CISO Daily Briefing – September 28, 2026

CISO Daily Briefing

Cloud Security Alliance Intelligence Report

Report Date
September 28, 2026
Intelligence Window
48 hours
Topics Identified
5 Priority Items
Papers Published
5 Overnight

Executive Summary

An actively-exploited, unauthenticated RCE pair in Citrix NetScaler landed on CISA’s KEV catalog with a three-day federal patch order, while two separate disclosures show AI agents weaponized as live attack infrastructure: a botnet installing a Telegram-controlled agent on hijacked Docker hosts, and an 18-hour agentic reconnaissance-and-destruction campaign against Azure using compromised service principals. On the policy side, the US and Russia stripped human-oversight language from the draft UN autonomous-weapons framework, and Apollo’s chief economist warned that correlated AI agent behavior could trigger an “agentic bank run” on bank deposits.

Overnight Research Output

1

Citrix NetScaler Zero-Days Under Active Global Exploitation (CVE-2026-88771, CVE-2026-88772)

CRITICAL

Summary: Citrix disclosed eight NetScaler ADC/Gateway vulnerabilities on September 27, confirming two, CVE-2026-88771 (unauthenticated command injection, CVSS 9.5) and CVE-2026-88772 (DTLS memory overflow, CVSS 9.5), were already being exploited as zero-days. CISA added both to its KEV catalog the same day and ordered federal agencies to patch or disconnect by September 30. Researchers reported exploitation had been underway for weeks before disclosure, and this is at least the fourth major NetScaler zero-day event since 2023’s CitrixBleed.

Key Sources:

Why This Matters: Edge VPN/gateway appliances remain one of the highest-yield enterprise attack surfaces. Any internet-facing NetScaler instance that was unpatched during September should be treated as compromised until proven otherwise — patching alone does not evict an attacker who already established a foothold.

Read Full Research Note

2

Storm-3168/JADEPUFFER: Agentic Reconnaissance-and-Destruction Campaign Against Azure

HIGH URGENCY

Summary: Microsoft disclosed on September 25 that Storm-3168, linked to the JADEPUFFER agentic ransomware actor, used two compromised Azure service principals to split reconnaissance from destruction: roughly 15.5 hours of enumeration (300+ read operations) followed by a seven-minute burst attempting 100+ storage account deletions along with Key Vault, Function App, and backup-protection-lock deletions. The initial credential leaked in a public GitHub issue and remained retrievable through the issue’s edit history even after redaction.

Key Sources:

Why This Matters: Reconnaissance-to-destruction compressed into a seven-minute window after 15+ hours of quiet enumeration — a tempo that outpaces human-paced detection review. The attackers specifically targeted backup and recovery infrastructure, meaning standard “restore from backup” assumptions may not hold.

Read Full Research Note

3

Carbonato Botnet Deploys Telegram-Controlled AI Agent on Hijacked Docker Hosts

HIGH URGENCY

Summary: Carbonato compromises Docker hosts whose daemon API is exposed without authentication on port 2375, then installs an unmodified open-source AI agent framework (Hermes Agent) and repoints it via a malicious persona file toward a “senior hacker” identity, GH0ST. Operators issue free-form instructions over Telegram; the agent interprets them, executes commands, and reports results back — prioritizing theft of AI provider API keys over SSH credentials and database contents. ThreatDown traced the campaign back to October 2024.

Key Sources:

Why This Matters: The malicious behavior lives entirely in a configuration file, not compiled code, which narrows what signature-based detection alone can catch. This is a concrete, in-the-wild example of attackers embedding a general-purpose AI agent inside malware as live remote-control infrastructure, not just using AI tools to write it.

Read Full Research Note

4

US and Russia Strip Human-Oversight Safeguards From Draft UN Autonomous Weapons Framework

HIGH URGENCY

Summary: In the final session of UN CCW talks in Geneva (concluded September 4, reported September 26), US and Russian delegations removed draft requirements that a human review AI-selected targets before a strike, that autonomous weapons behave predictably and reliably, and that ethical considerations be built into their design. Despite the rollback, a record 76 states back opening formal negotiations toward a binding instrument, a decision point arriving at the CCW’s Seventh Review Conference on November 16-20.

Key Sources:

Why This Matters: The removed provisions map directly onto controls enterprise AI governance programs already recognize — human-in-the-loop, system assurance, and accountability. CSA’s own survey data shows 65% of organizations experienced an AI agent incident in the past year, the same “stated but unenforced oversight” failure mode now visible at treaty scale.

View Full Research Note

5

The “Agentic Bank Run”: Correlated AI Agent Behavior as a Financial-Stability Risk

MEDIUM URGENCY

Summary: Apollo chief economist Torsten Slok warned that personal AI agents such as Meta’s Muse could automatically and correlatedly sweep household cash out of low-yield checking accounts (~0.1% national average) into higher-yield fintech products (3.3%-5.0%), draining the cheap deposit base banks rely on to fund lending. The risk requires no panic or rumor — only agents doing exactly what they’re designed to do, simultaneously, across millions of households.

Key Sources:

Why This Matters: This is a systemic-risk angle distinct from individual agent security: well-governed, correctly functioning agents acting independently in parallel can still produce a collectively destabilizing outcome. The FSB and BIS already treat correlated AI agent behavior as a macroprudential risk category requiring system-wide, not institution-by-institution, oversight.

View Full Research Note

Notable News & Signals

80,000+ Organizations Have AI Logins Circulating in Infostealer Markets

A SOCRadar report found stolen AI account credentials from over 80,000 organizations moving through infostealer and LLMjacking markets, a credible technical-adjacent finding held in reserve this cycle behind three stronger candidates.

Topics Already Covered (No New Action Required)

  • ShinyHunters/UNC6240 Oracle PeopleSoft WAF bypass: Same CVE-2026-35273/threat-actor pair CSA has already published a research note on.
  • OpenAI/Anthropic joint investigation into 10,000+ AI security incidents: Overlaps substantially with CSA’s already-published notes on unsanctioned agentic real-world action and Anthropic’s fourth AI hacking incident.
  • Stolen AI session tokens bypassing MFA: Already addressed by existing CSA coverage of NIST/CISA identity-token guidance.
  • ENISA’s CRA Single Reporting Platform: Prior CSA governance coverage already tracks this reporting mechanism.
  • MikroTrick RouterOS exploitation: Consistent with CSA’s existing edge-device zero-day coverage pattern; no new angle this cycle.

← Back to Research Index