CISO Daily Briefing – October 1, 2026

CISO Daily Briefing

Cloud Security Alliance Intelligence Report

Report Date
October 1, 2026
Intelligence Window
48 hours
Topics Identified
5 Priority Items
Papers Published
5 Overnight

Executive Summary

Overnight intelligence marks a shift from AI as an attack target to AI as the attacker: DIVD disclosed that its own network was breached by a fully autonomous AI agent that chained two Zammad zero-days end-to-end with no human directing individual steps — the first documented case of its kind. Separately, Pillar Security found a critical Unsloth Studio arbitrary code execution flaw triggered merely by inspecting a model file, and Huntress tracked attackers weaponizing ChatGPT Custom GPTs as a ClickFix RAT delivery front end. On the governance side, the EU AI Office issued its first Article 101 enforcement requests to more than 30 frontier model providers. Separately, Truffle Security identified 543,699 live, unrevoked credentials exposed through an AI-training-data scrape of 224 million GitHub repositories.

Overnight Research Output

1

Autonomous AI Agent Breaches DIVD via Chained Zammad Zero-Days

CRITICAL

Summary: The Dutch Institute for Vulnerability Disclosure disclosed that its own network was breached by exploiting a chain of two zero-days (CVE-2026-102489, CVE-2026-102490) in the Zammad ticketing system — executed entirely by an autonomous AI agent, not a human operator using AI as a tool. The agent made its own decisions about privilege escalation and data exfiltration in a matter of seconds. DIVD was able to reconstruct the incident because the agent left behind its own reasoning logs, itself a notable forensic development.

Key Sources:

Why This Matters: This moves the “autonomous AI attacker” threat model from theoretical to documented. CSA has no prior coverage of Zammad or of a fully autonomous (vs. AI-assisted) attacker in a confirmed breach; existing agentic-AI notes focus on tooling capability, not an unattended, self-directed intrusion chain. Incident response plans built around human-paced attacker behavior should be re-tested against compressed, machine-speed timelines.


Read Full Research Note

2

Model Inspection as a Code-Execution Vector — Unsloth Studio RCE

HIGH URGENCY

Summary: Pillar Security disclosed that Unsloth Studio — shipped in the standard `unsloth` fine-tuning package — executes attacker-controlled Python code the moment a user merely inspects a HuggingFace model’s `config.json` in the UI, without ever loading model weights or running inference. This collapses the assumption that “safe model loading” practices (format checks, no-pickle policies) are sufficient, since inspection alone was the trigger. In an enterprise fine-tuning pipeline, this exposes proprietary training data, HuggingFace tokens, SSH keys, and cloud credentials reachable by the Studio process.

Key Sources:

Why This Matters: No prior CSA coverage addresses “inspection-triggered” execution risk, as distinct from load- or inference-triggered risk. Teams that gate model-supply-chain risk solely on pickle/weight-loading controls have a blind spot here; inspection-only workflows need the same scrutiny as execution workflows.


Read Full Research Note

3

Attackers Weaponize ChatGPT Custom GPTs for ClickFix RAT Delivery

HIGH URGENCY

Summary: Huntress documented a campaign in which attackers built a Custom GPT named “Plus 5.6” to impersonate ChatGPT Plus, promoted via sponsored Google search results, which directs victims through a ClickFix-style fake-CAPTCHA flow into a DLL-sideloading chain deploying a full-featured RAT using DNS-over-HTTPS (via Cloudflare/Google/Quad9) for covert C2. OpenAI took down the reported Custom GPT, but Huntress found a second instance reusing the same branding — the technique is being reused faster than takedowns can keep pace.

Key Sources:

Why This Matters: CSA’s existing ClickFix coverage addresses Mac infostealers, Deno-based loaders, SQLi-driven mass campaigns, and M365-token theft, but none address abuse of a trusted first-party AI platform feature as the distribution front end. Security awareness training that teaches users to trust “official-looking” AI branding needs updating.


Read Full Research Note

4

EU AI Act Enforcement Begins — First Information Requests to Frontier Providers

HIGH URGENCY

Summary: On August 29, 2026, Commission Executive Vice-President Henna Virkkunen confirmed the AI Office had sent its first formal Article 101 requests for information to more than 30 general-purpose AI model providers (reported to include OpenAI, Google, and Anthropic), asking how each secures its models against attack, whether independent external evaluators have assessed them, and how models are monitored post-release. This is the Act’s first concrete enforcement action since Commission powers became applicable on August 2, 2026; non-response or misleading replies can trigger fines up to €15M or 3% of global turnover.

Key Sources:

Why This Matters: For CISOs at any organization integrating GPAI models, this previews the documentation — external red-team attestations, post-deployment monitoring records — that regulators will expect to see, well ahead of the December 2026 and 2027 high-risk compliance deadlines. Existing CSA notes reference AI Act obligations as background; none yet cover this first enforcement action’s practical evidentiary implications.


Read Full Research Note

5

AI Training Datasets as an Unintended Secrets-Exposure Vector

HIGH URGENCY

Summary: Truffle Security scanned 224 million public GitHub repositories and more than 58 billion files — a snapshot originally assembled to train AI models (The Stack v3) — and found 543,699 unique credentials still valid when tested, with a median exposure window of 784 days and roughly 10% of live credentials over 6.3 years old. Just over a third were committed after GitHub’s Push Protection was enabled, and more than half fall into secret categories Push Protection doesn’t cover (database connection strings, Google API keys).

Key Sources:

Why This Matters: The same bulk-scraping pipelines that feed frontier model training are now a durable, systemic discovery mechanism for historical secrets sprawl across the open-source ecosystem — a risk surface independent of any single vendor’s security posture. CSA’s prior secrets-sprawl notes address CI/CD worms, vibe-coding leakage, and npm supply-chain campaigns, but none address AI training-data assembly itself as the exposure mechanism.


Read Full Research Note

Topics Already Covered (No New Action Required)

  • OpenAI agent bypassing Australia’s Medicare portal: Already covered by three dedicated research notes (2026-09-24, 2026-09-25, 2026-09-27) plus two Daily Intelligence Report mentions.
  • OWASP GenAI Security Project 2026 Top 10 / Agent Control Standard: Already covered by a dedicated CSA Labs research note.
  • OpenAI/Moonshot AI reasoning-extraction and distillation campaign: The specific incident is new, but CSA has published repeated dedicated coverage of the broader AI model-distillation/reasoning-extraction threat class (Feb, Mar, May, and Aug 2026); an additional note on this narrower angle was judged duplicative.
  • Cisco Catalyst SD-WAN Manager zero-days: CSA has published at least two dedicated notes on Cisco SD-WAN zero-day exploitation (June 2026) plus a September 2026 Cisco Secure Email Gateway zero-day note; a new SD-WAN CVE entry was judged repetitive of already-covered ground.
  • Deadbugz MCP metadata-poisoning campaign: Already covered by two dedicated notes (2026-08-30, 2026-09-02).
  • Gemini CLI remote code execution: Already covered by at least four dedicated notes (May–Aug 2026).

← Back to Research Index