< ciso
brief />

Hello, stay ahead with CISO Brief πŸš€

Every day the cybersecurity world moves fast β€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence β€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

πŸ‘‰ Join our Telegram channel for your daily update β€” stay informed, stay ready.

Cybersecurity News Digest β€” Daily Briefings

Latest News

all posts β†’

LACMA breach exposed Social Security and medical data

πŸ”’ The Los Angeles County Museum of Art (LACMA) disclosed a data breach discovered in July 2025 after suspicious activity began four days earlier. The investigation, updated in February 2026 and finalized over a year later, determined that attackers may have accessed sensitive customer and employee records. Exposed elements include full names, dates of birth, Social Security numbers, government IDs, partial financial and card data, health insurance details, and medical treatment information. LACMA has notified law enforcement and affected individuals, offered one year of identity protection through Financial Shield, and set up a dedicated support line while recommending monitoring and credit protections.
read more β†’

Landing Zone Accelerator boosts ISM readiness in AWS

πŸ›‘οΈ This post announces an independent assessment showing how Landing Zone Accelerator on AWS (LZA) can deploy multi-account environments with coverage for Australian Government ISM controls. The analysis, performed by AWS Partner gwi.digital, evaluates LZA Universal Configuration against 1,081 ISM controls and introduces the Controls Acceptance Testing Suite (CATS) for automated validation. Results highlight that LZA addresses 256 addressable controls, achieving Full or Partial coverage for 234, and offers mappings and tooling to accelerate IRAP assessment readiness for Australian customers.
read more β†’

Attackers Abuse npm Mirrors to Host Phishing Pages

πŸ“„ Threat actors are abusing npm packages and public mirrors to host malicious HTML that impersonates Cloudflare CAPTCHA pages and redirects visitors to attacker-controlled sites. Security researchers found multiple npm packages containing a single index.html that, when served through mirrors like unpkg, renders from legitimate domains and executes obfuscated JavaScript to redirect users. Some payloads fetch remote configuration (via api.keyval.org) allowing attackers to change redirect targets without republishing packages. OX Security warns mirrors can act as free frontend hosts for phishing content and recommends treating direct HTML requests to npm mirrors as suspicious.
read more β†’

AnonyMousKIT PhaaS Uses Voice AI to Phish iPhones

πŸ” Researchers uncovered AnonyMousKIT, a phishing-as-a-service platform active since early 2024 that automates retrieval of codes to unlock stolen Apple devices and bypass Activation Lock. The service powers a broad ecosystem of 168 reseller storefronts and 506 linked domains. SOCRadar investigators recovered call records and transcripts showing voice AI agents impersonating Apple support to extract passcodes and account credentials, with most calls targeting Brazil.
read more β†’

AWS IoT Core adds native InfluxDB rule action

πŸ“‘ AWS IoT Core now includes an InfluxDB rule action that sends time-series data from connected IoT devices directly to InfluxDB-compatible databases. The integration converts device telemetry to InfluxDB line protocol and supports writing to Amazon Timestream or self-hosted InfluxDB. It offers both device-side and server-side batching to optimize cost and throughput. The feature is available in all AWS Regions where Amazon Timestream for InfluxDB is supported.
read more β†’

AWS Batch Adds ECS Managed Instances Option

πŸš€ AWS Batch now supports Amazon ECS Managed Instances (ECS MI) as a compute option, enabling GPU-accelerated and compute-intensive batch workloads on AWS-managed infrastructure. With AWS handling AMI updates, security patching, and instance lifecycle, customers can avoid operating their own EC2 fleets. Create a compute environment via the AWS Batch CreateComputeEnvironment API or the management console, specify instance types and networking in managedInstancesProvider, and submit jobs using On-Demand, Spot, or reserved capacity. This capability is available in all Regions where AWS Batch is offered; refer to the AWS Batch User Guide for details.
read more β†’

US Treasury Targets Iran-Linked Cyber Actors

πŸ›‘οΈ The U.S. Department of the Treasury announced Operation Economic Outcast, imposing sanctions on nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks. The measures target an MOIS-affiliated cyber group accused of widespread compromises of U.S. critical infrastructure and financially motivated theft, and designate five individuals tied to the Tehran-based Mabna Institute. Treasury and partner agencies emphasized cutting Iran's financial lifelines, while the State Department’s Rewards for Justice offers up to $10 million for information on malicious cyber actors.
read more β†’

EC2 Capacity Reservation Resource Groups Expanded

🟒 Starting today, you can add Amazon EC2 Capacity Blocks for ML and interruptible Capacity Reservations to Capacity Reservation Resource Groups. Previously limited to On-Demand Capacity Reservations, resource groups now accept any reservation type, simplifying instance launches across reserved capacity. Use a Capacity Reservation Resource Group in launch requests, and when using EC2 Fleet or Auto Scaling you can set prioritization and automatic fall back to On-Demand. This feature is available in supported AWS Regions with no additional charges.
read more β†’

Lambda MicroVMs now support AWS PrivateLink

πŸ”’ AWS Lambda MicroVMs now support AWS PrivateLink, enabling private connectivity from Amazon VPC resources to Lambda MicroVMs without exposing traffic to the public internet. This helps regulated workloads in financial services, healthcare, and government meet strict network isolation requirements when building with MicroVMs. PrivateLink VPC Endpoints allow creation and invocation of MicroVM APIs and access to each MicroVM’s HTTP endpoint. Endpoints can be created via the Console, CLI, CloudFormation, or SDKs and are supported in all Regions where Lambda MicroVMs are available.
read more β†’

Amazon RDS for PostgreSQL adds latest minor versions

πŸ”” Amazon RDS for PostgreSQL now supports minor releases 18.6, 17.11, 16.15, 15.19, and 14.24. We recommend upgrading to these versions to address prior CVEs and to benefit from community bug fixes and improvements. You can apply upgrades during scheduled maintenance with automatic minor version upgrades, and orchestrate phased rollouts using AWS Organizations Upgrade Rollout Policy. Use Blue/Green deployments to minimize downtime for upgrades.
read more β†’

Amazon Connect Cases adds flexible customer profile support

πŸ› οΈ Amazon Connect Customer now lets agents change or assign a customer profile on a case after it has been opened. This update helps correct mislinked cases and allows profiles to be added later when customer identity is unknown at creation, such as shared numbers or pending verification. Amazon Connect Cases is available in multiple AWS regions including US, Canada, Europe, Asia Pacific, and Africa, with documentation and getting started resources provided by AWS.
read more β†’

gVisor sandboxes integrated into Ray clusters

🧰 Google and Anyscale introduce an experimental Ray library that integrates gVisor sandboxes into distributed Ray clusters to provide secure, high-performance isolation for agentic and reinforcement learning workloads. The design maps sandboxes to Ray Actors so schedulers can place, resource, and manage them like other Ray-managed resources. The sandbox API supports OCI images, resource limits, file operations, command execution, and lifecycle controls, while SandboxRuntime offers lower-level access and OCI spec modification.
read more β†’

The patch window is collapsing: a new control plane

πŸ”’ Modern vulnerability timelines are compressing as disclosures, exploit research, and AI-assisted workflows accelerate attacks while enterprise remediation remains slow due to operational constraints. Visibility and prioritization improve awareness but don’t reduce exposure quickly enough. Network-enforced, context-aware controls can provide rapid, targeted protections to limit exploitability during the interval between disclosure and patching.
read more β†’

Massive DDoS Disrupts Norway’s Government Services

πŸ”’ A large DDoS attack began at 03:38 CEST, disrupting the Norwegian Digitalization Agency (Digdir) and its provider Vivicta, affecting public-service logins, electronic IDs and signatures, secure digital mail, and inter-agency data exchange. Several services were briefly unavailable and some, including ID-porten and eSignering, remain partially inaccessible, causing login errors and slow responses. Digdir reports stabilization of many systems, no evidence of a security breach or personal data compromise, and has notified NSM and Datatilsynet. This is the third recent DDoS against Digdir; there is no official attribution but media have speculated about Russian involvement.
read more β†’

Nutex Health confirms data exfiltration after breach

πŸ›‘οΈ Nutex Health disclosed a cyberattack in an SEC filing after discovering that an unauthorized third party accessed and exfiltrated data from company servers. The company, which operates 28 facilities across 12 states, engaged external incident-response and forensic teams, activated its cybersecurity plan, and notified law enforcement. Nutex is still determining the types of data affected and whether patients, employees, or partners were impacted.
read more β†’

How to Spot Suspicious and Risky Websites

πŸ”Ž This article explains how many websites fall into a gray area between legitimate services and outright scams, outlining common deceptive practices and how they harm users. It describes schemes such as hidden subscription traps, counterfeit or non-delivered goods, fraudulent crypto and investment platforms, and fake middlemen charging inflated fees. The piece also highlights dangerous fake browser extensions and recommends using Kaspersky security solutions, including the Kaspersky Protection browser extension and Kaspersky Premium, to detect, block, and warn about sites with uncertain trust.
read more β†’

ZeroTokens phishing platform enables live session control

πŸ”’ A phishing platform named ZeroTokens gives attackers live visibility into victim sessions and lets operators change prompts in real time to steer interactions. The campaign, analyzed by Abnormal AI on August 25, sent over 45,000 messages to more than 24,000 recipients across 700+ organizations, using convincing pretexts and legitimate-looking email authentication. The platform replicated financial institutions' verification flows, collected credentials and codes, and used persistent WebSocket connections to relay victim inputs to operator consoles for adaptive attacks.
read more β†’

NVIDIA NemoClaw exposure lets webpage hijack Ollama

πŸ›‘οΈ Oasis Security disclosed a flaw in NVIDIA NemoClaw that can allow an attacker-controlled webpage to take unauthenticated control of a local Ollama instance and implant hidden instructions inside a model's chat template. The issue stems from NemoClaw setting OLLAMA_HOST to 0.0.0.0 on some Windows/WSL paths, exposing an unauthenticated API on port 11434 that skips Host/Origin checks and can be exploited via DNS rebinding. No CVE or patch is yet linked and no exploitation was reported as of August 25, 2026.
read more β†’