Skip to main content

CISO Daily — Executive Cyber Intelligence for Security Leaders

AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

Anthropic has confirmed the first large-scale cyberattack executed autonomously by an AI system. A Chinese state actor directed Claude Code through the full intrusion lifecycle against 30 global organisations with minimal human involvement. This briefing translates the implications for CISOs and their boards.

Briefing
about 1 month ago

Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer

NIST's post-quantum cryptography standards are final, NSA compliance deadlines for national security systems begin in January 2027, and adversaries are already collecting encrypted data for future decryption. This briefing provides CISOs with the governance framework for starting migration now.

Risk Analysis
3 months ago
Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer

Latest News

View all
  • CVE-2026-21962: The Oracle WebLogic Flaw That Was Exploited for Seven Months Before Anyone Noticed

    CVE-2026-21962: The Oracle WebLogic Flaw That Was Exploited for Seven Months Before Anyone Noticed

    CISA added a maximum-severity Oracle WebLogic and HTTP Server flaw to its Known Exploited Vulnerabilities catalogue on August 24, with a three-day federal remediation deadline -- but Oracle patched the bug back in January, and a China-linked threat actor has reportedly been exploiting it against government infrastructure since then. For CISOs, the real story is not the CVE. It is why a patched, unauthenticated, CVSS 10 vulnerability sat unremediated for seven months.

    incident-report
  • Black Hat USA 2026: The Executive Threat Briefing

    Black Hat USA 2026: The Executive Threat Briefing

    Black Hat USA 2026 ran in Las Vegas this week. The themes that dominated — AI infrastructure exploitation as an independent attack discipline, nation-state credential harvesting through trusted third-party networks, and autonomous agent weaponisation — carry direct implications for enterprise risk posture. This briefing distils what security leaders need to know.

    Briefing
    7 min read
    AgentForger: When a Phishing Link Becomes a Persistent AI Insider

    AgentForger: When a Phishing Link Becomes a Persistent AI Insider

    Zenity Labs' disclosure of AgentForger demonstrates that enterprise AI agents can be weaponised from outside the organisation via a single phishing link, creating an attacker-controlled agent that inherits authorised access to email, calendar, Slack, and Teams. OpenAI patched the specific flaw in June — but the governance problem is structural and ongoing.

    Risk Analysis
    7 min read