Security had the kind of week that gets budgets approved. A perfect-10 flaw under active attack, the guards themselves compromised, and a workforce quietly wiring its own tools into your data. One thread runs through all of it.
The flaw scored a perfect 10
Adobe’s ColdFusion vulnerability hits the maximum CVSS score: unauthenticated code execution, no login required. Attackers were exploiting it within hours of disclosure, faster than most admins read the advisory. Check your exposure →

Then the locks failed
It gets worse. BeyondTrust, a company whose whole job is guarding privileged access, patched twin 9.2 flaws that let attackers skip authentication entirely. When the guard booth is the way in, the model needs rethinking. Read the details →
Your robots have no ID
While the human doors were failing, the machine ones were never built. Orchid Security’s research puts 67 percent of nonhuman accounts, the identities AI agents inherit, at completely unmanaged. See the gap →

The money already voted
CFOs read the same headlines. 91 percent of organizations plan to raise threat-intelligence spend even as software budgets tighten, and the investors followed: Keyfactor took a billion-dollar bet on machine identity, and a UK fund raised £60 million just for cybersecurity seed deals. Why this budget never dies →
One number
Hours. The time between the ColdFusion disclosure and confirmed in-the-wild attacks. Your patch window is now measured on a stopwatch. The timeline →
One thing to use
The shadow AI playbook. Your employees are already wiring personal AI tools to company data, and bans do not work. The three controls that do are in here. Steal the controls →
That is the thread: the doors failed, the guards failed, and the machines never had badges. Hit reply with the security story you want dug into. Forwarded this? Claim your own copy.
Dr. Joseph Joshua
P.S. Next issue: your coding tool may speak Chinese.
AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.
