Blog

Exposure at Speed: How AI is Collapsing the Cyber Defensive Window

Why the shrinking defensive window changes cyber risk for professionals entrusted with confidential information

· Updated · By

An hourglass beside four digital access routes — internet-facing systems, cloud, machine identities and AI — converging on a glass vault of confidential files.
Image: IamVera.ai — original editorial illustration

IamVERA Cybersecurity Intelligence Report
Assessment period: 19 September–2 October 2026
Outlook: Q4 2026
Published: 2 October 2026


Executive assessment

The defining cybersecurity trend entering Q4 2026 is not simply that more vulnerabilities are being discovered or that attackers are using artificial intelligence. It is that the time between opportunity and exploitation is shrinking while the number of routes to sensitive information is expanding.

We describe this as exposure at speed.

AI is accelerating vulnerability discovery, reconnaissance, exploit development and other established stages of the attack chain. At the same time, organisations are distributing access across cloud platforms, internet-facing appliances, service accounts, API credentials, automation, third-party integrations and, increasingly, AI agents. Attackers therefore have more potential routes to valuable information while defenders have less time to determine which of those routes has become dangerous.

Google Threat Intelligence Group (GTIG) recorded monthly vulnerability disclosures rising from 5,045 in January 2026 to 10,740 in August. It observed 141 vulnerabilities that were both disclosed and exploited during January–August 2026, compared with 127 throughout 2025. Yet only 0.23% of vulnerabilities disclosed in 2026 — approximately one in 431 — were observed under active exploitation.[1]

That distinction is critical. The challenge is not to treat every new vulnerability as an emergency. It is to identify and respond to the small proportion that can provide attackers with meaningful access.

Zero-days remain central to that picture. They represented 62% of the vulnerabilities GTIG observed being exploited between January and August 2026, with the monthly count reaching 22 in August. At the same time, GTIG suggests that much of the growth in exploitation during 2026 is being driven by faster weaponisation of high-risk vulnerabilities after disclosure — n-days — rather than by an equivalent increase in zero-day discovery.[1]

The distinction creates two different defensive problems. Unknown vulnerabilities demand resilience, exposure reduction and containment because a patch may not exist. Newly disclosed vulnerabilities demand speed: organisations must quickly determine whether the affected technology is present, exposed and important enough to justify emergency action.

Microsoft's 2026 Digital Defense Report describes a similar acceleration. Microsoft states that AI is compressing portions of the attack chain “from days to seconds” and reports a median weaponisation interval below 24 hours in activity visible to its researchers.[2] These are Microsoft observations rather than universal measurements, but they reinforce a broader shift towards shorter decision windows.

Identity is changing simultaneously. A TeamFiltration campaign analysed by Proofpoint targeted 5,714 Microsoft 365 accounts across 28 tenants. All seven confirmed compromises involved unmanaged functional or service accounts without MFA.[3] Unit 42's recent research similarly shows how machine identities can acquire authority without the ownership and lifecycle controls normally applied to employees.[4][5]

The final element is economic. Across the ransomware activity analysed by Zscaler ThreatLabz, the ten leading groups by reported leak volume claimed 896.2 TB of exfiltrated data, a 275.8% year-on-year increase within the report's methodology.[6] The underlying data covers April 2025 to March 2026 and is not a universal measurement of ransomware activity, but it illustrates a wider shift: information itself increasingly provides the leverage.

For professionals entrusted with privileged, medical, identity, financial, board-level or transaction information, this matters because recovery does not necessarily reverse the most serious harm.

A system can be restored and a credential revoked. Confidentiality cannot be fully restored once information has been acquired by an unauthorised party, even if further dissemination can still be contained.

The central assessment of this report is therefore:

Cyber risk is becoming an exposure-at-speed problem. AI is shortening the defensive window while cloud services, machine identities and connected systems expand the paths through which sensitive information can be reached.

Four findings

1. Exploitation speed matters more than total vulnerability volume.
Most disclosed vulnerabilities are not observed being exploited. The management problem is identifying the small subset where exposure, exploitability and business impact converge — and acting quickly enough.

2. Non-human identities are becoming a primary attack surface.
Service accounts, API keys, cloud identities, automation and AI agents can hold substantial authority without the governance routinely applied to employees.

3. Exfiltration can create lasting harm even where recovery succeeds.
When extortion depends on disclosure rather than encryption alone, restoring systems does not restore lost confidentiality.

4. AI is compressing existing attack chains faster than it is replacing them.
The immediate effect is faster discovery, reconnaissance, analysis, social engineering and exploitation, although early evidence of more AI-orchestrated activity is also emerging.


1. The shrinking defensive window

Raw vulnerability counts can distort the problem.

GTIG's dataset, covering January 2025 through August 2026, shows vulnerability disclosures rising sharply during 2026. But only 0.23% of 2026 disclosures were observed under exploitation.[1]

Security teams therefore face a prioritisation challenge rather than a simple patch-volume challenge.

Within that small exploited subset, GTIG recorded an average of 10.5 exploited vulnerabilities per month during 2025 and 18 per month between January and August 2026. Exploitation of High-Risk vulnerabilities more than doubled from 28 in 2025 to 75 during the first eight months of 2026.[1]

Zero-days nevertheless remain disproportionately important. They accounted for 62% of GTIG's observed exploited vulnerabilities in January–August 2026, while average monthly zero-day exploitation increased from eight in 2025 to eleven in 2026.[1]

The evidence therefore supports a more precise conclusion: zero-days remain a major component of observed exploitation, while GTIG suggests that rapid n-day weaponisation is contributing strongly to the increase in exploitation activity.

A useful example is CVE-2026-1731, an unauthenticated operating-system command-injection vulnerability affecting BeyondTrust Privileged Remote Access and Remote Support. The vulnerability was autonomously identified by the Hacktron AI research agent. GTIG observed the first threat cluster exploiting it four days after disclosure and another five clusters within seven days.[1]

Four days may be sufficient for an organisation with clear asset ownership, accurate exposure information and an emergency remediation process. It is a very short period for an organisation that first needs to establish whether it uses the affected product, who manages it, whether it is internet-facing and what business processes depend on it.

Microsoft independently reports a median weaponisation interval below 24 hours in activity visible to its researchers.[2] This does not mean every organisation must patch every vulnerability within a day. It means organisations increasingly need to determine which vulnerabilities cannot wait.

Internet-facing infrastructure deserves particular attention. Edge and security appliances accounted for 14% of vulnerabilities GTIG observed under exploitation between January and August 2026, and more than 65% of those exploited edge vulnerabilities carried a High or Critical GTIG threat-risk rating.[1]

Recent activity against Citrix NetScaler illustrates the related challenge posed by zero-days. Mandiant and GTIG identified active exploitation of CVE-2026-88772 from at least early September and Citrix separately reported exploitation of CVE-2026-88771. Both were exploited before conventional remediation was available. Mandiant observed root-level access, web shells, tunnelling, internal reconnaissance and credential theft, with likely affected organisations including legal and professional services in Europe and North America.[7]

The lesson is not simply “patch faster”. Where a fix is unavailable or exploitation may already have occurred, organisations need an exposure-reduction and evidence-preservation strategy.

For NetScaler, recommended mitigations included restricting the vulnerable attack surface and, where operationally feasible, disabling DTLS or blocking inbound UDP/443 until remediation was available.[7] CISA's addition of Fortinet FortiMail CVE-2026-104286 to its Known Exploited Vulnerabilities catalogue on 1 October provides another current example of an internet-facing security product requiring immediate exposure assessment rather than waiting for a normal maintenance cycle.[10]

The Dutch NCSC's response to the NetScaler vulnerabilities provides a particularly useful lesson for regulated organisations. It advised preserving a full memory dump, disk image and at least one month of relevant logs before updating or rebooting affected systems.[8]

This distinction is fundamental:

Patching answers “are we still vulnerable?” Forensics answers “were we already compromised?”

Updating a system may stop future exploitation while simultaneously removing evidence required to establish what happened beforehand.

For organisations processing personal data, that evidence may also be relevant to the GDPR breach-assessment process. Article 33 requires controllers to document personal-data breaches and, where applicable, notify the supervisory authority. Without sufficient evidence, determining which information was accessed or exfiltrated can become substantially harder.[9]

The shrinking defensive window is therefore not simply a race to install updates. It is the diminishing period in which organisations must understand their exposure, preserve evidence, contain risk and decide what matters.


2. The disappearing identity perimeter

Cybersecurity has spent years strengthening the authentication of people through MFA, conditional access, single sign-on, device controls and phishing-resistant credentials.

Modern organisations have meanwhile accumulated a parallel population of identities that are not people.

Applications authenticate to applications. SaaS integrations hold API tokens. Automation jobs use service accounts. Kubernetes components receive workload identities. CI/CD systems carry credentials. AI agents are beginning to receive permission to search files, query applications and invoke external services.

Many organisations cannot completely describe this second identity perimeter.

Proofpoint's September research illustrates the weakness. Its TeamFiltration activity, concentrated primarily in Chile during late July and August 2026, generated 32,825 authentication events against 5,714 accounts across 28 Microsoft 365 tenants. Seven accounts were confirmed compromised, all of them unmanaged functional or service accounts without MFA and without a prior legitimate login baseline.[3]

Seven compromises do not establish a general compromise rate, particularly given the geographical concentration of the campaign. The architectural problem, however, extends well beyond that sample.

Service identities do not leave an organisation in the way employees do. Their credentials may survive restructures, supplier changes and abandoned integrations. If nobody explicitly owns them, access can persist long after the original business purpose has disappeared.

This creates identity sediment: layers of credentials and authority accumulating beneath the visible organisation.

Unit 42's Kubernetes research highlights the same issue in a different environment. Operators automate administrative functions and often require significant privileges. The research identified abandoned and overly permissive operators whose RBAC permissions exceeded the functions they were expected to perform.[4]

AI agents will make this question more important because useful automation depends on authority. An agent that can only generate text has a limited security blast radius. One that can retrieve documents, access email, search internal systems or invoke APIs represents an identity and access-management problem as well as an AI-governance problem.

Unit 42's AWS research illustrates another important distinction. In a controlled experiment originally conducted in December 2025 and published in September 2026, AWS attached its AWSCompromisedKeyQuarantineV3 policy within ten seconds of an access key being exposed publicly on GitHub.[5]

The response is fast, but quarantine is not the same as revocation. The policy denies selected high-risk actions while seeking to limit disruption and fraudulent or unauthorised costs. Actions not explicitly blocked may remain possible.[5]

For confidential-data professions, that matters. A mechanism designed to reduce account abuse or financial damage does not necessarily guarantee that sensitive information can no longer be read.

Identity governance therefore needs to extend beyond the employee directory. Service accounts, API keys, cloud identities, integration credentials, workload identities and AI agents need clear owners, appropriate credential lifetimes and permissions limited to what they actually require.

The highest-risk identity in an organisation may not be the senior executive whose account receives constant scrutiny. It may be the forgotten service account that can access the same information without attracting attention.


3. Data theft is becoming the leverage

Ransomware remains associated with system encryption and operational disruption, but the economics of extortion increasingly extend beyond availability.

Across the ransomware activity analysed by Zscaler ThreatLabz, the ten leading groups by reported leak volume claimed 896.2 TB of exfiltrated information, representing a 275.8% year-on-year increase within the methodology used for its 2026 report.[6]

The figure is not a census of global ransomware. It includes attacker-reported leak volumes and covers April 2025 through March 2026.

Its strategic significance lies elsewhere: an attacker who steals sensitive information retains leverage even where the victim can recover every affected system.

ThreatLabz also describes attackers targeting staff in business functions such as finance, sales and HR, including through Microsoft Teams social engineering and Quick Assist.[6] The relevant privilege is therefore not always technical administrator access. Business authority can be just as valuable.

For confidential-data professions, this changes the meaning of successful recovery.

Privileged legal communications, patient information, identity documents, contracts, transaction records and board material derive much of their value from informational exclusivity: only authorised parties are supposed to possess them.

Once an unauthorised party acquires a copy, operational recovery and informational recovery diverge.

A restored system may work perfectly while the confidentiality loss remains. Backups therefore remain essential, but they restore availability — not confidentiality after disclosure.

The same distinction changes incident response. Organisations need to establish not only whether systems are operational again, but which identities the attacker controlled, what those identities could reach, what information was actually accessed and whether data left the environment.

This makes egress visibility, data classification and evidence retention increasingly relevant alongside traditional disaster recovery.


4. AI as attack-chain compression

The most immediate cybersecurity effect of AI is not the invention of an entirely new form of cybercrime.

It is the compression of attack methods that already work.

Microsoft reports threat actors using AI across reconnaissance, social engineering, vulnerability research, malware and exploit development and post-compromise analysis.[2] Much of that activity remains concentrated on specific stages of established attack workflows.

However, the trajectory is moving beyond isolated assistance. Microsoft also reports emerging AI-orchestrated activity in the wild and describes a controlled evaluation in which a frontier model chained 32 attack stages together.[2]

Both findings matter.

It would be premature to treat fully autonomous cyberattack as the dominant threat model. It would be equally inaccurate to think of AI merely as a tool for writing better phishing emails.

The direction is from assistance towards orchestration.

That matters because automation changes attack economics. An adversary can screen more potential victims, interpret advisories faster, compare patches with earlier software versions, personalise social engineering and analyse stolen information with less manual effort.

The underlying attacks may look familiar. Their throughput may not.

GTIG's vulnerability research provides an early signal on the defensive side. In the set it identified as likely AI-discovered vulnerabilities, 39% were Low Risk compared with 69% in the broader non-AI-discovered dataset, while 58% were Moderate Risk compared with 28%. Remote code execution appeared in 50% of AI-discovered cases compared with 26% across the wider CVE set.[1]

GTIG cautions that this distribution largely reflects how researchers scope and direct these systems. The stronger conclusion is therefore not that AI automatically discovers more dangerous vulnerabilities, but that autonomous research systems have already demonstrated an ability to identify consequential flaws, including CVE-2026-1731, which attackers began exploiting within days of disclosure.

AI infrastructure is simultaneously becoming worth attacking.

From January through August 2026, orchestration middleware accounted for 50% of the AI-related vulnerabilities analysed by GTIG. The research also identified weaknesses in inference infrastructure and enterprise AI gateways. Compromise of a gateway can expose third-party API credentials and private prompt streams containing PII or proprietary source code, while potentially providing a route towards connected cloud infrastructure.[1]

GTIG reports no observed zero-day exploitation of AI infrastructure in this dataset. It has, however, observed weaponisation of newly disclosed vulnerabilities in exposed AI middleware.[1]

The implication for organisations deploying AI is straightforward: the security boundary does not end at the foundation model. It includes the gateways, credentials, orchestration systems, integrations, permissions, logging and data flows surrounding it.

Both the value of an AI agent and its potential blast radius depend on the authority it receives.


5. Implications for confidential-data professions

Professionals entrusted with confidential information do not necessarily use the same systems or face identical legal obligations. What they share is dependence on information that must remain available to authorised parties and unavailable to others.

That makes exposure at speed particularly important.

A shorter defensive window increases the cost of slow prioritisation. More machine identities create additional paths towards sensitive information. Exfiltration means that successful recovery may still leave an irreversible confidentiality problem. AI can accelerate the interaction between all three.

This leads to a broader concept of information exposure management.

Security governs how systems and information are protected; privacy governance determines whether information should be collected, retained or disclosed in the first place.

Those disciplines increasingly reinforce one another.

Every unnecessary identifier increases the information potentially exposed when a system is compromised. An integration with access to an entire client repository creates a larger blast radius than one limited to the records it genuinely needs. An AI workflow receiving a complete confidential document when only a small extract is required similarly creates unnecessary exposure.

Data minimisation does not replace cybersecurity controls. It limits the consequences when those controls fail.

GTIG's AI-gateway findings demonstrate why this matters beyond theory. A compromised enterprise gateway may expose API credentials and private prompt streams containing personally identifiable information or proprietary source code.[1]

The relevant question is therefore not only whether an AI system is secure.

It is also:

What becomes available if this component, its identity or one of its integrations is compromised?

Evidence retention belongs to the same discussion. The Dutch NCSC's NetScaler guidance advised organisations to preserve memory, disk images and at least a month of relevant logging before remediation.[8]

Logs are not merely technical telemetry; in regulated environments, they may become essential evidence of whether confidentiality was lost.

Without that evidence, an organisation can face the incident and uncertainty about its own exposure at the same time.


6. Q4 2026 outlook

The following judgements are IamVERA assessments, not statements of observed fact. Confidence levels reflect the strength of the evidence and the visibility of the underlying drivers.

High confidence: the defensive window will remain under pressure

GTIG expects vulnerability discovery and exploitation rates to continue increasing in the short to medium term.[1] Microsoft independently reports a median weaponisation interval below 24 hours in activity visible to its researchers.[2]

The operational advantage will therefore come from connecting external threat intelligence to internal context quickly: whether an affected technology is present, exposed, exploitable and positioned in front of sensitive information or authority.

Traditional metrics such as the percentage of patches installed within 30 days will become less informative on their own. For a small number of exposures, thirty days is far too long. For thousands of others, immediate action would add little security value.

The important capability is knowing the difference.

High confidence: non-human identity will become a mainstream governance issue

The expansion of SaaS, cloud infrastructure, automation and agentic AI will continue to increase the number of identities belonging to software rather than people.

The immediate risk is unlikely to be an AI agent independently deciding to attack its organisation. A more plausible scenario is that an agent, integration or service account receives excessive authority, its credentials or orchestration layer are compromised, and the attacker inherits the permissions that made the automation useful.

Identity governance will therefore increasingly become part of AI governance.

Moderate-to-high confidence: AI orchestration will increase

We expect more cyber operations to incorporate AI orchestration during Q4, while fully autonomous end-to-end attacks remain less common than human-directed or hybrid operations.

The distinction between an “AI attack” and conventional cybercrime will consequently become less useful.

Credential theft remains credential theft if AI selects the targets. Vulnerability exploitation remains vulnerability exploitation if an agent analyses the patch. What changes is the amount of time and human effort required.

High confidence: information theft will remain central to extortion

Organisations handling high-value confidential information should continue preparing for incidents in which theft provides at least as much leverage as encryption.

This does not mean ransomware encryption will disappear. It means successful restoration alone is no longer an adequate measure of a successful response.

Organisations increasingly need to answer what an attacker could access, what was actually accessed and what information left the environment.

Moderate confidence: AI infrastructure will attract greater attacker attention

AI gateways and orchestration platforms are concentrating credentials, prompt data, internal integrations and access to downstream systems.

GTIG already reports n-day exploitation against exposed AI middleware, although it has not observed zero-day exploitation of AI infrastructure in the dataset considered here.[1]

As AI systems gain more authority, the incentive to compromise the surrounding infrastructure will increase accordingly.


7. Management priorities

The evidence does not justify replacing cybersecurity fundamentals. Strong authentication, asset management, patching, logging, endpoint protection, backups, least privilege and incident response remain essential.

Management should, however, adjust four priorities.

1. Measure time to exposure reduction

Do not measure vulnerability management through patch volume alone.

Management should know how quickly an actively exploited vulnerability can be connected to the organisation's own infrastructure and, where necessary, contained or isolated.

Microsoft makes the same underlying point in its 2026 Digital Defense Report: while attack timelines are compressing, enterprise remediation of critical external vulnerabilities can still take 30 to 60 days.[2] That mismatch creates a period in which an exposed system may remain vulnerable long after exploitation has become practical.

This requires current knowledge of internet-facing assets, clear ownership and an emergency path that can override normal maintenance cycles.

The relevant metric is therefore not simply how many patches were installed within a standard window, but how quickly the organisation can reduce exposure when a vulnerability becomes operationally urgent.

2. Give every machine identity an owner

Service accounts, API keys, automation, cloud identities, CI/CD credentials and AI agents should not exist indefinitely without clear ownership.

Someone should be able to state why each identity exists, what it can access, when its privileges were last reviewed and how quickly those privileges can be revoked.

Least privilege applies to software as much as it does to people.

3. Preserve evidence before destroying it

Updating or rebuilding a vulnerable system may stop an ongoing exposure while destroying the evidence needed to establish whether compromise already occurred.

Incident procedures should therefore distinguish between immediate containment and evidence preservation, particularly where personal, privileged or otherwise confidential information may be involved.

4. Reduce the informational blast radius

Assume that no preventive control is perfect and ask what becomes accessible when one control fails.

How much client information can one account reach? What does one integration retain? Does an AI workflow need the entire document? Does a service account require access to the complete repository?

Data minimisation, segmentation and least privilege support the same objective:

one compromise should not automatically become access to everything.

That is the management response to exposure at speed.


8. Methodology and sources

This report reviews cybersecurity research, advisories and threat intelligence published or materially updated between 19 September and 2 October 2026.

The publication window should not be confused with the underlying observation periods.

GTIG's vulnerability analysis covers January 2025 through August 2026, with most 2026 comparisons covering January–August.[1]

Microsoft's 2026 Digital Defense Report uses broader reporting periods, including telemetry spanning approximately July 2025 through June 2026 for parts of its analysis.[2]

Proofpoint's TeamFiltration activity occurred primarily between 21 July and 16 August 2026, although the research was published on 22 September.[3]

Unit 42's AWS article was published on 21 September 2026, but its deliberate credential-exposure experiment was conducted on 19 December 2025.[5]

Zscaler's ransomware analysis covers April 2025 through March 2026.[6]

The assessment therefore uses recent publications to identify structural developments rather than implying that all underlying incidents occurred during the fourteen-day publication window.

Vendor research represents activity visible through each organisation's own telemetry, investigations and methodology; it should not be interpreted as a complete census of the global threat landscape. Where a source uses tentative language, this report retains that uncertainty.

The Q4 section contains IamVERA analytical judgements derived from the evidence base. Confidence labels indicate the strength of the supporting evidence and the extent to which the underlying drivers are already observable.


References

[1] Google Threat Intelligence Group (2026). “Vulnerability Discovery and Exploitation Trends in the AI Era.” 30 September 2026.
https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era/

[2] Microsoft (2026). “2026 Digital Defense Report” and accompanying security analysis. 1 October 2026.
https://www.microsoft.com/en-us/security/security-insider/threat-landscape/2026-digital-defense-report
https://www.microsoft.com/en-us/security/blog/2026/10/01/insights-from-the-2026-microsoft-digital-defense-report/

[3] Proofpoint (2026). “Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts.” 22 September 2026.
https://www.proofpoint.com/us/blog/threat-insight/Spraying-in-the-Andes-TeamFiltration-Returns

[4] Palo Alto Networks Unit 42 (2026). “OperTraitors: How Kubernetes Operators Betray Your Security Posture.” 29 September 2026.
https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/

[5] Palo Alto Networks Unit 42 (2026). “From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies.” 21 September 2026.
https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/

[6] Zscaler ThreatLabz (2026). “Ransomware Leverage is Growing by the Terabyte.” 30 September 2026.
https://www.zscaler.com/blogs/security-research/ransomware-leverage-growing-terabyte-takeaways-threatlabz-2026-ransomware

[7] Google Threat Intelligence Group / Mandiant (2026). “Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances.” 29 September 2026.
https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances

[8] Nationaal Cyber Security Centrum (NCSC-NL) (2026). “Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu.” 27 September 2026; updated 30 September 2026.
https://www.ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu

[9] Regulation (EU) 2016/679, Article 33.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

[10] CISA (2026). “CISA Adds One Known Exploited Vulnerability to Catalog.” 1 October 2026.
https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog


IamVERA.ai

Independent analysis of AI, privacy and cybersecurity risk for professionals entrusted with confidential information.

← All articles in this topic ← All articles