Executive Summary Publicly available information collected in September 2026 highlighted common discussion points: "attacks that use legitimate connections and privileges to move laterally after infiltration," "malicious code in software supply chains that activates during normal use or after distribution resumes," and "governance over the scope of execution left to AI." An important defensive lesson is not only to strengthen perimeter defenses, but also to pre-define the extent of...