Already I get to say I Told You So.
I developed the Important and the Imperative series to help the busy executive to be aware of the flaws in our security methodologies. The problem is not a lack of focus it’s a lack of resources.
We have the perfect storm of rapid adoption of AI, AIOT, & Quantum Computing and shortage of qualified personnel while boomers are aging out.
Candidly I worry that the lack of personnel will make us more reliant on the very things we don’t know how to secure. Assuming there is no quick fix, the best advice I can think of is ensuring a human in the loop “fail safe” strategy.
Here is what’s in the news today that give credence to last weeks articles.
I said identity programs weren’t built to count machine identities. The weekend counted for them.
Three stories, one lesson. Microsoft confirmed a maximum-severity, unauthenticated remote-code-execution flaw in Entra ID — the front door to enterprise identity itself (CVE-2026-69836, patched server-side, no known exploitation). A threat actor is selling Azure directory dumps from nine Fortune 500-level companies — McDonald’s alone at 1.7 million records — including the lists of Global Administrators. And the Mirage2FA phishing service is stealing Microsoft 365 session cookies after victims complete legitimate MFA, with stolen tokens that survive password resets.
Business impact: your identity directory is now the target, the inventory, and the shopping list. If you cannot answer “how many identities can act in our environment right now, and who owns that count?” — the attackers can.
I said agentic AI changes the identity math. An agent just ran a ransomware campaign.
A suspected affiliate of The Gentlemen ransomware operation used an AI coding agent against at least eight organizations — including an Australian energy utility — to run LDAP pass-back attacks, backdoor VPNs, map networks, and stage SQL databases for theft. The agent also accidentally knocked a firewall offline, which is cold comfort: the next one won’t.
Business impact: machine-speed attackers are here before most machine-speed defenses. Every argument for governing AI agents as first-class identities just got a live demonstration.
I said unsigned fields are a provenance failure waiting to happen. Ask Visa.
University of Massachusetts Amherst researchers showed expired Visa contactless cards completing real purchases. Why? Visa’s EMV kernel treats expiration as a plaintext, terminal-side policy check — the expiry field is not part of the cryptographically signed record. Mastercard, Amex, and Discover sign it; their kernels caught the tampering.
Business impact: last week I argued that vCons matter because a signed container makes provenance provable and a proprietary blob makes it impossible. Same principle, different industry: what you don’t sign, you can’t defend.
And the one that goes beyond told-you-so: Iran-linked hackers disabled a UK power plant for four days.
Concurrent with water-infrastructure attacks across twelve US states. It is the first confirmed disabling cyberattack on UK energy of its kind. Add CISA’s warning that Medusa ransomware has now compromised more than 500 critical-infrastructure organizations, and the operational-technology picture is unambiguous.
Business impact: the water-sector playbook is now the energy-sector playbook. Monitoring your physical environment and monitoring your threat environment are converging into one discipline.
Conclusion
None of this was hard to predict, and that is the point. Are models are broken and we going to have to adapt, adopt and advance over and over again at least for the near future.
The discipline I keep returning to — discovery, agility, governance — is not a quantum thing, an identity thing, or an OT thing. It is the thing.
Discovery: you cannot protect identities, signatures, or plants you have not inventoried.
Agility: patched server-side, migrated to passkeys, re-signed with stronger algorithms — the organizations that survive are the ones that can change what they run.
Governance: every story above ends with the same question. Who owned this? The Global Administrator list, the AI agent’s credentials, the expiry field, the plant’s remote access. Somebody owned each one. Most of them didn’t know it.
I told you so isn’t a victory lap. It’s an invitation: the next round of headlines is just as predictable. Pick one thing you’ve been deferring — the identity count, the agent inventory, the unsigned field — and assign it an owner by Friday.
Three questions to close
How many identities — human, service, and AI agent — can act in your environment right now, and who owns that count?
Which of your records, tokens, or fields are policy-checked but not cryptographically signed?
If an AI agent ran a campaign against your network at machine speed tonight, would your response run at human speed?
Sources
UK power plant disabled by Iran-linked hackers; US water attacks (Security Affairs): https://securityaffairs.com/must-read
Entra ID CVE-2026-69836, Azure directory dumps, Mirage2FA session theft, Claude-assisted ransomware campaign, Medusa/CISA advisory (Cybersecurity News weekly bulletin, Aug 23, 2026): https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/
Zombie Card expired-Visa research, UMass Amherst at USENIX Security 2026 (Security Affairs): https://securityaffairs.com/must-read
Last week’s pieces referenced: Agentic AI & Identity Management (LinkedIn); vCons and provenance (The Imperative & The Important); Y2Q Readiness Workbook discovery worksheets.