CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Three maximum-severity, pre-authentication vulnerabilities dominate today’s technical landscape: N-able N-central’s fourth emergency hotfix in five weeks for a CVSS 10.0 unauthenticated RCE, a chained SSH bypass in MikroTik RouterOS (“MikroTrick”) already exploited before disclosure, and a Coder registry compromise pushing credential-stealing Terraform modules into AI development pipelines. On governance, the Five Eyes alliance has formalized frontier AI model scrutiny alongside industry access commitments. Most consequential strategically: independent research shows Claude, Codex, and Hermes will autonomously install unregistered packages referenced in vendors’ own llms.txt files, with confirmed callbacks from Fortune 500 networks.
Overnight Research Output
N-able N-central Fourth Hotfix Patches Maximum-Severity RCE
CRITICAL URGENCY
Summary: N-able shipped its fourth emergency hotfix in five weeks on September 6, patching CVE-2026-86218, a CVSS 10.0 pre-authentication remote code execution flaw in the N-central RMM platform used by MSPs to administer client fleets. No credentials are needed — any attacker who can reach the server can execute code. N-able’s advisory states it has no confirmations of exploitation, but Huntress independently confirmed a customer compromise on September 4, two days before the patch, and roughly 1,500 internet-facing N-central servers remain exposed.
Key Sources:
BleepingComputer — N-able patches max severity N-central flaw amid ongoing attacks
Huntress — Critical N-able N-central Vulnerability and Active Exploitation
MikroTrick — Chained MikroTik RouterOS Flaws Enable Unauthenticated Router Takeover
CRITICAL URGENCY
Summary: CERT Polska disclosed six RouterOS vulnerabilities on September 5, two of which chain into “MikroTrick”: an incomplete RSA key-validation flaw (CVE-2026-67276) lets attackers forge SSH authentication without the private key, and a username-parsing bug (CVE-2026-86060) escalates that foothold to full administrative control. Exploitation was already underway from September 2 — three days before the advisory — with attacker IPs and a decade-old BusyBox payload observed in the wild. MikroTik shipped fixes on September 3.
Key Sources:
Coder Registry Compromise Distributes Credential-Stealing Terraform Modules
HIGH URGENCY
Summary: An attacker compromised a Cloudflare API key belonging to Coder and, for roughly 14 hours on August 31, rerouted registry.coder.com traffic to serve tampered Terraform modules. The modules harvested cloud API keys, CI/CD credentials, SSH keys, and — in many configurations — AI provider and MCP credentials, because Coder’s registry is also used to install AI coding agents like Claude Code directly into provisioned workspaces. Coder scored the incident CVSS 9.0 (Critical); Terraform’s lock file does not hash-verify remote modules, so pinning alone would not have caught the substitution.
Key Sources:
Five Eyes Formalize Frontier AI Model Scrutiny and Industry Access Commitments
HIGH URGENCY
Summary: The Five Country Ministerial (Australia, Canada, New Zealand, UK, US) met in Sydney August 25–26 and, for what appears to be the first time, formalized frontier AI model oversight as a standing ministerial agenda item. The communiqué commits governments to defining “characteristics of an AI model that may require additional government scrutiny” while pledging to “deepen collaboration with industry” on “timely access to frontier models” — pairing tighter oversight with continued access. No specific scrutiny criteria have been published yet.
Key Sources:
GOV.UK — Five Country Ministerial Communiqué 2026
Australian Government Department of Home Affairs — Five Country Ministerial 2026
The llms.txt Trust Model Is Broken — AI Coding Agents Install Unregistered Packages
CRITICAL URGENCY
Summary: Independent research scanned 6,214 domains belonging to defense contractors, Fortune 500 firms, and Big Tech, finding 120 llms.txt/llms-full.txt files that referenced unregistered code packages or domains. After registering a sample and hosting benign “phone-home” packages, researchers received callbacks from a Fortune 500 network within an hour, with process-lineage evidence implicating Anthropic’s Claude, OpenAI’s Codex, and Nous Research’s Hermes. Agents treat vendor-published llms.txt content as authoritative and execute install commands without verifying the package exists or is owned by the vendor.
Key Sources:
Topics Already Covered (No New Action Required)
- Hugging Face rogue AI agent swarm / OpenAI incident: Extensively covered across four separate CSA research notes between September 1–6 (rogue agent swarm, emergent agent coordination systemic risk, agentic sandbox escape). Jack Clark’s Import AI commentary this cycle adds no new facts.
- AI-vendor and GPU concentration risk: Covered September 3–5 (GPU monoculture, AI agent collective supply chain concentration, AI access broker concentration). No new material this cycle changes that analysis.
- EU AI Act / SB 53 frontier disclosure governance: Covered September 3 (EU CRA reporting deadline) and September 5–6 (SB 53 critical threshold, AI incident disclosure gap). No fresher governance material surfaced this cycle.
- Latin America AI-enabled data-exfiltration campaign (Unit 42, Sept. 3): Reviewed as a technical candidate but superseded in priority by the three fresher, higher-severity items covered above; can be revisited if follow-on reporting emerges.