CyberSainya CYBERSAINYA The Signal · All editions →
CyberSainya
CYBERSAINYA
EXECUTIVE BRIEFING
Issue 005   Tuesday, September 8, 2026  ·  Weekly

The Signal

AI & Intelligence · Data · Applications · Cloud · Infrastructure · Network · Identity · Cybersecurity
Eight layers of your architecture, one briefing. Every item moves a number on your risk register, changes what you owe under compliance, or changes what your stack costs to run.

BUZZWORD OF THE WEEK  Passwordless — technically the state your users reach the moment they write the new one on a sticky note instead.
PASSWORD OF THE WEEK  there-is-no-password — Entra made it the default; enjoy the sticky notes.
IN THIS
ISSUE
AI & INTELLIGENCE
GPT-6 ‘Astra’ can find and exploit unknown flaws
DATA
Snowflake buys an MCP gateway; the platform governs agents
APPLICATIONS
A GitHub supply-chain hit puts AI developers in the crosshairs
CLOUD
Oracle cloud +93% — capex terrifies the market
CS
Get it in your inbox
Subscribe free —
a new edition weekly
INFRASTRUCTURE
The AI buildout is now running on borrowed money
NETWORK
SonicWall SMA hits CVSS 10 — Qilin already exploiting it
IDENTITY & ACCESS
Passkeys are the default; SMS/voice on the way out
CYBERSECURITY
CISA flagged seven exploited flaws in a single week
FRONT PAGE · SPANS ALL EIGHT LAYERS

The password is dying — and AI is holding the knife.

On September 1, Microsoft made passkeys the default in Entra ID and started retiring SMS and voice one-time codes with no opt-out. From October 30, any organization that still needs a text or a phone call to sign in has to buy it through Microsoft’s Security Store and pay the telecom bill itself. Read as an IT change it looks like housekeeping. Read as a security decision it is a concession: the human-verifiable secret — a password you type, a code read to you over the phone — can no longer outrun a machine-speed attacker.

That attacker now has AI. Voice codes fall to a cloned voice on a vishing call; SMS and password phishing run through automated kits at industrial scale; and on September 3 OpenAI began rolling out GPT-6, codenamed Astra, the first model to reach the “Critical” cybersecurity tier on its own Preparedness Framework — capable of finding and exploiting unknown software flaws, a power OpenAI restricted at launch. The same release that helps defenders lowers the bar for attackers. Passkeys are phishing-resistant precisely because there is no shared secret to steal or trick out of a human. Microsoft forcing the move is the industry admitting the old login was already lost.

Our read. Do not treat this as a Microsoft deadline to survive; treat it as the push to finish phishing-resistant MFA you have been deferring. Inventory who is still on SMS or voice this week, roll passkeys and Windows Hello ahead of October 30, and design the guest, B2B and break-glass paths before the prompts start blocking sign-ins. Then assume the caller is synthetic: put out-of-band verification on every high-value action, because a deepfaked “IT support” call is now cheap and convincing. The login and the human on the phone are both things you can no longer take on faith.

SIGNAL BRAIN TEASER
You have three keys and three locks but don’t know which key fits which. In the worst case, how many attempts guarantee you match all three? (answer at the foot)
1   AI & INTELLIGENCEFRONTIER MODELS · DUAL USE
THE MODEL THAT CAN FIND ZERO-DAYS

OpenAI’s new GPT-6 ‘Astra’ hit a ‘Critical’ cyber threshold — it can find and exploit unknown flaws.

On September 3 OpenAI began rolling out GPT-6, codenamed Astra, and buried in the launch was the line that matters most to security teams: the model reached the “Critical” cybersecurity level on OpenAI’s own Preparedness Framework, meaning it can locate and exploit previously unknown software vulnerabilities. OpenAI restricted that capability at launch, gating advanced cyber work behind a vetted program and a defensive track it calls Daybreak Blue. Astra is also state of the art at computer use, software engineering and science. The dual-use reality is now explicit: the same model that helps your team triage vulnerabilities can, in the wrong hands, hunt for them.

Adoption is running ahead of control. Agentic AI is now in production at roughly 72% of enterprises, but a governance gap of about 60% persists — capability arriving faster than the oversight around it.

Our read. Assume your adversary will get frontier cyber capability, gated or not, because capability diffuses. Prioritize the unglamorous fundamentals a machine attacker exploits fastest: shrink the patch window, cut internet-facing surface, and put exposure management in front of the assets that would actually get hit. And govern your own use — inventory where AI agents run and what they can reach — because the same capability now lives inside your walls.

A robot with a magnifying glass, a shield and a lockpick — defend and attack
BY THE NUMBERS
GPT-6 ‘Astra’ began rolling out Sept 3 and reached the “Critical” cyber tier on OpenAI’s Preparedness Framework — able to locate and exploit previously unknown software flaws. That capability is gated behind a vetted program and a defensive track (Daybreak Blue); Astra is also state-of-the-art at computer use, software engineering and science. Enterprise reality: agentic AI is in production at ~72% of firms, against a ~60% governance gap — capability arriving faster than the oversight around it.
VENDOR MAP
Anthropic, Microsoft, Google Cloud and AWS ship both the frontier models and the guardrails — red-team programs, usage policies, and defensive tooling (threat detection, secure-by-default agent controls). Judge a partner on the safety framework and the blue-team tooling they hand you, not just the leaderboard score — and on whether they make your own AI use inventoried and auditable.
2   DATADATA PLATFORMS · GOVERNANCE
THE PLATFORM BUYS THE MIDDLE

Snowflake buys an MCP gateway; the data platform keeps becoming the agent’s control point.

The data layer is consolidating around operating agents, not building them. Snowflake acquired Natoma, an MCP gateway that connects agents to enterprise systems, folding the agent-to-tool plumbing into the platform that holds the data. Databricks pushed the same direction with Agent Bricks and its Unity AI Gateway, positioned to govern AI workloads inside and outside Databricks with MCP services treated as governed assets. The message from both camps is identical: the conversation has moved from building AI systems to operating them under control.

Our read. This is good news if you use it deliberately. The data platform is the right place to enforce what an agent may touch, because that is where the sensitive material lives. Consolidate agent access and MCP connections on a governed gateway, keep lineage and per-agent limits, and avoid a sprawl of point integrations no one can audit. If agents are going to reach your data, make the reach something you granted and can revoke.

BY THE NUMBERS
Snowflake acquired Natoma, an MCP gateway that connects agents to enterprise systems — folding the agent-to-tool plumbing into the platform that holds the data. Databricks answered with Agent Bricks and a Unity AI Gateway that governs AI workloads with MCP services treated as governed assets, and reports 100,000+ agents on-platform. Both camps moved the same way: from building AI systems to operating them under control.
VENDOR MAP
Databricks, IBM, Microsoft and Google Cloud are all making the data platform the agent control point — lineage, per-agent access limits, and a governed gateway for MCP connections. A strong fit when you want agent access you explicitly granted and can revoke, audited in one place rather than scattered across point integrations no one owns.
SIGNAL BRAIN TEASER
Nine identical API keys, one is over-privileged (it weighs a little more). With a balance scale, what is the fewest weighings that will always find it? (answer at the foot)
3   APPLICATIONSSUPPLY CHAIN · CI/CD
THE PIPELINE IS THE TARGET

A GitHub supply-chain compromise put AI developers in the crosshairs — trust is the thing being forged.

The software supply chain is now a web of trust connecting developers, AI agents, repositories, credentials and cloud, and attackers are pulling on the threads. This month a GitHub-centered supply-chain compromise specifically targeted AI developers, and poisoned model files in open repositories have become a live malware-delivery vector — arbitrary code that runs the moment a model is loaded. IBM’s X-Force reports roughly a fourfold increase in significant supply-chain and third-party compromises since 2020, driven by attackers abusing the trust between CI/CD automation and SaaS integrations. The AI angle compounds it: AI-assisted developers commit three to four times faster while introducing security findings at roughly ten times the rate.

Our read. Treat the pipeline like production. Enforce signed commits and builds, a real SBOM, secret scanning on every commit, and provenance checks on packages and model files — including the ones an agent pulls in on its own. Lock down the CI/CD-to-SaaS trust attackers keep abusing, and remember a regulation clock (the EU Cyber Resilience Act, NIST SSDF) is now attached to getting this right.

BY THE NUMBERS
IBM X-Force reports a ~4x rise in significant supply-chain and third-party compromises since 2020, driven by abuse of CI/CD-to-SaaS trust. This month a GitHub-centered compromise specifically targeted AI developers, and poisoned model files in open repos now run arbitrary code the moment a model loads. The AI angle compounds it: AI-assisted developers commit 3–4x faster while introducing security findings at ~10x the rate.
VENDOR MAP
Red Hat, Microsoft and IBM build provenance and pipeline governance into the platform — signed commits and builds, a real SBOM, secret scanning on every commit, and provenance checks on packages and model files (including what an agent pulls in on its own). The value is enforcement that travels with every build — and a regulation clock (EU CRA, NIST SSDF) is already attached.
SIGNAL BRAIN TEASER
A phishing kit sends 1,000 texts. 4% of people click, and 25% of those enter their code. How many codes does the attacker collect? (answer at the foot)
4   CLOUDCLOUD · CAPEX · MARKETS
ORACLE’S TERRIFYING NUMBER

Oracle’s cloud is booming and its spending is terrifying — OCI up 93%, capex headed to $90B+.

Oracle put the AI-cloud paradox on one slide. Cloud infrastructure revenue jumped 93% year over year, a pace that would flatter any hyperscaler — and the market sold the stock off about 7%, because capital spending overshot guidance at $55.7 billion and the company guided FY2027 capex to a staggering $90 to $95 billion, funded in part by tens of billions in new debt. Oracle handed over more than 1.2 gigawatts of data-center capacity in the year to feed it. Growth this fast, bought this expensively and financed with borrowing, is exactly the tension investors are now pricing across the sector.

Our read. The vendor economics are your negotiating context. Providers spending at this scale need committed, predictable demand, which is leverage for you on committed-use pricing and capacity guarantees — and a reason to watch the financial health of any single-vendor bet. Know your cost per workload, keep reversible options, and treat concentration risk in one AI-cloud provider as a board conversation, not a procurement footnote.

A data-center building balanced on a wobbling stack of coins, a red down-arrow
BY THE NUMBERS
Oracle cloud infrastructure revenue rose +93% YoY. FY2026 capex hit $55.7B — over guidance — and FY2027 capex is guided to $90–95B, funded in part by tens of billions in new debt. Oracle handed over >1.2 GW of data-center capacity in the year to feed it. Even so, the stock fell ~7% as the market priced the spend. Fast growth, bought expensively and financed by borrowing, is the tension now repeating across the sector.
VENDOR MAP
AWS, Google Cloud, Microsoft and Oracle are all spending at historic scale to win AI workloads — and that hands you leverage. Trade predictable demand for committed-use discounts, capacity guarantees and price protection. Know your cost per workload, keep a reversible exit path, and treat concentration in one AI-cloud provider — and that provider’s balance sheet — as a board conversation, not a procurement footnote.
5   INFRASTRUCTURE & HYBRID CLOUDCAPEX · DEBT · POWER
THE BUILDOUT GOES INTO DEBT

The AI buildout is now running on borrowed money — and that is a balance-sheet risk you inherit.

The most important shift in AI infrastructure this quarter was financial, not technical. The capital required has outgrown even the cash flows of the companies spending it, so the buildout is increasingly debt-financed: Oracle alone signaled plans to raise tens of billions more on top of a $55.7 billion capex year, and analysts across the sector are flagging the same move toward borrowing to fund GPU farms and the power to run them. Physical delivery remains the constraint behind the money — energized sites, transformers, interconnection — with more than 1.2 gigawatts delivered by a single provider giving a sense of the scale being wired up.

Our read. Debt-financed infrastructure changes your risk calculus even if you never borrow a dollar. A provider carrying heavy AI-capex debt is more exposed if demand softens or rates move, which is a continuity question for anyone concentrated on them. Favor providers whose spend is matched by durable demand, keep a hybrid or second-source option for critical workloads, and factor vendor financial resilience into long-term commitments.

BY THE NUMBERS
The AI buildout is now materially debt-financed: on top of a $55.7B FY2026 capex year, Oracle signaled plans to raise tens of billions more, with FY2027 guided to $90–95B — a move analysts flag across the sector. Physical delivery is the real constraint behind the money: energized sites, transformers and interconnection, with >1.2 GW delivered by a single provider hinting at the scale being wired up.
VENDOR MAP
Dell, HPE, Lenovo and IBM anchor the on-prem and hybrid alternative when single-vendor cloud concentration becomes a board-level risk. Their delivery-date and power guidance is the useful part — a second source for critical workloads, and a hedge against a provider whose heavy AI-capex debt is more exposed if demand softens or rates move.
SIGNAL BRAIN TEASER
The grid approves 30 MW a year; your new site needs 100 MW to run at full load. How many years until it gets there? (answer at the foot)
6   NETWORK & CONNECTIVITYEDGE · PATCH NOW
ANOTHER EDGE APPLIANCE AT CVSS 10

SonicWall’s SMA appliance hit a perfect-10 flaw — already exploited by Qilin ransomware.

The edge stayed on fire. A vulnerability in SonicWall’s SMA1000 secure-access appliances carries a CVSS score of 10.0, the maximum, and SonicWall confirmed active exploitation; CISA added it to the Known Exploited Vulnerabilities catalog on September 2. Threat actors tied to the Qilin (Agenda) ransomware operation have been linked to exploitation of the chain. SMA is a remote-access gateway — the same class of internet-facing box that keeps handing attackers a front door — and it joined a week in which CISA flagged seven exploited flaws at once.

Our read. If you run SonicWall SMA, treat a CVSS 10 with confirmed exploitation as an all-hands emergency: patch now, then hunt for post-exploitation activity, because a maximum-severity remote-access bug is a same-day ransomware on-ramp. More broadly, the edge-appliance pattern is not going to stop — every remote-access box you can retire in favor of identity-based access is one less perfect-10 to race a patch against.

A heavy gateway door with a glowing crack stamped 10, a figure slipping through
BY THE NUMBERS
SonicWall SMA1000 secure-access appliances carry a CVSS 10.0 (maximum) flaw with confirmed active exploitation; CISA added it to the KEV catalog on Sept 2. Actors tied to Qilin (Agenda) ransomware are linked to the chain. SMA is an internet-facing remote-access gateway — the class of box that keeps handing attackers a front door, and a same-day ransomware on-ramp. It was one of seven exploited flaws CISA flagged in a single week. Patch now, then hunt for post-exploitation activity.
VENDOR MAP
Zscaler, Palo Alto Networks, Cisco, Fortinet, Check Point and HPE (Aruba/Juniper) offer identity-based, zero-trust access that shrinks this exposure. Every remote-access appliance you retire in favor of ZTNA is one less perfect-10 to race a patch against. Favor an access model that removes the internet-facing box entirely, not just one that patches it faster.
7   IDENTITY & ACCESSPASSKEYS · MFA
PASSKEYS ARE THE FLOOR NOW

Passkeys just became the default — the operational scramble is real, and so is the payoff.

The front page’s mandate lands hardest here. With Entra defaulting to passkeys and SMS/voice on a retirement track, identity teams have a concrete, workforce-wide migration with hard dates: pricing and supported telecom providers disclosed September 18, a self-service password-reset campaign from October 5, and the cost of any remaining SMS/voice shifting to the enterprise on October 30. Windows Hello for Business and macOS Platform SSO now count as standalone MFA factors, and B2B guest passkeys are rolling out — so the migration reaches partners, not just employees. The upside is genuine: passkeys are phishing-resistant because there is no shared secret to steal.

Our read. Run this as a program, not a prompt. Inventory who still depends on SMS or voice and why, sequence passkey and Windows Hello rollout by risk, and design the guest, mobile and break-glass paths before blocking prompts start. Keep the caveat in view — passkey implementations have themselves been attacked this year — so pair the rollout with device trust and monitoring rather than treating passwordless as a finish line.

BY THE NUMBERS
Entra passkeys became the default Sept 1. The calendar: telecom pricing and supported providers disclosed Sept 18; a self-service password-reset push from Oct 5; SMS/voice cost shifts to the enterprise Oct 30, with no opt-out. Windows Hello for Business and macOS Platform SSO now count as standalone MFA, and B2B guest passkeys are rolling out — so the migration reaches partners, not just staff. Caveat: passkey implementations have themselves been attacked this year.
VENDOR MAP
Okta, Microsoft, CrowdStrike and Cisco are converging on phishing-resistant access and identity threat detection. Use the rollout to standardize on device-bound, phishing-resistant factors, sequence by risk, and design the guest, mobile and break-glass paths before blocking prompts start. Pair it with device trust and monitoring — passwordless is a floor, not a finish line.
SIGNAL BRAIN TEASER
I can’t be phished, can’t be typed, and I live only on your device. What am I? (answer at the foot)
8   CYBERSECURITYRANSOMWARE · EXPLOITATION
SEVEN IN A WEEK

CISA flagged seven actively exploited flaws in a week — and the victims got personal.

The exploitation cadence is relentless. In a single week CISA added seven actively exploited vulnerabilities to its catalog, spanning SonicWall, JFrog Artifactory, Sangoma Switchvox, the Starlette and Kestra frameworks and the LiteLLM proxy — a spread that runs from network edge to the AI tooling stack itself. Ransomware crews including Qilin are riding the chain, and one flagged flaw was used to drop a reverse shell, map a Docker environment, evade defenses, deploy a crypto-miner and harvest data. The human cost is getting starker: the Kido International attack saw criminals extort a nursery chain over children’s data, a reminder that extortion has no floor.

Our read. The defense is tempo. Shrink the gap between a patch and its deployment, because that gap is the whole game now, and instrument the AI tooling in your own stack — proxies, gateways, model registries — because attackers have noticed it is soft. Pair exposure management with tested incident response, and assume the extortion playbook will target whatever hurts most, not whatever is most technical.

A long wall with seven doors springing open at once, a robot rushing with patches
BY THE NUMBERS
CISA added seven actively exploited flaws in a single week — spanning SonicWall, JFrog Artifactory, Sangoma Switchvox, Starlette, Kestra and the LiteLLM proxy, i.e. network edge through the AI-tooling stack itself. Qilin and peers are riding the chain; one flaw was used to drop a reverse shell, map a Docker environment, evade defenses, deploy a crypto-miner and harvest data. The Kido nursery-chain attack saw criminals extort over children’s data — extortion has no floor.
VENDOR MAP
CrowdStrike, Palo Alto Networks, Microsoft and Fortinet cover detection and response; Tenable adds exposure management. The value compounds when detection, identity and exposure share one picture of risk — so a flagged CVE, the assets exposed to it, and the identities that touch them all line up. Buy the integration, not five disconnected consoles.
THE THROUGH-LINEACROSS ALL EIGHT LAYERS
The week has one spine: the ways you prove who and what to trust are being rewritten at once. The password is being retired because a human-verifiable secret cannot survive machine-speed, AI-assisted attacks (Identity, AI). The software supply chain and the AI tooling inside it have become the trust worth forging (Applications, Cybersecurity). The edge appliance keeps failing as the front door (Network). And the cloud you lean on is spending — and now borrowing — at a scale that makes its resilience your problem (Cloud, Infrastructure), while the data platform quietly becomes where you govern the agents in the middle (Data). Trust is the product this year, and it is being rebuilt in public. Get ahead of the parts with deadlines.
Brain teaser answers — Three keys, three locks: three attempts. Nine API keys: two weighings (split 3–3–3). Phishing kit: 10 codes. Power ramp: four years. Can’t be typed: a passkey.
ABOUT CYBERSAINYADIGITAL TRANSFORMATION PARTNER

CyberSainya is a digital transformation partner. We help organizations turn IT, security, and AI from sources of risk into engines of growth — complexity made simple. That means clear strategy, the right technology, and a partner who stays in the room long after the decision is made: advisory and consulting, security and IT assessments, executive workshops, and hands-on execution. Through our AI products division, CernoGlobus, we build practical, security-by-design AI that puts enterprise-grade protection behind everyday automation.

Advisory & assessments
Benchmark your control plane across all eight layers, then a clear plan to close the gaps — not a 90-page PDF nobody reads. Take the free assessment →
CernoGlobus · AI division
Security-by-design AI coworkers that automate the busywork without opening one more door.
Vendor-neutral by design. CyberSainya partners with Anthropic, Adobe, AWS, Check Point, Cisco, CrowdStrike, Databricks, Dell, Fortinet, Google Cloud, HPE, IBM, Lenovo, Lightspeed, Microsoft, Okta, Palo Alto Networks, Red Hat, Tenable, and Zscaler. So the tools we recommend fit your environment and your risk, never a quota.
© CyberSainya · cybersainya.com