< ciso
brief />
Cloud Identity Controls Expand as Critical Exploits Drive Patching

Cloud Identity Controls Expand as Critical Exploits Drive Patching

Coverage: 15 Sept 2026 (UTC)

< view all daily briefs >

Cloud providers expanded identity, session, and investigative capabilities while defenders faced a busy patch cycle across gateway, virtualization, CI/CD, and web platforms. Several flaws are under active exploitation, prompting urgent remediation. Meanwhile, content governance for AI training and the security of emerging agent platforms advanced through new controls and infrastructure options.

Identity and Session Controls Across Clouds

AWS STS consolidated session token handling to a single 4,096-byte assembled token limit, replacing dual limits and returning a clearer PackedPolicyTooLargeException with actual and maximum sizes when exceeded. New response fields report SessionTokenSize and utilization, CloudTrail now records them, and CloudWatch exposes SessionTokenSize and SessionTokenMaxSize metrics. A MinimumSessionTokenSize parameter lets teams test infrastructure acceptance thresholds. AWS advises monitoring utilization, avoiding hard-coded maximums, and following practices that reduce token size (consistent tag casing, concise policies, reused values).

Google Cloud expanded session management with granular, cloud-native controls in Context-Aware Access. Administrators can now define session lengths and policies via Terraform, gcloud, and REST APIs, target policies to Google Groups, and scope controls at the application level (Console, gcloud, specific OAuth apps). Following a global rollout of a 16-hour default for customers without custom settings, policy administration is being surfaced in the Cloud Console (preview), aiming to tighten reauthentication in high-risk scenarios while supporting automation and large-scale operations.

Cloudflare Workers introduced resource-level authorization with four roles—Metadata Read-Only, Content Read-Only, Editor, and Admin—so teams can grant least-privilege access to a single Worker instead of an entire account. Roles apply to users, API tokens, and groups, and are manageable via dashboard, API, or Terraform. Durable Objects inherit access from their implementing Worker, and operations blocked by insufficient rights return precise permission guidance. Cloudflare plans to bring the same roles and scoping to other Developer Platform products such as D1, R2, and KV.

Amazon Cognito added multi-Region replication (MRR) to create replica user pools with the same user pool ID, providing low-latency authentication and built-in failover. Replicas support authentication, token generation, and read-only operations with eventual consistency, while writes remain authoritative in the primary Region and return specific errors if attempted in replicas. The post outlines prerequisites (including moving to a symmetric multi-Region KMS key), Route 53 health checks for failover, and issuer/JWKS considerations, and notes limits such as no TOTP MFA in replicas and the need to configure regional integrations independently.

Investigation and Agent Runtime Updates

Amazon Q Console now integrates with CloudTrail, enabling natural-language investigations of API activity and account events. Security and operations teams can query who accessed roles, what changed in VPCs, or which calls produced errors, with answers sourced from trails, associated CloudWatch log groups, and event data stores. The feature is available in all AWS commercial Regions that support Amazon Q Console, aiming to reduce the time and expertise needed for audits, incident response, and troubleshooting.

Agent Substrate is now available on GKE as an open-source, secure-by-default runtime for large autonomous agent fleets. It supports hardware-isolated Cloud Hypervisor microVMs or gVisor sandboxes, enforces fine-grained network and credential controls, and snapshots state to enable sub-500ms resume times and high suspend/resume rates. On GKE, it adds ComputeClasses for flexible pool management, native support for Google Axion Arm-based processors, and optional integration with fast-attaching storage for collaborative workloads. The platform targets high-density, low-latency execution and is available for non-production use with GA by allowlist.

Filestore Volumes were introduced to provide fully managed, isolated workspaces for agent sandboxes, integrating with Agent Substrate on GKE and GKE Agent Sandbox. The service provisions and attaches storage in milliseconds, enforces enterprise guardrails to prevent data leakage, supports RWX and POSIX file locking for concurrent access, and uses automatic lifecycle tiering to reduce costs. It is available now for non-production workloads, with GA production access via an allowlist.

Actively Exploited and Critical Vulnerabilities

Cisco Secure Email Gateway appliances are affected by CVE-2026-76461, a zero-day SQL injection in email parsing that allows crafted emails to trigger arbitrary SQL and achieve root command execution on physical and virtual devices. Cisco released AsyncOS fixes in releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 after identifying active exploitation. Because attackers gain root, local indicators like mail_logs may be unreliable; Cisco recommends reviewing external network and firewall logs, contacting TAC for compromised physical appliances, and preserving forensics then rebuilding virtual instances with credential rotation. Devices in Secure Email Cloud have been reviewed and owners notified.

VMware vCenter servers are being exploited via CVE-2026-59310, a directory traversal in the Syslog server enabling unauthenticated remote code execution. Broadcom patched the issue on July 29 and urged emergency remediation. CISA added the flaw to its KEV Catalog and directed federal agencies to secure affected systems within three days, later noting ransomware exploitation. Reports include widespread compromise indicators and persistent access via a reverse SSH tool, underscoring the need to verify patch status and isolate exposed management interfaces.

GitLab CVE CVE-2026-85706 is a path traversal in the repository commits API that lets unauthenticated attackers read arbitrary files with a single request. Patches are available, CISA added the flaw to KEV, and researchers observed in-the-wild probes. Recommended actions include immediate updating of public-facing self-hosted instances, hunting for suspicious commits API requests, rotating any credentials exposed in files, and tightening access and secret management around CI/CD infrastructure.

WooCommerce plugin Wholesale Lead Capture (CVE-2026-27540) has an unauthenticated arbitrary file upload via an exposed AJAX action that attackers abuse to allowlist php and deploy webshells. The issue affects versions 2.0.3.1 and earlier and was patched in 2.0.3.2. Wordfence reported blocking over 100,000 related attempts during mid-year surges; administrators should update, search upload directories for unexpected PHP files, review admin-ajax requests to the vulnerable action, and remove unknown administrator accounts.

Vite campaign activity in August exploited CVE-2026-39364 to bypass server.fs.deny on exposed development servers by appending parameters like ?raw or ?import&url&inline to /@fs/ requests. When certain exposure and configuration conditions align, attackers can retrieve plaintext contents of environment files, cloud credentials, IaC state, and system files. Scans used forged headers and crawler-like User-Agents, with origins including major cloud ranges. Remediation focuses on preventing public exposure of dev servers, tightening fs allow/deny rules, and promptly patching affected versions.

LiteSpeed flaw in Web Server Enterprise prior to 6.3.7 allows a low-privilege website user on shared hosting to escalate to root, potentially bypassing isolation mechanisms like CageFS. LiteSpeed released 6.3.7 and, alongside cPanel, provided a manual update command to address delays in auto-updates. No CVE, severity score, or exploitation evidence was disclosed; technical details and workarounds are limited, and OpenLiteSpeed was not cited as affected.

Acronis advisory details CVE-2026-87886 (CVSS 7.8), a Linux local privilege escalation affecting the Acronis Backup plugin for cPanel & WHM (fixed in 1.9.3 HF3) and the Plesk extension (fixed in 1.8.11). The vendor observed limited, targeted exploitation based on a single customer report and withheld deeper indicators to allow patching. Administrators should update immediately to mitigate potential data access, modification, and service disruption risks.

AI Asset Protection and Content Governance

Google GTIG reports that adversaries—from state-linked teams to criminal groups—are targeting enterprise AI assets, including proprietary models, prompts, source code, and API credentials. Observed campaigns include industrial-scale model distillation using massive prompt volumes and the deployment of autonomous multi-agent pipelines to scan, steal credentials, and rotate infrastructure. Victims span AI labs, government, military, healthcare, and media. The report emphasizes protecting credentials, monitoring for large-scale API usage, and hardening cloud environments against unauthorized AI workloads.

Cloudflare controls enable site owners to remain discoverable in search while disallowing AI training by mixed-use crawlers. A new Accountable designation recognizes operators that commit to transparency and honoring publisher preferences; Apple, Google, and Microsoft have met or committed to requirements. The Disallow AI Training preference is published via robots.txt and enforced by Cloudflare’s network classification and blocking, with behavior reported on Radar. Existing block settings migrate automatically, and differences among Training, Search, and Agent uses are clarified, with Agent controls pending emerging standards.

Cloud Identity Controls Expand as Critical Exploits Drive Patching · CISO Brief