It took 103 seconds.
That's how long a Claude Code agent reportedly needed to wipe out 48,218 live project files and destroy a developer's local Git object store—while working on a task it had been explicitly told to keep away from the originals.
The developer had asked the agent to repair software used to analyze historical stock options data, work only on copies, and leave the working files alone. According to the developer's since-deleted Reddit post and the agent's own incident write-up, as reported by TechRadar, a cleanup script written while rebuilding a test "mirror" treated Windows directory junctions as ordinary folders, followed them into the live tree, and deleted roughly 55,550 files. About 7,300 were supposed to go. The rest were the real project. Then the agent flagged its own mistake: "I broke something."
The details remain user-reported and haven't been independently confirmed. But the shape of the failure is instantly familiar to anyone who has run a security program: a control that existed only as an instruction, a system that behaved differently than everyone assumed, and no hard boundary to stop the damage once it started.
That's a fitting way to open October, now in its 23rd year as Cybersecurity Awareness Month.
Two themes, one message
This year's campaign, co-led as always by U.S. CISA and the National Cybersecurity Alliance (NCA), runs on two tracks.
CISA's theme, "Securing the Next 250," ties cyber resilience to America's 250th anniversary and aims squarely at critical infrastructure. The agency is pushing owners and operators to practice what it calls the 3Rs: Reduce, Replace, Recover—shrink the attack surface by patching and prioritizing, replace end-of-support technology before it becomes the easiest way in, and build operations that can keep running and recover quickly after a successful attack.
CISA's framing of the threat is blunt. The landscape isn't fundamentally changing, the agency argues—it's scaling. By the end of August 2026, the total number of published CVEs had already exceeded all of 2025, and AI is accelerating both vulnerability discovery and mass exploitation. CISA's answer is to "patch smarter, not harder," prioritizing flaws in the Known Exploited Vulnerabilities (KEV) Catalog and following its directive guidance on end-of-support edge devices (BOD 26-02).
[RELATED: CISA's KEV Nomination Form Weaponizes Community Intelligence]
The NCA's consumer and workforce theme, "Don't Make It Easy for Them," sticks with four fundamentals: strong passwords and a password manager, multifactor authentication (MFA), recognizing and reporting scams, and keeping software updated. Small habits, repeated consistently.
Read together, the two themes say the same thing from opposite ends of the stack: attackers don't need to be brilliant when defenders are predictable, exposed, or untested.
The confidence gap is the real vulnerability
Nowhere is that clearer than in the NCA's 2026 Small Business Cybersecurity Awareness & Practices Survey, developed with CISA and based on responses from 1,000 SMB leaders across 10 industries.
The headline finding: confidence is running well ahead of capability.
-
56.1% of SMBs could not confirm a clean security record over the past year—50.5% reported a confirmed or suspected incident, and another 5.6% simply didn't know.
-
Yet 86.3% rate their confidence in managing cyber risk as medium to very high, and 58.8% say they're highly confident they could recover quickly from a day-plus outage.
-
86.8% have deployed MFA, but only 51.1% require it across all key business accounts.
-
88.4% have backups, but only 61.4% have ever tested them.
-
87.3% are using AI tools, but only 45.6% have formal guidelines governing that use.
The pattern isn't underinvestment. It's under-operationalization: tools purchased, practices never enforced, tested, or documented. And it's not just a small-business problem. The same gap—"we have MFA" versus "we are protected"—shows up at every size of organization, just with more zeros attached.
The broader breach data point the same direction. Verizon's 2026 Data Breach Investigations Report, as cited this week by IntelliGRC, found that 31% of breaches now begin with vulnerability exploitation—overtaking stolen credentials for the first time—and 48% involved a third party.
Agents don't follow scripts. Environments have to
Which brings us back to the 48,000 files. The incident landed in the middle of an industry-wide scramble to govern agentic AI, and several practitioners argue it exposes a design flaw in how many organizations think about oversight.
"Incidents like this show that the current concept of 'human-in-the-loop' is too simplistic," said Greg Qualls, Senior Director at Upsun. "It's not enough to add a human reviewer somewhere within a complex process and assume that makes an AI agent secure. Some processes need no intervention, while others need much stronger checks. Fixing a typo and deleting thousands of files clearly don't carry the same level of risk, so oversight shouldn't be the same either."
For Qualls, the most telling detail was the instruction the agent was given—and ignored in effect.
"The agent was told to leave the original working files alone. That's the heart of the problem," he said. "An instruction in a prompt works as a strong suggestion, not a control. If there's something an agent must never do, telling it isn't enough. The environment it runs in has to make that action impossible, or at least reversible."
His prescription is as much infrastructure as AI: "Give agents more freedom as they prove they can handle it, and put hard technical limits around the actions that carry real consequences."
Diana Kelley, CISO at Noma Security, makes the same case from an architecture angle. "We need to stop thinking about AI agents as if they were people. They are software systems: models combined with code, permissions, tools, data, and network access," she said. "The more useful questions are architectural: What can this software reach? What can it change? What constrains it? And what happens when it is wrong?"
Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint, says enterprise controls need to catch up fast. AvePoint's own research found that 88% of organizations experienced an agent-related security incident in the past year. "Security teams need to treat every agent as a non-human identity with an owner, scoped credentials, explicit tool permissions, network egress limits, and policy enforcement outside the model," she said—along with tested ability to "revoke tokens, quarantine an agent, terminate queued actions, and restore affected data and configurations to a known-good state."
The visibility problem may be even more basic. According to the 2026 Pathlock AI Governance Gap Report, 51% of organizations aren't confident they know about all the AI agents operating in their systems, and 31% are unsure whether AI-related incidents have occurred at all. "Organizations need continuous visibility into which human and non-human identities have access, what actions they perform, and whether those actions are appropriate within their business context," said Chris Radkowski, Security and Risk Expert at Pathlock.
That's an identity problem at its core, notes Michael Marino, SVP of Strategy at Keeper Security: "Non-human identities and AI agents are creating privileged access at a scale that security teams cannot manage manually." His answer is the modern PAM playbook—least privilege, just-in-time access, and zero standing privilege.
And when AI writes and reviews the same code, warns Dom Glavach, CISO at Black Duck, "the two systems can share the same blind spot." Pairing AI-driven analysis with deterministic testing, he argues, provides "the perspective diversity necessary to close these gaps."
The basics got faster, not obsolete
If AI is the headline, the fundamentals are still the story. Several experts argue AI hasn't made basic hygiene less important—it's made neglect more expensive, faster.
"Many successful attacks don't start with a highly sophisticated technique. They start with an opportunity we've left open," said Victoria Dimmick, CEO of Titania. Unpatched vulnerabilities, unnecessary internet routes, overly permissive rules, and "temporary" exceptions that never expire all add up—and configurations drift. "A policy that was correct six months ago does not tell you whether your network is secure today," she said. "Verify it. Don't assume it."
Kevin Greene, Chief Cybersecurity Technologist, Public Sector, at BeyondTrust, puts end-of-life technology at the center of the problem—exactly where CISA's Replace pillar points. "End-of-support doesn't mean broken. It means no more security patches to close attack vectors," he said, citing the FBI's takedown of the Volt Typhoon botnet built from end-of-life routers that Chinese state actors used to preposition inside U.S. water, energy, and transportation networks. "Resiliency is decided before the attack, not after."
On the human side, the threat has outgrown the break room poster. "A phishing email can now be generated in seconds, written for one employee by name, and sent at a scale no scammer could manage by hand," said Brian Long, CEO and co-founder of Adaptive Security. "Phone calls can carry a cloned voice, and video calls a cloned face." He recommends running Cybersecurity Awareness Month as four weekly habits—passwords, voice and video verification, fully automated attacks, and approved AI tool use. "This October, let's swap the poster for a habit."
And much of that phishing is landing on phones. Zimperium's 2026 Global Mobile Threat Report found phishing events on employee mobile devices grew 380% since January 2025. "Employees need clear ways to verify and report suspicious requests, and security teams need the ability to detect threats on the mobile devices and apps where those requests are received," said Kern Smith, VP of Global Solutions Engineering at Zimperium.
Assume breach, then prove recovery
CISA's third R—Recover—may be the one most organizations are least prepared to demonstrate. The NCA survey found that breached organizations are far more likely to have a documented, followed incident response plan (74.9%) than those that haven't been hit (51.5%). Preparedness, in other words, is still mostly learned the hard way.
"Nearly every organization that ends up calling an incident response firm had locks," said Jeremiah Clark, CTO at Fenix24. "Prevention is a probability game, and eventually the dice come up wrong." His test is simple and uncomfortable: "A green backup job isn't assurance. A completed restore and a working login is." His one ask for October: "Pick the three systems the business can't live without and actually restore them. End to end. Timed. Whatever breaks is the real plan."
Agnidipta Sarkar, Chief Evangelist at ColorTokens, wants boards to change the question entirely. "'Are we secure?' is a comforting question with no useful answer," he said. The better one: "When, not if, we are breached, how much of our business will keep running?" He urges boards to define a Maximum Acceptable Material Impact—the worst disruption the enterprise can absorb—and the minimum set of capabilities that must stay unaffected. "Resilience is not how fast you rebuild; it is how little you have to."
Inside the network, Ram Varadarajan, CEO at Acalvio, notes that AI is compressing post-compromise reconnaissance too, helping intruders decide what to probe next with less human direction. Deception—planted credentials and decoy servers that trigger high-fidelity alerts—gives defenders a way to shape those decisions. "An attacker may find a way to gain access, but deception makes sure they can't trust what they find once they're in."
"Securing the Next 250" invites a longer time horizon, and two experts point to a threat that's already collecting interest.
"No quantum computer can do this yet, but the resource estimates keep shrinking," said Fredrik Forlund, VP & GM at Blancco, noting that CISA, NSA, and NIST have warned that "harvest now, decrypt later" collection is already underway. "This year's Cybersecurity Awareness Month should be a reminder that no single security control is ever permanent or sufficient on its own."
Forlund's hedge is one of the most underused controls in security: data sanitization. "By permanently and verifiably removing data that's no longer needed, including redundant, obsolete, or trivial information, organizations shrink the pool of sensitive data sitting exposed and reduce their attack surface," he said. "Less data retained means less to lose if encryption ever gives way."
Jason Soroko, Senior Fellow at Sectigo, cautions that post-quantum migration won't be a single project. "Quantum readiness isn't a switch you flip overnight. It's a continuous, uneven migration across every system an organization owns," he said. Inventory comes first, but context—which cryptographic assets support critical systems—is what lets teams prioritize and build crypto agility.
Pull the threads together, and a practical agenda emerges for security leaders.
-
Put hard limits on agents – Inventory every AI agent, treat each as a non-human identity with an owner and scoped permissions, and enforce "never do this" rules in the environment—sandboxes, least privilege, dry runs, reversible actions—not in the prompt.
-
Scale oversight to risk – Reserve human approval for high-impact, hard-to-reverse actions instead of sprinkling reviewers across every workflow.
-
Close the enforcement gap – Require MFA everywhere, not "some" accounts. Turn deployed tools into enforced, monitored practices.
-
Retire what's unsupported – Map end-of-life devices, especially internet-facing edge gear, and prioritize KEV-listed flaws.
-
Test recovery, don't assume it – Restore your three most critical systems end to end, timed. Write—or update—an incident response plan before you need it.
-
Shrink the data footprint – Sanitize what you don't need, and start a cryptographic inventory for post-quantum planning.
-
Make awareness a habit – Weekly, practical training on AI-powered phishing, voice and video impersonation, and approved AI tool use.
The 48,000-file incident wasn't a sophisticated attack. It was a trusted system doing something everyone assumed it wouldn't—at machine speed, with nothing in the environment to stop it. That's the throughline of this year's Cybersecurity Awareness Month, whether the subject is AI agents, MFA coverage, end-of-life routers, or backups nobody has ever restored.
The 3Rs, the four habits, the board-level resilience questions—they all come back to the same discipline Victoria Dimmick summed up in four words: Verify it. Don't assume it.
~~~
Want to dig deeper into SMB security, AI governance, and resilience with practitioners who are doing the work? Join us at an upcoming SecureWorld conference this fall.
[RELATED: The Security Champion Playbook Is Changing]

