Quick reads. Clear signals. Your edge for the week ahead.
This week, I kept coming back to one question: What do we trust with the most access?
Increasingly, the answer is edge gateways, software-development pipelines, and AI agents—and those are exactly where the pressure is building. For executives, the issue is no longer just whether the technology works. It is whether that trust is visible, limited, and reversible when something goes wrong.
NetScaler vulnerabilities are already being exploited
Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway on September 27. Two are already being exploited, including an unauthenticated remote-code-execution vulnerability affecting every deployment—even those using the default configuration.
The takeaway: Confirm ownership of every internet-facing gateway, identify affected versions, apply the updates, and check for evidence of compromise. When the default configuration is vulnerable, incomplete asset visibility becomes part of the incident.
Read the Citrix security bulletin.
Investors are betting that AI security requires data and identity controls
On September 22, Goldman Sachs announced a $400 million investment in Cyera, valuing the company at more than $12 billion. Cyera is combining data security with non-human identity management to control what people, machines, and AI agents can access.
This is more than another large funding round. It signals where the security market is heading: AI governance is moving beyond prompts and models toward the identities, permissions, tools, and data agents can use.
The takeaway: Before scaling AI agents, organizations need to understand what information each agent can reach, which identity it uses, and whether that access can be monitored and revoked.
Read the Goldman Sachs announcement.
The software pipeline is now privileged production infrastructure
Google Threat Intelligence and Mandiant reported that attackers are increasingly targeting trusted scanners, developer tools, build caches, automation credentials, and CI/CD systems. These pipelines often have direct access to source code, secrets, registries, and cloud environments.
Their recommendations include single-use build runners, short-lived identities, restricted outbound access, isolated caches, and manual approval before untrusted code can access secrets or production-grade runners.
The takeaway: CI/CD security should receive the same governance and monitoring as production infrastructure. A compromised pipeline can distribute trusted, properly signed malicious software at scale.
Read Google’s CI/CD security guidance.
Bank cybersecurity examinations now align with NIST CSF 2.0
On September 21, the Office of the Comptroller of the Currency updated its Cybersecurity Supervision Work Program. Examiners will use a structure aligned with the six NIST Cybersecurity Framework 2.0 functions: Govern, Identify, Protect, Detect, Respond, and Recover.
The OCC emphasized that the update creates no new regulatory expectations. Even so, it makes the supervisory lens clearer and places governance alongside technical controls.
The takeaway: Financial institutions should be able to show how existing controls, responsibilities, testing, and evidence map to the six functions—even though the work program itself is not a required self-assessment.
Frontier AI models are arriving with tiered security access
Anthropic released Claude Opus 5.5 on September 22 with stronger agentic coding capabilities and safeguards designed for advanced cyber use. Anthropic says most cybersecurity requests will be rerouted to a less capable model unless the user participates in its verification program.
The release also includes action screening, sandboxing, code review, prompt-injection defenses, and controls intended to reduce unauthorized boundary crossing.
The takeaway: AI procurement can no longer be based solely on performance and cost. Leaders should understand which model actually handles sensitive requests, what actions are screened, and what additional access verified users receive.
Read Anthropic’s announcement.
Where does your organization still grant the most trust with the least visibility—the edge, the development pipeline, or AI agents?
Upcoming DC Edge Executive Dinners
Private, invitation-only evenings for senior cybersecurity and technology leaders. No stages, slides, or sales pitches.
- San Francisco — October 7, 2026
- Palo Alto — October 8, 2026
- Dallas
- Austin — October 27, 2026
- Seattle
- Kansas City — October 29, 2026
- Houston — November 12, 2026
- St. Louis — November 19, 2026
- Denver — December 16, 2026
Interested in attending? View upcoming dinners and request an invitation.
Interested in sponsoring? Explore sponsorship opportunities.