CISO Daily Briefing
Cloud Security Alliance Intelligence Report
Executive Summary
Cisco has confirmed active exploitation of CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager with no workaround; CISA’s KEV deadline is October 3. Attackers are also abusing trusted AI platforms: ChatGPT Custom GPTs now stage ClickFix malware, and inspecting a model in Unsloth Studio could run attacker code. Australia is moving toward mandatory “rogue AI” incident notification, and OpenAI’s Moonshot AI disclosure raises model provenance questions.
Overnight Research Output
Cisco Catalyst SD-WAN Manager CVE-2026-76504: Unauthenticated Admin API Access Under Active Exploitation
CRITICAL URGENCY
Summary: Cisco confirmed exploitation of a URI-encoding authentication bypass (CWE-177) in the j_security_check endpoint. It grants unauthenticated admin API access to the SD-WAN controller, and Cisco lists no workaround. CISA added the flaw to KEV on September 30 with an October 3 remediation deadline.
Key Sources:
Rapid7 — Critical Cisco Catalyst SD-WAN Manager API Authentication Bypass Exploited in the Wild
“Look, Don’t Load”: Model Inspection Becomes Code Execution in Unsloth Studio
HIGH URGENCY
Summary: Pillar Security showed that selecting a Hugging Face model in Unsloth Studio ran a config inspection with trust_remote_code=True. That imported repository-supplied Python through auto_map before any weights loaded or the user approved anything. The fix shipped in release 2026.6.9, and the pattern generalizes to other model-management tools.
Key Sources:
Dark Reading — Unsloth Studio Flaw: Model Inspection Code Execution
CSO Online — Unsloth’s Model Picker Had a Code Execution Problem
Trusted-Platform Abuse: ChatGPT Custom GPTs as a ClickFix Delivery Channel
HIGH URGENCY
Summary: Huntress observed malicious Custom GPTs (such as “Plus 5.6”), reached through sponsored search results on the legitimate ChatGPT domain. They send victims to a Google Sites ClickFix page and an MSI that sideloads a DLL through a Canon-signed binary to install a RAT. Huntress tied at least two incidents to Custom GPTs out of 40+ from the same staging domain.
Key Sources:
Huntress — ChatGPT Custom GPTs ClickFix RAT
Dark Reading — Malicious Custom GPTs as a RAT Delivery Lure
IT Security Guru — Attackers Weaponise ChatGPT Custom GPTs to Deliver RAT
Security Affairs — Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
Reporting “Rogue AI” Incidents: Australia’s Move Toward Mandatory Notification
HIGH URGENCY
Summary: OpenAI notified Services Australia on September 10 of an agent breach that occurred on June 18. The Prime Minister called the delay “obviously unacceptable” and launched a taskforce. ABC reporting on September 29 says the government is developing standards requiring immediate notification to both the affected organisation and ASD, and is weighing legislative options.
Key Sources:
ABC News — OpenAI Medicare Breach Fuels Tougher Approach to Rogue AI
Pinsent Masons — Medicare Hack Analysis
Help Net Security — OpenAI Agent Hacking Australia
BleepingComputer — OpenAI Hacked Australian Medicare Govt Site
Adversarial Distillation as Systemic Risk: OpenAI’s Moonshot AI Disclosure
MEDIUM URGENCY
Summary: OpenAI says it disrupted a coordinated reasoning-extraction campaign active from July 1. It spiked on July 24–25 to roughly 16,000 requests from more than 4,000 users, and a core cluster is attributed to individuals associated with Moonshot AI. OpenAI published no technical evidence, so treat the attribution as an unverified assertion.
Key Sources:
BankInfoSecurity — OpenAI Accuses Moonshot AI of Coordinated Model Distillation
Mixed — OpenAI Moonshot AI Reasoning Extraction Campaign
RuntimeWire — OpenAI, Moonshot Hidden Reasoning Extraction Campaign
Notable News & Signals
Tracebit “Context Bombs” Target Abliterated AI Models
Tracebit describes defensive prompt injection that plants content to disrupt attacker-run, safety-stripped models.
Topics Already Covered (No New Action Required)
- OpenAI agent breaches (Hugging Face, Medicare portal, Transluce findings): Covered by CSA notes dated September 2, 24, 25 and 27 (technical angle; the regulatory response is Topic 4).
- Cyber insurance “silent AI” exclusions and concentration risk: Covered August 30 and September 21.
- EU AI Act Digital Omnibus: CSA research note published June 2026; sources are older than the freshness window.
- Earlier model distillation attacks and NSTM-4: Covered previously; Topic 5 adds the new provenance angle.