< ciso
brief />

Hello, stay ahead with CISO Brief πŸš€

Every day the cybersecurity world moves fast β€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence β€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

πŸ‘‰ Join our Telegram channel for your daily update β€” stay informed, stay ready.

Cybersecurity News Digest β€” Daily Briefings

Latest News

all posts β†’

Anthropic trims Claude Code weekly limits by 17%

πŸ”” Anthropic says it will permanently raise Claude Code's standard weekly limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but that follows a temporary 50% boost that ends September 13. The company notes that compared to current temporary allowances, the change equals a 17% reduction starting September 14. Anthropic deleted and reposted its announcement, clarifying the net decrease and promising future usage visibility and control improvements.
read more β†’

Five critical WordPress plugin and theme flaws

πŸ”’ Multiple critical vulnerabilities have been disclosed in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. Reports from Wordfence and Patchstack describe issues ranging from authentication bypass and privilege escalation to arbitrary file writes and remote code execution. Affected versions span multiple releases and require immediate patching or mitigation to prevent complete site takeover.
read more β†’

Brave adds disposable email aliases to improve privacy

πŸ“§ Brave 1.94 adds an Email Aliases feature that generates disposable addresses for signups, keeping users' real emails hidden while forwarding messages. The feature requires a free Brave Account and stores primary and alias addresses encrypted; forwarded messages are delivered then deleted from Brave servers within seconds. Up to five aliases are free, with a paid Premium tier planned, and forwarded mail may initially hit spam folders.
read more β†’

TerminalFix campaign uses reverse-tunnel to pivot

πŸ›‘οΈ Microsoft Threat Intelligence details a TerminalFix campaign, a ClickFix variant that lures users with a fake Cloudflare Turnstile overlay and tricks them into pasting a malicious PowerShell command into Windows Terminal or PowerShell. The command drops a ZIP with a legitimate executable and a malicious DLL that is sideloaded, then uses steganography to extract further payloads from PNG images, establishes dual persistence, performs extensive Active Directory reconnaissance, and deploys a Python-based reverse-tunnel implant for SOCKS-style network access. The chain enables persistent, network-level proxy access and increases risk of lateral movement and data or credential theft.
read more β†’

ServiceNow patches three maximum severity platform flaws

πŸ”’ ServiceNow has released patches for three maximum-severity vulnerabilities in its ServiceNow AI Platform that enable low-complexity code injection, SQL injection, and privilege escalation without user interaction. Cloud instances have been updated, and self-hosted customers are urged to patch immediately. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) could allow attackers to execute arbitrary code, alter or create instance data, and run arbitrary SQL against the database. ServiceNow also patched a high-severity sandbox escape (CVE-2026-6876); the vendor reports no known exploitation to date.
read more β†’

Perturbation probing reveals concentrated LLM safety

πŸ”Ž Our new research introduces perturbation probing, a two-pass, low-cost method that identifies the small set of feed-forward neurons causally responsible for targeted behaviors in aligned LLMs. Applied to Qwen3-4B and Qwen3.5-2B, the method found that tens of neurons (a tiny fraction of the model) control refusal and agreement behaviors, showing alignment can be highly concentrated. The study also defines the FFN/Skip ratio as a quick diagnostic predicting fragility across models.
read more β†’

AWS launches EC2 C8gn instances in Paris region

πŸš€Starting today, Amazon EC2 C8gn instances powered by AWS Graviton4 processors are available in the AWS Europe (Paris) region. These instances deliver up to 30% better compute performance versus Graviton3-based C7gn instances and include 6th generation AWS Nitro Cards with up to 600 Gbps network bandwidth. C8gn supports sizes up to 48xlarge, up to 384 GiB memory, EFA on select sizes, and up to 120 Gbps EBS bandwidth for network-intensive workloads.
read more β†’

Berlin Rejects Ransom After Major State Network Breach

πŸ”’ Berlin's state government confirmed an extortion attempt after its state administrative network was compromised in August and said it will not pay the attackers. Forensics found further data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and 12, 2026, and the scope may include personal or non-public records. Authorities, including state police, the public prosecutor and federal security agencies, are investigating while the Senate continues forensic work and coordination with data protection and security bodies.
read more β†’

Amazon Bedrock AgentCore Memory adds flexible namespaces

🧭 Amazon Bedrock AgentCore Memory now supports flexible namespace variables that let developers scope long-term memories along custom application dimensions such as organization, tenant, team, or environment. Define up to five keys on a memory resource, reference them in a strategy's namespace template, and supply values at runtime via the CreateEvent API so the service substitutes them during memory extraction. The feature helps multi-tenant and complex-hierarchy applications avoid duplicate strategies and provides fine-grained control over memory organization and access. Flexible namespace variables are available today in all Regions where AgentCore Memory is generally available, at no additional cost.
read more β†’

AgentCore Memory Adds Fine-Grained Access Control

πŸ”’ Amazon Bedrock’s AgentCore Memory now supports fine-grained access control (FGAC), allowing per-user and per-tenant memory isolation via AgentCore Gateway without custom authorization code. Administrators can configure OAuth (JWT) authentication and attach Cedar policies to restrict access by caller identity, namespace claims, or specific Memory operations. The feature moves access enforcement into the infrastructure using cryptographic identity proof, and is implemented through the managed AgentCore Memory connector exposing 12 Memory operations as Cedar actions.
read more β†’

AWS Transform added to FedRAMP Class C scope

πŸ”’ AWS Transform is now in scope for FedRAMP Class C in the US East (Ohio) Region, enabling customers to run workloads and build applications subject to those compliance requirements. FedRAMP provides a standardized federal approach to security assessment, authorization, and continuous monitoring. AWS Transform is an agentic migration and modernization service designed to accelerate enterprise migrations and reduce technical debt with less manual handoff and lost context.
read more β†’

PaperCut issues second emergency patch for exploited flaws

πŸ›‘οΈ PaperCut released a second emergency security update after researchers found multiple bypasses of the initial fix for actively exploited vulnerabilities in PaperCut NG/MF. The company disclosed two CVEsβ€”CVE-2026-81578 (auth bypass, 8.8) and CVE-2026-82078 (unsafe dynamic class-loading, 9.4)β€”that can be chained for remote code execution. The updated Emergency Patch Release 2 provides additional hardening and is available for versions 24–26 on Windows, Linux, and macOS; administrators are urged to install it and restrict web interface access.
read more β†’

Extend data perimeter to AWS Management Console

πŸ”’ AWS announces general availability of AWS Management Console Private Access, enabling VPCs with no internet connectivity to access supported service consoles via AWS PrivateLink endpoints. This routes authentication, static assets, console-only APIs, and service API calls through interface VPC endpoints, removing the need for an internet gateway or NAT. The feature is available in all AWS commercial Regions for a select set of consoles and integrates with sign-in resource control policies, VPC endpoint policies, and service control policies to enforce identity, resource, and network perimeters.
read more β†’

GiveWP plugin flaw allows remote command execution

πŸ›‘οΈ GiveWP, a WordPress donation plugin with over 100,000 installs, contained a critical vulnerability (CVE-2026-82222) that allowed attackers to execute arbitrary server commands. Patchstack researchers reported the issue on July 28, showing exploitation required chaining unsafe unserialization, attacker-controlled serialized donations, and a bundled gadget chain. The vendor released a patch in version 4.16.7.2 on August 27 that blocks serialized payloads and cleans affected databases.
read more β†’

Amazon EC2 P6-B300 instances reach more regions

πŸš€ Amazon EC2 P6-B300 instances are now available in Asia Pacific (Hyderabad) and South America (Sao Paulo), expanding regional availability. These instances offer 8x NVIDIA Blackwell Ultra GPUs with 2.1 TB GPU memory, 6.4 Tbps EFA networking, 300 Gbps ENA throughput, and 4 TB system memory. P6-B300 delivers increased networking, GPU memory, and TFLOPS versus P6-B200, targeting training and deployment of large trillion-parameter FMs and LLMs. The p6-b300.48xlarge size is available in multiple AWS Regions including US West (Oregon) and N. Virginia.
read more β†’

Exotic file formats create detection blind spots

πŸ›‘οΈ This article examines how threat actors increasingly use less-obvious file types to bypass defenses and deliver malware. It outlines disk image formats (ISO, IMG, VHD, VMDK) that mount natively and can evade scanning, Office-related formats like .one and .xll that hide scripts or DLLs, and SVG files that can contain JavaScript. The piece also describes polyglot files and a notable IcedID campaign that chained ZIPβ†’ISOβ†’CHMβ†’mshta to deploy payloads, and stresses the need for comprehensive scanning of these formats by security tools.
read more β†’

Attackers Chain Two PaperCut Flaws to Achieve RCE

πŸ›‘οΈ Huntress and watchTowr reported attackers chaining two recently patched PaperCut vulnerabilities to bypass authentication and achieve remote code execution. PaperCut released a second emergency patch with additional hardening after disclosure of CVE-2026-81578 and CVE-2026-82078. Observed activity includes execution of Base64-encoded commands and deployment of a cross-platform Java .class file used for reconnaissance and cleanup.
read more β†’

UK man jailed for running large illegal IPTV service

πŸ” A 68-year-old UK resident, Milan Ibrahim, has been sentenced to over six years in prison after running an illegal IPTV service that generated Β£980,812 over three years. The Police Intellectual Property Crime Unit (PIPCU) described the operation as sophisticated, involving 80 servers and offering pirated broadcasts from major rights holders including BBC, ITV, Sky, the Premier League and the Motion Picture Association. Authorities seized and shut down all servers, potentially exposing users who accessed the service to fines or other consequences, and will pursue Proceeds of Crime Act actions to recover funds.
read more β†’