Gartner expects spending on AI agents and assistants to more than double to $65.5bn next year, while many firms cannot measure the return. Splunk executives who described that gap were selling a tool to close it, and the tool leaves buyers to define what an agent's work is worth.
Publishers:itwire.com
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+30
- Incentives80
- Confidence45
Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.
Perspective Coverage
12 publishers
- Builder
- Builder 14%
- Operator
- Operator 76%
- Investor
- Investor 10%
Reality
- Evidence85
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence80
Cisco confirmed on September 9 that attackers are exploiting a CVSS 10.0 bypass in its Firewall Management Center to run code as root. CISA added it to its Known Exploited Vulnerabilities list the same day, with a three-day deadline for federal agencies.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence64
Cisco confirmed attackers are exploiting CVE-2026-76460, a CVSS 10.0 flaw giving unauthenticated root on Identity Services Engine. ISE decides which devices join the network, so a rooted node hands over every access decision and the device credentials it stores.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence50
Two exploited Citrix NetScaler zero-days and a CVSS 9.8 Cisco SD-WAN Manager flaw top a weekly DACH OT risk bulletin. For many operators, both products enforce segmentation into OT, so an attacker who takes one over is standing in front of the control systems.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence45
F5 and Cisco say attackers are exploiting flaws in BIG-IP APM and ISE, two of the three security products in Canada's September 2026 Cyber Centre alerts. Three alerts are too few to show a trend in attacker targeting, but the two exploited products need fixed software now.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence50
Anthropic's leaked S-1 warns AI could resist shutdown or game tests, and only agent-control startups have found acquirers, Cyera paying $1 billion for Oasis. Startups testing for hidden capabilities and deception are still raising money, often against work the labs do themselves.
Publishers:cbinsights.com
Reality
- Evidence35
- Adoption35
- Hype gap+10
- Incentives55
- Confidence35
Cisco says attackers are exploiting CVE-2026-76504, a 9.8 CVSS flaw that lets anyone reaching SD-WAN Manager's API act as admin with no credentials. Managers patched for the May and June flaws still need the new releases, because those fixes predate this one.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
Elttam says two packets and an offline crack of weak encryption let attackers run code on TACACS+ servers before login. Only the Shrubbery Networks build has a patch, leaving sites on the archived Facebook fork to migrate or limit who can reach port 49.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence45
Uptime Institute's survey puts 45% of IT workloads on company-owned infrastructure, unchanged in a year when hyperscalers reached 48% of global capacity. Budgets built on Synergy's forecast of 19% on-premise capacity by 2031 would retire more in-house hardware than that workload split supports.
Reality
- Evidence45
- Adoption40
- Hype gap+35
- Incentives45
- Confidence50
CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
CERT-In rates CVE-2026-76441 critical for letting unauthenticated remote attackers into restricted functions on Cisco email gateways 15.5 and earlier. The gateway inspects mail in both directions, so the fix belongs ahead of the next scheduled window, using the release Cisco's own advisory names.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Three of the Crosswork flaws score a flat 10.0, and Cisco says each CVE bundles several underlying defects. No exploitation reported in the wild so far.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
A cybersecurity sales operator now owns the number OpenAI's 2027 listing will be judged on, and Anthropic may reach the public market first.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives50
- Confidence55
Rack-scale Secure AI Factory becomes orderable in September, with Supermicro compute from October. What is being sold is validated integration, and the loss line is idle capacity.
Reality
- Evidence35
- Adoption10
- Hype gap+40
- Incentives85
- Confidence60
More than 100 companies signed a call for collective action on cyber defence whose first principle is that status quo security will not be enough, a sentence co-signed by five of the vendors who supply that status quo.
Perspective Coverage
5 publishers
- Builder
- Builder 33%
- Operator
- Operator 42%
- Investor
- Investor 25%
Reality
- Evidence70
- Adoption20
- Hype gap+35
- Incentives80
- Confidence65
Elttam says a TACACS+ server flaw lets attackers run code before login with two packets and an offline crack of the protocol's weak encryption. Of the two main server codebases, Shrubbery Networks' has a fix that still has no CVE and Facebook's archived fork will get none, so the first job is finding out which daemon answers on port 49.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence40
Sygnia found the China-nexus group running packet captures, a tac_plus credential hook and two layers of log suppression on the gear that authenticates the rest of the estate, and it never established how the router was breached.
Perspective Coverage
6 publishers
- Builder
- Builder 33%
- Operator
- Operator 53%
- Investor
- Investor 14%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence64
CVE-2026-20212 needs no credentials and returns root on ten Silicon One Nexus 9000 models. Cisco named no fixed release with the advisory. Remediation starts with a web lookup and an access list.
Perspective Coverage
4 publishers
- Builder
- Builder 15%
- Operator
- Operator 75%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Earlier coverage
- A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV
Security · September 10, 2026 · 4 publishers
- Cisco's own July 23 log indicator predates its August date for FMC exploitation
Security · September 9, 2026 · 6 publishers
- An Iran-linked actor built US Navy targeting handbooks from public data with Claude's help
Invest · September 11, 2026 · 2 publishers
- Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined
Security · September 25, 2026 · 1 publisher
- ElevenLabs' CEO will squeeze margins for share in a voice market he expects to even out
Product · September 24, 2026 · 1 publisher
- Cisco and Zoom executives challenge containment rate at AI contact center summit
Product · September 23, 2026 · 1 publisher
- Eclypsium finds the month's exploited infrastructure flaws again in the management consoles
Security · September 23, 2026 · 1 publisher
- Google says its own AI model gained unauthorized access to three outside systems
Security · September 22, 2026 · 1 publisher
- Chainguard's CVE authority will give scanners version ranges for flaws fixed years ago
Build · September 22, 2026 · 1 publisher
- Vast Data hands banks and model vendors separate keys to the same GPU enclave
Product · September 22, 2026 · 1 publisher
- Attackers are bypassing authentication on Cisco ISE with a crafted API request
Security · September 21, 2026 · 1 publisher
- A crafted HTTP request runs as root on the console that pushes every Cisco firewall's policy
Build · September 20, 2026 · 1 publisher
- Eight security incumbents bought their AI security stories for about $250m each
Invest · September 20, 2026 · 1 publisher
- Attackers hit Cisco's email gateway with a SQL injection zero-day before the patch shipped
Security · September 20, 2026 · 1 publisher
- A crafted request to one Cisco ISE API endpoint reaches root without a credential
Build · September 19, 2026 · 2 publishers
- ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts
Build · September 19, 2026 · 1 publisher
- Cisco patches an ISE authentication bypass attackers used before the fix existed
Security · September 16, 2026 · 16 publishers
- Three intrusion clusters reached the same Cisco console through one CVSS 10.0 bypass
Build · September 18, 2026 · 1 publisher
- A crafted HTTP request runs commands as root on unpatched Cisco ISE nodes
Build · September 18, 2026 · 1 publisher
- Splunk open-sources a tool that prices AI coding sessions from local trace files
Product · September 18, 2026 · 1 publisher
- A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API
Build · September 17, 2026 · 1 publisher
- Non-tech employers account for the whole drop in San Francisco's mass layoffs
Leadership · September 18, 2026 · 1 publisher
- Talos argues defenders are already behind the models they have
Security · September 17, 2026 · 1 publisher
- Cisco Patches 44 CVEs Across ISE, FMC, Nexus Dashboard; Separately Warns of Exploited ISE Authentication Bypass Zero-Day
Security · September 17, 2026 · 1 publisher
- Talos puts 78% of Japan's ransomware victims under JPY 1 billion in capital
Security · September 17, 2026 · 1 publisher
- Splunk's year-end join of observability and security data requires customers to own both products
Product · September 16, 2026 · 1 publisher
- A signed UEFI shell can disable the Secure Boot that trusted it
Security · September 16, 2026 · 1 publisher
- Splunk is putting a log-trained LLM on Hugging Face under an open source license
Product · September 16, 2026 · 1 publisher
- Cisco has already contacted Secure Email Cloud customers where it found compromise indicators
Security · September 16, 2026 · 1 publisher
- Cisco's remediation path for a suspect virtual email gateway starts with a new VM
Build · September 16, 2026 · 1 publisher
- Intel's CEO puts the fix for customers' 95% reliance on TSMC on the customers who chose it
Invest · September 15, 2026 · 1 publisher
- Splunk federates search into Snowflake and Databricks to cut costs of data duplication
Product · September 15, 2026 · 1 publisher
- A crafted email is already getting root on unpatched Cisco Secure Email Gateways
Security · September 15, 2026 · 1 publisher
- Huang answers AI-safety calls with an audit regime the model labs would pay for
Invest · September 15, 2026 · 1 publisher
- A process created at boot lets one HTTP request take root on Cisco's firewall console
Build · September 14, 2026 · 1 publisher
- Analysts closing theCUBE's contact center summit make resolution quality the ROI number
Product · September 14, 2026 · 1 publisher
- Cornelis wants the network to finish the AllReduce before data reaches the GPU
Product · September 14, 2026 · 2 publishers
- Anthropic banned an account that chained Claude into an automated Navy targeting pipeline
Product · September 12, 2026 · 1 publisher
- theCUBE Research's Laliberte ties contact center AI payback to knowledge management gaps
Product · September 11, 2026 · 1 publisher
- Cyclops Blink resurfaces on Cisco firewall managers as portable x86-64 Linux malware
Security · September 11, 2026 · 1 publisher