CISO Daily Briefing
ALT CISO BRIEFING
Cloud Security Alliance Intelligence Report
Executive Summary
AI was both attacker tooling and attack surface this week. A financially motivated operator used the open-source agentic pentest tool ARTEX with commercial LLMs to steal data from South Korean financial firms, and the Shai-Hulud worm compromised the tensorlake npm SDK used for AI agent infrastructure. Attackers also hijacked three ccTLD registries to obtain rogue Google certificates. On governance, PCI SSC now expects human approval of agent actions touching cardholder data, while Google’s OSS VRP suspension shows AI report floods straining vulnerability triage.
Overnight Research Output
ARTEX and AI-Orchestrated Intrusions: Korean Financial Sector Campaign
CRITICAL
Summary: An unattributed, financially motivated operator used the open-source agentic pentest tool ARTEX with commercial LLMs, including Claude Code, to exfiltrate data from South Korean financial firms. The campaign surfaced only because the operator left open directories exposing session histories and configs.
Key Sources:
The Hacker News — ARTEX AI Pentesting Tool Used in Data Theft
iTnews — CrowdStrike says China-based suspect used AI tools in South Korean bank hacks
Cyber Magazine — CrowdStrike on South Korea bank AI cyber attack
Tensorlake npm Compromise: Shai-Hulud Worm Targets AI Agent Infrastructure SDKs
HIGH URGENCY
Summary: Malicious tensorlake version 0.5.144, published 8 October and flagged by Socket within about 11 minutes, runs through a preinstall hook, harvests CI, Kubernetes and Vault credentials, resolves C2 via an Ethereum contract with GitHub fallback, and self-propagates.
Key Sources:
ccTLD Registry Compromise and Rogue Google Certificates: Trust-Chain Exposure
HIGH URGENCY
Summary: Attackers compromised operators of .gh, .sl and .as and altered authoritative DNS to pass domain validation, obtaining at least 12 certificates (22-27 September) for Google and YouTube names. Chrome blocked them via CRLSets; non-Chrome clients and agents rely on revocation.
Key Sources:
BleepingComputer — Hackers hijack Google domains after breaching ccTLD registries
PCI SSC AI Security Guidance: Human Approval and Accountability for Agent Actions
HIGH URGENCY
Summary: PCI SSC guidance reported 9 October states AI use does not bypass PCI DSS, expects a named human to accept responsibility for AI output, calls for defining which agent actions need human approval, and requires access limits enforced by independent controls such as identity policy and network isolation.
Key Sources:
Help Net Security — PCI SSC guidance on AI in payment environments
PCI SSC Blog — AI Principles: Securing the Use of AI in Payment Environments
When AI Floods the Disclosure Pipeline: Google’s OSS VRP Suspension
HIGH URGENCY
Summary: Google paused its OSS VRP on 1 October through at least Q1 2027 because most automated submissions were invalid or hallucinated. Real vulnerabilities in critical dependencies risk going unreported or untriaged as AI-assisted discovery scales.
Key Sources:
BleepingComputer — Google halts open-source bug bounty program amid AI spam surge
Notable News & Signals
Edge-device activity continues
Citrix NetScaler flaws, a Cisco SD-WAN authentication bypass and FBI action against Flax Typhoon continued, with little AI-specific angle.
Topics Already Covered (No New Action Required)
- OpenAI GPT-6.1 Astra shelving: Covered by a CSA research note published 30 September.