CTIPilot
‹Fri · 25 Sep 2026
All daily briefs ↗
Daily brief · UTC day

Friday, 25 September 2026

2 verified findings from 1 run · 2 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01A forged JWT with the wrong signature algorithm walks straight into admin on WSO2's API gateway stack. WSO2's own advisory (WSO2-2026-5328, 2026-05-03) fixed CVE-2026-5430: a JSON Web Token signed with an unsupported algorithm is accepted instead of rejected, letting an unauthenticated attacker forge an admin-scoped session across WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway. WatchTowr's honeypots caught the first forged-token exploitation attempt on 2026-09-13, four months after the fix shipped, and CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-24. Any organization running an internet- or partner-facing WSO2 API gateway below the fixed update level must patch now and treat the gateway as untrusted until it is rebuilt. →
  2. 02Swiss parliament sends a sovereign-cloud mandate to the Federal Council despite its own recommendation to reject it. Switzerland's Federal Assembly moved motion 24.3209 to "referred to the Federal Council" status on 2026-09-23, its own official record shows; the outcome for a motion that has cleared both parliamentary chambers. The Council of States had adopted the motion by a 31:11 vote in March 2026; the motion instructs the Federal Council to submit a legal revision enabling a federally co-financed sovereign cloud service and an independent data-exchange platform to host administration, industry and critical-infrastructure data inside Switzerland, over the Federal Council's own recommendation to reject it. No operational obligation exists yet; the Federal Council must still draft the requested legislation. →

01Research, reports & policy1 item

NOTABLENATOA1

Switzerland's parliament refers a motion ordering a sovereign government cloud and independent data-exchange platform to the Federal Council, over the Federal Council's own recommendation to reject it

Switzerland's Federal Assembly's own Curia Vista record for motion 24.3209, "Für eine souveräne digitale Infrastruktur in der Schweiz im Zeitalter der künstlichen Intelligenz," shows its status moved to "Überwiesen an den Bundesrat" (referred to the Federal Council) on 2026-09-23, with the National Council's own committee deliberation on the motion recorded as concluded shortly before (Swiss Federal Assembly, Curia Vista, 2026-09-23/BusinessStates?$format=json)). The Council of States adopted the motion first, in March 2026, by a 31:11 vote (Netzwoche, 2026-03-23); the referral status now recorded is the outcome for a motion that has cleared both parliamentary chambers, despite the Federal Council formally recommending rejection. The motion instructs the Federal Council to submit a legal revision letting the federal government, cantons, research institutions and the private sector jointly advance, co-finance, steer and monitor a sovereign digital infrastructure, specifically an independent cloud service and an independent data-exchange platform intended to host administration, industry and critical-infrastructure data inside Switzerland ("Die Motion verlangt eine Gesetzesrevision, damit der Bund gemeinsam mit Kantonen, Forschungsinstitutionen und Privatwirtschaft den Aufbau einer souveränen digitalen Infrastruktur vorantreiben, mitfinanzieren, steuern und überwachen kann," translated from German, Laux Lawyers AG, 2026-09). The Federal Council's own rejection cited existing legal bases under the EMBAG federal-IT-infrastructure act and ongoing work on Swiss digital-sovereignty strategy as already covering the request (Netzwoche, 2026-03-23); parliament decided further legislative action is required regardless.

This is a directional, strategic-level signal rather than an immediate operational obligation: the Federal Council must still draft and pass the legislation before any sovereign-cloud or exchange-platform requirement takes effect. It is nonetheless the trigger event for a legislative process that will determine where and by whom federal, cantonal and critical-infrastructure workloads may legally be hosted, with downstream implications for data-residency and supply-chain risk assessments across the constituency this brief serves. Public-sector IT and procurement teams tracking Swiss Government Cloud planning should treat this motion as the point at which a domestic-hosting requirement moved from proposal to a parliamentary mandate the Federal Council cannot simply decline.

"BusinessStatusId": 209, "BusinessStatusName": "Überwiesen an den Bundesrat", "BusinessStatusDate": "/Date(1790187732000)/"

Swiss Federal Assembly, Curia Vista OData service (motion 24.3209 status record) 2026-09-23

The motion demands a legal revision so that the federal government, together with cantons, research institutions and the private sector, can advance, co-finance, steer and monitor the build-out of a sovereign digital infrastructure. In particular, an independent cloud service and an independent exchange platform are envisaged, to host data from companies, administration and critical infrastructure inside Switzerland where possible.

Laux Lawyers AG (translated from German)
policy25 Sep 04:27Zmulti-sourceOpen finding ↗

02Updates to prior coverage2 items

HIGHupdatedNATOB2

Open-source AI pentesting harnesses (Strix, Cairn, Hermes) run an autonomous intrusion-and-skimmer campaign against online retailers for about $25 a target

First published 2026-09-23 · open finding →

Updaterun 2026-09-25T0404Z-intelsourcesbodysourcing_note

Anthropic identified and banned the account behind Hermes's use of an earlier Claude model in this campaign, and Cloudflare took down the operator's staging infrastructure; the operator rebuilt within hours and the campaign continued. Both reactive controls had only marginal disruptive effect.

Anthropic identified and banned the account associated with the campaign after determining that Hermes's operator ran it on an earlier Claude model, Opus 4.6, whose safeguards attempts on newer Claude releases did not get past (Computing UK, 2026-09-23). Cloudflare separately confirmed it had shut down servers connected to the operation. Both actions had only marginal disruptive effect: "researchers said the attacker repeatedly rebuilt the infrastructure and continued the attacks" (Computing UK, 2026-09-23). For defenders, the reinforced lesson is that model-provider account bans and infrastructure takedowns are reactive controls with a short disruption window against a campaign whose own operator economics (a mean cost of $25.46 per target) make rebuilding after a takedown cheap; the underlying web-application defect classes this campaign walks through remain the more durable point of intervention.

HIGHCVE-2026-48842 +3exploitedupdatedNATOA2

CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)

First published 2026-05-28 · open finding →

Updaterun 2026-09-25T0404Z-intelcvestagsactionstechniquesclassificationevidenceentitiesaffected_productssourcesbody

Canada's Cyber Centre updated its advisory on 2026-09-21 to record in-the-wild exploitation of CVE-2026-48842, and NCSC Switzerland updated its own advisory on 2026-09-24 to match, four months after the May patch. Exploitation status moves from patch-available-only to confirmed exploited; the action item is replaced accordingly.

Canada's Cyber Centre updated its advisory on 2026-09-21 to record that "open-source reporting indicates that CVE-2026-48842 is being exploited in the wild" (Canadian Centre for Cyber Security, 2026-09-21), four months after the May patch. NCSC Switzerland updated its own Cyber Security Hub advisory to match on 2026-09-24, recording "Current exploitation status: Actively exploited" and citing the Canadian update as its source (NCSC Switzerland, 2026-09-24). Threat-monitoring nonprofit Shadowserver tracks more than 523,000 internet-exposed Roundcube instances, with no public breakdown of how many remain unpatched (BleepingComputer, 2026-09-24). Where immediate patching is not possible, disabling or removing the virtuser_query plugin removes the vulnerable code path entirely; the plugin is opt-in and mainly used by hosting/ISP-style deployments rather than single-tenant installs.

03Deep dive1 item

HIGHCVE-2026-5430exploitedNATOA1

CVE-2026-5430, WSO2 API Manager, API Control Plane, Traffic Manager, Universal Gateway: a JWT algorithm-confusion bypass reaches full administrative control of the API gateway, exploited since 13 September (CVSS 10.0/9.8)

WSO2's API management stack sits between client applications and the backend services, keys and secrets it fronts, so a broken authentication boundary at the gateway compromises everything behind it. CVE-2026-5430 is exactly that break: a JSON Web Token verifier that should refuse any token signed with an algorithm it does not support instead accepts it, so a forged token is treated as a legitimate, admin-scoped session (WSO2, 2026-05-03). The bug reaches WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway across the release lines WSO2's advisory lists (4.1.0 through 4.6.0), and needs no credentials and no user interaction, WSO2 rates it CVSS 10.0 on multi-tenant deployments and 9.8 on single-tenant, where impact stays inside one security-authority boundary. WSO2 published the fix on 2026-05-03; four months later, on 2026-09-13, exposure-management firm watchTowr's honeypot network caught the first forged-token exploitation attempt in the wild, and watchTowr says it "easily reproduced" the vulnerability based on the vendor's own patch (SecurityWeek, 2026-09-16). CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on 2026-09-24, alongside an unrelated Adobe Commerce flaw (CISA, 2026-09-24).

The forged admin token is not a narrow read-only leak: watchTowr's Yordan Ganchev describes it as yielding "access to every API backend endpoint and its credentials, consumer keys and secrets for every registered application," and notes the gateway is "by definition made to intercept API requests on their way to internal systems," turning a compromised node into what he calls a "Lateral Movement-as-a-Service" product for reaching everything the gateway fronts (SecurityWeek, 2026-09-16). Ganchev also cautions that the observed attack targeted the wrong WSO2 product in watchTowr's own honeypot mix, but the same forged payload worked when replayed against the correct one; a coincidence that will not repeat on every real deployment. One notable inconsistency for defenders relying on the KEV catalog alone: CISA's own alert lists this addition as "WSO2 Multiple Products Path Traversal Vulnerability", a title that matches neither WSO2's advisory nor any researcher account, all of which agree this is a JWT-signature bypass, not path traversal (CISA, 2026-09-24; WSO2, 2026-05-03). A team that searches its KEV feed only for "path traversal" risks missing that this is the entry meant.

Kill chain: an attacker crafts a JWT whose header names a signing algorithm the gateway's verifier does not support, then presents it at the API Manager, Control Plane, Traffic Manager or Universal Gateway front door (T1190, exploiting the public- or partner-facing gateway interface); the verifier's missing algorithm check accepts the token instead of rejecting it, so the forged credential (T1606, Forge Web Credentials) is treated as an authenticated, administrator-scoped session with no legitimate login behind it. From that session the attacker can read every backend endpoint's credentials, every registered application's consumer keys and secrets, and tap API traffic passing through the gateway to internal systems.

Hunt and detection, telemetry class first: in gateway and Carbon HTTP access and authentication logs, look for admin-scoped sessions or privileged API calls with no corresponding identity-provider login event in the same window, that absence, not any single request, is the signal. Where a WAF or reverse proxy in front of the gateway logs JWT or Authorization header fields, check for alg values a correctly configured verifier should never have accepted. In application and consumer-key audit trails, flag reuse, mass export, or unexpected changes to registered applications' keys and secrets immediately following an anomalous authentication event. Start any hunt at 2026-09-13, the date of watchTowr's first observed exploitation attempt, and only look earlier with a specific reason to. Triage: a legitimate admin session traces back to a real, logged identity-provider authentication; an admin-scoped session or privileged API call with nothing behind it in the identity provider's own logs is the discriminator; an old version banner or a single stray Bearer token alone is not enough to escalate on.

Hardening: inventory every WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway node (including partner-facing, OEM and forgotten lab instances) and bring each to its fixed update level (community users can apply WSO2's published fixes directly from its carbon-apimgt and product-apim repositories; support subscribers apply the corresponding WSO2 Updates release). Where immediate patching is not possible, remove management and gateway interfaces from public exposure. Because upgrading fixes the software but says nothing about the window between May and the patch date, any node found running below the fixed level should be treated as untrusted: rotate consumer keys, application secrets and admin credentials, and review every registered application and backend the gateway fronted before trusting it again (WSO2, 2026-05-03; Inception Security, 2026-09-21).

JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access.

WSO2 2026-05-03

The forged token yields access to every API backend endpoint and its credentials, consumer keys and secrets for every registered application

watchTowr's Yordan Ganchev, via SecurityWeek

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CISA 2026-09-24
vulnerability25 Sep 04:26Zmulti-sourceOpen finding ↗

04Action items1 item

Verification & coverage notes1 run

2026-09-25T0404Z-intel · Sonnet 5 · window 26 h · 2 entries published

Verification & coverage notes

2 new entries (vulnerability: 1 deep-dive, policy: 1), 2 updates, 1 deep dive, critical: 0. Standard-cadence window (gap 24.0h, window 26.0h), no catch-up disclosure required.

Dropped by verification (iteration 2): an ASP France ("Coup de pouce énergie" payment-notice IDOR breach) incident entry was composed in Phase 4 and survived Phase 5.5, but two independent cold-reader passes (iteration 1's low-confidence editorial flag, iteration 2's full independent re-read) both found it does not clearly clear the stricter incident/breach relevance bar: no home-region nexus (France, not Switzerland), no named actor, an IDOR is not a novel or materially evolved TTP, and the incident's scale (143,518 records) is not globally significant. Iteration 1's disposition leaned on this store's own precedent for non-home-region public-sector breaches (the AFPA and Japan Digital Agency entries); iteration 2's independent read did not find that precedent persuasive for this specific item. Dropped rather than force a marginal call past two independent challenges, quality over quantity resolves this doubt toward drop.

Mechanical KEV sweep: tools/kev_window_diff.py found 2 in-window CISA KEV additions (2026-09-24): CVE-2026-5430 (WSO2, NOT COVERED, composed as this run's deep dive) and CVE-2026-71362 (Adobe Commerce, COVERED by 2026-08-16/cve-2026-71362-adobe-commerce-customer-account-takeover, whose own cves[].status already read [exploited, patch-available] before this run; the KEV addition is bookkeeping on an already-exploited CVE per PD-13 and ships nothing).

Borderline-drop: Adobe Campaign Classic APSB26-142 revision (18 CVEs, 8 at CVSS 10.0), single-sourced (Adobe's own bulletin plus an NCSC-NL RSS mention only; no second named outlet found), no confirmed exploitation, no PoC, no exposure-forcing mechanic beyond the CVSS score itself. Routine patch-cycle per PD-11(b); does not clear the beyond-normal-cadence bar.

Borderline-drop: IBM MQ (CVE-2026-10747) + Langflow OSS (11 further CVEs, incl. 3× CVSS 9.8), both fixed, no exploitation reported, no PoC, no forcing mechanic beyond severity. Routine patch-cycle per PD-11(b).

Borderline-drop: Recorded Future Insikt Group's "Russia New Generation Warfare" hybrid-campaign update (S3), single-source analytic synthesis with forward-looking indicators; no Switzerland-specific nexus stated (Europe-wide framing only); reads as strategic-level trend/outlook content rather than technical, actionable tradecraft. The retired synthesis/outlook kinds existed for exactly this shape; declined per PD-11 and the v4.0 scope narrowing.

Not published, added to state/coverage_backlog.md: Maileva (Docaposte/La Poste dematerialised-mail brand), confirmed service disruption since 2026-09-23 after unauthorized account-access attempts, but no party names a mechanism, actor, or confirmed data theft; same blocking shape as the Ville du Tampon/Familea/Pays de l'Aigle rows already on the backlog. No evidence-bound techniques[] could be composed without inventing one.

Coverage backlog: all 9 open rows re-checked on today's facts (S1 for the VMware row, S3 for Spring Ring and the three remaining PD-11(d) research items, S4 for the six leak-site/blocked-mechanism rows); all nine: no change. One new row added (Maileva, above).

Cross-domain overlap (deliberate, resolved): S3 independently surfaced Recorded Future's Russia hybrid-warfare update and flagged it as potentially overlapping S2's home-region/policy mission; S2 did not independently surface the same story. Composed as a single disposition (borderline-drop, above) rather than two.

Deep dive: 2026-09-25/cve-2026-5430-wso2-jwt-algorithm-confusion-admin-bypass. Selected under deep-dive criterion 1 (active in-the-wild exploitation with non-trivial exposure, an admin-bypass on API-gateway infrastructure watchTowr characterises as "Lateral-Movement-as-a-Service"). No deep dive published elsewhere today; category identity-infra does not appear in the prior 30 days' rotation.

Notable sourcing finding, main-agent verified: CISA's own alert for CVE-2026-5430 titles it "WSO2 Multiple Products Path Traversal Vulnerability," matching neither WSO2's advisory nor any researcher account, all of which agree on a JWT algorithm-confusion authentication bypass. Confirmed directly against CISA's alert page; disclosed in the entry body so readers searching KEV by category are not misled. (The KEV catalog's own JSON record elaborates further with an "unrestricted file upload"/RCE description and a CWE-347 assignment, but that record is a blocked-source landing-page pattern this pipeline never cites; the entry states only what the cited alert page supports.)

Single-source entries: none. The Swiss sovereign-digital-infrastructure motion traces to the Swiss parliament's own Curia Vista OData record (primary), plus Netzwoche's March 2026 reporting of the Council of States vote and a Laux Lawyers AG legal roundup (both corroborating), genuinely multi-source, not a single first-party record standing alone.

Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0, no product or supplier watchlist configured this deployment.

Coverage gaps: several S3 rotation-source listing pages (volexity, bitdefender-threat-debrief, group-ib, hunt-io, resecurity, pwn-ai) returned 200 but client-side-rendered/stale content with no drillable in-window post list, recipe gaps, not transport failures, logged in work/2026-09-25T0404Z-intel/findings.S3.yaml. S4's ico-uk and cnil-fr listing pages fetched cleanly but surfaced no on-point in-window enforcement notice through the listing alone; venarix.com is a JS-driven SPA with no working recipe. S1 did not sweep its 14-source rotation slice this run (essential-tier + the two mandatory KEV-diff priority pulls consumed the productive research budget); no gap serious enough to have missed a qualifying item, per S1's own assessment.

Essential-coverage: all essential-tier sources across all four domains fetched successfully this run (no misses to disclose).