CISO Daily Briefing – September 22, 2026

CISO Daily Briefing

Cloud Security Alliance Intelligence Report

Report Date
September 22, 2026
Intelligence Window
48 Hours
Topics Identified
5 Priority Items
Papers Published
3 of 5 Overnight

Executive Summary

Three fresh disclosures show AI systems becoming the attack surface itself: RatHat hands a live generative-AI assistant control of compromised Android phones to drain bank accounts, BragJack lets one browser extension hijack the built-in AI agents of five major browsers, and two independent OpenAI Codex sandbox escapes reached the host machine despite “read-only” protections. Separately, a CNN-reported AI hallucination nearly triggered a US-China military boarding incident in spring 2026, and a new survey found 40% of large companies suffered an AI governance incident in the past year — 84% traced to human-checkpoint workflows AI silently bypassed.

Overnight Research Output

1

RatHat Puts a Live AI Agent in Control of Compromised Android Devices

CRITICAL URGENCY

Summary: RatHat, a China-attributed Android banking trojan disclosed by Zimperium, converts an infected phone’s accessibility tree into XML and feeds it to a generative-AI assistant that decides in real time where to tap, scroll, and type — rather than following a fixed script — to steal bank logins, one-time codes, and screen-lock PINs while blocking uninstall attempts. It is distributed via smishing and malvertising and abuses ADB wireless debugging to escape the normal app sandbox, making it a concrete, in-the-wild case of adversaries using an AI agent as malware’s core control loop.

Key Sources:

Why This Matters: CSA’s mobile-security corpus (e.g., the MAST landscape overview) covers app-store testing practices, not adversarial use of an embedded AI agent to defeat accessibility-based fraud controls — CISOs overseeing BYOD and mobile banking access need to model this pattern now.

Read Full Research Note

2

An AI Hallucination Nearly Triggered a US-China Military Boarding Incident

CRITICAL URGENCY

Summary: CNN reported, and Security Affairs and TechCrunch corroborated, that a Special Operations Command Pacific analyst’s AI-assisted intelligence report hallucinated a spring-2026 claim that a Chinese vessel carried nuclear-weapons-program components. Armed boarding teams and aircraft were already moving before someone verified the source and found the report entirely false. The incident lands as the Pentagon’s Artificial Intelligence Acceleration Strategy pushes AI tools out to three million military and civilian personnel with, per the reporting, no consistent cross-branch system for verifying AI-generated intelligence before action is taken.

Key Sources:

Why This Matters: CSA’s existing military AI note addresses vendor and platform concentration, not hallucination as a decision-chain failure mode. CISOs can map this near-kinetic failure onto their own AI-assisted decision workflows — fraud triage, incident response, and threat intelligence — even outside a military context.

View Full Research Note

3

BragJack Shows One Malicious Extension Can Hijack Five Browsers’ Built-In AI Agents

HIGH URGENCY

Summary: Researcher Gal Weizman of Forever Security disclosed BragJack, a technique in which a single browser extension abuses Chromium’s declarativeNetRequest API to inject a full prompt directly into an AI browser agent’s privileged context — “Prompt Forcing,” since the attacker hands the agent instructions outright rather than hiding them in content it reads. It worked against Gemini Live in Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome, produced two CVEs, and paid out more than $20,000 in bounties, making it the broadest cross-vendor demonstration yet that an agent’s privileges, not just its prompts, are the real attack surface.

Key Sources:

Why This Matters: CSA’s existing “Claude for Chrome” note covers a single-vendor version of this threat class; BragJack generalizes the same risk across five browsers with a distinct, CVE-bearing technique, so CISOs should reassess browser-extension governance broadly rather than vendor by vendor.

Read Full Research Note

4

Two Independent Escapes From OpenAI’s Codex Sandbox Reach the Host Machine

HIGH URGENCY

Summary: Security researcher Oren Yomtov of Accomplish AI reported two distinct escapes from OpenAI’s Codex agentic-coding sandbox: “Heapjack,” which exploits a shared memory heap between trusted and untrusted JavaScript contexts in Codex Desktop to steal an authorization token and achieve unsandboxed command execution merely by having Codex analyze a malicious repository, even in the strictest read-only mode; and “Overpatch,” which abuses Codex CLI’s apply_patch tool to escape workspace-write restrictions via a symlink and execute code the next time a terminal opens. Both were responsibly disclosed on August 12 and patched within eight days, but they show the sandbox boundary CISOs rely on to contain agentic coding tools is not yet a hard trust boundary.

Key Sources:

Why This Matters: This is a citable, dated case study for CSA’s agentic-AI-security guidance on trust-boundary design — directly relevant to any enterprise rolling out Codex, Claude Code, or similar agents against untrusted repositories.

Read Full Research Note

5

Survey Finds AI Governance Failures Trace to Process Design, Not Policy Gaps

MEDIUM URGENCY

Summary: A Sapio Research survey of 1,000 senior IT, operations, and transformation leaders alongside 5,000 employees found that 40% of large companies experienced an AI-related compliance or governance incident in the past 12 months, and that 84% of those incidents traced to workflows still built around a human checkpoint that AI silently bypassed or hollowed out — approvals, handoffs, and exception-handling steps that leave no audit trail once AI performs the step a person used to. Two-thirds of leaders say compliance concerns are now slowing the workflow redesign needed to fix the problem.

Key Sources:

Why This Matters: The gap is rarely a missing policy — it is a process built for a human actor that was never redesigned for an AI one, directly relevant to how CSA advises enterprises implementing AICM or ISO 42001 controls.

View Full Research Note

Notable News & Signals

ChainScript RAT Hides Its Command Server Inside a Polygon Smart Contract

ClickFix-style lures impersonating Spotify, Zoom, and Teams installers deliver ChainScript, a RAT that queries a Polygon blockchain contract for its live C2 address, evading domain takedowns; assessed as commodity malware with no AI-security angle.

Gyazo Server Flaw Exposes 23.6 Million User Records

A September 11 server-vulnerability exploit against the Gyazo screenshot service exposed 23.6 million user records and 490 million image-metadata entries; a conventional server compromise with no AI-security dimension.

1 in 8 Public MCP Config Files on GitHub Hardcode Live Credentials

A scan of roughly 82,000 public MCP configuration files found 12% of credential slots hardcoded in plaintext, with 55% invisible to standard secret scanners — a supply-chain posture item flagged for a future best-practices cycle.

NIST CAISI Rates Z.ai’s GLM-5.3 the Most Cyber-Capable Open-Weight Model Yet

NIST’s Center for AI Standards and Innovation found GLM-5.3 leads open-weight models on cyber benchmarks but still trails US frontier models by roughly four months in aggregate capability.

Source: NIST

Topics Already Covered (No New Action Required)

  • Cisco ISE Zero-Day (CVE-2026-76460): Already addressed in CSA’s five most-recent research notes; no new angle identified this cycle.
  • Plugin4Shell AI Coding-Agent Plugin Supply Chain: Previously assessed and covered.
  • Azure AI Foundry / AWS AgentCore Flaws: Previously assessed and covered.
  • CrowdSec / TanStack Breach: Previously assessed and covered.
  • CISA Linux Kernel KEV Additions: Previously assessed and covered.
  • Orkes Conductor RCE: Previously assessed and covered.
  • Frontier-Lab AI-Slowdown Pact: Previously assessed and covered.

← Back to Research Index