Reporting focused on how AI-driven risk is moving from an emerging concern into funded security programs as enterprises embed AI into workflows that touch sensitive data across cloud and SaaS. The 2026 Thales Data Threat Report survey data indicates more organizations now allocate a dedicated AI security budget (30%, up from 20% year-over-year) while also highlighting operationalized AI-enabled abuse, including deepfakes (reported by 59% of respondents) and reputational harm from AI-generated misinformation (48%). The same survey frames cloud as a primary attack surface—cloud storage, cloud applications, and cloud management infrastructure were the most-cited targets—and emphasizes credential theft/compromise as a leading technique against cloud management planes.
Separate commentary and interview-style content described the shift toward autonomous/agentic AI in offensive operations, where AI agents can continuously run phishing, automate lateral movement via path discovery, and adapt malware behavior during intrusions, pushing defenders toward more machine-guided response and governance. A weekly roundup reinforced that enterprises are rapidly connecting AI assistants to high-impact systems (ticketing, code repos, chat, cloud dashboards) with limited human oversight, while also mixing in unrelated items. Other items in the set were either general workforce/generic security guidance or IoT best-practices-style content and did not materially add to the AI-budget/agentic-threat story.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
In a March 2 interview, SimSpace's Jason Rivera says autonomous AI agents are enabling continuous phishing, adaptive malware behavior, and automated lateral movement without waiting for human input. He describes this as a shift that will change defender workflows and increase the need for governance.
The 2026 Thales Data Threat Report, published in early March, reports that 30% of surveyed organizations now have a dedicated AI security budget, up from 20% the prior year. The report frames this as evidence that AI risk has moved into formal security spending decisions.
The weekly roundup notes multiple arrests and seizures tied to phishing, DDoS, and fraud activity. These are presented collectively as recent law-enforcement actions during the review period.
The roundup says CISA guidance was issued and references a federal directive to replace edge devices, reflecting an official government response to edge security risks. No exact issuance date is given in the source summary.
The weekly review identifies critical or actively exploited vulnerabilities affecting Soliton Systems FileZen and SolarWinds Serv-U among the week's major developments. The reference does not specify separate disclosure dates for these items.
Help Net Security highlights a self-spreading npm supply-chain attack that used typosquatting to target developers. The roundup presents this as a distinct malware campaign active by the time of publication.
The roundup reports a malware campaign abusing the OpenClaw agent ecosystem via ClawHub, marking a supply-chain style compromise involving that agent environment. The reference does not provide a more precise date for when the campaign began or was discovered.
The weekly roundup cites a ransomware incident affecting Advantest as one of the notable security events during the period. No more specific incident date is provided in the reference, so the event is anchored to the roundup's publication timeframe.
The roundup states that a Cisco Catalyst SD-WAN zero-day had been exploited since 2023, establishing the earliest dated activity mentioned in the references. This indicates long-running real-world exploitation before the 2026 reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcehelpnetsecurity.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.