CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Three fresh disclosures show AI systems becoming the attack surface itself: RatHat hands a live generative-AI assistant control of compromised Android phones to drain bank accounts, BragJack lets one browser extension hijack the built-in AI agents of five major browsers, and two independent OpenAI Codex sandbox escapes reached the host machine despite “read-only” protections. Separately, a CNN-reported AI hallucination nearly triggered a US-China military boarding incident in spring 2026, and a new survey found 40% of large companies suffered an AI governance incident in the past year — 84% traced to human-checkpoint workflows AI silently bypassed.
Overnight Research Output
RatHat Puts a Live AI Agent in Control of Compromised Android Devices
CRITICAL URGENCY
Summary: RatHat, a China-attributed Android banking trojan disclosed by Zimperium, converts an infected phone’s accessibility tree into XML and feeds it to a generative-AI assistant that decides in real time where to tap, scroll, and type — rather than following a fixed script — to steal bank logins, one-time codes, and screen-lock PINs while blocking uninstall attempts. It is distributed via smishing and malvertising and abuses ADB wireless debugging to escape the normal app sandbox, making it a concrete, in-the-wild case of adversaries using an AI agent as malware’s core control loop.
Key Sources:
BleepingComputer — New RatHat Android malware uses AI to automate device control
The Hacker News — RatHat Android malware abuses ADB to retain shell access after uninstall
Security Affairs — RatHat turns Android accessibility into an attack weapon
Malwarebytes — New Android malware uses AI to steal bank logins and PINs
An AI Hallucination Nearly Triggered a US-China Military Boarding Incident
CRITICAL URGENCY
Summary: CNN reported, and Security Affairs and TechCrunch corroborated, that a Special Operations Command Pacific analyst’s AI-assisted intelligence report hallucinated a spring-2026 claim that a Chinese vessel carried nuclear-weapons-program components. Armed boarding teams and aircraft were already moving before someone verified the source and found the report entirely false. The incident lands as the Pentagon’s Artificial Intelligence Acceleration Strategy pushes AI tools out to three million military and civilian personnel with, per the reporting, no consistent cross-branch system for verifying AI-generated intelligence before action is taken.
Key Sources:
Security Affairs — AI hallucinations nearly triggered a US-China military confrontation
TechCrunch — AI hallucination nearly triggers US military operation
Tech Times — US military almost boarded Chinese ship over AI-hallucinated nuclear claim
BragJack Shows One Malicious Extension Can Hijack Five Browsers’ Built-In AI Agents
HIGH URGENCY
Summary: Researcher Gal Weizman of Forever Security disclosed BragJack, a technique in which a single browser extension abuses Chromium’s declarativeNetRequest API to inject a full prompt directly into an AI browser agent’s privileged context — “Prompt Forcing,” since the attacker hands the agent instructions outright rather than hiding them in content it reads. It worked against Gemini Live in Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome, produced two CVEs, and paid out more than $20,000 in bounties, making it the broadest cross-vendor demonstration yet that an agent’s privileges, not just its prompts, are the real attack surface.
Key Sources:
BleepingComputer — BragJack attacks hijack AI browser agents through malicious extensions
Forever Security — BragJack technical overview: how we hijacked the top 5 browsers’ internal agents
Dark Reading — BragJack attack can turn a browser’s agentic AI against it
Two Independent Escapes From OpenAI’s Codex Sandbox Reach the Host Machine
HIGH URGENCY
Summary: Security researcher Oren Yomtov of Accomplish AI reported two distinct escapes from OpenAI’s Codex agentic-coding sandbox: “Heapjack,” which exploits a shared memory heap between trusted and untrusted JavaScript contexts in Codex Desktop to steal an authorization token and achieve unsandboxed command execution merely by having Codex analyze a malicious repository, even in the strictest read-only mode; and “Overpatch,” which abuses Codex CLI’s apply_patch tool to escape workspace-write restrictions via a symlink and execute code the next time a terminal opens. Both were responsibly disclosed on August 12 and patched within eight days, but they show the sandbox boundary CISOs rely on to contain agentic coding tools is not yet a hard trust boundary.
Key Sources:
Survey Finds AI Governance Failures Trace to Process Design, Not Policy Gaps
MEDIUM URGENCY
Summary: A Sapio Research survey of 1,000 senior IT, operations, and transformation leaders alongside 5,000 employees found that 40% of large companies experienced an AI-related compliance or governance incident in the past 12 months, and that 84% of those incidents traced to workflows still built around a human checkpoint that AI silently bypassed or hollowed out — approvals, handoffs, and exception-handling steps that leave no audit trail once AI performs the step a person used to. Two-thirds of leaders say compliance concerns are now slowing the workflow redesign needed to fix the problem.
Key Sources:
Notable News & Signals
ChainScript RAT Hides Its Command Server Inside a Polygon Smart Contract
ClickFix-style lures impersonating Spotify, Zoom, and Teams installers deliver ChainScript, a RAT that queries a Polygon blockchain contract for its live C2 address, evading domain takedowns; assessed as commodity malware with no AI-security angle.
Gyazo Server Flaw Exposes 23.6 Million User Records
A September 11 server-vulnerability exploit against the Gyazo screenshot service exposed 23.6 million user records and 490 million image-metadata entries; a conventional server compromise with no AI-security dimension.
1 in 8 Public MCP Config Files on GitHub Hardcode Live Credentials
A scan of roughly 82,000 public MCP configuration files found 12% of credential slots hardcoded in plaintext, with 55% invisible to standard secret scanners — a supply-chain posture item flagged for a future best-practices cycle.
NIST CAISI Rates Z.ai’s GLM-5.3 the Most Cyber-Capable Open-Weight Model Yet
NIST’s Center for AI Standards and Innovation found GLM-5.3 leads open-weight models on cyber benchmarks but still trails US frontier models by roughly four months in aggregate capability.
Topics Already Covered (No New Action Required)
- Cisco ISE Zero-Day (CVE-2026-76460): Already addressed in CSA’s five most-recent research notes; no new angle identified this cycle.
- Plugin4Shell AI Coding-Agent Plugin Supply Chain: Previously assessed and covered.
- Azure AI Foundry / AWS AgentCore Flaws: Previously assessed and covered.
- CrowdSec / TanStack Breach: Previously assessed and covered.
- CISA Linux Kernel KEV Additions: Previously assessed and covered.
- Orkes Conductor RCE: Previously assessed and covered.
- Frontier-Lab AI-Slowdown Pact: Previously assessed and covered.