CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
The past 48 hours produced five priority developments spanning critical infrastructure, AI supply chain, and nation-state activity. Cisco disclosed a CVSS 10.0 authentication bypass in Identity Services Engine under active exploitation, now on CISA’s KEV list with a September 19 patch deadline. Mandiant documented attackers hijacking a live AI coding-assistant session to plant a poisoned dependency and unleash the Shai-Hulud worm across roughly 100 repositories. Separately, a China-aligned group deployed a new backdoor against Latin American governments, researchers showed one browser extension can hijack AI assistants across five major browsers, and OpenAI published a voluntary model-misalignment disclosure framework.
Overnight Research Output
Cisco ISE Zero-Day Authentication Bypass (CVE-2026-76460): Active Exploitation of Enterprise Identity Infrastructure
CRITICAL URGENCY
Summary: Cisco disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) unauthenticated authentication bypass in Identity Services Engine’s management interface, and confirmed it is under active exploitation in the wild. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a September 19, 2026 remediation deadline for federal agencies. Because ISE functions as the identity backbone for enterprise network access control, successful exploitation can grant attackers root-level device access and a foothold for network-wide compromise, making this one of the highest-priority patching actions of the week.
Key Sources:
AI Coding Assistant Session Hijacking as a New Supply Chain Attack Vector
CRITICAL URGENCY
Summary: Mandiant published a case study of an attacker hijacking an active AI coding-assistant session and using it to seed a poisoned dependency recommendation, which a developer accepted. That recommendation triggered an infostealer deployment and a self-propagating Shai-Hulud worm outbreak across roughly 100 internal repositories. Unlike prior package-repository poisoning incidents, this attack compromises the trust relationship between developers and their AI assistants directly inside the development workflow, giving attackers a live, interactive channel for social engineering at the point of code review.
Key Sources:
FamousSparrow’s SparroWocky Backdoor: Active Nation-State Espionage Campaign Against Latin American Governments
HIGH URGENCY
Summary: ESET disclosed an active, ongoing espionage campaign by the China-aligned FamousSparrow group deploying SparroWocky, a previously unreported modular backdoor, against government targets across eight Latin American countries. ESET assesses the regional focus as a likely response to U.S. initiatives in the region. The campaign includes fresh technical indicators rather than retrospective analysis, meaning defenders in the affected region and allied sectors should expect continued activity.
Key Sources:
OpenAI’s Model Misalignment Reporting Framework: Voluntary Transparency Alongside Mandatory AI Incident Reporting
HIGH URGENCY
Summary: OpenAI published a new internal framework for tracking, investigating, and disclosing model misalignment incidents, releasing it alongside six newly disclosed incident reports spanning October 2025 through July 2026. OpenAI frames this as voluntary, lab-initiated transparency — distinct from the mandatory incident-reporting regimes CSA has already analyzed under EU AI Act Article 55. The contrast raises open questions about consistency, independent verifiability, and whether voluntary disclosure will hold up under competitive pressure as more labs adopt similar practices.
Key Sources:
OpenAI — Our framework for reporting model misalignment
BragJack: One Browser Extension Defeats the Security Model of Five Competing Agentic AI Browsers
HIGH URGENCY
Summary: Researchers at Forever Security demonstrated that a single malicious browser extension could hijack the built-in AI assistants across five competing Chromium-based browsers — Gemini in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome — using the same fundamental technique. All five products share an architecture that grants an AI “brain” broad access to a browser “body,” meaning the vulnerability class was inherited independently rather than copied. This is a structural, cross-vendor finding rather than a single-product bug.
Key Sources:
Notable News & Signals
Dutch NCSC: Check Point VPN Flaw Exploitation Now “Imminent”
The Dutch NCSC escalated its warning on the Check Point VPN certificate-parsing flaws CSA covered September 15, now assessing exploitation as imminent for unpatched Security Gateways.
Topics Already Covered (No New Action Required)
- Check Point VPN certificate flaws: Dutch NCSC’s “exploitation imminent” warning updates CSA’s existing September 15 research note; no new topic needed.
- Cisco FMC / Qilin ransomware: Already covered September 14; a distinct product line and CVE from the new ISE authentication-bypass flaw above.
- JFrog Artifactory, GitLab CVSS 10 file-read flaw, PaperCut agent-swarm exploitation, Chrome V8 zero-day: All already covered in CSA notes published September 11–15.
- EU AI Act Article 55 incident reporting, EU CRA single reporting platform: Already covered September 12 and 14; today’s OpenAI topic is deliberately framed as a contrast to this existing coverage rather than a duplicate.
- Frontier model monoculture/concentration risk: Multi-agent collusion and frontier model pacing already covered September 11, 12, and 15; today’s BragJack topic is scoped narrowly to the agentic-browser product category to avoid overlap.