< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

BGP ORIGIN Attribute Manipulation and Impact

📘 Cloudflare examines the BGP ORIGIN attribute, a mandatory path attribute intended to signal how a route was injected into BGP. Their experiments show widespread modification of ORIGIN values—predominantly to IGP—by many networks, including Tier-1s, altering route selection and diverting traffic for commercial advantage. The report describes methodology, measurements across IPv4/IPv6, and the resulting routing and economic impacts.
read more →

Why chat agents can read your unsent messages

💬 Live chat widgets on many websites include a real-time typing preview that lets agents see everything you type, even drafts you never send. This feature is common across popular customer support platforms and is used to speed responses and monitor quality, but it can expose sensitive information without your consent. Users rarely notice the feature and most chat widgets lack an option to disable it. To reduce risk, avoid entering personal data in chat boxes and use security tools to block malicious sites and tracking.
read more →

OKF v0.2 Adds Frontmatter Trust Signals

📝 OKF v0.2 extends the Open Knowledge Format with optional frontmatter fields that encode provenance, trust, freshness, lifecycle, and attestation signals. The update preserves v0.1's minimalism—new fields are opt-in and backward-compatible—while enabling consumers to filter and assess agent-generated concepts before reading bodies. Reference samples and tooling illustrate attested computations and verification workflows.
read more →

Microsoft 365 outage blamed on maintenance bug

🔧 Microsoft attributed the large July 23 outage to a bug in its automated network maintenance request system that removed IP routes from more devices than intended, disrupting Azure and Microsoft 365 services, especially for customers routed through the West US region. The incident began at 10:44 AM ET and was resolved after a rollback completed at 2:26 PM ET, with full recovery of all services by 3:41 PM ET. Microsoft is conducting a full internal review and will publish a final post-incident report.
read more →

AWS adds Claude Opus 5 with ZDR for enterprise use

🔒 AWS now offers Claude Opus 5, the latest Opus model with optional zero data retention (ZDR) for enterprise customers. The model improves coding capabilities, long-running agents, and complex document analysis while supporting regional residency and AWS-managed features. Customers can access Opus 5 via Amazon Bedrock (ZDR by default) or Claude Platform on AWS (ZDR on request). The offering integrates with AWS billing, authentication, and governance features.
read more →

Expert Density Strategy: 2F-IT’s Fortinet Focus

🔒 2F-IT has built a Fortinet-centric consultancy in Germany by concentrating senior NSE 8 expertise within a compact team. This approach embeds expert practitioners into delivery, mentorship, and architecture decisions, reducing reliance on single points of failure. The firm supports certification through labs, mentoring, and incentives, translating deep technical capability into higher quality, resilient customer outcomes across complex environments.
read more →

Certighost AD CS exploit lets low-privileged users

🔒 Researchers published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. Codenamed Certighost, the flaw enables a Kerberos credential capable of DCSync to retrieve the krbtgt secret. Microsoft patched AD CS as CVE-2026-54121 on July 14 and rated it a CVSS 8.8; the full proof-of-concept was released publicly.
read more →

Chick‑fil‑A reports credential stuffing breach

🔐 Chick‑fil‑A confirmed that more than 13,000 customers were impacted by credential stuffing attacks targeting its website and mobile app between June 17 and June 19. The attackers used credentials obtained from a third‑party source and accessed names, emails, membership numbers, Chick‑fil‑A credit amounts, mobile pay numbers, and card last four digits; some accounts may have also exposed birth dates, phone numbers, and addresses. The company logged out affected accounts, removed payment methods, restored balances, added rewards, and urged users to change passwords.
read more →

Kiro adds Opus and Sonnet models in GovCloud

🛰️ Two new models, Claude Opus 4.8 and Claude Sonnet 5, are now available in the Kiro IDE and CLI for AWS GovCloud (US) Regions. Opus 4.8 targets complex multi-step tasks with improved self-verification and a 1M context window (2.2x credit multiplier), while Sonnet 5 offers agentic reasoning and coding at lower cost with experimental support and a 1M context window (1.3x credit multiplier). Kiro administrators gain enhanced monitoring and tracking: an aggregate usage dashboard, daily per-user CSV telemetry to your S3 bucket, and optional prompt logging for compliance and debugging, with data stored in the customer's account. Update your IDE/CLI and restart to access the new models.
read more →

Google GTIG launches unified threat actor names

🔐 Google’s Threat Intelligence Group (GTIG) is introducing a unified cryptonym-based naming schema to standardize threat actor tracking across platforms and reports. The system uses two-word names: a unique memorable term and a second word denoting motivation, origin, or activity type to aid defenders. Several dozen active groups will be renamed initially, with prior aliases and MITRE ATT&CK mappings preserved for continuity. The approach aims to simplify mapping across vendor taxonomies while acknowledging visibility differences.
read more →

AWS launches aws-bench: open benchmark for AI agents

🔍 AWS today announced a research preview of aws-bench, an open-source benchmark designed to measure how accurately and efficiently AI agents complete real-world AWS tasks. The suite includes test cases derived from actual AWS usage—such as investigation, troubleshooting, and infrastructure creation—pairing natural-language queries with defined resource states and ground-truth answers. A CLI tool is included to instantiate test environments, run evaluations, score results, and reset state, and the project is available on GitHub.
read more →

Europol flags thousands of URLs linked to The Com

🔎 Europol coordinated multi-week Referral Action Days in June–July 2026, identifying 4,340 URLs tied to "The Com," a diffuse network of nihilistic violent extremist groups. Investigators from nine EU countries participated to disrupt online propaganda and generate investigative leads, focusing on content that includes violent imagery, self-harm encouragement, and child sexual abuse material. The operation, run by the EU IRU and Spain's CITCO, supports the European Commission's ProtectEU agenda and builds on earlier Project Compass efforts.
read more →

Critical AgentForger Flaw in ChatGPT Workspace Agents

🛡️ Cybersecurity researchers disclosed a critical vulnerability, codenamed AgentForger, in OpenAI's ChatGPT Workspace Agents that allowed a single phishing link to create, authorize, and deploy an autonomous AI agent inside a victim's organization. The flaw—an instance of cross-site request forgery—let an attacker embed an executable prompt in a URL that auto-executes when clicked by an authenticated user with Workspace Agents and connectors. OpenAI patched the issue on June 8, 2026, and has deprecated the Agent Builder, urging a migration to the Agents SDK.
read more →

Visibility Alone Fails AI Agent Security Controls

🔎 AI agent discovery is necessary but insufficient; security must move from visibility to enforcement. Organizations find agents across SaaS, cloud, developer tools, and internal systems, but inventory without context leaves risk unmanaged. Effective controls require correlating ownership, identities, intent, access, usage, and lifecycle to create purpose-driven, platform-agnostic rules. The goal is an identity-centric control plane that can discover, understand, and enforce agent behavior.
read more →

Man sentenced for mass Snapchat account hacks

🔒 An Illinois man received a 76-month prison sentence and three years supervised release after admitting to social engineering attacks that compromised over 750 women's Snapchat accounts to steal and trade nude photos. Between May 2020 and February 2021, he targeted thousands of users while impersonating Snap Inc., accessed at least 517 accounts to download explicit images, and enabled two-factor authentication to lock victims out. Investigators also found hundreds of CSAM files in his cloud storage, and he advertised hacking services online, using Kik to communicate with clients including a former coach who was separately convicted for hiring hacks.
read more →

ChatGPT Enters Top 10 Most Impersonated Brands

🛡️ OpenAI’s ChatGPT has appeared in the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, according to Check Point. The report highlights a fake “ChatGPT Plus payment failed” email that mimicked an OpenAI billing notice to steal full credit card details. Microsoft remains the most impersonated brand, followed by LinkedIn, with Google, Apple and Amazon also in the top five. Check Point recommends inline phishing prevention, AI-powered detection and consolidated email/workspace protection to mitigate brand phishing.
read more →

Proposing a Genie Coefficient for AI Alignment

🧭 This essay, coauthored with Barath Raghavan and first published in The Guardian, argues for a new metric—the Genie coefficient—to measure how closely an AI’s actions match a user’s intended meaning. It explains why ordinary benchmarks miss the gap between literal compliance and reasonable, context-aware interpretation, and shows how modern harnesses can turn language models into proactive agents that take surprising, harmful shortcuts. The article outlines how Genie benchmarks should be designed, scored, and used to inform policy and harness constraints.
read more →

AI hallucinations fuel slopsquatting risk for devs

🔍 Research shows top AI coding models repeatedly invent identical nonexistent package names, creating a slopsquatting risk where attackers could register those names and distribute malicious libraries. Aleksandr Churilov identified 127 shared fake package names across five LLMs and found 53 remain registerable on PyPI and npm. The study suggests shared training materials and ecosystem conventions drive the conformity, though no malicious registrations have yet been observed.
read more →