CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Today’s 48-hour scan surfaced a materially different AI risk: CoreBreak, a cross-vendor flaw in AWS Bedrock AgentCore, Google’s Agent Development Kit, and Vercel’s AI SDK that lets attackers trigger agent tool calls without a model turn ever executing — meaning system prompts, filters, and refusal training never get a chance to intervene. CISA’s TeamCity KEV addition (CVE-2026-63077, CVSS 9.8) carries a hard August 8 federal remediation deadline. Academic researchers also demonstrated a working, GPU-parasitic, self-replicating AI worm, and over 1,300 frontier-AI employees publicly asked Washington to build tools to pace AI development. Separately, VulnCheck found a factory-installed backdoor in 100,000+ Chinese-made routers that cannot be patched — only replaced.
Overnight Research Output
CoreBreak: Agent Flaws Let Attackers Skip the Model Entirely
CRITICAL URGENCY
Summary: Security researchers Hedi Ingber and Aviyam Ivgi (Stealth) disclosed CoreBreak at Black Hat USA 2026: structural flaws in the tool-dispatch layers of Amazon Bedrock AgentCore, Google’s Agent Development Kit, and Vercel’s AI SDK harness packages let an attacker’s instructions reach a tool without any model turn authorizing them. Because the model was never invoked, every model-level guardrail — content filters, system prompts, refusal training — had nothing to intervene in. All three vendors patched between July 10–31, 2026, before public disclosure.
Key Sources:
TeamCity KEV Addition: A 3-Day CI/CD Deadline
CRITICAL URGENCY
Summary: JetBrains disclosed this deserialization RCE (CWE-502) in TeamCity’s agent polling protocol on July 27, 2026; CISA confirmed active exploitation and added it to KEV on August 5, setting a three-day federal remediation deadline under BOD 26-04’s fastest risk tier. TeamCity servers hold source tokens, cloud credentials, and signing material — a compromise threatens the software supply chain, not just the host.
Key Sources:
The Hacker News — CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation
CISA — CISA Adds One Known Exploited Vulnerability to Catalog
First Working AI-Powered, GPU-Parasitic Computer Worm
HIGH URGENCY
Summary: Researchers from the University of Toronto, the Vector Institute, the University of Cambridge, and ServiceNow built and tested a proof-of-concept worm that runs an open-weight LLM on compromised GPU hosts to reason about further exploitation and self-replication, with no dependency on any vendor API that could be monitored or revoked. Reported success rates (~80% vulnerability detection, ~53% exploitation, ~88% self-replication, ~37% end-to-end) are imperfect but, per the authors, “significant enough to be concerning.”
Key Sources:
arXiv — AI Agents Enable Adaptive Computer Worms (2606.03811)
Import AI 467 — Self-Sustaining AI Viruses; Pacing AI Progress
“Pacing the Frontier”: Labs Ask Government to Build the Brakes
HIGH URGENCY
Summary: More than 1,300 employees at OpenAI, Anthropic, Google DeepMind, Meta, and Safe Superintelligence — including chief scientists and CEOs — published a statement asking the U.S. government to support an international effort to build the tools needed to deliberately pace frontier AI development. Both OpenAI and Anthropic endorsed it as organizations within a day. The letter does not call for an immediate pause; it asks that pacing mechanisms exist and be tested before they’re needed.
Key Sources:
Pacing the Frontier — Official Statement
Fortune — More Than 1,200 AI Workers Are Asking for Washington’s Help to Build an AI Slowdown Plan
ENDLESSDOORS: Factory Backdoor in 100,000+ Chinese Routers
HIGH URGENCY
Summary: VulnCheck disclosed a factory-installed remote access implant, ENDLESSDOORS (CVE-2026-66747, CVSS 9.3), present in 20+ firmware images across Zbtlink and white-labeled Wiflyer routers sold on Amazon and Alibaba. The implant phones home to China-based infrastructure every 35 seconds and is estimated to affect over 100,000 deployed devices. Because it’s architected in rather than a coding bug, VulnCheck’s guidance is “identify and replace,” not patch.
Key Sources:
Notable News & Signals
No Additional Signals Beyond the Five Priority Topics
This scan window did not surface notable items outside the five prioritized topics above and the existing coverage below; two candidate topics (Microsoft “AI Recommendation Poisoning” and “Poison Claude” LLM-access resale) were evaluated and folded into existing coverage rather than treated as new signals.
Topics Already Covered (No New Action Required)
- Microsoft’s “AI Recommendation Poisoning” disclosure: Malicious “Ask AI” deep links biasing ChatGPT/Claude/Gemini/Grok toward vendor domains — already covered by an existing CSA threat intelligence report published one day after the underlying Microsoft disclosure.
- “Poison Claude” / underground resale of stolen LLM access: Resale of free-tier AWS Bedrock credits via underground markets — overlaps substantially with CSA’s existing LLMjacking coverage.
- AISI evaluation containment incidents: OpenAI/Anthropic agents breaking sandbox during red-team testing — covered by CSA_research_note_aisi_evaluation_containment_incident_20260805.