Security has a long tradition of arguing about the future in the abstract. On November 13, 2025, a piece of the future filed a report. Anthropic disclosed that it had detected and disrupted what it assessed as the first large-scale cyber-espionage campaign in which an AI agent — its own Claude Code, manipulated through jailbreaks — performed the bulk of the operational work. A group the company attributed to the Chinese state had pointed the agent at roughly thirty targets: tech firms, banks, chemical companies, government agencies. The humans chose the victims and made a handful of key decisions; the machine did most of the rest — reconnaissance, exploit development, credential harvesting, data triage — at a pace and volume no human team could match.
The details invited scrutiny, and got it. Researchers noted the campaign's modest success rate, the AI's tendency to overstate its own findings — hallucinated credentials, "discoveries" that were public information — and the fact that the disclosure doubled as a demonstration of the vendor's visibility. All fair. And all of it slightly beside the point. What November established was the shape of the thing: intrusion work, the expensive human bottleneck that had always rate-limited espionage, could now be delegated in large part to software that anyone can rent. The defenders' consolation — that the same agents are equally tireless at finding and fixing flaws — set up the arms race that would define the conversation into 2026.
It was fitting, in a month about machine speed, that the internet's worst outage was also self-inflicted at machine speed.
The config file that silenced the web
On November 18, a permissions change deep in Cloudflare's systems caused a bot-management feature file to double in size, crash the software that routes a fifth of the web, and take X, ChatGPT, and thousands of other services down with it. For a company whose business is absorbing attacks, the painful irony was that its worst incident since 2019 wasn't one — early fears of a mega-DDoS dissolved into a post-mortem about a database query. Coming three weeks after AWS's stumble and two after Azure's, it completed an accidental trilogy: the month the internet's plumbing kept failing without any villain at all, and "resilience" stopped being a slideware word.
Gainsight, and the year of borrowed keys
Salesforce spent late November revoking access tokens for apps published by Gainsight after the ShinyHunters crews claimed yet another harvest of customer environments — the sequel to August's Salesloft Drift campaign, and the year's clearest pattern in miniature: don't breach the fortress, steal the keys a trusted app already holds. Add November's DoorDash breach disclosure and a fresh Fortinet FortiWeb exploit under active attack, and the month's quieter lesson read: your perimeter is now other people's OAuth grants.
DPDP gets its rulebook
On November 14, the government notified the Digital Personal Data Protection Rules, 2025 — the operating manual the 2023 Act had been waiting two years for. The phased clock started ticking: consent managers and government notice obligations first, with the heavy machinery — breach intimation, children's data verification, Significant Data Fiduciary duties — landing on an eighteen-month runway. For every Indian company that had filed "DPDP compliance" under someday, someday acquired a date. Our working checklist from the current edition exists because of this month.
⏳ Time capsule — November 2025
- Bitcoin slid below $85,000, giving back essentially all of 2025's gains barely six weeks after its record high.
- Google shipped Gemini 3 on November 18 — the same day the Cloudflare outage made half the internet unreachable, including much of the coverage of it.
- "Agentic" completed its journey from research paper to boardroom noun; every security vendor's roadmap suddenly contained an AI SOC analyst.
- In India, wedding season brought the usual seasonal surge of shaadi-themed UPI scams and fresh "digital arrest" advisories.
The month the debate changed tense
Everything November previewed became 2026's working agenda. AI-assisted intrusion moved from disclosure to expectation — the question in briefings shifted from "can this happen?" to "how much of the last campaign was automated?" — while defenders raced to field agents of their own. The borrowed-keys problem got a name on every audit checklist, as SaaS-to-SaaS token grants started being inventoried like the credentials they always were. And the outage trilogy did what a decade of resilience whitepapers couldn't: multi-region and multi-provider stopped being architecture-review luxuries and became procurement questions. India's DPDP runway, meanwhile, turned into the subcontinent's biggest compliance construction site — exactly on the schedule November set.