
Sign up to save your podcasts
Or


In this episode of IT SPARC Cast – CVE of the Week, John and Lou discuss the first fully autonomous AI-driven ransomware attack ever documented. Researchers observed an AI agent independently executing an entire ransomware campaign—from credential harvesting and privilege escalation to encrypting production systems and adapting to failures in real time.
They also examine a new wave of critical UniFi security patches and explain why automatic patching is quickly becoming a necessity rather than a convenience. As AI accelerates both attacks and defenses, organizations must rethink how they approach patch management, Zero Trust, and cyber resilience.
⸻
📄 Show Notes
🚨 CVE of the Week
First Fully Agentic Ransomware Attack Raises New Security Concerns
Researchers have documented what appears to be the first fully autonomous AI-powered ransomware attack. After receiving initial access from a human operator, the AI independently:
The attack relied on known vulnerabilities, reinforcing the importance of rapid patching, strong identity controls, credential protection, and Zero Trust architectures. As AI becomes more capable, organizations should expect increasingly automated attacks that can operate at massive scale.
https://www.techtarget.com/searchsecurity/news/366645613/First-fully-agentic-ransomware-attack-sparks-readiness-concerns
⸻
Ubiquiti Releases 25 Security Fixes, Including Seven Critical Vulnerabilities
Ubiquiti has released patches for 25 security vulnerabilities, including seven critical flaws rated between 9.1 and 10.0 CVSS, affecting UniFi networking, Protect, Identity, access control, and related products.
If automatic updates were enabled, many systems were protected before administrators even learned about the vulnerabilities. The discussion highlights why waiting weeks for maintenance windows is no longer practical. AI-assisted attacks can weaponize newly disclosed vulnerabilities far faster than traditional patch cycles.
Recommended actions:
https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.html
⸻
💬 Mail Bag
Listener Blake shared that he has chosen not to deploy AI agents because of security concerns.
John and Lou discuss the balance organizations must strike between security and productivity. While AI introduces new risks, avoiding it entirely may also create competitive disadvantages. The key is deploying AI responsibly with appropriate safeguards and human oversight.
⸻
📣 Wrap Up
We’d love to hear your thoughts.
Are your patching policies ready for AI-powered attacks? Is continuous patching becoming unavoidable?
Follow IT SPARC Cast
IT SPARC Cast
@ITSPARCCast on X
https://www.linkedin.com/company/sparc-sales/ on LinkedIn
John Barger
@john_Video on X
https://www.linkedin.com/in/johnbarger/ on LinkedIn
Lou Schmidt
@loudoggeek on X
https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn
Hosted on Acast. See acast.com/privacy for more information.
By John BargerIn this episode of IT SPARC Cast – CVE of the Week, John and Lou discuss the first fully autonomous AI-driven ransomware attack ever documented. Researchers observed an AI agent independently executing an entire ransomware campaign—from credential harvesting and privilege escalation to encrypting production systems and adapting to failures in real time.
They also examine a new wave of critical UniFi security patches and explain why automatic patching is quickly becoming a necessity rather than a convenience. As AI accelerates both attacks and defenses, organizations must rethink how they approach patch management, Zero Trust, and cyber resilience.
⸻
📄 Show Notes
🚨 CVE of the Week
First Fully Agentic Ransomware Attack Raises New Security Concerns
Researchers have documented what appears to be the first fully autonomous AI-powered ransomware attack. After receiving initial access from a human operator, the AI independently:
The attack relied on known vulnerabilities, reinforcing the importance of rapid patching, strong identity controls, credential protection, and Zero Trust architectures. As AI becomes more capable, organizations should expect increasingly automated attacks that can operate at massive scale.
https://www.techtarget.com/searchsecurity/news/366645613/First-fully-agentic-ransomware-attack-sparks-readiness-concerns
⸻
Ubiquiti Releases 25 Security Fixes, Including Seven Critical Vulnerabilities
Ubiquiti has released patches for 25 security vulnerabilities, including seven critical flaws rated between 9.1 and 10.0 CVSS, affecting UniFi networking, Protect, Identity, access control, and related products.
If automatic updates were enabled, many systems were protected before administrators even learned about the vulnerabilities. The discussion highlights why waiting weeks for maintenance windows is no longer practical. AI-assisted attacks can weaponize newly disclosed vulnerabilities far faster than traditional patch cycles.
Recommended actions:
https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.html
⸻
💬 Mail Bag
Listener Blake shared that he has chosen not to deploy AI agents because of security concerns.
John and Lou discuss the balance organizations must strike between security and productivity. While AI introduces new risks, avoiding it entirely may also create competitive disadvantages. The key is deploying AI responsibly with appropriate safeguards and human oversight.
⸻
📣 Wrap Up
We’d love to hear your thoughts.
Are your patching policies ready for AI-powered attacks? Is continuous patching becoming unavoidable?
Follow IT SPARC Cast
IT SPARC Cast
@ITSPARCCast on X
https://www.linkedin.com/company/sparc-sales/ on LinkedIn
John Barger
@john_Video on X
https://www.linkedin.com/in/johnbarger/ on LinkedIn
Lou Schmidt
@loudoggeek on X
https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn
Hosted on Acast. See acast.com/privacy for more information.