| IN THIS ISSUE |
AI & INTELLIGENCE GPT-6 ‘Astra’ can find and exploit unknown flaws | DATA Snowflake buys an MCP gateway; the platform governs agents | APPLICATIONS A GitHub supply-chain hit puts AI developers in the crosshairs | CLOUD Oracle cloud +93% — capex terrifies the market |
CS
Get it in your inbox
Subscribe free — a new edition weekly |
INFRASTRUCTURE The AI buildout is now running on borrowed money | NETWORK SonicWall SMA hits CVSS 10 — Qilin already exploiting it | IDENTITY & ACCESS Passkeys are the default; SMS/voice on the way out | CYBERSECURITY CISA flagged seven exploited flaws in a single week |
On September 1, Microsoft made passkeys the default in Entra ID and started retiring SMS and voice one-time codes with no opt-out. From October 30, any organization that still needs a text or a phone call to sign in has to buy it through Microsoft’s Security Store and pay the telecom bill itself. Read as an IT change it looks like housekeeping. Read as a security decision it is a concession: the human-verifiable secret — a password you type, a code read to you over the phone — can no longer outrun a machine-speed attacker.
That attacker now has AI. Voice codes fall to a cloned voice on a vishing call; SMS and password phishing run through automated kits at industrial scale; and on September 3 OpenAI began rolling out GPT-6, codenamed Astra, the first model to reach the “Critical” cybersecurity tier on its own Preparedness Framework — capable of finding and exploiting unknown software flaws, a power OpenAI restricted at launch. The same release that helps defenders lowers the bar for attackers. Passkeys are phishing-resistant precisely because there is no shared secret to steal or trick out of a human. Microsoft forcing the move is the industry admitting the old login was already lost.
Our read. Do not treat this as a Microsoft deadline to survive; treat it as the push to finish phishing-resistant MFA you have been deferring. Inventory who is still on SMS or voice this week, roll passkeys and Windows Hello ahead of October 30, and design the guest, B2B and break-glass paths before the prompts start blocking sign-ins. Then assume the caller is synthetic: put out-of-band verification on every high-value action, because a deepfaked “IT support” call is now cheap and convincing. The login and the human on the phone are both things you can no longer take on faith.
| 1 AI & INTELLIGENCE | FRONTIER MODELS · DUAL USE |
On September 3 OpenAI began rolling out GPT-6, codenamed Astra, and buried in the launch was the line that matters most to security teams: the model reached the “Critical” cybersecurity level on OpenAI’s own Preparedness Framework, meaning it can locate and exploit previously unknown software vulnerabilities. OpenAI restricted that capability at launch, gating advanced cyber work behind a vetted program and a defensive track it calls Daybreak Blue. Astra is also state of the art at computer use, software engineering and science. The dual-use reality is now explicit: the same model that helps your team triage vulnerabilities can, in the wrong hands, hunt for them.
Adoption is running ahead of control. Agentic AI is now in production at roughly 72% of enterprises, but a governance gap of about 60% persists — capability arriving faster than the oversight around it.
Our read. Assume your adversary will get frontier cyber capability, gated or not, because capability diffuses. Prioritize the unglamorous fundamentals a machine attacker exploits fastest: shrink the patch window, cut internet-facing surface, and put exposure management in front of the assets that would actually get hit. And govern your own use — inventory where AI agents run and what they can reach — because the same capability now lives inside your walls.
| 2 DATA | DATA PLATFORMS · GOVERNANCE |
The data layer is consolidating around operating agents, not building them. Snowflake acquired Natoma, an MCP gateway that connects agents to enterprise systems, folding the agent-to-tool plumbing into the platform that holds the data. Databricks pushed the same direction with Agent Bricks and its Unity AI Gateway, positioned to govern AI workloads inside and outside Databricks with MCP services treated as governed assets. The message from both camps is identical: the conversation has moved from building AI systems to operating them under control.
Our read. This is good news if you use it deliberately. The data platform is the right place to enforce what an agent may touch, because that is where the sensitive material lives. Consolidate agent access and MCP connections on a governed gateway, keep lineage and per-agent limits, and avoid a sprawl of point integrations no one can audit. If agents are going to reach your data, make the reach something you granted and can revoke.
| 3 APPLICATIONS | SUPPLY CHAIN · CI/CD |
The software supply chain is now a web of trust connecting developers, AI agents, repositories, credentials and cloud, and attackers are pulling on the threads. This month a GitHub-centered supply-chain compromise specifically targeted AI developers, and poisoned model files in open repositories have become a live malware-delivery vector — arbitrary code that runs the moment a model is loaded. IBM’s X-Force reports roughly a fourfold increase in significant supply-chain and third-party compromises since 2020, driven by attackers abusing the trust between CI/CD automation and SaaS integrations. The AI angle compounds it: AI-assisted developers commit three to four times faster while introducing security findings at roughly ten times the rate.
Our read. Treat the pipeline like production. Enforce signed commits and builds, a real SBOM, secret scanning on every commit, and provenance checks on packages and model files — including the ones an agent pulls in on its own. Lock down the CI/CD-to-SaaS trust attackers keep abusing, and remember a regulation clock (the EU Cyber Resilience Act, NIST SSDF) is now attached to getting this right.
| 4 CLOUD | CLOUD · CAPEX · MARKETS |
Oracle put the AI-cloud paradox on one slide. Cloud infrastructure revenue jumped 93% year over year, a pace that would flatter any hyperscaler — and the market sold the stock off about 7%, because capital spending overshot guidance at $55.7 billion and the company guided FY2027 capex to a staggering $90 to $95 billion, funded in part by tens of billions in new debt. Oracle handed over more than 1.2 gigawatts of data-center capacity in the year to feed it. Growth this fast, bought this expensively and financed with borrowing, is exactly the tension investors are now pricing across the sector.
Our read. The vendor economics are your negotiating context. Providers spending at this scale need committed, predictable demand, which is leverage for you on committed-use pricing and capacity guarantees — and a reason to watch the financial health of any single-vendor bet. Know your cost per workload, keep reversible options, and treat concentration risk in one AI-cloud provider as a board conversation, not a procurement footnote.
| 5 INFRASTRUCTURE & HYBRID CLOUD | CAPEX · DEBT · POWER |
The most important shift in AI infrastructure this quarter was financial, not technical. The capital required has outgrown even the cash flows of the companies spending it, so the buildout is increasingly debt-financed: Oracle alone signaled plans to raise tens of billions more on top of a $55.7 billion capex year, and analysts across the sector are flagging the same move toward borrowing to fund GPU farms and the power to run them. Physical delivery remains the constraint behind the money — energized sites, transformers, interconnection — with more than 1.2 gigawatts delivered by a single provider giving a sense of the scale being wired up.
Our read. Debt-financed infrastructure changes your risk calculus even if you never borrow a dollar. A provider carrying heavy AI-capex debt is more exposed if demand softens or rates move, which is a continuity question for anyone concentrated on them. Favor providers whose spend is matched by durable demand, keep a hybrid or second-source option for critical workloads, and factor vendor financial resilience into long-term commitments.
| 6 NETWORK & CONNECTIVITY | EDGE · PATCH NOW |
The edge stayed on fire. A vulnerability in SonicWall’s SMA1000 secure-access appliances carries a CVSS score of 10.0, the maximum, and SonicWall confirmed active exploitation; CISA added it to the Known Exploited Vulnerabilities catalog on September 2. Threat actors tied to the Qilin (Agenda) ransomware operation have been linked to exploitation of the chain. SMA is a remote-access gateway — the same class of internet-facing box that keeps handing attackers a front door — and it joined a week in which CISA flagged seven exploited flaws at once.
Our read. If you run SonicWall SMA, treat a CVSS 10 with confirmed exploitation as an all-hands emergency: patch now, then hunt for post-exploitation activity, because a maximum-severity remote-access bug is a same-day ransomware on-ramp. More broadly, the edge-appliance pattern is not going to stop — every remote-access box you can retire in favor of identity-based access is one less perfect-10 to race a patch against.
| 7 IDENTITY & ACCESS | PASSKEYS · MFA |
The front page’s mandate lands hardest here. With Entra defaulting to passkeys and SMS/voice on a retirement track, identity teams have a concrete, workforce-wide migration with hard dates: pricing and supported telecom providers disclosed September 18, a self-service password-reset campaign from October 5, and the cost of any remaining SMS/voice shifting to the enterprise on October 30. Windows Hello for Business and macOS Platform SSO now count as standalone MFA factors, and B2B guest passkeys are rolling out — so the migration reaches partners, not just employees. The upside is genuine: passkeys are phishing-resistant because there is no shared secret to steal.
Our read. Run this as a program, not a prompt. Inventory who still depends on SMS or voice and why, sequence passkey and Windows Hello rollout by risk, and design the guest, mobile and break-glass paths before blocking prompts start. Keep the caveat in view — passkey implementations have themselves been attacked this year — so pair the rollout with device trust and monitoring rather than treating passwordless as a finish line.
| 8 CYBERSECURITY | RANSOMWARE · EXPLOITATION |
The exploitation cadence is relentless. In a single week CISA added seven actively exploited vulnerabilities to its catalog, spanning SonicWall, JFrog Artifactory, Sangoma Switchvox, the Starlette and Kestra frameworks and the LiteLLM proxy — a spread that runs from network edge to the AI tooling stack itself. Ransomware crews including Qilin are riding the chain, and one flagged flaw was used to drop a reverse shell, map a Docker environment, evade defenses, deploy a crypto-miner and harvest data. The human cost is getting starker: the Kido International attack saw criminals extort a nursery chain over children’s data, a reminder that extortion has no floor.
Our read. The defense is tempo. Shrink the gap between a patch and its deployment, because that gap is the whole game now, and instrument the AI tooling in your own stack — proxies, gateways, model registries — because attackers have noticed it is soft. Pair exposure management with tested incident response, and assume the extortion playbook will target whatever hurts most, not whatever is most technical.
| THE THROUGH-LINE | ACROSS ALL EIGHT LAYERS |
| ABOUT CYBERSAINYA | DIGITAL TRANSFORMATION PARTNER |
CyberSainya is a digital transformation partner. We help organizations turn IT, security, and AI from sources of risk into engines of growth — complexity made simple. That means clear strategy, the right technology, and a partner who stays in the room long after the decision is made: advisory and consulting, security and IT assessments, executive workshops, and hands-on execution. Through our AI products division, CernoGlobus, we build practical, security-by-design AI that puts enterprise-grade protection behind everyday automation.