CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
An unpatched GeoServer zero-day is already under active internet-wide probing with no CVE or vendor patch available, and a year-long SaaS guest-access campaign called City-Forum has quietly harvested data from misconfigured Salesforce and ServiceNow portals since March 2025. Separately, sandbox research confirmed DPRK IT-worker infiltration has reached a U.S. federal agency, with operatives now using real-time AI deepfakes to defeat hiring checks. OWASP’s 2026 LLM Top 10 introduces incident-weighted rankings, and four independent disclosures show consumer devices and browser extensions have converged into an ambient residential proxy layer that undermines IP-based trust controls enterprise-wide.
Overnight Research Output
Unpatched GeoServer Zero-Day: Active Exploitation Before a Patch
CRITICAL URGENCY
Summary: Researcher q1uf3ng disclosed an unauthenticated SQL injection in GeoServer’s jsonArrayContains OGC Filter function on August 12; attack-surface firm watchTowr observed exploitation attempts within hours from a small, concentrated cluster of source IPs. Where GeoServer’s database account holds elevated privileges — commonly on PostGIS or Oracle JDBC backends — the injection can escalate to remote code execution. No CVE has been assigned and no vendor patch exists. GeoServer’s user base spans government, defense, and research institutions, and this is the second time in three years the same filter function has produced a critical SQL injection.
Key Sources:
The Hacker News — Unpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts
SecurityWeek — Hackers Exploiting Unpatched GeoServer Zero-Day
Security Affairs — GeoServer Zero-Day Is Already Being Probed
City-Forum: A Year-Long SaaS Guest-Access Data Theft Campaign
HIGH URGENCY
Summary: SaaS security firm Reco traced a data-theft operation, City-Forum, to a single Contabo-hosted server that has harvested data from Salesforce Experience Cloud and ServiceNow Service Portal deployments since at least March 2025 — with no platform vulnerability involved, only over-permissive guest-user configurations. The campaign built custom tooling against Salesforce’s legacy Aura framework, its newer Lightning Web Runtime UI API (the first publicly reported in-the-wild abuse of that surface), and an undocumented ServiceNow search endpoint. Reported targets include telecoms, banks, software vendors, and public-sector portals, with more than 560,000 requests logged against its most heavily targeted victim.
Key Sources:
BleepingComputer — City-Forum Data-Theft Attacks Target Salesforce, ServiceNow Portals
Dark Reading — Long-Running Data Theft Campaign Targeting Salesforce, ServiceNow
Techzine — City-Forum Extracts Data From Salesforce and ServiceNow
DPRK IT Worker Infiltration: Sandboxed Honeypots Expose the Threat
HIGH URGENCY
Summary: Researchers Mauro Eldritch, Heiner García, and ANY.RUN stood up a fake DeFi startup and issued monitored sandbox “workstations” to suspected North Korean hires, capturing document forgery, reconnaissance commands, and AI-assisted deception from day one of employment. An eleven-nation joint advisory confirmed operatives now use real-time AI deepfake video to defeat live interview verification, and that the scheme funneled roughly $800 million to DPRK weapons programs in 2024. Separately, the FBI disclosed that a North Korean IT worker had been employed inside a U.S. federal agency for months before discovery — extending the scheme’s targets beyond the Fortune 500 and crypto firms that previously dominated reporting.
Key Sources:
The Hacker News — North Korean Remote Workers Are Infiltrating Government and Businesses
TechCrunch — North Korean Remote IT Staffer Worked for US Government Agency, Says FBI
The Hacker News — Researchers Built a Fake Crypto Startup to Catch North Korean IT Workers
OWASP’s 2026 LLM Top 10: Incident Data Meets Judgment
MEDIUM URGENCY
Summary: The OWASP GenAI Security Project published the 2026 LLM Top 10 on August 3, the first edition to weight rankings using empirical incident data — 6,639 classified reports out of 7,714 collected — alongside a 75/25 blend favoring practitioner voting. Prompt Injection and Sensitive Information Disclosure held the top two spots for a third year, but Excessive Agency jumped from 6th to 3rd and Unbounded Consumption from 10th to 6th, while Improper Output Handling fell from 5th to 10th, the largest single swing on the list.
Key Sources:
OWASP GenAI Security Project — OWASP GenAI LLM Top 10 2026
Help Net Security — OWASP 2026 LLM Top 10: “The model will be fooled”
The Proxy-for-Profit Economy: Consumer Devices as Attack Infrastructure
HIGH URGENCY
Summary: Four disclosures over six weeks — the FBI’s seizure of the NetNut proxy platform tied to the 2M+ device Popa botnet, Bitsight’s finding that H96 streaming sticks double as residential proxies and ad-fraud clickers, Spur’s discovery of proxy SDKs in 42% of LG webOS and 25%+ of Samsung Tizen apps, and Socket’s identification of 737 Chrome VPN extensions routing traffic through an undisclosed SOCKS5 network — together show consumer hardware and browser extensions converging into a commercial proxy layer indistinguishable from botnet infrastructure. Google’s Threat Intelligence Group observed 316 distinct threat clusters on NetNut exit nodes in a single week.
Key Sources:
Krebs on Security — FBI Seizes NetNut Proxy Platform Tied to Popa Botnet
Krebs on Security — Read This Before You Buy That TV Streaming Stick
The Hacker News — 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies
Notable News & Signals
No additional notable signals beyond today’s five topics
Every high-confidence item surfaced by this cycle’s scan was substantial enough to warrant a full research note; none were held back as minor signals. See the “Topics Already Covered” section below for stories excluded as duplicates of prior-cycle analysis.
Topics Already Covered (No New Action Required)
- Cross-vendor LLM reasoning-trace theft (OpenAI, Anthropic, Google APIs): Covered by the Aug 14 cycle’s dedicated research note.
- Atlassian Rovo prompt-injection (invisible content injection, RovoBlast URL pre-fill): Covered by the Aug 14 cycle’s dedicated research note.
- Keyv-linked npm worm planting Claude Code/VS Code persistence hooks: Covered by the Aug 14 cycle’s dedicated research note.
- NIST joining the DOE-led Genesis Mission for AI-secured critical infrastructure: Covered by the Aug 14 cycle’s dedicated research note.
- White House “cyber privateer” memo authorizing private-sector offensive operations: Covered by the Aug 14 cycle’s dedicated research note.
- Anthropic Claude Opus 4.7/Mythos 5 evaluation-escape and backdoor incidents: Covered by existing CSA evaluation-escape and MAESTRO-analysis notes (Aug 10, Aug 13).
- VMware vCenter Syslog Server RCE and Microsoft Defender “ShieldBreak”: Covered by the Aug 13 cycle’s dedicated notes.
- SharePoint authentication bypass (CVE-2026-55040): Covered by the Aug 12 cycle’s dedicated research note.
- AI provider concentration risk and EU AI Act Article 50 transparency obligations: Already heavily saturated in the existing corpus.