Hi,
While Big Tech has soared, some investors are pivoting to real assets – like energy infrastructure and clean tech.
Our latest report highlights four energy transition stocks that may benefit from this shift in investor sentiment.
Click below to see the report:
Find out how these four companies fit into the bigger story of asset rotation and sustainability.
– The Cheap Investor
AI Agents Hit 395 Orgs. Good News for CrowdStrike?
On August 31, a single threat actor compromised eleven organizations in twenty-six seconds. The campaign achieved remote code execution in under four hours, domain admin access in six hours, and compromised 11 organizations in 26 seconds once launched. This was not a nation-state with a nine-figure budget. It was one person with a laptop, an API key, and a swarm of autonomous AI agents.
GreyNoise says the campaign began on August 31, combining OpenAI Codex and DeepSeek models with commodity offensive tools. The agents were tasked with building, testing, and refining exploits for CVE-2026-81578 and CVE-2026-82078, both security flaws affecting PaperCut Software and publicly reported as actively exploited in late August. PaperCut issued emergency patches on August 28, at the time warning that it was “aware of confirmed customer incidents” and was treating the matter with the highest priority. The attacker was already inside at least 395 organizations three days later. Credentials were harvested from 280 victims, operating system or domain secrets from 147, and administrator privileges were obtained at 12 organizations. Most of the victims were in education, accounting for just over half of identified victim organizations.
The Bull Case
The argument for owning CrowdStrike, Palo Alto Networks, and Zscaler here practically writes itself. The compression of what would once have required a specialist team into the equivalent of a single person’s afternoon is not a forecast: it is a measured, documented event with a timestamp. That is exactly the kind of event that moves enterprise security budgets.
CrowdStrike’s net new annual recurring revenue rose 32% year over year in the first quarter of fiscal 2027, and AI Detection and Response has emerged as an important new growth area, with ending ARR growing more than 250% sequentially. The PaperCut campaign is the kind of incident that validates every line of that pitch. CrowdStrike introduced Falcon Guardian at Fal.Con on September 1, an AI Detection and Response solution delivering runtime enforcement from the endpoint where AI agents execute. What CrowdStrike has publicly said is that Falcon Guardian brings visibility and runtime enforcement for AI agents; the company has not, in its own product materials, limited the claim to OpenAI Codex agents specifically.
Verizon’s 2026 Data Breach Investigations Report found vulnerability exploitation is now the number one initial breach vector, at 31% of breaches, up 55% year over year. Median time to full patching rose to 43 days, up from 32 in 2025, while full remediation of CISA’s Known Exploited Vulnerabilities catalog dropped from 38% to 26% in a single year. Patching is getting slower as the attack surface grows faster. That is a structural demand driver, not a one-quarter event.
The Bear Case
The counter-argument is older than AI and has beaten the bulls before: fear spikes, budgets shift, patches ship, and security spending normalizes. PaperCut sent emergency patches on August 28. Every organization still unpatched a week later made a choice, not because no product existed to help them, but because they had not yet deployed what they owned.
A 2026 Arkose Labs report based on a global survey of 300 enterprise leaders found 97% expect a material AI-agent-driven incident within the next 12 months, and nearly half expect one within six months. Yet only 6% of security budgets are currently allocated to this risk. That gap is real, and CrowdStrike, Palo Alto and Zscaler will try to close it. But closing it requires customers to buy new products, integrate them, and keep paying for them. Each of those steps is a place the churn rate rises.
Agents are entering production faster than organizations are building governance around them, which means the addressable market for AI security is genuine. What is less clear is whether the margin profile of selling runtime agent security at scale looks like endpoint detection, or whether the competitive intensity from Microsoft’s bundled security stack compresses pricing before the category matures. AI has a dual impact: attackers use it to accelerate vulnerability discovery and automate attacks, while defenders use it to detect anomalies and respond faster. Both sides of that sentence are product pitches from the same vendors.
Where the Evidence Leads
The PaperCut campaign is a category-defining data point, not because 395 breaches is an extreme number historically, but because of what it proves about cost and skill thresholds. Reporting on GreyNoise’s findings described the attacker using a DeepSeek model in an OpenAI Codex harness, supported by persistent memory and orchestration tooling, to run hundreds of autonomous agents. The upfront investment was minimal. The output was industrial.
That changes the risk calculus for enterprises in a way that generic AI threat warnings have not. The bear case rests on patching catching up and budgets normalizing. With median patching time now at 43 days and rising, catching up looks harder than it did in 2023. The bull case is better supported today than it was seventy-two hours ago. The watch item is whether Falcon Guardian and comparable products from Palo Alto and Zscaler can demonstrate measurable detection rates against agentic campaigns quickly enough to lock in multi-year contracts before the news cycle moves on.
The evidence leans bullish on structural demand. It is agnostic on which platform captures the most of it.
