{"id":5799,"date":"2026-08-30T15:14:58","date_gmt":"2026-08-30T20:14:58","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5799"},"modified":"2026-08-30T15:14:58","modified_gmt":"2026-08-30T20:14:58","slug":"security-operations-weekly-august-30-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5799","title":{"rendered":"Security Operations Weekly &mdash; August 30, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#0f2c4d;background:linear-gradient(135deg,#0f2c4d 0%,#1e5a8f 50%,#2b8fb3 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">August 30, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">Security Operations Weekly<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">This was the week the arithmetic stopped being deniable. Dark Reading put the gap between discovery and repair at the centre of three separate pieces, the bug bounty economy started repricing around machine-generated findings, and CISA told the industry that most of what attackers actually use should have been eradicated decades ago &mdash; then handed federal agencies a three-day clock on a perfect-10 Oracle flaw. Microsoft&rsquo;s answer was to stop pretending the patch window can be won and move the fight to network-level containment. Everything else on the agenda &mdash; kill switches for agents, the MFA trap, AI spend &mdash; is a different way of asking the same question: what do you do when you cannot fix everything in time?<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>This week at a glance<\/h2>\n<p>The dominant story is a subtraction problem, and this week it came with arithmetic. CVE.ICU counted 50,340 vulnerabilities published through August 2026, up 72% on last year, of which fewer than 1% are exploitable. Intake is compounding while repair stays bounded by change windows and human attention &mdash; and as OpenSSF&rsquo;s Christopher Robinson puts it, &ldquo;discovery was never the bottleneck. Fixing was.&rdquo; The bug bounty market is repricing around the same curve: report volume has roughly doubled at HackerOne, spiked 450% year on year at ZDI in April, and curl shut its programme in January after its confirmed-vulnerability rate fell below 5%.<\/p>\n<p>CISA supplied the week&rsquo;s two hardest numbers. Its Vulnerability Review finds that seven of the ten most frequent CWEs in the KEV catalogue account for 41.5% of everything on it &mdash; cross-site scripting, command injection, SQL injection, input validation, path traversal &mdash; and concludes that &ldquo;the problem is not technical complexity: it is organizational culture, developer workflows, and systemic gaps in Secure by Design adoption.&rdquo; Then it set its tightest remediation deadline yet, three days, on CVE-2026-21962, a CVSS 10.0 Oracle HTTP Server and WebLogic proxy flaw that had been public since January. SecurityWeek&rsquo;s silent-patching piece argues the other side of the same coin: runZero&rsquo;s Tod Beardsley notes that &ldquo;given enough prompt engineering, all patches are advisories,&rdquo; so quiet fixes cost attackers hours and cost defenders the signal.<\/p>\n<p>Microsoft&rsquo;s intervention is the one that changes operating models rather than backlogs, and it came from Azure Networking rather than the security org: Igor Sakhnov&rsquo;s argument is that the exploitation timeline is &ldquo;rapidly shrinking&rdquo; and &ldquo;when a workload cannot immediately defend itself, another layer must help provide protection&rdquo; &mdash; segmentation, traffic controls, temporary isolation. Read alongside Arcjet&rsquo;s account of an AI agent executing 17,000+ actions in a single campaign, and the AI Kill Switch Act now attaching $20 million-a-day penalties to a control nobody can yet evidence, the shape of the year&rsquo;s architecture debate is clear: automate the response, then work out how to stop it.<\/p>\n<p>Underneath, the operational material was unusually good. CISA&rsquo;s new Logging Reference Architecture is a serviceable enterprise baseline &mdash; six months searchable, one year retrievable &mdash; for anyone who never reads federal directives. AWS shipped per-rule hit counts for Network Firewall, on by default and free, which is the most boring and most immediately useful thing in this issue. Okta&rsquo;s shares rose 19% on $805 million of quarterly revenue and explicit AI-agent identity demand, and CrowdStrike posted $333 million of net new ARR, up 51% &mdash; the consolidation trade is still on, in the same week the industry argued for blast-radius limits. And one corrective is worth the time: the talent shortage is better described as a triage-throughput problem than a hiring one.<\/p>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/08\/topic-map-security-operations-2026-08-30.png\" alt=\"Topic map of this week's Security Operations Weekly themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&rsquo;s topic map &mdash; the discovery-versus-repair gap and the repricing of bug hunting (offensive security investment, the vulnpocalypse, Nucleus, NIST&rsquo;s AI bet), the collapsing patch window (silent patching, Microsoft&rsquo;s shift to network-level containment, CISA&rsquo;s three-day clock on a perfect-10 Oracle flaw), agentic AI in the SOC (kill switches, Black Hat and CVE Program concerns, machine-speed defence, AI cost discipline), identity as an operational surface (the MFA trap, the continuous identity model, Okta), mission risk as the frame for what actually gets fixed, and the plumbing underneath it all (CISA logging guidance, AWS Network Firewall hygiene, CrowdStrike&rsquo;s Mythos momentum, Corelight at the Black Hat NOC).<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5798\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#0f172a;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>Weekly News<\/h3>\n<h4>The gap between finding and fixing<\/h4>\n<div class=\"cluster-intro\">Three Dark Reading pieces and a vendor bet, all circling the same arithmetic: intake is compounding, remediation capacity is not, and the price of a submitted bug is moving accordingly.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/offensive-security-investments-surge-ai-threats-increase\">Offensive Security Investments Surge as AI Threats Increase<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/vulnpocalypse-repricing-bug-bounty-economy\">The Vulnpocalypse Is Repricing the Bug Bounty Economy<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/vulnerability-gap-why-discovery-is-outrunning-repair\">The Vulnerability Gap: Why Discovery Is Outrunning Repair<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 24, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/www.csoonline.com\/article\/4213644\/nucleus-wants-to-get-ahead-of-scanners-on-new-vulnerabilities.html\">Nucleus wants to get ahead of scanners on new vulnerabilities<\/a><\/td>\n<td class=\"src\">CSO Online<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>The patch window is closing faster than the queue drains<\/h4>\n<div class=\"cluster-intro\">A three-day federal deadline, a maximum-severity Oracle flaw, a warning that silent fixes blind the people who need the signal, and Microsoft&rsquo;s argument for changing the terrain instead of the timing.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/www.securityweek.com\/silent-patches-dont-stop-attackers-they-blind-defenders\/\">Silent Patches Don&rsquo;t Stop Attackers &ndash; They Blind Defenders<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/www.csoonline.com\/article\/4214135\/microsoft-warns-patch-window-is-collapsing-urges-shift-to-network-level-containment.html\">Microsoft warns patch window is collapsing, urges shift to network-level containment<\/a><\/td>\n<td class=\"src\">CSO Online<\/td>\n<td class=\"dt\">Aug 26, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/25\/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw\/5292107\">CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw<\/a><\/td>\n<td class=\"src\">The Register<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/28\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/5293194\">CISA: Most exploited vulnerabilities should have been eradicated decades ago<\/a><\/td>\n<td class=\"src\">The Register<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Agentic AI in the SOC: kill switches, machine speed and cost<\/h4>\n<div class=\"cluster-intro\">Black Hat&rsquo;s agenda carried into the week &mdash; how to stop an agent once it is running, why human-speed defence has already lost, and a corrective on how much of it you actually have to pay for.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/defining-ai-kill-switch-hard-but-necessary\">Defining an AI Kill Switch Is Hard, but Necessary<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/agentic-ai-risks-cve-program-concerns-black-hat-usa-2026\">Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 27, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/www.scworld.com\/perspective\/why-human-speed-defense-has-failed\">Why human-speed defense has failed<\/a><\/td>\n<td class=\"src\">SC Media<\/td>\n<td class=\"dt\">Aug 26, 2026<\/td>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/thenewstack.io\/minimize-ai-security-spend\/\">Tokenmaxxing is out. How to minimize AI spend without sacrificing security capability.<\/a><\/td>\n<td class=\"src\">The New Stack<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Identity as an operational surface<\/h4>\n<div class=\"cluster-intro\">The second instalment of the continuous identity argument, a hard look at what MFA does and does not buy you, and an earnings print that says the market is buying identity as the AI control point.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/continuous-identity-part-2-why-identity-needs-a-new-operating-model\">Continuous Identity, Part 2: Why Identity Needs a New Operating Model<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 24, 2026<\/td>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/www.securityweek.com\/the-mfa-identity-trap-when-authentication-creates-a-false-sense-of-security\/\">The MFA Identity Trap: When Authentication Creates a False Sense of Security<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Aug 26, 2026<\/td>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.securityweek.com\/okta-shares-surge-on-strong-earnings-growing-demand-for-ai-identity-security\/\">Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Aug 27, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Plumbing, hygiene and platform gravity<\/h4>\n<div class=\"cluster-intro\">The unglamorous half of the issue: a federal logging baseline that works fine in the private sector, a firewall-rule hit counter, and the consolidation trade showing up in a share price.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/24\/cybersecurity-logging-guidelines-strategy\/\">CISA&rsquo;s logging guidance works beyond government<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Aug 24, 2026<\/td>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/24\/aws-network-firewall-rule-hit-count-capability\/\">AWS makes it easier to spot firewall rules that have gone quiet<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Aug 24, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/siliconangle.com\/2026\/08\/29\/crowdstrikes-post-mythos-surge-moat-momentum-and-the-blast-radius-test\/\">CrowdStrike&rsquo;s post-Mythos surge: Moat, momentum and the blast-radius test<\/a><\/td>\n<td class=\"src\">SiliconANGLE<\/td>\n<td class=\"dt\">Aug 29, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Foundational Reading<\/h3>\n<h4>How mature SOCs actually run<\/h4>\n<div class=\"cluster-intro\">Three field reports worth more than a vendor demo: a global bank&rsquo;s mission-driven programme, a practitioner view of AI in SOC modernisation, and the NOC that has to defend the most hostile network of the year.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/mission-driven-security-inside-global-bank-defense\">Mission-Driven Security: Inside a Global Bank&rsquo;s Defense<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 14, 2026<\/td>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/ai-s-transformative-role-in-modernizing-the-soc-with-expert-karthik-kannan\">AI&rsquo;s transformative role in modernizing the SOC with expert Karthik Kannan<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 13, 2026<\/td>\n<\/tr>\n<tr>\n<td>21. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/securing-black-hat-s-noc-lessons-from-james-pope-of-corelight\">Securing Black Hat&rsquo;s NOC: Lessons from James Pope of Corelight<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 13, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Bug hunting at machine scale, and the people question<\/h4>\n<div class=\"cluster-intro\">What NIST is proposing to do about an AI-driven bug-hunt tsunami, and a contrarian case that the staffing crisis the industry keeps citing was always a hiring-practice problem.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>22. <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ai-driven-bug-tsunami-nist-looks-to-ai\">Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to &hellip; AI<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 14, 2026<\/td>\n<\/tr>\n<tr>\n<td>23. <a href=\"https:\/\/www.scworld.com\/perspective\/the-cybersecurity-talent-shortage-was-never-real\">The cybersecurity talent shortage was never real<\/a><\/td>\n<td class=\"src\">SC Media<\/td>\n<td class=\"dt\">Aug 12, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. Discovery is compounding. Repair is not.<\/h4>\n<p class=\"meta\">Dark Reading &middot; CSO Online &middot; August 24&ndash;28, 2026<\/p>\n<p>Christopher Robinson, chief security architect at the Open Source Security Foundation, gave Dark Reading the line that frames this entire issue: &ldquo;Discovery was never the bottleneck. Fixing was.&rdquo; The piece puts the mismatch at discovery measured in hours against remediation still measured in weeks and months, and reaches for IBM&rsquo;s Cost of a Data Breach Report 2026 for the pressure on the other end &mdash; one in four malicious breaches was AI-enabled, up 56% year on year, at an average $6 million, roughly $1 million above the overall average. The statistic that should sting any vulnerability programme is where automation has actually been deployed: more than 50% of organisations now point AI agents at threat detection, and only 18% point them at vulnerability management. The intake side automated first, and the queue is what is left over.<\/p>\n<p>The companion piece explains where the intake pressure comes from and who is funding it. Omdia research cited in the article has 88% of organisations willing to spend more on offensive security, 99% investing in software supply chain security, and cyber resilience as the number one spending priority &mdash; while only 44% actually generate an SBOM at build time, which is the one point at which it would be cheap. Theresa Lanowitz, head of evangelism at AT&amp;T Cybersecurity and formerly an Omdia principal analyst, argues traditional practices &ldquo;are no longer working,&rdquo; and her prescription for agentic tooling &mdash; &ldquo;You want to limit the blast radius of what that agent is actually able to do&rdquo; &mdash; is the same instinct Microsoft applies to networks two sections down. Inside a defending organisation the practical effect is throughput: more people, running better tools, pointed at your estate every quarter, some of them working for you.<\/p>\n<p>The bug bounty piece is where the economics show. HackerOne&rsquo;s report volume has roughly doubled year on year, according to CEO Kara Sprague; Trend&rsquo;s Zero Day Initiative recorded a 450% year-on-year spike in April 2026, per head of threat awareness Dustin Childs; Bugcrowd absorbed a 300% surge over three weeks and has settled at double its historical volume, with CEO Dave Gerry putting 82% of researchers now using AI somewhere in their workflow. Quality moved the other way. Daniel Stenberg says curl&rsquo;s confirmed-vulnerability rate fell from over 15% to under 5% by 2025, and the project closed its bounty programme in January 2026 over submissions that &ldquo;take a serious mental toll to manage.&rdquo; Prices are repricing to match: Childs expects &ldquo;$2,000 to $50,000 bugs&rdquo; to &ldquo;become very scarce, or the price is going to be pressed down,&rdquo; and researcher Wojciech Regu&#322;a reports a full macOS TCC bypass falling from around $30,500 to roughly $5,000. The top of the market is untouched &mdash; HackerOne&rsquo;s payouts rose 25% in the first half of 2026, as did the number of researchers clearing $100,000 &mdash; but the middle is being hollowed out. The second-order effect is what matters to a SOC: the report stream reaching your programme is now filtered by that economics, and the filter is not tuned to your risk model.<\/p>\n<p>Nucleus&rsquo;s pitch, covered by CSO Online, is the commercial answer, and it arrives with a worked example worth stealing as a metric. CVE-2026-44416 was published on 20 August carrying a CVSS of 9.8; Nucleus says its Early Warning System confirmed affected customer systems on 21 August, at a point when Tenable had not yet shipped a plugin for it. Co-founder and chief product officer Scott Kuffer draws the division of labour as &ldquo;AI helps determine what should happen; deterministic automation makes sure it happens consistently,&rdquo; with a Discover capability and a Helix agent due in September. Whether or not you buy the product, run the measurement: the interval between public disclosure and your first confirmed identification of an affected asset. It is almost always an inventory problem rather than a tooling one. NIST is meeting the same arithmetic at institutional scale &mdash; Jerry Gamblin&rsquo;s CVE.ICU counted 50,340 CVEs published through August 2026, a 72% jump on 2025, of which fewer than 1% are exploitable &mdash; and its 12 August request for information on using AI inside the NVD is open for comment until 13 October.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/vulnerability-gap-why-discovery-is-outrunning-repair\">Dark Reading (the vulnerability gap)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/offensive-security-investments-surge-ai-threats-increase\">Dark Reading (offensive security investment surge)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/vulnpocalypse-repricing-bug-bounty-economy\">Dark Reading (the vulnpocalypse and bug bounty pricing)<\/a> &middot; <a href=\"https:\/\/www.csoonline.com\/article\/4213644\/nucleus-wants-to-get-ahead-of-scanners-on-new-vulnerabilities.html\">CSO Online (Nucleus ahead of scanners)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ai-driven-bug-tsunami-nist-looks-to-ai\">Dark Reading (NIST and the AI bug-hunt tsunami)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. CISA&rsquo;s three-day clock, and Microsoft&rsquo;s argument for changing the terrain<\/h4>\n<p class=\"meta\">The Register &middot; CSO Online &middot; SecurityWeek &middot; August 25&ndash;28, 2026<\/p>\n<p>The flaw is CVE-2026-21962, a CVSS 10.0 improper-access-control bug (CWE-284) in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, affecting versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. CISA added it to the KEV catalogue on 24 August under BOD 26-04, &ldquo;Prioritizing Security Updates Based on Risk,&rdquo; and gave federal civilian agencies three days &mdash; its tightest window to date, and not a period in which any large organisation convenes a change advisory board, stages a test environment and rolls a fix through production. It is an incident-response window with a patch in it. The detail that makes it worse is the timeline: Oracle disclosed the flaw on 20 January. CloudSEK cyber intelligence analyst Vikas Kundu ran a honeypot from 22 January to 3 February and reported &ldquo;high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic.&rdquo; Seven months of opportunistic exploitation preceded the three-day clock. Only FCEB agencies are formally bound, but KEV deadlines are already a de facto private-sector benchmark, and auditors will quote this precedent long after the flaw is forgotten.<\/p>\n<p>The Register&rsquo;s other CISA story is the more damning one, because it is about classes rather than instances, and it is better evidenced than the headline suggests. CISA&rsquo;s Vulnerability Review, covering 2024&ndash;2025 data, finds that seven of the ten most frequent CWEs in the 2024 CVE list appeared on MITRE&rsquo;s 2023 &ldquo;stubborn weaknesses&rdquo; list, and that seven of the ten most frequent CWEs in the KEV catalogue account for 41.5% of everything on it. The names are all familiar: cross-site scripting (CWE-79), OS command injection (CWE-78), SQL injection (CWE-89), improper input validation (CWE-20), path traversal (CWE-22). Memory safety and improper input validation alone made up 16.7% of 2025 KEV entries, and three of the top five KEV entries came from holes that were simply never fixed. MITRE first called this family &ldquo;unforgivable vulnerabilities&rdquo; in 2007. CISA&rsquo;s conclusion is a governance statement rather than a technical one &mdash; &ldquo;the problem is not technical complexity: it is organizational culture, developer workflows, and systemic gaps in Secure by Design adoption&rdquo; &mdash; which makes it a procurement lever more than an operations lever. It belongs in your vendor questionnaires.<\/p>\n<p>Tod Beardsley, now VP of security research at runZero and previously section chief for vulnerability response at CISA, makes the defender-visibility case in SecurityWeek, and his formulation is the one to quote back at vendors: &ldquo;Silent patches do not keep vulnerabilities secret. They just keep the details secret from everyone except the people already capable of weaponizing them.&rdquo; His observation that LLM-assisted reverse engineering means &ldquo;given enough prompt engineering, all patches are advisories&rdquo; closes off the last defence of the practice. Notably, his worked example is a commercial arrangement rather than an oversight: Broadcom&rsquo;s June 2026 programme giving paying customers early access to validated Spring Framework patches through a private Spring Enterprise Repository, ahead of open-source users. The operational ask is to treat undocumented vendor updates as a detection gap, and to push for disclosure of security-relevant fixes contractually wherever you have the leverage.<\/p>\n<p>Microsoft&rsquo;s contribution is the strategic one, and it is telling that it came from Igor Sakhnov, corporate vice president and general manager for Azure Networking, rather than from the security organisation. His argument is that the interval between disclosure and exploitation is &ldquo;rapidly shrinking&rdquo; while &ldquo;modern attack campaigns operate at internet scale,&rdquo; and so &ldquo;when a workload cannot immediately defend itself, another layer must help provide protection.&rdquo; The recommendation is network-level controls operating around workloads rather than inside them &mdash; segmentation, traffic controls, WAF and IPS policy, temporary isolation &mdash; with prioritisation reserved for what is both actively exploited and externally exposed. Sakhnov is careful that this is not a licence to stop patching: &ldquo;The objective is not to avoid patching&hellip; The objective is to create a meaningful layer of defense during the period when patching has not yet been completed.&rdquo; The concession is real all the same, and for teams already stretched by the intake problem above it is the only recommendation in this issue that reduces work rather than adding it, because containment scales per-segment rather than per-CVE.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/25\/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw\/5292107\">The Register (three-day deadline, perfect-10 Oracle flaw)<\/a> &middot; <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/28\/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago\/5293194\">The Register (CISA on decades-old defect classes)<\/a> &middot; <a href=\"https:\/\/www.securityweek.com\/silent-patches-dont-stop-attackers-they-blind-defenders\/\">SecurityWeek (silent patches blind defenders)<\/a> &middot; <a href=\"https:\/\/www.csoonline.com\/article\/4214135\/microsoft-warns-patch-window-is-collapsing-urges-shift-to-network-level-containment.html\">CSO Online (Microsoft on network-level containment)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. Kill switches, machine speed, and what the funnel costs<\/h4>\n<p class=\"meta\">Dark Reading &middot; SC Media &middot; The New Stack &middot; August 25&ndash;28, 2026<\/p>\n<p>The kill-switch conversation has a bill attached to it now. Representatives Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) have introduced the AI Kill Switch Act, carrying penalties of up to $20 million per day for non-compliance, and Dark Reading&rsquo;s piece is largely an inventory of why the requirement is harder to satisfy than to legislate. Eran Kahana, a fellow at Stanford Law School, supplies the sharpest version: &ldquo;An agent does not need intent to undermine a kill switch&hellip; It needs only an optimization objective that treats shutdown as one more obstacle.&rdquo; Raj Rajamani, co-founder and CEO of JetStream, points at the architectural problem &mdash; &ldquo;We need to think about an AI system as a whole and make sure that every part&hellip; has a kill switch, not just the brain&rdquo; &mdash; which is the practical objection for anyone deploying agents into a response path. Stopping the process is easy. Revoking credentials that outlive it, unwinding writes to systems that do not roll back, and proving afterwards that the stop was honoured are the hard parts, and none of the three frameworks the piece cites (NIST&rsquo;s AI RMF, UC Berkeley&rsquo;s Agentic AI Risk-Management Standards Profile, the AI Life Cycle Core Principles) yet tells you how to evidence them.<\/p>\n<p>David Mytton, CEO of Arcjet, supplies the pressure on the other side in SC Media, and unusually for this genre he shows the working. The campaign he describes ran for weeks with an attack phase of several days, during which an AI agent executed more than 17,000 actions and surfaced a zero-day in a package-registry proxy, Jinja2 template injection, HDF5 file leaks, exposed credentials, a Kubernetes misconfiguration and CVE-2026-46331, a Linux kernel privilege escalation. His concession is the honest part &mdash; &ldquo;a capable human could have found the same flaws&rdquo; &mdash; and his conclusion follows from the tempo rather than the novelty: &ldquo;The baseline has changed. Defense has to run at the same speed as the attack, on models we actually control.&rdquo; Read alongside the kill-switch piece it is a single argument: you will automate the response path, so decide now what &ldquo;stop&rdquo; means, who can say it, and what evidence survives.<\/p>\n<p>Dark Reading&rsquo;s Black Hat wrap-up shows the same tension running through the conference floor, and picks out a second thread worth tracking independently: sustained concern about the CVE Program itself. Cybersecurity Dive&rsquo;s Eric Geller reported &ldquo;a lot of concern about what happens in the AI era when people are using these tools to discover bugs and report them at a rate that is completely unprecedented,&rdquo; with opinion split between those who expect the programme to absorb it as it absorbed fuzzing and those who insist &ldquo;this is categorically different&rdquo; and needs a new cataloguing approach for inaccurate machine-generated reports. The governance mood was blunter: a DHS official&rsquo;s &ldquo;We&rsquo;re not going to let you build a Terminator factory&rdquo; is quotable, but it is the CVE thread that will land on your prioritisation pipeline first.<\/p>\n<p>The cost corrective is the reason to keep this cluster together, because it is the only item here that comes with a per-day number attached. Matt Coons, senior manager of security operations at GitLab, supplies the numbers in The New Stack: by funnelling with deterministic filters first and escalating only low-confidence cases, his team runs detection at roughly $1 a day, with only 1&ndash;2% of cases reaching the second-tier model and a 1&ndash;2% accuracy difference against frontier models that cost about five times more per token. &ldquo;The narrower and more precise the funnel feeding your models, the lower your cost per accurate outcome,&rdquo; he writes &mdash; which is also, incidentally, the shape Karthik Kannan of Anvilogic argues for when he puts AI at data normalisation and detection engineering rather than at alert triage. Useful ammunition for anyone about to sit through a quarter of agentic-SOC pitches.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/defining-ai-kill-switch-hard-but-necessary\">Dark Reading (defining an AI kill switch)<\/a> &middot; <a href=\"https:\/\/www.scworld.com\/perspective\/why-human-speed-defense-has-failed\">SC Media (why human-speed defense has failed)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/agentic-ai-risks-cve-program-concerns-black-hat-usa-2026\">Dark Reading (Black Hat USA 2026 agentic risk and CVE Program concerns)<\/a> &middot; <a href=\"https:\/\/thenewstack.io\/minimize-ai-security-spend\/\">The New Stack (minimising AI security spend)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/ai-s-transformative-role-in-modernizing-the-soc-with-expert-karthik-kannan\">Dark Reading (Karthik Kannan on modernising the SOC)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. Identity: the operating model, the trap, and the earnings print<\/h4>\n<p class=\"meta\">Dark Reading &middot; SecurityWeek &middot; August 24&ndash;27, 2026<\/p>\n<p>Part two of the continuous identity series is written by Ian Glazer &mdash; head of continuous identity product strategy at CrowdStrike, and a co-founder of IDPro &mdash; and it moves from diagnosis to operating model. Glazer frames identity as having passed through two questions and arrived at a third: &ldquo;Who are you?&rdquo; gave way to &ldquo;Who should have access to what?&rdquo;, and both are now being displaced by &ldquo;Is this access appropriate right now?&rdquo; The inputs he lists for answering it continuously &mdash; device compliance, user behaviour and risk profile, the scope and task authorisation of an AI agent, expiry of the business justification, threat intelligence, workload change &mdash; are the giveaway: that is a detection-engineering feed, not a governance calendar. His formulation is that &ldquo;trust, and the access derived from it, will become something that must be continuously earned,&rdquo; which in operational terms means identity stops producing quarterly attestations and starts producing decisions, with a latency budget and an on-call rotation attached. Very few programmes are staffed for that, and the ownership boundary between IAM and the SOC is where it will be fought.<\/p>\n<p>Torsten George, chief marketing officer at ID Dataweb, supplies the necessary counterweight to a decade of &ldquo;just turn on MFA,&rdquo; and his central distinction is worth putting on a slide: MFA proves control of an authenticator, not the identity of the person holding it. He cites roughly 70% of enterprise workforce users as MFA-protected, and separates three functions organisations routinely conflate &mdash; identity verification, authentication, and identity threat detection &mdash; noting that NIST&rsquo;s Digital Identity Guidelines already draw the first two apart. The consequences are the failure modes every SOC has seen: phishing, social engineering, SIM swapping, session theft, account-recovery abuse and help-desk manipulation, each of which leaves &ldquo;MFA succeeded&rdquo; in the log. &ldquo;MFA may work exactly as designed while granting access to an impostor,&rdquo; George writes, and &ldquo;identity risk is dynamic &mdash; a trustworthy identity at login can become compromised minutes later.&rdquo; The operational conclusion is to instrument the failure modes rather than the coverage percentage: alert on enrolment changes, factor downgrades, help-desk resets and successful authentications from sessions the user never started.<\/p>\n<p>Okta&rsquo;s numbers are the market pricing the same thesis. Second-quarter fiscal 2027 revenue, for the quarter ended 31 July, came in at $805 million, up 11%, with subscription revenue of $793 million up 12%, GAAP net income of $116 million, free cash flow of $227 million against $162 million a year earlier, and remaining performance obligations of $4.86 billion up 17%. Shares rose more than 19% in extended trading, from a $134.42 close to above $160, and full-year guidance moved to $3.216&ndash;$3.226 billion. CEO Todd McKinnon attributed the demand directly: &ldquo;As AI agents transform every layer of technology, every agent needs a trusted identity and clear controls over what it can access and do&rdquo; &mdash; a thesis the company is buying into with Okta for AI Agents, Auth0 for AI Agents and the Permiso Security acquisition. Treat it as a signal about where controls will be expected to live at your next audit rather than as a product endorsement: the identity plane is becoming the place where questions about machine authority get answered, and the operational load lands on the same teams already absorbing the continuous-evaluation shift above.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/continuous-identity-part-2-why-identity-needs-a-new-operating-model\">Dark Reading (continuous identity, part 2)<\/a> &middot; <a href=\"https:\/\/www.securityweek.com\/the-mfa-identity-trap-when-authentication-creates-a-false-sense-of-security\/\">SecurityWeek (the MFA identity trap)<\/a> &middot; <a href=\"https:\/\/www.securityweek.com\/okta-shares-surge-on-strong-earnings-growing-demand-for-ai-identity-security\/\">SecurityWeek (Okta earnings and AI identity demand)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. Logging you already have, firewall rules you forgot, and the consolidation trade<\/h4>\n<p class=\"meta\">Help Net Security &middot; SiliconANGLE &middot; August 24&ndash;29, 2026<\/p>\n<p>The document Help Net Security is reading is CISA&rsquo;s Logging Reference Architecture, released this month under OMB Memorandum M-26-14, and its framing is better than most commercial logging standards because it starts from use rather than collection: &ldquo;when an attack hits, can you actually use the logs you&rsquo;ve collected to catch it and reconstruct what happened.&rdquo; It splits logging into two operational goals worth borrowing wholesale &mdash; Continuous Event Monitoring for near-real-time detection, and Threat Hunting, Investigation, Response and Forensics for post-compromise reconstruction &mdash; which is a cleaner way to argue retention than storage cost. The federal baseline is a usable number to benchmark against: actively searchable for six months, retrievable for one year. Two details transfer directly to any enterprise pipeline: the logging plane is itself &ldquo;a security-critical capability whose compromise can blind detection, corrupt evidence, disrupt sharing,&rdquo; and normalisation must &ldquo;preserve the relationship between the original record and the derived output&rdquo; &mdash; which is the requirement most SIEM parsing quietly breaks. Agencies have 90 days from publication to file logging plans and 320 days to reach the &ldquo;Advanced&rdquo; tier; if your own retention policy was set by budget rather than investigative need, this is a free rewrite.<\/p>\n<p>The AWS Network Firewall rule hit-count capability is the smallest item in this issue and probably the highest effort-to-value ratio in it. Every long-lived rule set accumulates rules that no longer match anything: services decommissioned, ranges re-addressed, exceptions granted for a migration that finished two years ago. The counter increments whenever a rule match generates an alert log, and AWS pitches it as a way to &ldquo;identify and remove unused rules, accelerate incident response, and validate security control effectiveness for compliance.&rdquo; Three operational caveats before you plan the sweep: it covers stateful rules in custom and managed rule groups only, stateless rules are not supported, and pass-action rules must carry the &ldquo;alert&rdquo; keyword or they will never appear in the metrics &mdash; which is exactly the category of quiet permanent exception you most want to find. It is on by default at no additional Network Firewall charge (log storage and query costs still apply), surfaces in the Top Rule Hits view, CloudWatch Logs Insights and Athena, and is available in every region except the Middle East (UAE and Bahrain). Schedule it as quarterly hygiene and let the counters accumulate between runs.<\/p>\n<p>SiliconANGLE&rsquo;s read on CrowdStrike is the market frame around this week&rsquo;s architecture arguments, and the quarter was emphatic: net new ARR of $333 million, up 51% year on year and more than $45 million above the top of guidance; ending ARR of $5.84 billion, up 25%; Flex ARR of $2.29 billion, up 101%; cloud security at $905 million, next-gen SIEM at $695 million and identity at $585 million; a 26% free-cash-flow margin, and the stock up more than 20% on the day. CEO George Kurtz calls Flex &ldquo;the commercial harness,&rdquo; and the demand story SiliconANGLE tells is one of AI security moving from a future concern to a budget line &mdash; a deputy group CISO at a financial-services firm quoted as saying their strategy &ldquo;really changed from we didn&rsquo;t care about this [AI security] that much&hellip; to we need to do this because of Mythos,&rdquo; Anthropic&rsquo;s model. The operator&rsquo;s half is the blast-radius test the headline names, and it decomposes usefully into three planes: the update plane, where a defective update rides privileged access across the estate; the platform plane, where one error propagates through integrated modules; and the agentic action plane, where machine-speed decisions execute across systems without adequate controls. Consolidation is a real efficiency &mdash; fewer integrations, one telemetry model, less analyst context-switching &mdash; and it concentrates risk in exactly the way containment advocates spent the rest of this week warning about. Holding both positions requires writing down what happens when the platform is the thing that is down.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/24\/cybersecurity-logging-guidelines-strategy\/\">Help Net Security (CISA logging guidance beyond government)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/24\/aws-network-firewall-rule-hit-count-capability\/\">Help Net Security (AWS Network Firewall rule hit counts)<\/a> &middot; <a href=\"https:\/\/siliconangle.com\/2026\/08\/29\/crowdstrikes-post-mythos-surge-moat-momentum-and-the-blast-radius-test\/\">SiliconANGLE (CrowdStrike post-Mythos surge)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. Foundational: mission, the NOC, the tsunami, and the shortage that was not<\/h4>\n<p class=\"meta\">Dark Reading &middot; SC Media &middot; August 12&ndash;14, 2026<\/p>\n<p>Cezary Piekarski, group CISO at Standard Chartered, gives the leadership version of a mission-driven programme, and the phrase worth taking from the interview is &ldquo;worry productively&rdquo;: pick the risks that matter to what the organisation is actually for, and stop treating everything else as unfinished business. He describes a programme built on the connection between the work and its purpose &mdash; &ldquo;we have a job that is so directly connected to doing something good to the society&rdquo; &mdash; and his forecast is the operationally relevant part: &ldquo;The future of cybersecurity is very much integrated. It&rsquo;s very much intelligence-led, and it&rsquo;s very much automated.&rdquo; It is a short video, and a useful counterweight to the queue-shaped view of the job that every other item in this issue reinforces.<\/p>\n<p>James Pope &mdash; senior director of security product research and technical marketing engineering at Corelight, and Black Hat&rsquo;s SOC lead since 2014 &mdash; gives the best free lesson in detection engineering published this month, because the constraints are extreme enough to expose what actually matters. The network is rebuilt from scratch for each event and then defended by a team of more than 100 analysts, threat hunters and partners against thousands of security professionals, with no endpoint agents, no device certificates and no asset inventory to lean on. That leaves network traffic as the primary evidence, and what it surfaces is instructive precisely because of who is on the wire: a corporate messaging app transmitting an employee database in cleartext, MCP servers running without TLS in 2026, and VPNs leaking GPS telemetry. Pope&rsquo;s conclusion generalises uncomfortably &mdash; &ldquo;if security companies at a security conference have some of these issues, that&rsquo;s a challenge for everybody, and it&rsquo;s probably worse at other places&rdquo; &mdash; and his recommendation costs nothing: &ldquo;Wireshark is free. Zeek is free. There&rsquo;s no reason not to look.&rdquo;<\/p>\n<p>Dark Reading&rsquo;s piece on NIST closes the loop on this issue&rsquo;s opening argument. Facing 50,340 CVEs published through August 2026 &mdash; a 72% jump on 2025, of which fewer than 1% are exploitable &mdash; the institution responsible for the vulnerability metadata everyone else builds on issued a request for information on 12 August about using AI inside the NVD, open for comment until 13 October, alongside its &ldquo;Gold Eagle&rdquo; prioritisation effort and existing reliance on KEV and EPSS. NIST&rsquo;s own framing is that the ecosystem &ldquo;is rapidly evolving and is characterized by AI-enabled cyber tools.&rdquo; The risk is the one Bugcrowd&rsquo;s Trey Ford names in a sentence worth keeping: &ldquo;Speed without accuracy moves the trust problem downstream.&rdquo; Enrichment errors do not stay at NIST; they propagate silently into every tool that consumes NVD data, including yours. Worth watching closely rather than cheering.<\/p>\n<p>Finally, Anurag Gurtu&rsquo;s argument that the cybersecurity talent shortage was never real is not the hiring-practices critique the title suggests &mdash; it is a throughput argument, and a sharper one. His claim is that alert volume scales with infrastructure while headcount scales with budget cycles: &ldquo;The &lsquo;shortage&rsquo; isn&rsquo;t a shortage of qualified people. It&rsquo;s a mismatch between a triage workload that scales with infrastructure and a workforce that scales with budget cycles.&rdquo; Hence &ldquo;we cannot out-hire an exponential curve,&rdquo; and hence his conclusion that automating the queue removes the bottleneck rather than staffing around it. Read it with the author&rsquo;s interest in view &mdash; Gurtu is co-founder and CEO of Airrived, and the supporting figures he cites for enterprises on agentic platforms, roughly 90% of frontline triage automated and mean time to respond down about 80%, are vendor-side numbers rather than independent measurements. The framing is still the useful part: if the constraint is triage throughput rather than hiring, then every automation decision in this issue is a capacity decision, and should be argued and measured as one.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/mission-driven-security-inside-global-bank-defense\">Dark Reading (mission-driven security at a global bank)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/securing-black-hat-s-noc-lessons-from-james-pope-of-corelight\">Dark Reading (securing the Black Hat NOC)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ai-driven-bug-tsunami-nist-looks-to-ai\">Dark Reading (NIST and the AI bug-hunt tsunami)<\/a> &middot; <a href=\"https:\/\/www.scworld.com\/perspective\/the-cybersecurity-talent-shortage-was-never-real\">SC Media (the talent shortage was never real)<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Calls to action --><\/p>\n<h2>Calls to action<\/h2>\n<p>Five things worth doing in the next week, drawn directly from this issue:<\/p>\n<ul style=\"font-size:14.5px;line-height:1.6;color:#1f2937;padding-left:20px;margin:0 0 14px 0;\">\n<li><strong>Rehearse a three-day remediation, not a fourteen-day one.<\/strong> CISA&rsquo;s tightest-ever deadline on a CVSS 10.0 Oracle flaw is the new reference point auditors will quote. Pick a representative critical system and walk the clock: who declares, who approves the emergency change, who tests, who signs off at 02:00. If the answer takes longer than three days on paper, it will take longer in practice.<\/li>\n<li><strong>Measure your disclosure-to-detection interval.<\/strong> For the last five significant CVEs affecting your stack, record the time between public disclosure and your first confirmed identification of affected assets. That single number tells you whether the discovery-versus-repair gap is costing you at the tooling layer or the inventory layer, and it is the metric behind every vendor pitch in this issue.<\/li>\n<li><strong>Write down what your kill switch actually does.<\/strong> Before the next agentic capability goes into the response path, document three things: how authority is revoked, what state cannot be rolled back, and what evidence exists afterwards that the stop was honoured. If any of the three is blank, the switch is a slide, not a control.<\/li>\n<li><strong>Stop reporting MFA coverage and start reporting MFA failure modes.<\/strong> Replace the enrolment percentage on your dashboard with alerts on factor enrolment changes, downgrades to weaker factors, help-desk resets and successful authentications from sessions the user never initiated. Coverage measures deployment; those four measure resistance.<\/li>\n<li><strong>Run the firewall-rule hit-count sweep.<\/strong> Turn on per-rule hit counts, let them accumulate for a full change cycle, then retire everything that has matched nothing. Stale allow rules are permanent undocumented exceptions, and this is the cheapest cleanup available to any team this quarter.<\/li>\n<\/ul>\n<p>            <!-- Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>Whether three days becomes the new KEV normal.<\/strong> One tightest-ever deadline is an outlier; a second one inside a quarter is a policy shift, and it would force emergency-change capability into organisations that currently have none.<\/li>\n<li><strong>How bug bounty programmes reprice after the vulnpocalypse.<\/strong> Watch payout structures and scope language for evidence that programmes are shifting budget from submission volume to exploit depth &mdash; and whether the report stream reaching enterprise programmes thins out as a result.<\/li>\n<li><strong>Whether network-level containment gets funded or just endorsed.<\/strong> Microsoft&rsquo;s recommendation is architecturally correct and expensive. The test is whether segmentation projects appear in 2027 budgets or whether the advice is absorbed as rhetoric while the patch queue keeps getting the money.<\/li>\n<li><strong>Vendor answers to the kill-switch question.<\/strong> Specifically, whether anyone ships revocation that covers issued credentials and in-flight tool calls, plus an exportable record proving the stop took effect. That is the feature to demand in the next round of agentic-SOC demos.<\/li>\n<li><strong>Silent patching as a contractual issue.<\/strong> Watch for enterprise buyers putting security-fix disclosure obligations into renewals. If that starts appearing in commercial terms, the visibility problem becomes solvable at procurement rather than at the SIEM.<\/li>\n<li><strong>Identity operations staffing.<\/strong> The continuous-identity model implies an on-call function that most IAM teams do not have. Watch job postings for identity roles with response-time expectations attached &mdash; that is where the operating-model shift shows up first.<\/li>\n<li><strong>Concentration risk in the consolidation trade.<\/strong> CrowdStrike&rsquo;s momentum and Okta&rsquo;s earnings both reward platform gravity in the same week that the industry argues for blast-radius limits. Watch whether anyone publishes a serious platform-failure playbook rather than a slide about resilience.<\/li>\n<li><strong>Whether the talent-shortage argument changes any hiring practice.<\/strong> The claim is testable: if teams drop certification filters and open genuine junior pipelines, and the roles fill, the shortage was never the constraint. Watch for anyone willing to run that experiment publicly.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">Security Operations Weekly<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>August 30, 2026 &middot; Weekly Edition Security Operations Weekly This was the week the arithmetic stopped being deniable. Dark Reading put the gap between discovery and repair at the centre of three separate pieces, the bug bounty economy started repricing around machine-generated findings, and CISA told the industry that most&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[38],"tags":[],"class_list":["post-5799","post","type-post","status-publish","format-standard","hentry","category-security-operations"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5799","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5799"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5799\/revisions"}],"predecessor-version":[{"id":5802,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5799\/revisions\/5802"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5799"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}