CISO Daily Briefing
ALT CISO BRIEFING
Cloud Security Alliance Intelligence Report
alt_ciso variant, but ALT-CISO-GOALS is 105 days old (stale-goals threshold: 30 days). Per the fallback instruction embedded in the generator prompt, this briefing uses the standard daily-briefing structure rather than the 17-section decision-support format, so it does not reflect genuine CISO-goals-driven customization today.
Executive Summary
Three fresh disclosures show AI agents becoming the attack surface rather than just the target: RatHat hands a live generative-AI assistant control of a compromised Android phone’s accessibility tree to drain bank accounts, BragJack lets one browser extension hijack the built-in AI agents of five major browsers, and two OpenAI Codex sandbox escapes show that “read-only” agentic coding sandboxes still leak to the host machine. Separately, a Sapio Research survey found 40% of large companies had an AI governance incident in the past year, most traced to workflows never redesigned for an AI actor. Most urgent: a corroborated report that an AI hallucination nearly triggered a US-China military boarding incident in spring 2026, landing just as the Pentagon pushes AI tools out to three million personnel.
Overnight Research Output
RatHat Puts a Live AI Agent in Control of Compromised Android Devices
CRITICAL URGENCY
Summary: RatHat, attributed to China-based operators and disclosed by Zimperium, converts an infected Android phone’s accessibility tree into XML and feeds it to a generative-AI assistant that decides in real time where to tap, scroll, and type — rather than following a fixed script — to steal bank logins, one-time codes, and screen-lock PINs while actively blocking uninstall attempts. It spreads via smishing and malvertising and abuses ADB wireless debugging to escape the normal app sandbox, making it a concrete, in-the-wild instance of adversaries operationalizing an AI agent as malware’s control loop rather than using AI only for content generation.
Key Sources:
New RatHat Android malware uses AI to automate device control
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
An AI Hallucination Nearly Triggered a US-China Military Boarding Incident
CRITICAL URGENCY
Summary: CNN reported, and Security Affairs and TechCrunch corroborated on September 18-20, that a Special Operations Command Pacific analyst’s AI-assisted intelligence report hallucinated a claim in spring 2026 that a Chinese vessel in the Middle East was carrying nuclear-weapons-program components. Armed boarding teams and aircraft were already moving before someone verified the source and found the report “entirely false,” with one source describing the near-miss as something that “almost started a war.” The incident lands as the Pentagon’s AI Acceleration Strategy pushes AI tools out to three million military and civilian personnel with, per the reporting, no consistent cross-branch system for verifying AI-generated intelligence before action is taken.
Key Sources:
AI Hallucinations Nearly Triggered a US-China Military Confrontation
AI hallucination nearly triggers US military operation
US Military Almost Boarded Chinese Ship Over AI-Hallucinated Nuclear Claim
BragJack Shows One Malicious Extension Can Hijack Five Browsers’ Built-In AI Agents
HIGH URGENCY
Summary: Researcher Gal Weizman of Forever Security disclosed BragJack, a technique in which a single installed browser extension abuses Chromium’s declarativeNetRequest API to intercept traffic and inject a full prompt directly into an AI browser agent’s privileged context — a method the researcher calls “Prompt Forcing” to distinguish it from conventional prompt injection, since the attacker hands the agent instructions outright rather than hiding them in content it reads. The technique worked against Gemini Live in Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome, produced two CVEs, and paid out more than $20,000 in bounties.
Key Sources:
BragJack attacks hijack AI browser agents through malicious extensions
BragJack Technical Overview: How We Hijacked Top 5 Browsers’ Internal Agents
Two Independent Escapes From OpenAI’s Codex Sandbox Reach the Host Machine
HIGH URGENCY
Summary: Security researcher Oren Yomtov of Accomplish AI reported two distinct escapes from OpenAI’s Codex agentic-coding sandbox: “Heapjack,” which exploits a shared memory heap between trusted and untrusted JavaScript contexts in Codex Desktop to steal an authorization token and achieve unsandboxed command execution merely by having Codex analyze a malicious repository, and “Overpatch,” which abuses Codex CLI’s apply_patch tool to escape workspace-write restrictions via a symlink and execute code the next time a terminal opens. Both were responsibly disclosed on August 12 and patched within eight days.
Key Sources:
Survey Finds AI Governance Failures Trace to Process Design, Not Policy Gaps
MEDIUM URGENCY
Summary: A Sapio Research survey of 1,000 senior IT, operations, and transformation leaders alongside 5,000 employees found that 40% of large companies experienced an AI-related compliance or governance incident in the past 12 months, and that 84% of those incidents traced to workflows still built around a human checkpoint that AI silently bypassed or hollowed out — approvals, handoffs, and exception-handling steps that leave no audit trail once AI performs the step a person used to. Two-thirds of leaders say compliance concerns are now slowing the workflow redesign needed to fix the problem.
Key Sources:
AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor
Two in Five Organisations Hit by AI-Related Compliance Failures in Past Year
Notable News & Signals
1 in 8 MCP Credential Slots Contain Hardcoded Secrets
Hush Security analyzed ~82,000 public MCP configuration files on GitHub and found 12% of credential slots hardcoded, over half in formats standard scanners can’t recognize.
NIST CAISI: GLM-5.3 Is the Most Cyber-Capable Open-Weight Model Yet
CAISI’s benchmark assessment finds Z.ai’s open-weight GLM-5.3 leads other open models on offensive cyber tasks but still trails US frontier models by roughly four months.
Gyazo Breach Exposes 23.6 Million User Records
A server vulnerability let attackers steal 23.6 million Gyazo user records and metadata for 490 million images; no AI-security angle, but a large image-sharing platform breach worth tracking.
ChainScript RAT Uses Polygon Blockchain to Rotate C2 Infrastructure
ClickFix lures deliver a new RAT that queries a Polygon smart contract for its live C2 address, an EtherHiding-style technique that defeats static-address blocking.
Topics Already Covered (No New Action Required)
- Cisco ISE zero-day CVE-2026-76460: Already assessed and excluded in the 2026-09-21 report as covered by CSA’s five most-recent research notes.
- Plugin4Shell AI coding-agent plugin supply chain: Already assessed and excluded in the 2026-09-21 report.
- Azure AI Foundry and AWS AgentCore flaws: Already assessed and excluded in the 2026-09-21 report.
- CrowdStrike/TanStack breach: Already assessed and excluded in the 2026-09-21 report.
- CISA Linux kernel KEV additions: Already assessed and excluded in the 2026-09-21 report.
- Orkes Conductor RCE: Already assessed and excluded in the 2026-09-21 report.
- Frontier-lab AI-slowdown pact: Already assessed and excluded in the 2026-09-21 report.