CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Cisco disclosed a maximum-severity authentication bypass (CVE-2026-20079, CVSS 10.0) in Secure Firewall Management Center now being actively exploited by three separate threat clusters, including a Qilin ransomware affiliate and a Sandworm-linked espionage operator, the clearest all-hands item this cycle. Microsoft disclosed a passkey-themed phishing campaign hijacking cloud accounts alongside a generative-AI-drafted CEO-fraud operation that sent over a million scam emails in three days, while Huntress documented attackers weaponizing Claude Artifacts and shared AI conversation links to distribute infostealers. On the governance side, ENISA’s Cyber Resilience Act reporting platform went live, starting a binding 24-hour disclosure clock. Separately, new telemetry shows AI-related SOC alert volume up 685%, with just 0.02% representing real attacks.
Overnight Research Output
Three Threat Clusters, One Maximum-Severity Cisco Flaw
CRITICAL
Summary: Cisco Talos confirmed three independent threat clusters exploiting a maximum-severity authentication bypass (CVE-2026-20079) and a chained static-credential flaw (CVE-2026-20316) in Secure Firewall Management Center. One cluster shows tooling overlap with Sandworm’s Cyclops Blink implant; a second deployed Qilin ransomware after living-off-the-land reconnaissance; a third focused on opportunistic credential theft. Both CVEs sit in CISA’s KEV catalog, and Cisco warns that patching alone will not remove implants already planted on compromised, internet-exposed instances.
Key Sources:
The Hacker News — Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
BleepingComputer — Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos — Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Trusted AI Platforms as Malware Delivery Infrastructure
HIGH URGENCY
Summary: Over the summer, threat actors ran three campaigns, FakeAgent, ClaudeFix, and AI-chatbot-poisoned search results, that abused Claude Artifacts and shared AI conversation links to distribute the SectopRAT, MacSync, and AMOS infostealers. Because the malicious content lives on claude.ai or chatgpt.com domains, allowlisting and domain-reputation controls fail by design, and victims execute ClickFix-style clipboard commands believing they are following legitimate troubleshooting guidance.
Key Sources:
Huntress — The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms
BleepingComputer — How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
GenAI Writes the Phishing Lures Behind MSFT Takeovers
HIGH URGENCY
Summary: Microsoft disclosed a passkey-themed vishing/smishing campaign (Storm-3121, Storm-3032) that tricks employees into adversary-in-the-middle or device-code phishing, then registers attacker-controlled MFA methods for persistent access, alongside a separate GenAI-assisted CEO-fraud campaign that sent over one million tailored invoice-scam emails in three days. CSA’s own research on the Forg365 phishing kit previously documented the same AI-lure-plus-fake-passkey-enrollment pattern.
Key Sources:
CRA Reporting Clock Starts: ENISA’s SRP Goes Live
HIGH URGENCY
Summary: ENISA’s Single Reporting Platform went live on September 11, the same day the CRA’s Article 14 vulnerability and incident reporting obligation became legally binding. Manufacturers of digital products sold into the EU, including legacy products still on the market, must now file an early warning within 24 hours of active exploitation, with fuller reports due at 72 hours and final reports at 14 days or one month.
Key Sources:
AI Adoption Is Flooding the SOC With Noise
MEDIUM URGENCY
Summary: An analysis of roughly 16.9 million SOC alerts found AI-related alert volume grew 685% between February and June 2026, but 94.1% is noise from legitimate developer and business AI use, 5.8% is genuine policy risk, and only 0.02% is a confirmed attack. None of the confirmed attacks involved an organization’s own AI agents; all exploited employee trust in AI brand names as phishing lures.
Key Sources:
Topics Already Covered (No New Action Required)
- JFrog Artifactory authentication-chain exploitation: Covered in CSA research notes published 9/11 and 9/12.
- GitLab CVE-2026-85706 path-traversal KEV entry: Covered 9/12.
- PaperCut NG/MF active exploitation: Covered 9/11 and 9/13.
- OpenAI-agent RubyGems/RubyDoc RCE campaign: Covered 9/13.
- Anthropic’s September threat-intelligence report (Claude misuse, seven-lab distillation campaign, GTG-20006/Midnight Blizzard, EU AI Act Article 55 disclosure-gap analysis): Covered 9/10 and 9/12.
- Five Eyes frontier-model screening communiqué: Covered 9/11.
- Frontier-model monoculture risk and multi-agent collusion: Covered 9/11 and 9/12.
- AI liability/insurance convergence: Covered 9/13.
- Texas TRAIGA enforcement portal: Covered 9/13.