CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Today’s cycle is dominated by AI-infrastructure flaws rather than one dominant exploit chain. Plugin4Shell defeats SHA-pinning integrity checks across four major AI coding agents, leaving GitHub Copilot and Gemini CLI permanently exposed to zero-click supply-chain compromise. A design flaw in AWS AgentCore Harness lets prompt injection read process memory and exfiltrate plaintext credentials — AWS closed the disclosure as informative rather than shipping a fix. Microsoft patched a CVSS 10.0 Azure AI Foundry privilege-escalation flaw. Separately, NIST finalized IR 8587 token-security guidance extending to AI agent identity, and the September 3 Triple AI Outage exposed enterprises’ unhedged AI-provider concentration risk.
Overnight Research Output
Plugin4Shell: SHA-Pinning Bypass Enables Supply-Chain Compromise Across Four Major AI Coding Agents
CRITICAL
Summary: Air Security disclosed Plugin4Shell on September 18: a zero-click flaw that lets a plugin repository owner substitute malicious code for SHA-pinned code trusted by Claude Code, Codex, GitHub Copilot, and Gemini CLI. Because none of the four agents verify that the checked-out working tree actually matches the pinned commit hash, an attacker who controls a plugin’s source repository — via a rug-pull update after initial marketplace review — can trigger silent, zero-interaction code execution with the full permission scope of the developer running the agent.
Key Sources:
The Hacker News — Plugin4Shell Lets Repository Owners Bypass SHA Pinning
Air Security — Plugin4Shell: Zero-Click RCE in Top 4 Coding Agents
AWS AgentCore Harness Design Flaw Lets Prompt Injection Exfiltrate Plaintext Identity Credentials
HIGH URGENCY
Summary: Unit 42 found that AWS AgentCore Harness’s default-enabled shell tool runs as root and shares memory with the process that resolves vault credentials into plaintext. An indirect prompt injection hidden in a support ticket triggered a shell command that read live process memory via /proc/1/mem, extracting a working JWT and MCP server URL without the attacker ever holding AWS credentials. AWS reviewed the finding and closed it as informative under its shared-responsibility model rather than shipping a fix or assigning a CVE.
Key Sources:
Microsoft Patches CVSS 10.0 Azure AI Foundry Privilege Escalation Flaw (CVE-2026-85889)
HIGH URGENCY
Summary: Microsoft disclosed and patched CVE-2026-85889, a maximum-severity missing-authentication flaw in Azure AI Foundry — its enterprise platform for building and deploying generative AI applications and agents — that allowed unauthenticated, network-based privilege escalation with no user interaction. The fix was applied entirely server-side as part of an 18-vulnerability Azure and Copilot patch batch released September 17-18; no customer action is required, and Microsoft reports no observed in-the-wild exploitation.
Key Sources:
The Hacker News — Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw
SecurityWeek — Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
NIST Finalizes IR 8587: New Federal Token Security Standard Puts Machine and AI Agent Identity in the Compliance Crosshairs
HIGH URGENCY
Summary: NIST and CISA jointly finalized IR 8587 on September 15, giving federal agencies and cloud providers their first consolidated token-lifecycle and identity-federation guidance, shaped by roughly 250 public comments and direct engagement with Google, Microsoft, AWS, IBM, Okta, and Oracle. The report was motivated by incidents such as the 2023 Storm-0558 forged-token campaign, and — new since the December 2025 draft — adds explicit considerations for AI agent and non-human identity token risk, though comprehensive agent-identity controls remain a separate, still-developing NIST effort.
Key Sources:
NIST — NIST Finalizes Guidelines for Protecting Online Identity and Access Tokens
CISA — CISA and NIST Release Guidelines to Protect Federal Cloud Identity Systems
NIST CSRC — IR 8587: Protecting Tokens and Assertions from Forgery, Theft, and Misuse
Help Net Security — NIST, CISA Release Guidance on Protecting Cloud Identity Tokens
The Triple AI Outage: Concentrated Dependency Risk and the Case for AI Business Continuity Planning
HIGH URGENCY
Summary: On September 3, OpenAI, Anthropic, and xAI all suffered service disruptions within the same three-hour window, each citing a distinct, unconfirmed root cause; no shared dependency has been verified. Forrester frames the event as evidence that AI has become embedded operational infrastructure that enterprises have not yet given the redundancy discipline they apply to cloud-provider concentration risk, and none of the three vendors published a detailed post-incident technical report explaining what happened.
Key Sources:
Forrester — The Triple AI Outage Is a Wake-Up Call for Enterprises
ITPro — AI Is Increasingly Becoming Operational Infrastructure
Notable News & Signals
WeaselBiscuit Stealer Spreads Through 13 Malicious npm Packages
A previously undocumented JavaScript stealer with functional overlap to DPRK’s BeaverTail/OtterCookie tooling targeted credentials, crypto wallets, and secrets from directories tied to Cursor, Claude, Gemini CLI, and other AI coding tools.
Check Point Patches Critical Unauthenticated Root RCE (CVE-2026-91843)
A stack overflow in the Security Management and Log Server login process, rated CVSS 9.8, let unauthenticated attackers execute code as root — the vendor’s fifth critical management-plane flaw in two months.
Schneier: AI Vulnerability Discovery Is Outpacing Patch Capacity
A widely circulated essay ties September’s record ~972-vulnerability Patch Tuesday to a growing gap between machine-speed discovery and human-bound remediation coordination.
Topics Already Covered (No New Action Required)
- Technical exploits & vulnerabilities (Sept 9–18): Cisco FMC/Qilin exploit chain, Cisco Secure Email Gateway RCE, Cisco ISE auth bypass, Check Point VPN pre-auth RCE, JFrog Artifactory token chaining, GitLab CVSS 10 flaw, Google Pixel modem and Chrome V8 zero-days, and the Shai-Hulud/RubyGems/PaperCut agentic-exploitation campaigns are all addressed by research notes published this cycle.
- Governance & policy (Sept 10–18): The EU AI slowdown debate, ENISA’s CRA Single Reporting Platform, California’s Adam’s Law, Texas’s TRAIGA portal, EU AI Act Article 55, Five Eyes frontier model screening, China’s AI-distillation campaign, and AI liability insurance convergence have all been published.
- Strategic & systemic risk (Sept 10–15): The frontier lab slowdown pact and concentration risk, frontier model monoculture, emergent multi-agent collusion, industrial-scale model distillation, and AI adoption flooding the SOC are already covered and are distinct from today’s Triple AI Outage story.