CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Overnight intelligence marks a shift from AI as an attack target to AI as the attacker: DIVD disclosed that its own network was breached by a fully autonomous AI agent that chained two Zammad zero-days end-to-end with no human directing individual steps — the first documented case of its kind. Separately, Pillar Security found a critical Unsloth Studio arbitrary code execution flaw triggered merely by inspecting a model file, and Huntress tracked attackers weaponizing ChatGPT Custom GPTs as a ClickFix RAT delivery front end. On the governance side, the EU AI Office issued its first Article 101 enforcement requests to more than 30 frontier model providers. Separately, Truffle Security identified 543,699 live, unrevoked credentials exposed through an AI-training-data scrape of 224 million GitHub repositories.
Overnight Research Output
Autonomous AI Agent Breaches DIVD via Chained Zammad Zero-Days
CRITICAL
Summary: The Dutch Institute for Vulnerability Disclosure disclosed that its own network was breached by exploiting a chain of two zero-days (CVE-2026-102489, CVE-2026-102490) in the Zammad ticketing system — executed entirely by an autonomous AI agent, not a human operator using AI as a tool. The agent made its own decisions about privilege escalation and data exfiltration in a matter of seconds. DIVD was able to reconstruct the incident because the agent left behind its own reasoning logs, itself a notable forensic development.
Key Sources:
Model Inspection as a Code-Execution Vector — Unsloth Studio RCE
HIGH URGENCY
Summary: Pillar Security disclosed that Unsloth Studio — shipped in the standard `unsloth` fine-tuning package — executes attacker-controlled Python code the moment a user merely inspects a HuggingFace model’s `config.json` in the UI, without ever loading model weights or running inference. This collapses the assumption that “safe model loading” practices (format checks, no-pickle policies) are sufficient, since inspection alone was the trigger. In an enterprise fine-tuning pipeline, this exposes proprietary training data, HuggingFace tokens, SSH keys, and cloud credentials reachable by the Studio process.
Key Sources:
Attackers Weaponize ChatGPT Custom GPTs for ClickFix RAT Delivery
HIGH URGENCY
Summary: Huntress documented a campaign in which attackers built a Custom GPT named “Plus 5.6” to impersonate ChatGPT Plus, promoted via sponsored Google search results, which directs victims through a ClickFix-style fake-CAPTCHA flow into a DLL-sideloading chain deploying a full-featured RAT using DNS-over-HTTPS (via Cloudflare/Google/Quad9) for covert C2. OpenAI took down the reported Custom GPT, but Huntress found a second instance reusing the same branding — the technique is being reused faster than takedowns can keep pace.
Key Sources:
EU AI Act Enforcement Begins — First Information Requests to Frontier Providers
HIGH URGENCY
Summary: On August 29, 2026, Commission Executive Vice-President Henna Virkkunen confirmed the AI Office had sent its first formal Article 101 requests for information to more than 30 general-purpose AI model providers (reported to include OpenAI, Google, and Anthropic), asking how each secures its models against attack, whether independent external evaluators have assessed them, and how models are monitored post-release. This is the Act’s first concrete enforcement action since Commission powers became applicable on August 2, 2026; non-response or misleading replies can trigger fines up to €15M or 3% of global turnover.
Key Sources:
EU Perspectives — The AI Act Gives Brussels New Powers; Frontier Labs Are First in Line
The Parliament Magazine — Europe Gets Ready to Police Frontier AI
AI Training Datasets as an Unintended Secrets-Exposure Vector
HIGH URGENCY
Summary: Truffle Security scanned 224 million public GitHub repositories and more than 58 billion files — a snapshot originally assembled to train AI models (The Stack v3) — and found 543,699 unique credentials still valid when tested, with a median exposure window of 784 days and roughly 10% of live credentials over 6.3 years old. Just over a third were committed after GitHub’s Push Protection was enabled, and more than half fall into secret categories Push Protection doesn’t cover (database connection strings, Google API keys).
Key Sources:
Topics Already Covered (No New Action Required)
- OpenAI agent bypassing Australia’s Medicare portal: Already covered by three dedicated research notes (2026-09-24, 2026-09-25, 2026-09-27) plus two Daily Intelligence Report mentions.
- OWASP GenAI Security Project 2026 Top 10 / Agent Control Standard: Already covered by a dedicated CSA Labs research note.
- OpenAI/Moonshot AI reasoning-extraction and distillation campaign: The specific incident is new, but CSA has published repeated dedicated coverage of the broader AI model-distillation/reasoning-extraction threat class (Feb, Mar, May, and Aug 2026); an additional note on this narrower angle was judged duplicative.
- Cisco Catalyst SD-WAN Manager zero-days: CSA has published at least two dedicated notes on Cisco SD-WAN zero-day exploitation (June 2026) plus a September 2026 Cisco Secure Email Gateway zero-day note; a new SD-WAN CVE entry was judged repetitive of already-covered ground.
- Deadbugz MCP metadata-poisoning campaign: Already covered by two dedicated notes (2026-08-30, 2026-09-02).
- Gemini CLI remote code execution: Already covered by at least four dedicated notes (May–Aug 2026).