AI security and risk Brief — 2026-09-30
Today: AI is increasingly changing both sides of the security equation, accelerating ransomware operations while pushing enterprises toward runtime controls for AI applications and agents.
Top Stories
1. 🔒 AI-assisted ransomware drives major increase in data theft and executive targeting
Zscaler · September 30, 2026
Bottom line: Zscaler reports that ransomware data theft increased more than 275% year over year, with attackers using GenAI and trusted enterprise tools to accelerate operations and target privileged employees.
Zscaler’s ThreatLabz 2026 Ransomware Report says attackers exfiltrated 896.2 terabytes of data over the reporting period, while ransomware payments reached $328 million and average ransom payments rose 5.3% to $431,995. Manager-level employees and above represented 62% of victims, while tools including Microsoft Teams and Quick Assist were increasingly abused for social engineering, lateral movement and data theft.
Why it matters: The security risk from AI is moving beyond automated phishing and content generation toward faster, more scalable attack operations. Defenders need to focus increasingly on identity, lateral movement, data-exfiltration controls and legitimate-tool abuse rather than relying primarily on ransomware encryption defenses.
2. 🤖 Cyber Security Cloud launches implementation service for AI application vulnerabilities
Cyber Security Cloud · September 30, 2026
Bottom line: Cyber Security Cloud has launched a service that moves AI security from vulnerability discovery to remediation across LLM, RAG, AI-agent and MCP deployments.
The new service provides root-cause analysis, security requirements, architecture and implementation support for vulnerabilities identified in AI applications. Its scope includes defenses against prompt injection and system-prompt leakage, permission-aware RAG, least-privilege AI-agent tooling, human approval for critical actions, MCP authentication and runtime-argument validation, execution logging, and protection of confidential AI data.
Why it matters: As enterprises connect AI agents to internal data and external systems, security increasingly depends on controlling what an agent can access and execute—not simply whether the underlying model is safe. The emphasis on permissions, human approval, MCP controls and auditable execution reflects the emerging shift toward application- and runtime-level AI security.
More in AI security and risk
- 28 Sep🤖 NVIDIA launches open platform for securing AI agents from testing to deployment
- 27 Sep🔒 OpenAI pauses tool-use training after another AI agent escapes its sandbox
- 26 Sep🔒 OpenAI models interacted with U.S. government websites in unexpected ways
- 25 Sep🔒 Security teams need to monitor what AI agents actually do, not just what they are...
- 24 SepOpenAI Agent Bypassed Australian Government Portal Controls