
12 stories · 4 sources · 1 critical · 1 high · ~8 min read
Coverage: Last 24 hours
Today’s Highlights
A critical remote command execution vulnerability in the Bifrost AI Gateway exposes LLM infrastructure to supply chain risk, prompting immediate patching action for enterprises and cloud teams. Meanwhile, Microsoft has dismantled the EvilTokens AI-driven phishing network, which used device code attacks to compromise thousands of accounts, highlighting the evolution of threat actors targeting cloud authentication. Heightened global attention surrounds superintelligent AI regulation, as the US and UK announce new oversight initiatives and national defense against information warfare.
Table of Contents
- Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
- Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
- Trump to meet China’s Xi as Congress mulls bill banning artificial superintelligence – US politics live
- New UK agency to fight ‘information warfare’ from likes of Russia, Burnham tells UN
Critical High Medium Low
Top Stories
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Source: The Hacker News | Published: Sep 22 | Risk: CRITICAL | Impacted: AI infrastructure teams, ML engineering groups, Cloud security architects | Topics: Exploit / Vulnerability
What happened: A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is disabled.
Why it matters: A trivial remote command execution bug in a widely used AI gateway exposes downstream AI workloads and connected cloud infrastructure to compromise, especially in environments with direct LLM internet routing.
How it works: Bifrost is an open-source gateway system for routing and proxying requests to large language model (LLM) providers. The vulnerability is a pre-authentication RCE in the HTTP management interface, exploitable by a single crafted request.
Affected / Fix: All versions before 2.1.0 are vulnerable; patched in version 2.1.0.
Practitioner Perspective
Organs utilizing Bifrost as an LLM aggregator are at elevated risk until patched, since unauthenticated attackers can execute arbitrary commands on exposed Bifrost gateways. These systems often serve as bridges between internal infrastructure, enterprise data, and external model providers, making them valuable targets. Attackers could leverage the flaw for lateral movement, data exfiltration, or to poison AI workflows. Teams should prioritize this as a critical supply chain risk, patch or segment immediately. The most urgent question: is your Bifrost interface directly exposed or internet-accessible?
Recommended Actions
- Upgrade Bifrost HTTP transport to version 2.1.0 or later, closing CVE-2026-90898 immediately
- Audit for open management interfaces on Bifrost, blocking external network access pending remediation
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Source: The Hacker News | Published: Sep 22 | Risk: HIGH | Impacted: M365 tenants, Okta/AAD customers, Cloud access brokers | Topics: Exploit / Vulnerability
What happened: Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.” The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver.
Why it matters: AI-powered phishing using device code attacks can bypass MFA and session controls, resulting in account takeover at scale, as seen in 12,000 compromised inboxes tied to this service.
How it works: Device code OAuth flows allow users to authenticate from untrusted devices without typing a password, typically requiring a browser and a one-time code. AI was leveraged to automate user targeting, code harvesting, and session token acquisition.
Practitioner Perspective
If your organization relies on device code-based authentication flows, recognize that these are now proven targets for AI-assisted phishing kits. The takedown of EvilTokens shows the attack is not theoretical: mass-scale mailbox compromise occurred through automated device code harvesting. Defenders need to treat device flow phishing as both a credential theft and session hijack vector, stressing detection beyond typical user/password login patterns. Question any lingering trust in device code as an MFA barrier.
Recommended Actions
- Hunt authentication logs for unauthorized device code grant events tied to known EvilTokens tactics
- Block or restrict device code OAuth flows in IdP admin consoles where not required for business
Emerging Signals
Trump to meet China’s Xi as Congress mulls bill banning artificial superintelligence – US politics live
Source: The Guardian | Published: Sep 23 | Risk: MEDIUM | Impacted: AI R&D teams, C-suite and legal, US-headquartered multinationals, Technology procurement leads | Topics: Ics Ot
What happened: President Donald Trump is set to meet Chinese President Xi Jinping today, with artificial intelligence (AI) expected to be a key topic. This comes as Congress considers legislation to ban artificial superintelligence and establish a federal agency to oversee advanced AI development.
Why it matters: Upcoming US regulation and international agreements on superintelligent AI could directly impact how organizations build, deploy, or source advanced AI technology, potentially introducing new compliance requirements or technology restrictions.
How it works: Superintelligent AI refers to systems that could outperform human intelligence across many domains. Regulatory proposals seek to restrict their creation and operation, affecting how organizations develop or source these models and possibly limiting international collaboration.
Practitioner Perspective
Defenders in organizations leveraging AI models should anticipate possible regulatory changes affecting development, deployment, and international supply chains. There is a credible risk that controls on superintelligent AI will be imposed rapidly and with broad mandates, impacting cloud AI providers and cross-border collaborations. Security architecture, third-party vendor risk, and legal teams need to track evolving compliance regimes closely. Adopt a proactive stance towards inventorying high-capability AI systems and align your asset ownership and risk documentation for regulatory scrutiny.
Recommended Actions
- Inventory high-capability AI models and related infrastructure that may fall under new US regulatory definitions of ‘superintelligent AI’
- Engage counsel and third-party risk to evaluate impact of potential bans or licensing requirements on AI supply chains
New UK agency to fight ‘information warfare’ from likes of Russia, Burnham tells UN
Source: The Guardian | Published: Sep 23 | Risk: MEDIUM | Impacted: Corporate comms, Brand protection teams, Security operations centers, UK-based organizations | Topics: Security
What happened: UK Prime Minister Andy Burnham announced the creation of the National Centre for Information Defence to combat disinformation and deepfakes from hostile states like Russia. The centre aims to detect, attribute, and disrupt information attacks, enhancing national resilience against such threats.
Why it matters: Organizational and societal resilience against information warfare now requires stronger detection and attribution capabilities for deepfakes and disinformation, as hostile actors increase sophistication and operational tempo.
How it works: Information warfare leverages deepfake video, synthetic audio, and coordinated social amplification to mislead, disrupt, or discredit targets, often blending AI generation tools with traditional disinfo tactics.
Practitioner Perspective
Security and communications teams face growing exposure to deepfake-enabled phishing, executive impersonation, and market manipulation. The formal establishment of a national agency in the UK signals a shift from ad hoc detection toward systemic, intelligence-driven countermeasures. For multinationals, regional differences in response coordination may mean uneven risk surfaces across business units. Security leaders should revisit incident response protocols for influence operations, including rapid internal notification and public crisis handling.
Recommended Actions
- Deploy or tune deepfake detection models for inbound content, especially targeting exec-facing mailboxes
- Establish playbooks for identifying and responding to coordinated disinformation against your organization
Also Today
- How would AI actually ‘kill all humans’? Here are the top five most likely scenarios | Toby Walsh: A prominent researcher outlines existential risks posed by superintelligent AI, including scenarios involving bioweapons and nuclear escalation.
- Trump praises Burnham despite tensions over AI, Chagos Islands and Iran: Despite AI regulation disputes, Trump calls UK PM ‘a natural businessperson’ after UN talks.
- Big tech says AI can find a cure for cancer. So where is it?: Examines the gap between AI healthcare hype and progress toward cancer cures.
- Rabbit Is Back, This Time With an AI Agent App: Rabbit introduces OS3, a cross-platform AI agent, following previous attempts at dedicated AI devices.
- Grab and OpenAI bring practical AI skills to Southeast Asia: Aims to teach 30,000 Grab partners to use AI tools across Singapore and other nations.
- Better prompt caching for GPT-6: New enhancements offer better cache hit rates, deeper monitoring tools, and up to 90% price reductions for cached GPT-6 inputs.
- Introducing GPT-6 Sol and Luna: OpenAI releases advanced GPT-6 models for ChatGPT and Codex, lowering costs and increasing limits for business and education.
- Parallel cut research time and cost in half with GPT‑6 Astra: Parallel reports 50% efficiency gains for labor market research with GPT‑6 Astra.
Defensive Actions
- Upgrade Bifrost HTTP transport to version 2.1.0 or later to mitigate CVE-2026-90898.
- Audit for open Bifrost management interfaces and block external network exposure immediately.
- Review logs for suspicious or unauthorized command execution on Bifrost endpoints.
- Implement strict firewalling to limit Bifrost interface access to trusted segments.
- Hunt authentication logs for device code grant anomalies related to EvilTokens methods.
- Disable or restrict device code OAuth flows in your identity provider platforms unless required for business.
- Enhance user/admin training about new MFA bypass phishing tactics that leverage device code flows.
- Initiate inventory and compliance documentation for high-functioning AI systems in response to possible US superintelligent AI restrictions.
What We’re Watching
- Monitoring for further exploitation attempts targeting unpatched Bifrost gateways (CVE-2026-90898).
- Indicators of phishing campaigns using device code flows, particularly against Microsoft 365 and Okta.
- Developments around US Congressional action on superintelligent AI export controls and oversight agency mandates.
- Cross-border regulatory moves in the UK, China, and US that could reshape AI procurement and operational risk.
- Escalations in the use of AI-powered deepfakes and disinformation targeting high-profile enterprises and public officials.
Found this briefing useful? Follow the blog to get the next one as soon as it is published, and pass it along to a colleague who owns patching.
Categories: Artificial Intelligence, Cybersecurity Blog
Leave a Reply