SANS survey of 536 cybersecurity professionals: AI adoption outpaces risk governance
This digest was compiled by AI from multiple sources — links to the originals are below.

AI adoption in cybersecurity has outpaced governance, with 78% of 536 SANS survey respondents now including AI in their strategy compared with 50% a year earlier. Only 36% of those surveyed have a formal AI risk program. The same week, a suspected China-nexus APT is assessed to be behind exploitation of a VMware vCenter flaw, with Babuk-derived ransomware assessed as a smoke screen rather than the primary objective.
Key Facts
- 78% of 536 surveyed security practitioners now say AI is part of their cybersecurity strategy, up from 50% a year earlier.
- Only 36% of survey respondents have a formal AI risk program.
- A suspected China-nexus APT is assessed to be behind exploitation of CVE-2026-59310, a VMware vCenter directory-traversal flaw with CVSS 9.8, leading to Babuk-derived ransomware deployment in at least one case.
- Apple patched CVE-2026-65400, a macOS Screen Sharing authentication flaw with CVSS 9.8, after active exploitation placed Monero miners on systems with exposed port 5900; emergency updates shipped in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
- The Babuk ransomware deployment is assessed as a smoke screen intended to distract from the intrusion and encrypt evidence rather than serve as the primary objective.
AI Governance Gap
The SANS survey of 536 security professionals found 78% now include AI in their cybersecurity strategy, compared with 50% a year earlier. Only 36% of respondents said their organization has a formal AI risk program. The survey data shows AI adoption moving faster than governance, with 78% strategic use against 36% formal risk oversight.
VMware Exploitation
A suspected China-nexus APT is assessed to be behind the exploitation of CVE-2026-59310, a VMware vCenter directory-traversal vulnerability with a CVSS score of 9.8. In at least one compromised instance, the attack led to deployment of a backdoor, a reverse SSH binary, and Babuk-derived ransomware. The vulnerability could be weaponized by a malicious actor to execute arbitrary code. The ransomware deployment is assessed as a smoke screen intended to distract from the underlying intrusion and encrypt forensic evidence, rather than as the primary objective.
macOS Miner Deployment
Apple recently patched CVE-2026-65400, a critical authentication flaw in the macOS Screen Sharing component with CVSS 9.8, in emergency updates. The updates shipped in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 earlier this month. The Netherlands National Cyber Security Center received a report of active abuse across multiple systems where port 5900 was accessible from the internet. In all observed cases, root gained access to the affected system and placed a Monero cryptocurrency miner.
1 source
SANS survey of 536 cybersecurity professionals: AI adoption outpaces risk governance



