The Human Take
AI driven threats. AI revolutionizes defense/offense. Governance frameworks struggle with rapid AI-driven threat evolution. We may as well just pack our bags and move off grid. Game over man.
This is… Well… This is Cyber
AI is a disrupter, no doubt about that. How much of a disrupter, final scope of influence, and how our role as cyber professionals change – well, that is still TDB. Sometimes all the AI news looks a little bleak from the trenches. How can you keep up with these ‘rapid AI-driven threats?’ Let’s start with not ignoring the basics.
CISA just released their vulnerability review for FY2024 and FY2025 (https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review), know what they found? Take a guess before reading the linked article. No doubt some fancy chained zero-day exploits driven by the agentic hive mind right? Nope, injection vulnerabilities. In FY2024 10.1% of all CVEs were injection based. In FY2025 only slightly better at 9.2%. Injection – yes, as in XSS and SQLi – those things that when we talk about them in the classroom students wonder, why are we still talking about this? Isn’t this old information? Maybe, but seems we haven’t figured it out yet.
Way back in the day I played basketball. I didn’t say I was good but I played basketball. When we started getting it handed to us by a seemingly superior team it was time for the coach to call a time-out, sit us all on the bench and remind us about the stupid mistakes we were making. Slow it down, stick to your man, no more stupid fouls. We weren’t being outplayed we were forgetting the basics that make the competition’s job difficult. Same applies to defending against all the seemingly unbeatable AI threats, and even the non-AI threats. Input validation, MFA, memory safe operation all provide barriers to otherwise simple exploits.
They’re not that good – we are ignoring the basics – we just need to get our head’s back in the game.

Weekly Cyber News Summary 2026-09-03
This week in cyber:
- Nation-state actors continue aggressive campaigns targeting critical infrastructure globally.
- AI-driven threats are manifesting in targeted attacks across various regions.
- AI is revolutionizing defense and offense, creating a complex paradox.
- Governance frameworks struggle to keep pace with rapid AI-driven threat evolution.
- Critical zero-day vulnerabilities are actively being exploited in major software.
- High-profile ransomware attacks are crippling global infrastructure and services.
- NIST Framework 2.0 quick start guides published.
- No major new global data privacy legislation was reported this week.
State-Sponsored Attacks
China’s DeepSeek AI Fuels Aggressive Hacking Campaigns (Nation-State Threats)
State-affiliated cyber groups, particularly those linked to China, are drastically increasing their attack volume by integrating Artificial Intelligence into their operations. Researchers note that these actors are delegating mundane tasks to AI and leveraging it to develop highly advanced and sophisticated malicious software.
This AI integration allows state actors to execute more attacks with greater efficiency, making their campaigns harder to detect and defend against. The threat is not just the volume, but the quality and complexity of the attacks being deployed across global targets.
Sources:
Regional Campaigns
Taiwan Targeted by AI-Driven Hacking Campaign (Taiwan AI Attack)
Taiwan has confirmed that its government was recently targeted by a sophisticated, AI-driven hacking campaign. This attack, uncovered by Israeli cybersecurity firm Dream, successfully stole sensitive credentials and various other data from an unnamed government entity in Asia.
In response to this new wave of AI-derived threats, the Taiwanese government has proactively established protective guidelines. These measures are designed to strengthen system monitoring across all agencies, allowing for earlier detection and blocking of these advanced attacks.
Sources:
AI Integration
The AI Cybersecurity Paradox: Threat Meets Defense (General Paradox)
The current state of cybersecurity is defined by the “AI Paradox”: the very technology used to defend against digital threats is simultaneously the most powerful tool in the attacker’s arsenal. Organizations must embrace autonomous AI defenses to combat the threats that AI itself introduces.
This paradox forces organizations to double down on foundational security principles like Zero Trust and cryptographic resilience. The age of AI in cybersecurity is here, forcing defenders to navigate a dual-edged sword that offers revolutionary tools while creating unprecedented risks.
Sources:
AI Policy and Posture Adaptation
No major updates reported this week (Skipped Section)
Despite the rapid deployment of AI tools, this week’s search did not yield specific, high-profile articles detailing a major shift in cybersecurity governance or compliance posture adaptation.
The industry appears to be in a phase of absorbing the implications of AI, rather than announcing a definitive, sweeping policy change. The focus remains on how to adapt, rather than what the new rule is.
Sources:
Zero-Day Exploits/CVEs
KnowledgeDeliver LMS Zero-Day Exploited to Deploy BLUEBEAM (Specific Exploit)
A critical zero-day vulnerability, designated CVE-2026-5426, was found in the KnowledgeDeliver Learning Management System (LMS). This flaw was actively exploited in the wild, allowing attackers to deploy the BLUEBEAM in-memory web shell.
The vulnerability, rated at CVSS 7.5, is particularly dangerous because it allows for the seamless deployment of the Godzilla web shell and subsequent delivery of Cobalt Strike Beacon to end-users. This demonstrates a high-impact, targeted attack against a widely used platform.
Sources:
Incident Reports
Georgia Real Estate Industry Crippled by Vendor Breach (SitusAMC/Real Estate)
A major cyberattack targeted SitusAMC, a critical real estate finance vendor that serves over 1,500 clients, including major names like JPMorgan Chase and Citi. The breach occurred on November 12, 2025.
The attack resulted in the theft of extensive data, including accounting records, legal agreements, and sensitive customer information belonging to residential mortgage holders. This incident highlights the systemic risk inherent in vendor-based supply chains.
Sources:
Framework Changes
NIST CSF 2.0: Outcomes-Based Framework Takes Center Stage (CSF 2.0 Update)
The NIST Cybersecurity Framework (CSF) has been updated to version 2.0, marking a significant shift from a checklist-driven model to an outcomes-based approach. The update introduces a crucial sixth function: Govern, alongside the original Identify, Protect, Detect, Respond, and Recover.
This change is highly beneficial for organizations, especially Small and Medium Businesses (SMBs), as it provides a flexible structure to manage risk. Furthermore, the new version includes enhanced mapping concepts to SP 800-53 controls and CCE identifiers, aiding automation and reporting.
Sources:
New Legislation
No major new global mandates reported this week (Skipped Section)
While the legislative landscape is constantly shifting, the last seven days did not bring a major announcement of a new, globally impactful data privacy law or sector-specific cybersecurity mandate.
However, the ongoing push for regulatory alignment, particularly around AI and data sovereignty, suggests that new rules are imminent. The market is currently awaiting the next major legislative wave.
Sources:



