CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
The past 48 hours produced a dense cluster of actively exploited vulnerabilities: a maximum-severity, unauthenticated root RCE in Cisco Secure Email Gateway that CISA added to the KEV catalog the same day it was disclosed, a suspected Chinese state actor (“Red Heron”) that weaponized a Gitea RCE within days to compromise 13 defense, election, energy, and aerospace organizations, and a month-long mass-scanning campaign harvesting AWS and Azure credentials from exposed Vite dev servers. Separately, the EU’s Cyber Resilience Act reporting obligations became legally binding on September 11, and researchers disclosed DDRop, a hardware attack that breaks the trust root underpinning Intel and AMD confidential computing used to protect AI model weights in the cloud. FCEB agencies face a September 17 patch deadline for the Cisco flaw.
Overnight Research Output
Cisco Secure Email Gateway Zero-Day (CVE-2026-76461) — Root RCE Exploited Before Patch
Critical
Summary: A CVSS 9.8 unauthenticated flaw in AsyncOS for Cisco Secure Email Gateway lets attackers send crafted emails that trigger SQL injection and escalate to root-level OS command execution, with no user interaction required. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog the same day Cisco disclosed it, indicating exploitation in the wild predated public awareness. Because email gateways sit at a trust boundary nearly every enterprise relies on, this is a priority patch for both federal agencies and private-sector defenders.
Key Sources:
The Hacker News — Cisco Secure Email Gateway Flaw
BleepingComputer — New Cisco Secure Email Zero-Day Exploited to Execute Commands as Root
Rapid7 — CVE-2026-76461 Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
Mass-Scanning Campaign Exploits Vite Flaw (CVE-2026-39364) to Harvest Cloud Credentials
High Urgency
Summary: Since August 2026, an automated scanning fleet operating from rented cloud infrastructure has run a sustained campaign — 807 session-grouped attacks and roughly 32,000 raw events per F5 Labs — against internet-exposed Vite development servers. The attackers use query-parameter manipulation to bypass the server.fs.deny protection and exfiltrate .env files, AWS keys, Azure tokens, and Terraform/IaC state files. It illustrates how developer-tooling misconfigurations, not just production systems, have become a primary cloud credential theft vector.
Key Sources:
Red Heron Weaponizes Gitea RCE Within Days, Compromises 13 Organizations Across Critical Sectors
High Urgency
Summary: A suspected Chinese state-linked actor, tracked as Red Heron, converted a public Gitea RCE proof-of-concept into an automated exploitation framework within days of its July 2026 disclosure. The group scanned 1,386 internet-facing Gitea instances across seven countries and confirmed compromises spanning defense, election, energy, aerospace, telecommunications, and government targets, including root-level access to a Proxmox virtualization cluster. It is a sharp data point on how quickly nation-state actors now operationalize DevOps-infrastructure disclosures into multi-sector espionage campaigns.
Key Sources:
The Hacker News — Red Heron Exploits Gitea RCE
Industrial Cyber — Red Heron Exploits Gitea RCE Flaw in Multinational Campaign
ENISA’s CRA Single Reporting Platform Goes Live — Reporting Obligations Now Binding
High Urgency
Summary: ENISA launched the EU Cyber Resilience Act’s Single Reporting Platform on September 11, 2026 — the same day CRA reporting obligations for actively exploited vulnerabilities and severe incidents became legally binding for manufacturers placing digital products, including AI-embedded products, on the EU market. The platform enforces a strict cadence: a 24-hour early warning, a 72-hour initial assessment, and a 14-day final report. This gives security and compliance teams a concrete new operational obligation rather than a distant regulatory milestone.
Key Sources:
ENISA — The CRA Single Reporting Platform Is Launched
Help Net Security — ENISA CRA Single Reporting Platform
Crowell & Moring — It’s Live: CRA Reporting Is Mandatory as of Today
DDRop Attack Breaks the Trust Root Under Intel and AMD Confidential Computing
High Urgency
Summary: Researchers disclosed DDRop, a sub-$200 hardware interposer attack that silently drops memory writes to defeat the freshness guarantees of Intel TDX, Intel SGX, and AMD SEV-SNP, achieving full compromise of protected VMs on TDX including attestation forgery. These are the hardware-rooted isolation mechanisms hyperscalers and AI vendors market as the basis for trustworthy multi-tenant isolation of sensitive workloads, including model weights and training data. A weakness spanning both major CPU vendors’ confidential computing lines is a concentration and trust-model risk that goes beyond any single cloud provider or product.
Key Sources:
The Hacker News — New DDRop Attack Breaks Intel TDX and AMD SEV-SNP
SC World — DDRop Attack Bypasses Intel and AMD Confidential Computing Defenses
Topics Already Covered (No New Action Required)
- OpenAI agent swarm behind the May 2026 RubyGems mass-publication attack: covered in Frontier Ready Daily (2026-09-08, 2026-09-09).
- Microsoft’s record 974-CVE Patch Tuesday and the discovery/patch gap: covered 2026-09-12.
- AI-driven SOC alert noise / analyst capacity overrun: covered 2026-09-12, 2026-09-13, 2026-09-14.
- GitLab CVSS 10 commits-API flaw exploited in the wild: covered 2026-09-15.
- Four-nation-state Chrome/Windows exploit kit cluster: covered 2026-09-13 (likely parent story to this cycle’s GRIMWEDGE/UTA0560 reporting).
- AI-scale open-source vulnerability discovery outpacing maintainer patching (Anthropic Mythos / Project Glasswing): already the subject of a published CSA artifact, “Project Glasswing: AI Discovery Outpaces Open Source Patching,” and a Lab Space research note.
- Human attacker matching AI-speed intrusion without AI tooling (Sysdig/Marimo): covered 2026-09-13.