Monday, and the news splits neatly across three layers of the same house: the machine that moves faster than your team, the human who trusts the wrong voice, and the old network door everyone forgot was unlocked. Different entry points, one lesson — the attacker takes whichever one you left soft.
The break-in was run by agents, not people
Security playbooks were built for attackers who work at human speed. That assumption is aging fast. Researchers report that AI agents exploited flaws in PaperCut print management software to breach 395 organizations — not a hand-cranked campaign but automated exploitation at a scale a human crew could not match. This lands the same week security press flagged that AI-driven attacks are outpacing human response, and that in a late-August open letter OpenAI, Anthropic, Google, Microsoft, AWS and more than 100 technology leaders warned that AI-enabled threats will grow more sophisticated in the months ahead.
The operator's take: the window between a CVE going public and a mass exploitation campaign is collapsing toward zero, because the exploitation is now automated. PaperCut is the kind of unglamorous internal service that never makes the priority list — which is exactly why it got hit 395 times. If your patch cadence for "boring" internal software is still measured in sprints, you're defending at human speed against attackers who aren't. Inventory the dull stuff, and put a machine-speed patch path on anything that listens on a network.
Revolut handed the data to someone pretending to be the government
The most expensive vulnerability this week wasn't in code. Revolut is working through a breach in which customer identity documents and financial data were handed over to someone impersonating a government official — a process failure and a social-engineering win, not a zero-day. No malware required when the front-line control is a human deciding whether a request looks official enough.
The operator's take: you can spend seven figures on endpoint tooling and still lose everything because someone approved a data disclosure over a convincing email or phone call. The defense here isn't a product — it's a procedure: out-of-band verification for any release of customer identity or financial data, no exceptions for "urgent" government requests, and a named second signer on anything that leaves the building. Attackers target the authority gradient because it works. Take the individual judgment call out of it and make disclosure a checklist, not a vibe.
The network edge is exposed again — this time Check Point
The oldest attack surface is still the most reliable. The Dutch NCSC is warning that critical Check Point VPN flaws are putting networks at risk, a reminder that the appliance you bolted to the perimeter to provide secure remote access is itself a high-value target.
The operator's take: VPN concentrators, firewalls, and remote-access gateways sit at the exact boundary attackers most want to cross, and they run software that gets patched far less aggressively than your servers. A flaw here isn't one user's problem — it's authenticated access to everything behind the tunnel. If you run Check Point remote access, this is a same-day patch, not a maintenance-window nicety. And it's worth asking the broader question: how much of your perimeter still depends on a single vendor's appliance staying flawless, and what does your access model look like the day it doesn't?
Also on my radar
- The identity-verification vendor got its identities stolen. IDScan confirmed a breach after 153 million driver's licenses leaked on the dark web — when your KYC provider is the one that gets popped, the "trust anchor" becomes the liability.
- A China-aligned crew is riding an input method. Threat actors are exploiting a critical flaw (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor — the keyboard software is a supply-chain path most asset inventories never list.
- AI defense is a measurement problem now. Research this week found AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick — the tooling works in the demo; the hard part is operationalizing it so it survives past the pilot.
The throughline: your attack surface isn't one thing you can harden, it's three that fail differently. Machines get exploited faster than you can respond, people get talked into opening the door, and the edge appliance you trusted turns out to have its own holes. Defense in 2026 means owning all three at once — patch at machine speed, put procedure where human judgment fails, and stop assuming the perimeter box is the one thing that stays clean. That's the Signal for today.
Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.