Two stories about AI are running, and both are incomplete. The tools genuinely compress work; the accounting, the calibration and the power bills are another matter. Twenty-five years ago the fibre outlasted the forecasts that paid for it, and nothing in a boom is cheaper than a confident number.
Google’s €13bn Finnish AI investment shows the race is no longer just about chips and models. It is about nuclear power, grids, cooling and construction. As data centres become industrial assets, countries with reliable, low-carbon energy will hold the decisive advantage as global AI
AI is shrinking the gap between flaw disclosure and exploitation, forcing boards to modernise security at machine speed. As agentic systems arm attackers and defenders alike, the opportunity lies in identity, cloud protection, automated response and AI governance, not apocalypse rhetoric globally.
AI agents are no longer side experiments. They are becoming live attack surface, carrying access to data, code and identity. For Australian businesses, the message is clear: adoption must be matched with control.
The past week has shown a clear shift in cyber risk. AI agent frameworks are no longer just productivity tools. They are becoming live execution environments that attackers can reach.
Security researchers have reported serious flaws across LangGraph, Langflow, coding agents and OpenClaw. The pattern is consistent. These systems often hold access to data, developer tools, credentials and internal systems. When they are exposed to untrusted input, a simple prompt, file, error report or contact card can become a path to code execution.
At the same time, ransomware is moving faster. The Gentlemen operation has claimed hundreds of victims and is showing self spreading behaviour. That reduces the time businesses have to isolate systems once compromise begins.
The Oracle PeopleSoft zero day is another warning. Attackers exploited a critical flaw before a patch was available, with higher education and enterprise environments among the targets.
Why it matters
For Australian businesses, the cyber perimeter has moved again. It is no longer defined only by email gateways, endpoints, cloud platforms and firewalls. AI agents, developer environments, remote management tools and identity systems are now part of the live attack surface.
That matters because these systems often sit close to the most sensitive parts of the organisation. They can access data, trigger workflows, read internal systems, write code and connect into cloud environments. When they are exposed too quickly, or deployed without proper controls, they give attackers a new way to move from a simple input into privileged action.
The ransomware numbers show why this is not a theoretical concern. According to OpenText Cybersecurity research reported in 2025, two in five Australian companies experienced a ransomware attack in the previous year. Nearly half of those were targeted more than once. While 97 per cent of respondents were confident they could recover, only 11 per cent of attacked organisations fully recovered their data. A further 3 per cent recovered nothing.
That gap between confidence and recovery is the real warning. AI may accelerate productivity, but it also accelerates exposure. Businesses cannot afford to treat agent frameworks, developer tools and remote access systems as experimental side projects. They need to be inventoried, isolated where necessary, stripped of excessive privileges, monitored continuously and governed with human approval for sensitive actions.
The lesson is not to slow down AI adoption. It is to build security into the way AI is deployed from the start. In this next phase, resilience will belong to organisations that understand one simple truth: the new perimeter is not a place. It is every system that can act on behalf of the business.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
AI is shrinking the gap between flaw disclosure and exploitation, forcing boards to modernise security at machine speed. As agentic systems arm attackers and defenders alike, the opportunity lies in identity, cloud protection, automated response and AI governance, not apocalypse rhetoric globally.
Three AI leaders agree the frontier may be moving faster than its safeguards. As markets weigh slower chip demand and rising cyber investment, the question is whether the warning is responsible leadership, strategic scaremongering or evidence that cybersecurity has become AI’s essential foundation.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!