CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
AI tooling is now an active ingredient in both attack and defense. A stolen Cloudflare API key let attackers hijack Brevo’s supply chain, injecting ClickFix malware into scripts embedded on 100,000+ customer websites for over five hours. Separately, researchers used Claude Opus 5 to compress a previously failed OpenAI account-takeover exploit chain into a 72-hour success, and North Korea’s Jade Sleet group used the Cursor AI coding assistant itself to trigger dormant macOS backdoors. On the compliance side, the EU AI Act’s Article 50 watermarking deadline lands December 2, 2026, and insurers still cannot price the concentration risk from undeclared enterprise reliance on a handful of frontier AI providers.
Overnight Research Output
Brevo Supply-Chain Attack Injects ClickFix Malware Into 100,000+ Websites
Critical
Summary: A stolen Cloudflare API key allowed attackers to create a malicious Cloudflare Worker that rewrote JavaScript served at the CDN edge for Brevo’s forms widget, Conversations widget, and SDK loader — scripts embedded directly on more than 100,000 customer websites. For roughly 5.5 hours on September 14, the worker ran two payloads simultaneously: a fake Cloudflare verification page pushing ClickFix malware instructions to ordinary visitors, and a detection routine that attempted to install a malicious WordPress plugin whenever a logged-in site administrator was present.
Key Sources:
BleepingComputer — Brevo supply-chain attack injected ClickFix scripts on customer sites
Sansec — Brevo supply chain attack hits 100k+ sites with WordPress backdoors and ClickFix malware
Claude Opus 5 Compresses an OpenAI Account-Takeover Exploit Chain From Weeks to Hours
High
Summary: Security firm Hacktron used Anthropic’s Claude Opus 5 to chain a libheif/ImageMagick heap-buffer-overflow bug in OpenAI’s Discourse-based staff help forum with a weakness in OpenAI’s “Sign in with OpenAI” SSO flow, gaining access to employee ChatGPT and Codex accounts — and, via Codex, an internal OpenAI code repository — in under 72 hours total. The same bug had defeated Claude Opus 4.8 across multiple sessions in the preceding weeks, making this a rare, dated before/after demonstration that a single frontier-model version jump can turn a non-viable exploit chain into a working one almost overnight.
Key Sources:
The Hacker News — Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
The Register — Researchers used Claude to hack OpenAI employees’ ChatGPT accounts
Security Affairs — AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
North Korean Jade Sleet Backdoors Trigger Through the Cursor AI Coding Assistant
High
Summary: SentinelOne disclosed that DPRK-linked group Jade Sleet (TraderTraitor/UNC4899/PUKCHONG) compromised an Indian IT services provider by embedding malicious provider references in a Terraform lock file inside a fake job-interview repository. Running terraform init silently installed the Rust-based FLATROOF and ROOFDECK macOS backdoors, which sat dormant from March 18 to March 29, 2026, before Cursor’s AI coding assistant launched them — seconds after the fact — the moment the victim’s DevOps engineer opened the infected project workspace. The incident reuses malware from the April 2026 KelpDAO/LayerZero crypto-bridge breach but targets a non-crypto IT firm, showing the group broadening its targeting beyond Web3.
Key Sources:
EU AI Act’s Article 50 Watermarking Grace Period Ends December 2, 2026
Medium
Summary: The EU AI Board’s ninth meeting on September 17, 2026 adopted no new rules and set no new deadline, but it reaffirmed the existing compliance calendar — specifically that the Article 50(2) grace period, which lets generative-AI systems already on the market before August 2, 2026 retrofit machine-readable output marking and deepfake-detection capability, expires December 2, 2026. With roughly ten weeks of runway left, this is a concrete near-term obligation, distinct from the December 2027 and August 2028 high-risk-system deadlines, that providers and deployers of “legacy” generative AI need to be actively retrofitting for now.
Key Sources:
Undeclared AI Usage Is Becoming Cyber Insurance’s Concentration-Risk Blind Spot
Medium
Summary: A cluster of September analyses — KYND’s “Wild West of AI Risk” webinar, Munich Re’s 2026 cyber insurance trends report, and a Logistics Viewpoints supply-chain concentration analysis — converge on the same structural gap: an estimated 60-80% of enterprise AI usage runs on a small handful of frontier foundation models, much of it undeclared to IT and security teams (Verizon 2026 data cited at 45% of employees using AI on corporate devices, 67% of that through personal, unmanaged accounts). Cyber insurers currently have no claims taxonomy or underwriting mechanism to price the correlated-loss exposure this creates, and IBM data cited in the same reporting shows AI-enabled breaches already averaging $6 million versus $5 million for conventional breaches.
Key Sources:
Notable News & Signals
Critical Check Point Management Server RCE (CVE-2026-91843)
A CVSS 9.8 unauthenticated stack overflow in Check Point’s login process lets attackers run code as root on Security/Log Management servers; no in-the-wild exploitation observed yet.
SolarWinds ARM Hard-Coded Key Enables Unauthenticated RCE
CVE-2026-28326 (CVSS 8.8) stems from a static key baked into every Access Rights Manager install through version 2026.2; patched in 2026.2.1, no exploitation reported.
ChainScript RAT Uses Polygon Blockchain to Hide C2 Infrastructure
ClickFix-style malvertising delivers a new RAT that resolves its C2 address from a Polygon smart contract, letting operators rotate infrastructure without traditional domain takedowns.
Topics Already Covered (No New Action Required)
- Cisco ISE zero-day (CVE-2026-76460): Covered in CSA research 2026-09-17.
- OpenAI misalignment disclosure framework: Six newly detailed incidents covered 2026-09-17; the September 19 follow-up reporting is the same framework story.
- CISA Linux kernel KEV additions and Orkes Conductor RCE exploitation: Both covered 2026-09-20.
- CrowdSec/TanStack breach and CISA cyber decoy guidance: Covered 2026-09-20.
- Plugin4Shell AI coding-agent plugin supply chain and NIST IR 8587 token-security guidance: Covered 2026-09-19.
- Azure AI Foundry and AWS AgentCore flaws: Covered 2026-09-19.
- Frontier-lab AI-slowdown pact (capability-race angle): Covered 2026-09-15; distinct from this cycle’s insurance-concentration angle (Topic 5).