CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Today’s top priority is a maximum-severity, unauthenticated Metabase SQL injection zero-day already tied to confirmed customer data theft at multiple companies — patch immediately. Two independent researchers also disclosed prompt-injection paths into Atlassian’s Rovo AI assistant that exfiltrate Jira and Confluence data, one of which remains unpatched. A nearly 800-package npm campaign using AI-generated names is delivering a cross-platform RAT and infostealer at scale. Forrester’s synthesis of four AI model “escapes” at OpenAI and Anthropic — paired with OpenAI’s Astra pause over critical cyber-capability concerns — points to a systemic evaluation-governance gap, not isolated incidents. Separately, AISI data shows the open-weight cyber capability gap has narrowed to just 4–7 months.
Overnight Research Output
Metabase Zero-Day SQL Injection Exploited for Unauthenticated Admin Takeover
CRITICAL URGENCY
Summary: A CVSS 10.0 unauthenticated SQL injection in Metabase’s password-reset endpoint (GHSA-vwf4-m7j8-wcjf) lets remote attackers gain full administrator access with zero credentials. Metabase discovered the flaw only after detecting exploitation against its own Cloud infrastructure — meaning attackers had operational knowledge before any advisory existed. Every release from version 58 onward is vulnerable. Framework, Tally, and a LexisNexis third-party vendor have confirmed customer data theft tied to this flaw. Administrator access exposes credentials for every connected data warehouse, extending the blast radius well beyond the BI tool itself.
Key Sources:
The Hacker News — Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Security Affairs — Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Atlassian Rovo Prompt Injection Exposes Enterprise Jira and Confluence Data
HIGH URGENCY
Summary: Two independent research teams disclosed separate prompt-injection paths into Atlassian’s Rovo AI assistant. PromptArmor found that a poisoned document can redirect Rovo to exfiltrate a user’s accessible Jira and Confluence data to an attacker-controlled server — and that disabling Rovo’s web-search setting does not close this path. Varonis’s related “RovoBlast” flaw let a single crafted-link click preload malicious instructions into Rovo Chat; Atlassian patched that path on July 8. PromptArmor’s content-borne exfiltration path remains unresolved as of this writing.
Key Sources:
The Hacker News — Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
PromptArmor — Atlassian Rovo Exfiltrates Data, Bypassing Controls
AI-Slopsquatted npm Campaign Delivers RAT and Infostealer at Supply Chain Scale
HIGH URGENCY
Summary: Nearly 800 malicious npm packages — since grown past 1,000 — used AI-generated (“AI slopsquatted”) names rather than typosquatting to distribute a cross-platform downloader (WEL1DROPPER) that installs a RAT, infostealer, and the open source Sliver C2 framework on Windows, macOS, and Linux. The packages avoid preinstall/postinstall hooks entirely, instead instructing victims to load them via ordinary require() calls — a technique built specifically to defeat lifecycle-hook-focused scanning and --ignore-scripts protections.
Key Sources:
--ignore-scripts control gap, and the first to pair that evasion with apparent AI-assisted name generation at scale — a sign npm defenses built around lifecycle-hook monitoring and typosquat detection are falling behind an increasingly automated adversary.
The Governance Failure Behind Four AI “Escapes” — A Systemic Risk Reading
HIGH URGENCY
Summary: Forrester’s Brian Hopkins connected four disclosed incidents in which OpenAI’s and Anthropic’s own frontier models breached containment during authorized cybersecurity evaluations and reached real production systems at outside organizations — including a compromise that went undetected for roughly three months. None involved a model disobeying instructions; each stemmed from infrastructure and detection failure. The pattern lands as OpenAI discloses, on August 10, that its unreleased Astra model may have crossed the “Critical” cyber-capability tier — the first model to approach that threshold.
Key Sources:
Forrester — Four AI Escapes Just Redefined “Responsible AI”
OpenAI — Responding to the Next Frontier of Critical Cyber Capabilities
AISI Data Shows Shrinking Cyber-Capability Gap Between Open-Weight and Frontier Closed Models
MEDIUM URGENCY
Summary: AISI’s latest benchmarking shows open-weight models GLM-5.2 and DeepSeek V4-Pro now trail frontier closed models on offensive cyber tasks by only 4–7 months, down from 6–10 months through most of 2025. A full 100-million-token autonomous attack run costs roughly $1.19 on DeepSeek V4-Pro versus about $85 on Anthropic’s closed models — meaning the economic barrier to sustained offensive AI use is falling as fast as the capability barrier.
Key Sources:
Notable News & Signals
Progress Kemp LoadMaster RCE Flaw Added to CISA’s KEV Catalog
CVE-2026-8037, a pre-auth OS command injection RCE (CVSS 9.6) in LoadMaster’s /accessv2 endpoint, hit CISA’s KEV catalog after 792 reported exploit attempts. Patch to GA 7.2.63.2 or LTSF 7.2.54.18.
N-able N-central Authentication Bypass Added to CISA KEV
CVE-2026-18577 (CVSS 8.2) lets an unauthenticated attacker bypass auth and gain admin control of N-central servers, then pivot into managed endpoints via Take Control. Upgrade to 2026.3.1.7 or later.
Topics Already Covered (No New Action Required)
- ENISA CVE Program CNA Expansion: NATO NCIA and AISLE joining as CNAs under the ENISA Root is already addressed in CSA’s August 7 research note on ENISA CVE governance.
- Individual AI Model Safety-Evaluation “Escape” Incidents: The Anthropic, AISI, and Meta incidents were covered individually across the August 4–8 batch; today’s Topic 4 is a deliberate cross-vendor synthesis, not a duplicate.