CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Today’s scan surfaced five priority items spanning active exploitation, AI supply-chain compromise, and systemic infrastructure risk. A critical, actively-exploited ServiceNow AI Platform sandbox escape (CVE-2026-6875, CVSS 9.5) tops the list, alongside a large-scale FakeGit/AgentBaiting campaign weaponizing 7,600 GitHub repos and fake MCP servers against both humans and AI coding agents. Academic disclosures add two further risk classes: a new mobile AI agent attack surface spanning five open-source frameworks, and Bit2Watt, a novel cyber-physical vulnerability letting ordinary cloud GPU tenants destabilize the power grid. On governance, DeepMind’s Demis Hassabis proposed a FINRA-style frontier AI standards body, signaling where U.S. AI oversight may be headed.
Overnight Research Output
ServiceNow Sandbox Escape: Pre-Auth RCE Under Active Attack
CRITICAL URGENCY
Summary: CVE-2026-6875, a CVSS 9.5 sandbox-escape vulnerability in the ServiceNow AI Platform, lets an unauthenticated attacker with network access to a vulnerable instance escape ServiceNow’s server-side script sandbox and execute arbitrary code — no credentials, phishing, or foothold required. ServiceNow disclosed the flaw July 13 alongside patches; Defused confirmed active exploitation beginning July 17, using a gadget chain distinct from the published proof of concept. Successful exploitation can create durable admin accounts and pivot through on-premises MID Server proxies into internal networks.
Key Sources:
BleepingComputer — Critical ServiceNow code execution flaw now exploited in attacks
Help Net Security — ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
FakeGit/AgentBaiting — 7,600 Repos, 800+ Fake AI Skills and MCP Servers
HIGH URGENCY
Summary: Island’s research documents an ongoing campaign spanning nearly 7,600 malicious GitHub repositories tied to about 6,600 fabricated developer profiles, with over 800 posing as AI Skills or MCP servers for tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker — driving 14M+ downloads and delivering the SmartLoader-to-StealC malware chain. The “AgentBaiting” angle is the more consequential finding: AI coding agents such as Claude Code, Gemini, and ChatGPT independently discovered and recommended the poisoned repositories to users, without any human first encountering a malicious link.
Key Sources:
The Hacker News — FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Island — AgentBaiting: How Fake AI Skills Deliver Malware at Scale
New Attack Surface in Open-Source Mobile AI Agent Frameworks
HIGH URGENCY
Summary: Academic researchers from Simon Fraser University, CUHK, Shandong University, and QAX’s Xingtu Lab identified two novel attack surfaces and seven distinct attacks against five widely used open-source mobile AI agent frameworks (AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, MobA — collectively 37,000+ GitHub stars). Every framework fell to at least six of the seven attacks, including a demonstrated chain from an invisible on-screen overlay planted by an unprivileged Android app to arbitrary code execution on the host PC driving the agent.
Key Sources:
A FINRA for Frontier AI: Hassabis’s Standards Body Proposal
HIGH URGENCY
Summary: Google DeepMind CEO Demis Hassabis published a July 14 proposal for a U.S.-led, FINRA-modeled “Frontier AI Standards Body” — industry-funded, federally-overseen — that would test frontier models pre-release for cyber, biological, and agentic-deception risk, moving from voluntary to mandatory submission over time. The proposal lands amid AISI findings that open-weight models are closing the capability gap with closed frontier models on cyber tasks, and amid a real split among lab leaders over how much enforcement authority any oversight body should hold.
Key Sources:
TechCrunch — DeepMind CEO calls for an independent standards body to regulate frontier AI
Axios — Google’s Hassabis calls for new US-led global AI watchdog “before year end”
UK AI Security Institute — How Far Behind the Frontier are Leading Open Weight Models on Cyber?
Bit2Watt — When a Cloud GPU Tenant Attacks the Power Grid
HIGH URGENCY
Summary: Zhejiang University researchers (paper accepted to CHES 2026) demonstrate that an entirely legitimate cloud GPU tenant — no exploit, no compromised credentials, no OT access — can toggle GPU workloads to induce power oscillations capable of destabilizing the local grid. Worst-case simulations of 1,000 manipulated GPUs on a 1MW system with 90% distributed energy resources drove total harmonic distortion to 46.8% and pushed the grid’s damping ratio negative, with a companion “Watt2Bit” technique enabling covert data exfiltration and cascading denial-of-service across the compute cluster.
Key Sources:
The Register — Malicious cloud customers can bring down the power grid
GBHackers — Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids
Notable News & Signals
No additional notable items this cycle
Beyond the five priority topics above, the 48-hour scan window did not surface further security-relevant items warranting a separate flag; NIST’s and ENISA’s news feeds were largely non-security housekeeping this week.
Topics Already Covered (No New Action Required)
- JADEPUFFER / ENCFORGE agentic ransomware (Langflow CVE-2025-3248): Covered by multiple existing CSA research notes published July 6–7, 2026, including the ENCFORGE AI-model-file-targeting follow-up.
- Hugging Face autonomous-AI-agent breach: Already covered by a dedicated CSA research note published within days of the July 20, 2026 disclosure.
- AI coding agent sandbox escapes (individual products): Cursor (CVE-2026-26268), Gemini CLI, and Antigravity sandbox escapes are each already covered by separate CSA research notes; the July 20 Pillar Security cross-tool study (adding Codex) was evaluated but judged too close to existing coverage to warrant a new note.
- MCP design-level and fake-MCP-package supply chain risk: Broadly covered by existing MCP Security Resource Center notes and prior fake-package incidents (Oura MCP, Bitwarden CLI); only FakeGit/AgentBaiting’s scale and agent-autonomous-discovery angle represented a genuine gap.