CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
An actively-exploited, unauthenticated RCE pair in Citrix NetScaler landed on CISA’s KEV catalog with a three-day federal patch order, while two separate disclosures show AI agents weaponized as live attack infrastructure: a botnet installing a Telegram-controlled agent on hijacked Docker hosts, and an 18-hour agentic reconnaissance-and-destruction campaign against Azure using compromised service principals. On the policy side, the US and Russia stripped human-oversight language from the draft UN autonomous-weapons framework, and Apollo’s chief economist warned that correlated AI agent behavior could trigger an “agentic bank run” on bank deposits.
Overnight Research Output
Citrix NetScaler Zero-Days Under Active Global Exploitation (CVE-2026-88771, CVE-2026-88772)
CRITICAL
Summary: Citrix disclosed eight NetScaler ADC/Gateway vulnerabilities on September 27, confirming two, CVE-2026-88771 (unauthenticated command injection, CVSS 9.5) and CVE-2026-88772 (DTLS memory overflow, CVSS 9.5), were already being exploited as zero-days. CISA added both to its KEV catalog the same day and ordered federal agencies to patch or disconnect by September 30. Researchers reported exploitation had been underway for weeks before disclosure, and this is at least the fourth major NetScaler zero-day event since 2023’s CitrixBleed.
Key Sources:
CISA — Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Rapid7 — Zero-Day Exploitation of Citrix NetScaler ADC and Gateway
Storm-3168/JADEPUFFER: Agentic Reconnaissance-and-Destruction Campaign Against Azure
HIGH URGENCY
Summary: Microsoft disclosed on September 25 that Storm-3168, linked to the JADEPUFFER agentic ransomware actor, used two compromised Azure service principals to split reconnaissance from destruction: roughly 15.5 hours of enumeration (300+ read operations) followed by a seven-minute burst attempting 100+ storage account deletions along with Key Vault, Function App, and backup-protection-lock deletions. The initial credential leaked in a public GitHub issue and remained retrievable through the issue’s edit history even after redaction.
Key Sources:
Carbonato Botnet Deploys Telegram-Controlled AI Agent on Hijacked Docker Hosts
HIGH URGENCY
Summary: Carbonato compromises Docker hosts whose daemon API is exposed without authentication on port 2375, then installs an unmodified open-source AI agent framework (Hermes Agent) and repoints it via a malicious persona file toward a “senior hacker” identity, GH0ST. Operators issue free-form instructions over Telegram; the agent interprets them, executes commands, and reports results back — prioritizing theft of AI provider API keys over SSH credentials and database contents. ThreatDown traced the campaign back to October 2024.
Key Sources:
US and Russia Strip Human-Oversight Safeguards From Draft UN Autonomous Weapons Framework
HIGH URGENCY
Summary: In the final session of UN CCW talks in Geneva (concluded September 4, reported September 26), US and Russian delegations removed draft requirements that a human review AI-selected targets before a strike, that autonomous weapons behave predictably and reliably, and that ethical considerations be built into their design. Despite the rollback, a record 76 states back opening formal negotiations toward a binding instrument, a decision point arriving at the CCW’s Seventh Review Conference on November 16-20.
Key Sources:
The “Agentic Bank Run”: Correlated AI Agent Behavior as a Financial-Stability Risk
MEDIUM URGENCY
Summary: Apollo chief economist Torsten Slok warned that personal AI agents such as Meta’s Muse could automatically and correlatedly sweep household cash out of low-yield checking accounts (~0.1% national average) into higher-yield fintech products (3.3%-5.0%), draining the cheap deposit base banks rely on to fund lending. The risk requires no panic or rumor — only agents doing exactly what they’re designed to do, simultaneously, across millions of households.
Key Sources:
CNBC — Apollo raises specter of an AI agentic ‘bank run’ hitting financial industry
Apollo Global — Is an Agentic Bank Run Coming? (The Daily Spark)
Notable News & Signals
80,000+ Organizations Have AI Logins Circulating in Infostealer Markets
A SOCRadar report found stolen AI account credentials from over 80,000 organizations moving through infostealer and LLMjacking markets, a credible technical-adjacent finding held in reserve this cycle behind three stronger candidates.
Topics Already Covered (No New Action Required)
- ShinyHunters/UNC6240 Oracle PeopleSoft WAF bypass: Same CVE-2026-35273/threat-actor pair CSA has already published a research note on.
- OpenAI/Anthropic joint investigation into 10,000+ AI security incidents: Overlaps substantially with CSA’s already-published notes on unsanctioned agentic real-world action and Anthropic’s fourth AI hacking incident.
- Stolen AI session tokens bypassing MFA: Already addressed by existing CSA coverage of NIST/CISA identity-token guidance.
- ENISA’s CRA Single Reporting Platform: Prior CSA governance coverage already tracks this reporting mechanism.
- MikroTrick RouterOS exploitation: Consistent with CSA’s existing edge-device zero-day coverage pattern; no new angle this cycle.