Policy versus enforcement, vulnerability triage, and the harness around the agent.
Readiness SignalAgentic AI
A Dutch vulnerability-disclosure nonprofit says an automated agent chained two Zammad zero-days to root in seconds
DIVD disclosed on October 1 an attack dated September 21; whose agent it was, and what data it touched, is not yet known.
Talking point
A Dutch security nonprofit reports that an automated agent chained two zero-day flaws in the Zammad help-desk software and went from a hijacked session to full control in seconds. By DIVD's own account the activity was loud and messy, and network segmentation limited the damage. The investigation is open, the operator is unidentified, and the data scope is unconfirmed, so this is one party's account.
Content angle
Post: 'Loud and messy still got to root.' Kill the myth of the elite AI attacker and replace it with the real lesson: segmentation and logging limited the damage. Workshop exercise: put the network on a whiteboard and mark the one system that, if popped at 2 a.m., reaches everything else. Ties to readiness as a repeatable methodology: containment is designed before the incident.
Source: Source: Help Net Security — DIVD breach
Readiness SignalRisk Methodology
Google: half of AI-discovered vulnerabilities allow remote code execution, and one was exploited within four days
Google's threat intelligence group says monthly CVE disclosures doubled from 5,045 in January to 10,740 in August 2026, while only 0.23% were exploited in the wild.
Talking point
Google reports monthly CVE disclosures doubled from 5,045 in January to 10,740 in August, with half of AI-discovered flaws enabling remote code execution versus 26% for other discovery methods. Only 0.23% of disclosed vulnerabilities were exploited in the wild, which makes the real control a documented prioritization rule rather than a promise to patch everything. Google's own caveat is that AI attribution in CVE data is incomplete, so the AI-found numbers are likely understated.
Content angle
Talk hook: 'Ten thousand vulnerabilities a month and 0.23% get used. Your patch policy is a prioritization policy.' Tie to DoCRA: reasonable security is proportionate to harm, and a triage rule you can defend beats a patch-everything promise you cannot keep. Short COO explainer: rank any vulnerability by internet exposure, whether it touches money or customer data, and whether it is known to be exploited.
Source: Source: Help Net Security — Google GTIG ; Google Cloud Threat Intelligence blog
Readiness SignalShadow AI
Delinea: 99.7% have AI data-access policies, but fewer than 20% caught unauthorized AI access as it happened
A vendor report says the gap between written AI policy and live enforcement is wide, and 42% cannot automatically revoke an AI agent's access when its session ends.
Talking point
The report finds that 99.7% of organizations have AI data-access policies, but only 57% say those policies are documented and enforced, 51% monitor AI access in real time, and fewer than 20% detected unauthorized access as it occurred. It also reports that 42% lack automatic revocation of AI access when a session ends, and that 76% of employees bypassed approval processes to deploy AI tools. It is a vendor-published study without a disclosed sample, so use the figures as directional.
Content angle
Post: 'A policy is a sentence. A control is something that fires when the agent acts.' Walk the 99.7 / 57 / 51 / under-20 drop as a four-step funnel. Tie to FCS IP: pilots fail on the human layer, and a 76% bypass rate is people routing around slow approvals. Pair with last week's AWS slow-approvals item for a two-week thread.
Source: Source: Help Net Security — Delinea report
Readiness SignalAgentic AI
Researchers report git-config and plugin-update tricks that run code in AI coding agents outside the sandbox
Several October 2 disclosures describe untrusted repositories and plugin updates reaching code execution in popular coding-agent tools; at least four of eight 'GitSpawn' flaws were unpatched at publication.
Talking point
Researchers report that opening an untrusted repository in several popular AI coding agents can execute code outside both the sandbox and the approval prompt, and that plugin updates can be swapped for malicious code. If confirmed, the weak point is the harness around the model: the sandbox, the approval step, and the update path. Some of the reported flaws were still unpatched at publication, and vendor responses should be checked directly.
Content angle
Explainer for non-technical executives: 'Your developers' AI assistant has a front door you didn't install.' Use the engineer-to-business translation: three sentences a board can use on what a coding agent is allowed to run, who approves its updates, and where credentials live on the same machine.
Source: Source: Adversa AI — coding agent resources, October 2026