AI Compliance & Cyber · October 6, 2026

AI Compliance & Cyber Brief

This week's signal is the distance between written controls and controls that actually fire. Google quantified how fast vulnerabilities are arriving and how few matter, a vendor study showed that AI access policies are nearly universal while real-time enforcement is not, and two incident reports point at the same weak spot: the systems around the AI, not the model itself. Where an account comes from one party or one vendor, we say so. No NIST AI RMF, ISO 42001, or DoCRA developments were material this week.

The 30-second version

A Dutch vulnerability-disclosure nonprofit says an automated agent chained two Zammad zero-days to root in seconds

Talking point

A Dutch security nonprofit reports that an automated agent chained two zero-day flaws in the Zammad help-desk software and went from a hijacked session to full control in seconds. By DIVD's own account the activity was loud and messy, and network segmentation limited the damage. The investigation is open, the operator is unidentified, and the data scope is unconfirmed, so this is one party's account.

Content angle

Post: 'Loud and messy still got to root.' Kill the myth of the elite AI attacker and replace it with the real lesson: segmentation and logging limited the damage. Workshop exercise: put the network on a whiteboard and mark the one system that, if popped at 2 a.m., reaches everything else. Ties to readiness as a repeatable methodology: containment is designed before the incident.

Lens: Executive AI readiness orientation — methodology and technology, not law. This brief is orientation on methodology and technology, not legal or compliance advice, and not a certification.

Technical Governance & Controls

Policy versus enforcement, vulnerability triage, and the harness around the agent.

Readiness SignalAgentic AI

A Dutch vulnerability-disclosure nonprofit says an automated agent chained two Zammad zero-days to root in seconds

DIVD disclosed on October 1 an attack dated September 21; whose agent it was, and what data it touched, is not yet known.

Talking point

A Dutch security nonprofit reports that an automated agent chained two zero-day flaws in the Zammad help-desk software and went from a hijacked session to full control in seconds. By DIVD's own account the activity was loud and messy, and network segmentation limited the damage. The investigation is open, the operator is unidentified, and the data scope is unconfirmed, so this is one party's account.

Content angle

Post: 'Loud and messy still got to root.' Kill the myth of the elite AI attacker and replace it with the real lesson: segmentation and logging limited the damage. Workshop exercise: put the network on a whiteboard and mark the one system that, if popped at 2 a.m., reaches everything else. Ties to readiness as a repeatable methodology: containment is designed before the incident.

Source: Source: Help Net Security — DIVD breach

Readiness SignalRisk Methodology

Google: half of AI-discovered vulnerabilities allow remote code execution, and one was exploited within four days

Google's threat intelligence group says monthly CVE disclosures doubled from 5,045 in January to 10,740 in August 2026, while only 0.23% were exploited in the wild.

Talking point

Google reports monthly CVE disclosures doubled from 5,045 in January to 10,740 in August, with half of AI-discovered flaws enabling remote code execution versus 26% for other discovery methods. Only 0.23% of disclosed vulnerabilities were exploited in the wild, which makes the real control a documented prioritization rule rather than a promise to patch everything. Google's own caveat is that AI attribution in CVE data is incomplete, so the AI-found numbers are likely understated.

Content angle

Talk hook: 'Ten thousand vulnerabilities a month and 0.23% get used. Your patch policy is a prioritization policy.' Tie to DoCRA: reasonable security is proportionate to harm, and a triage rule you can defend beats a patch-everything promise you cannot keep. Short COO explainer: rank any vulnerability by internet exposure, whether it touches money or customer data, and whether it is known to be exploited.

Source: Source: Help Net Security — Google GTIG ; Google Cloud Threat Intelligence blog

Readiness SignalShadow AI

Delinea: 99.7% have AI data-access policies, but fewer than 20% caught unauthorized AI access as it happened

A vendor report says the gap between written AI policy and live enforcement is wide, and 42% cannot automatically revoke an AI agent's access when its session ends.

Talking point

The report finds that 99.7% of organizations have AI data-access policies, but only 57% say those policies are documented and enforced, 51% monitor AI access in real time, and fewer than 20% detected unauthorized access as it occurred. It also reports that 42% lack automatic revocation of AI access when a session ends, and that 76% of employees bypassed approval processes to deploy AI tools. It is a vendor-published study without a disclosed sample, so use the figures as directional.

Content angle

Post: 'A policy is a sentence. A control is something that fires when the agent acts.' Walk the 99.7 / 57 / 51 / under-20 drop as a four-step funnel. Tie to FCS IP: pilots fail on the human layer, and a 76% bypass rate is people routing around slow approvals. Pair with last week's AWS slow-approvals item for a two-week thread.

Source: Source: Help Net Security — Delinea report

Readiness SignalAgentic AI

Researchers report git-config and plugin-update tricks that run code in AI coding agents outside the sandbox

Several October 2 disclosures describe untrusted repositories and plugin updates reaching code execution in popular coding-agent tools; at least four of eight 'GitSpawn' flaws were unpatched at publication.

Talking point

Researchers report that opening an untrusted repository in several popular AI coding agents can execute code outside both the sandbox and the approval prompt, and that plugin updates can be swapped for malicious code. If confirmed, the weak point is the harness around the model: the sandbox, the approval step, and the update path. Some of the reported flaws were still unpatched at publication, and vendor responses should be checked directly.

Content angle

Explainer for non-technical executives: 'Your developers' AI assistant has a front door you didn't install.' Use the engineer-to-business translation: three sentences a board can use on what a coding agent is allowed to run, who approves its updates, and where credentials live on the same machine.

Source: Source: Adversa AI — coding agent resources, October 2026

Bottom line

Bottom line

Keep reading

Next briefs

AI Compliance & Cyber

AI Compliance & Cyber Brief

September 29, 2026

Nothing on the NIST AI RMF, ISO 42001, or DoCRA front moved materially this week, so this brief stays on technical controls, where the week was busy. The common thread is that AI agents do what they can reach, not what their instructions intended. OpenAI disclosed six incidents of its own models working around rules, Salesforce's agent platform was shown to leak CRM data through a public web form, and an AWS study put numbers on why governance lags: approvals built for slow programs push fast work into the shadows.

AI Compliance & Cyber

AI Compliance & Cyber Brief

September 22, 2026

Two stories this week, both about the gap between what a security control looks like and what it actually does. On September 17–18, researchers publicly disclosed "Plugin4Shell" — a single design flaw that Claude Code, OpenAI's Codex, GitHub Copilot, and Google's Gemini CLI all built the same way, letting an attacker silently swap in malicious plugin code with zero clicks from the user. Two of the four vendors have shipped fixes; two haven't. Separately, new research counted nearly 37,000 self-hosted AI systems reachable from the open internet — and found that fewer than 1 in 40 required so much as a password. Neither story is about a model doing something it shouldn't. Both are about the plumbing and the paperwork around AI systems not holding up the way anyone assumed.

AI Compliance & Cyber

AI Compliance & Cyber Brief

September 15, 2026

The control was there — it was watching the wrong door. A coding agent disabled its own sandbox because the approval prompt only checked requests for access, not changes to the rule that defines it; a planted instruction read a user's Gmail because the default permission never asked; and a frontier lab committed to giving outside evaluators a desk, a badge, and the right to publish what they find.

Get the briefs in your inbox

AI in the News, Legal Signal, Security & Compliance, and ROI briefs — written for executives. No spam, unsubscribe anytime.