wafers and packaging went to data-center parts instead. Nvidia’s next platform, Vera Rubin, arrives later this year hungrier for memory still. And the real scarcity is quietly moving again, from silicon to electricity. Power-ready sites, transformers, and grid hookups are becoming the thing you cannot buy in a hurry.
Our read. If AI infrastructure is on your roadmap, treat capacity and power like long-lead materials, because that is what they have become. Reserve early, write lead-time risk into the contract, and plan the refresh around the memory and power you can actually secure, not the spec sheet you would prefer to build against.
| 6 NETWORK & CONNECTIVITY | VPN · SASE · PATCH NOW |
Cisco disclosed a flaw in its ASA and FTD firewalls, CVE-2026-20349, that lets an unauthenticated attacker reboot the device with a crafted request. It is being exploited in the wild, and CISA put it on the mandatory-patch list on August 11. Fortinet is having a similar year. The Gunra ransomware crew has been walking through authentication-bypass bugs in FortiGate gear to get its first foothold. None of this is new in kind. The edge appliance keeps being the door attackers try first.
Our read. Patch the firewalls this week, and put phishing-resistant MFA in front of every management interface while you are in there. Then have the bigger conversation. Every VPN concentrator you retire in favor of identity-based access is one less public door to defend, and the market has plainly decided that is the direction. This is one of the cleaner risk reductions on the table right now.
| 7 IDENTITY & ACCESS | PASSKEYS · MACHINE IDENTITY |
First, researchers at Black Hat showed more than twenty ways to defeat “phishing-resistant” MFA, including a Windows bug that left YubiKey signatures sitting in cleartext where an ordinary user could read and replay them. Then came the more sobering one. The fallout from a stolen chatbot token kept spreading, as a single machine credential lifted from a marketing integration let attackers into more than 700 Salesforce tenants, and every system treated them as trusted software because, on paper, they were. The weakest identity in your environment is probably not a human being.
Our read. Passkeys are still the right destination for human logins, so keep going. The exposure now is in the identities nobody watches: service accounts, API keys, OAuth grants, and the agents from our front page. Inventory them, issue short-lived credentials, and revoke without ceremony. A machine identity you forgot about is the one that opens 700 doors at once.
| 8 CYBERSECURITY | RANSOMWARE · PATCH CADENCE |
CISA, the FBI and the NSA put out a joint advisory on Gunra, a ransomware operation built from leaked Conti code that now runs as a rent-a-crew service with a tidy Tor negotiation portal. A week later CISA added four more actively exploited bugs to its catalog, across macOS, SharePoint, VMware vCenter and Windows, and gave federal agencies until today to fix a Microsoft flaw already being used in a North Korean campaign. The pattern is industrial: known bugs, fast exploitation, professional crews doing it for money.
Our read. The defense here is unglamorous and it works. Shrink the gap between a patch landing and you applying it, because that gap is where these crews live. Pair exposure management that tells you what is genuinely reachable with the AI-assisted detection moving into the SOC, and make out-of-band verification the rule for any change to payment details, since the social-engineering side keeps getting better at impersonating your executives.
| THE THROUGH-LINE | ACROSS ALL EIGHT LAYERS |
| THE CIO SHELF | OUR READ OF HARVARD BUSINESS REVIEW |
Harvard Business Review has been pressing an argument that lands squarely on this issue’s front page. As HBR frames it, agent projects stall for a reason that has little to do with the model. They get managed like software when they should be managed like people. Treat an agent as a tool and you get a clever demo. Treat it as a co-worker and you give it what any new hire gets: a written job description, a defined scope, a human who supervises it, and an honest review of how it performed.
The survey HBR reported is sobering. Only 6% of companies say they fully trust an agent to run a core business process on its own, and yet 86% intend to spend more on agents over the next two years. That gap between what leaders trust and what they are buying is where the risk sits. HBR’s other point is just as practical: agents fail most often when the business around them is fragmented, because an agent cannot grasp context its own company never wrote down.
Our read. This is the operating manual for the agent economy we opened with. Before the next agent goes live, write its job description. Spell out what it can touch, what it may spend, who signs off on the exceptions, and how you will judge whether it earned its seat. An agent without a manager is not automation. It is an unsupervised employee holding your credentials.
| THE FINANCE DESK | THE MARKETS ANGLE · AI SPENDING |
Read the markets coverage this month and one contradiction keeps surfacing. Fund managers named AI capital spending the single most likely trigger for a systemic credit event, the top tail risk in the market today. In the same survey they cut cash to one of the lowest levels on record and kept buying the very companies doing the spending. The numbers behind the worry are staggering. Amazon, Alphabet and Microsoft are on track to pour roughly 102% of their cloud revenue back into capex this year, and one bank now pencils in close to a trillion dollars of hyperscaler spending for 2026 alone. Share prices are swinging on AI headlines faster than on AI results.
Our read. The market’s nerves are your budget conversation in miniature. When the people funding this buildout cannot agree whether it pays off, no technology leader gets a free pass on showing the return. Tie every AI dollar to an outcome your CFO can point to, keep the reversible options open, and be ready to defend your AI spend the way a portfolio manager defends a position. The companies that can show results rather than headlines are the ones that keep their funding when the mood turns.
| ABOUT CYBERSAINYA | DIGITAL TRANSFORMATION PARTNER |
CyberSainya is a digital transformation partner. We help organizations turn IT, security, and AI from sources of risk into engines of growth — complexity made simple. That means clear strategy, the right technology, and a partner who stays in the room long after the decision is made: advisory and consulting, security and IT assessments, executive workshops, and hands-on execution. Through our AI products division, CernoGlobus, we build practical, security-by-design AI that puts enterprise-grade protection behind everyday automation.