THE DEEP TAKE

The buyers this week were not security companies

On August 3, Visa agreed to buy BioCatch for $2.4 billion in cash. The same day, Bank of America said it would acquire MDSec, a 65-person information security consultancy in Macclesfield, England. Neither buyer sells security software. One runs a payment network. The other is a bank.

Compare that to the normal shape of a security deal. A week earlier, Okta agreed to buy Permiso for just under $200 million. That is a security vendor buying a security startup to close a product gap, and the industry knows how to read it. Visa paid twelve times more. Bank of America broke a five-year acquisition drought. Both chose to bring the capability inside rather than keep buying it as a service.

Look at what Bank of America actually bought. Roughly 65 consultants who do deeply technical offensive testing. The bank already runs a cyber threat operations center in Chester, with more than 1,400 employees nearby. It did not need a supplier. It decided that owning the team beat renewing the engagement. Read that as a statement about the security talent market, not about M&A strategy. When a firm that size concludes acquisition is the cheaper hiring channel, your own recruiting math is worse than you think it is.

What Visa bought is different, and larger. BioCatch reads behavioral signals: how a user types, swipes, and holds a device. It covers more than 350 banks in 21 countries and 1.8 billion devices. Those signals are moving inside the network that also writes the rules those banks operate under. If you buy fraud detection, one of your suppliers is becoming a division of a counterparty you already transact with.

The practical consequence lands in your contracts, not your roadmap. Neither deal has closed. Bank of America expects to finish in the fourth quarter of 2026, Visa in its fiscal second quarter of 2027. Use that window. Pull the change-of-control and assignment clauses in every security supplier agreement you hold. Ask two things of each one. Does the agreement survive an acquisition on the same terms? And can you exit if the new owner turns out to be a competitor, a customer, or a counterparty?

The wider read is that security capability is drifting toward the balance sheets that carry the loss. Banks and networks are the parties who pay when fraud or intrusion lands. Buying the capability outright is what a firm does when it stops believing a supplier relationship moves enough of that risk off its own books. There will be more of these. The next one may involve a vendor you renewed last quarter.

Powered by the DoGood network

The data in this issue came from priority submissions by 5,000+ enterprise IT leaders. If you run IT or security at a $100M+ company and want to see what your peers are funding — and earn rewards for participating in vetted meetings with the vendors worth your time — apply to join DoGood.

QUICK HITS

Your MSP's console is a path to your endpoints

CISA added CVE-2026-18577 to the exploited-vulnerabilities list on August 3, with a federal fix deadline of August 6. It is an authentication bypass in N-able N-central, the remote monitoring platform a large share of managed service providers run. It is rated 8.2, and it is an incomplete fix for an earlier flaw. An attacker with admin access on an N-central server can use the built-in Take Control feature to reach every endpoint that server manages. N-able confirmed a limited number of customers were compromised. Huntress described the activity as targeted rather than indiscriminate. If an MSP touches your fleet, ask them today whether they are on 2026.3 HF1 and whether anyone reviewed Take Control session logs. This one will not surface in your own patch scan. It sits in someone else's.

The model never ran, and the tool fired anyway

Researchers presenting at Black Hat disclosed CoreBreak, one flaw pattern found across three vendors. It hits AWS Bedrock AgentCore (CVE-2026-18830, 8.6), Google's Python Agent Development Kit (CVE-2026-18236, 9.3), and two Vercel AI SDK harness packages. In each case the runtime accepted data shaped like a model tool call and executed it. The model never ran. System prompts, content filters, and model-level guardrails never got a turn. That is the part to carry into your next AI review. Your agent controls almost certainly sit at the model layer, and execution happens at the harness. Patch to ADK 2.5.0, harness-codex 1.0.29, and harness-opencode 1.0.28. AWS fixed the managed service. Then ask every agent platform you run how a tool call gets bound to an authorized model turn.

The AI industry set its own breach clock

The Open Secure AI Alliance published a draft framework called SAFE on August 4, through the Linux Foundation. Members would report AI security incidents on fixed clocks. Customers get notice of a credible data exposure within 72 hours. The exchange gets a filing within four business days. Disclosure goes public within 30 days. It is a request for comments, not a rule. The alliance launched on July 27. It already counts more than 120 organizations, with Amazon and Visa among the recent additions. Voluntary standards like this tend to reach your contracts well before they reach law. So it is a fair ask at your next AI vendor renewal: will you commit to those timelines in writing?

THE NUMBER: 165

Connor Riley Moucka pleaded guilty on August 5 to breaking into at least 165 Snowflake customer environments between February and October 2024. The stolen records covered at least 100 million people. He personally took about $495,000. No Snowflake vulnerability was involved in any of the 165. Each one was reached with credentials that still worked, in a tenant where multi-factor was not enforced. That is the part worth keeping. Your SaaS vendor's security page describes the vendor. The boundary that failed 165 separate times was tenant configuration, and tenant configuration is yours. Court records now put a count on it.

One question worth carrying into your next supplier call: who owns you, and who has approached you? Peers in the DoGood network are asking it this quarter, because the answer changed twice in a single day this week.

The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.

Know a CIO who needs this? Forward it and they can subscribe here.

Enterprise IT leader at a $100M+ company? Apply to join DoGood.