Back to Cybersecurity Growth

Podcast Episode

Patch Now, Govern Faster: SharePoint Fire Drills, Vendor Blast Radius & the AI Agent Gap

Cybersecurity Growth·Cybersecurity Growth·7 August 2026·32 min

About this episode

Patch now, govern faster. This week Shawn Valle and Garrett Gross break down three stories every security leader needs on their radar: the SharePoint zero-days under active attack (and CISA's 72-hour patch mandate), the Craneware breach that put 2,000 hospitals in the blast radius of a single vendor, and Gartner's warning that AI agents are hitting production 8x faster than governance can keep up — with $234B at risk.Cybersecurity Growth is a show for aspiring and existing cybersecurity leaders, hosted by Shawn Valle and Garrett Gross.⏱️ CHAPTERS 0:00 Cold open + welcome 2:30 A word from Cybersecurity Growth 3:30 SharePoint zero-days: CISA says patch in 3 days 11:00 Craneware breach: one vendor, 2,000 hospitals of blast radius 18:30 Gartner: AI agents outpacing governance 8-to-1, $234B at risk 26:00 Rapid takeaways you can use Monday morning🔗 STORIES WE COVEREDCISA urges immediate SharePoint patching: https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-sharepoint-vulnerabilities/CISA SharePoint hardening alert: https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitationsCraneware breach (TechCrunch): https://techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/Gartner: agentic AI puts $234B at risk (CIO): https://www.cio.com/article/4192242/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says.htmlGartner on tiered AI agent governance: https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure 🎓 LEVEL UP YOUR LEADERSHIP The Cybersecurity Growth platform is live — self-paced courses like "The First 100 Days of a CISO," program-building templates, and a community of global cyber leaders. Courses count toward CPEs (CISSP and more). Free trials at https://CybersecurityGrowth.com📬 CONNECTSubscribe on YouTube + hit the bellListen on your favorite podcast appShorts on TikTokLive every other week on Twitch + YouTube New episodes every 2 weeks. Thanks for growing with us.#Cybersecurity #CISO #Leadership #AISecurity #SharePoint #ThirdPartyRisk #AIGovernance #CyberLeadershipSHOW NOTES Patch Now, Govern FasterSharePoint under fire (3:30). Four SharePoint CVEs are being actively exploited, including an unauthenticated RCE, and CISA gave federal agencies just 3 days to patch. Attackers are chaining bugs to steal IIS machine keys and persist — meaning patching alone won't evict them; key rotation is required. We debate the real leadership call: emergency weekend change window vs. normal change control, and whether on-prem SharePoint should exist in your environment at all in 2026.The vendor blast radius problem (11:00). Craneware — billing software behind ~2,000 US hospitals and ~10,000 clinics and pharmacies — confirmed attackers exfiltrated a significant volume of data. Same week, Hugging Face disclosed a malicious-dataset attack that stole credentials off its infrastructure. Two supply-chain intrusions in one news cycle is a pattern. We dig into what a real vendor-breach playbook looks like, and how much disclosure — and how fast — you should demand from critical vendors.The AI agent governance gap (18:30). Gartner says AI agents are entering production 7–8x faster than orgs are building governance, with $234B in enterprise software spend at risk by 2030 and 40%+ of agentic AI projects predicted to be canceled by 2027. Their contrarian take: uniform governance across all agents guarantees failure — tier it by autonomy and risk. The real question is organizational, not technical: who owns agent identity and authorization at your company?Monday-morning takeaways (26:00). Ask your team: do we run on-prem SharePoint anywhere, and which critical vendors have breach-notification SLAs in their contracts? Then start an AI agent inventory — even a spreadsheet of what agents exist, what they can touch, and who approved them puts you ahead of most orgs.Hosted by Shawn Valle (Founder & Chief Strategist, Cybersecurity Growth) and Garrett Gross. Learn more at https://CybersecurityGrowth.com