CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Three independently confirmed active-exploitation events anchor this cycle: attackers are chaining three JFrog Artifactory authentication flaws into full administrative takeover of build-pipeline infrastructure, and the Dutch NCSC has issued a rare pre-exploitation warning that two critical Check Point VPN flaws (CVSS 9.8) face imminent exploitation. Mandiant separately disclosed a new supply-chain vector in which an attacker hijacked an active AI coding-assistant session to spread the Shai-Hulud worm across roughly 100 repositories. On the governance side, the EU’s Cyber Resilience Act reporting obligations are now legally binding, backed by a reporting platform that launched with no API support. Separately, Cisco Talos found Qilin ransomware operators using AI-generated attack scripts against Japanese SMEs, a pattern with implications well beyond Japan.
Overnight Research Output
Three JFrog Artifactory Flaws Chained for In-the-Wild Admin Takeover
CRITICAL
Summary: Wiz Research documented sustained in-the-wild exploitation of three Artifactory vulnerabilities (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329) between August 15 and September 8, 2026, with attackers converting unauthenticated access into full admin control in as few as two HTTP requests. Once inside, attackers deployed layered malicious Groovy plugins, a custom Rust-based backdoor, and persistent rogue administrator accounts. CISA added the most severe flaw to its Known Exploited Vulnerabilities catalog on September 2 with a 3-day federal remediation deadline. Six weeks after disclosure, 49-62% of internet-reachable instances remain vulnerable, and patching alone does not remove attacker-planted backdoors or stolen credentials.
Key Sources:
Wiz Research — Artifactory Under Attack: In-the-Wild Exploitation
The Hacker News — Attackers Chain JFrog Artifactory Flaws to Gain Admin Control
Dutch NCSC Warns Exploitation of Critical Check Point VPN Flaws Is Imminent
CRITICAL
Summary: Check Point patched two unauthenticated, pre-authentication remote-code-execution flaws (CVE-2026-85102, CVE-2026-85103, both CVSS 9.8) in VPN certificate-handling code affecting Quantum Security Gateways, Security Management Servers, and Spark Firewalls. Check Point found no evidence of exploitation at disclosure, but the Dutch NCSC issued a formal advisory the next day assessing both likelihood and impact as high and warning that large-scale exploitation is expected soon. This is a genuine pre-exploitation patch window rather than a post-mortem — a rare and valuable head start for defenders on a top ransomware initial-access vector.
Key Sources:
Mandiant: Attacker Hijacks AI Coding-Assistant Session, Spreads Shai-Hulud Worm
HIGH
Summary: Mandiant’s AI Risk and Resilience Report 2026 discloses an intrusion at an unnamed SaaS provider in which an attacker hijacked a developer’s active AI coding-assistant session, used it to recommend an already-poisoned package, then stole GitHub OAuth tokens and spread the self-propagating Shai-Hulud worm across roughly 100 internal repositories. A second employee was infected when the worm republished a poisoned package inside the company’s own npm namespace. Mandiant does not disclose how the attacker gained control of the session in the first place, leaving initial access as the case study’s central open question.
Key Sources:
ENISA Launches EU Cyber Resilience Act Single Reporting Platform
HIGH
Summary: ENISA switched on the Cyber Resilience Act’s Single Reporting Platform on September 11, 2026, the same day the CRA’s vulnerability and incident reporting obligations became legally binding on any manufacturer selling digital products into the EU. Reports must move through a national CSIRT under strict 24-hour early-warning, 72-hour assessment, and 14-day final-report deadlines, with fines reaching €15 million or 2.5% of global turnover for non-compliance. The platform launched supporting only manual web-form submission, with no API access — a compressed and imperfect rollout that mirrors the readiness gap CSA has already documented among European manufacturers.
Key Sources:
Cisco Talos: Japan’s H1 2026 Ransomware Surge Concentrated on SMEs, Qilin Uses AI Scripts
MEDIUM
Summary: Cisco Talos recorded 90 ransomware incidents in Japan across H1 2026, up 4.7% year-over-year, with organizations capitalized under JPY 1 billion accounting for 78% of victims (up from 69% a year earlier). The ransomware-as-a-service landscape turned over almost completely, with newcomer The Gentlemen leading incident counts. Most notably, Talos assessed with medium-to-high confidence that Python scripts recovered from a Qilin-linked open directory — built to destroy Active Directory infrastructure and disable Veeam backups — were generated with LLM assistance, based on documentation-style comments and redundant logging.
Key Sources:
Topics Already Covered (No New Action Required)
- Cisco Secure Email Gateway RCE: Covered by a research note published 2026-09-18 in the prior scan cycle.
- Cisco FMC / Qilin Exploit Chain: Covered by a research note published 2026-09-18; distinct from today’s Talos Japan SME/AI-tooling trend story.
- Google Pixel Modem Zero-Day: Covered by a research note published 2026-09-18 in the prior scan cycle.
- EU AI Act Slowdown (von der Leyen): Covered by a research note published 2026-09-18; distinct from today’s CRA reporting-platform story.
- China AI-Distillation Campaign: Covered by a research note published 2026-09-18 in the prior scan cycle.
- Cisco ISE Authentication Bypass (CVE-2026-76460): Covered by a research note published 2026-09-17.
- BragJack Agentic Browser Monoculture: Covered by a research note published 2026-09-17.
- FamousSparrow / SparrowOcky Backdoor: Covered by a research note published 2026-09-17.
- OpenAI’s Misalignment Reporting Framework: Covered by a research note published 2026-09-17.