< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Amazon S3 Vectors adds metadata pre-filtering option

🔎 Amazon S3 Vectors now supports metadata pre-filtering to evaluate filters before similarity search, returning up to 5x more matching vectors when filters are selective. It also introduces a $startsWith prefix-match operator for filtering on paths and URLs. New indexes in vector buckets enable pre-filtering by default; existing indexes can be updated with the UpdateIndexMode API. The feature is available at no extra cost across commercial and China AWS Regions and will be deployed in the coming days.
read more →

DIVD: Zammad zero-days enabled AI-driven breach

đź”’ The Dutch Institute for Vulnerability Disclosure (DIVD) reports its network was compromised via a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. The attacker used an autonomous AI agent to perform session hijacking, remote code execution, and privilege escalation to root in seconds. DIVD, working with Merlon Security, advised users to upgrade to version 7 or take instances offline while investigations continue.
read more →

OpenAI GPT-6 Astra UltraFast on Amazon Bedrock

🚀 Amazon Web Services now supports OpenAI GPT-6 Astra in an UltraFast mode on Amazon Bedrock, offering a premium speed tier for latency-sensitive workloads. UltraFast promises up to 6x faster inference and throughput up to 300 tokens per second, enabling real-time coding assistants, interactive agents, and responsive customer experiences. AWS provides the underlying inference engine with controls for security, governance, and auditability.
read more →

Over 543,000 Valid Credentials Exposed on GitHub

đź”’ Truffle Security scanned 224 million GitHub repositories and found 543,699 unique credentials that remained valid in July, appearing across more than 1.1 million files and forks. The median exposure time for a credential was 784 days, with about 10% older than 6.3 years and some dating back to 2009. GitHub's Push Protection reduced exposures in covered categories by 53%, but many secrets (like DB strings and Google API keys) remain outside its default scope. Researchers urge immediate rotation, history cleanup, and automated expiration of secrets.
read more →

Aurora Serverless adds instant 16 ACU scaling

⚡ Amazon Aurora Serverless now scales in larger increments, adding up to 16 ACUs within a second and scaling up to 256 ACUs as workloads demand. This launch speeds scaling to meet capacity needs and automatically scales to zero when idle, reducing costs. The enhancement is enabled by default on platform versions 3 and 4, with upgrade paths for versions 1 and 2. Check your cluster's platform version in the AWS Console or via the RDS API.
read more →

Aurora and RDS add AMD-powered R8a instances

🖥️ Amazon Aurora and Amazon RDS now support R8a database instances powered by 5th generation AMD EPYC processors, offering each vCPU as a physical core for consistent per‑core performance. R8a instances deliver up to 75 Gbps network bandwidth and 60 Gbps Amazon EBS bandwidth and are built on the AWS Nitro System with sixth‑generation Nitro Cards. Supported engines include Aurora PostgreSQL/MySQL, RDS for PostgreSQL, MySQL and MariaDB. R8a instances are available in multiple US, Canada, Asia Pacific and European regions and can be launched via the RDS console or AWS CLI.
read more →

Amazon RDS adds AMD M8a instances for databases

🔔 Amazon RDS for PostgreSQL, MySQL, and MariaDB now supports M8a instances powered by 5th‑generation AMD EPYC processors. Each vCPU maps to a physical core for consistent per‑core performance, with up to 75 Gbps network and 60 Gbps EBS bandwidth for high I/O workloads. Built on the AWS Nitro System with sixth‑generation Nitro Cards, M8a instances are available across multiple US, Europe, and Asia Pacific regions. Provision via the RDS Console or AWS CLI and consult RDS documentation for supported engine versions and pricing.
read more →

Zimbra RCE Exploited to Deploy Web Shells and Steal Mail

🛡️ Microsoft found threat actors exploiting CVE-2026-73570 in Zimbra Collaboration Suite to deploy JSP web shells, establish reverse shells, escalate privileges, and exfiltrate mailbox data. The unauthenticated command injection flaw affected systems with SNMP notifications enabled and the optional zimbra-snmp package installed, and was patched in Zimbra 10.1.20 in July 2026. Attackers used varied persistence and lateral-movement techniques, including systemd services, cron jobs, SSH identity reuse, and custom Go-based tooling to harvest credentials and export mailbox databases. Organizations are urged to patch, remove the zimbra-snmp package if necessary, restrict SNMP/SMTP access, rotate secrets, and hunt for web shells and other artifacts.
read more →

Amazon RDS adds MySQL 26.7 in preview

🆕 Amazon RDS for MySQL 26.7 is now available in the Amazon RDS Database Preview Environment, enabling evaluation of the MySQL 26.7 pre-release on Amazon RDS. The release follows the new YY.M calendar versioning and includes bug fixes, security patches, and features like the Change Stream Applier to improve replication apply throughput. Preview instances are retained up to 60 days, snapshots are limited to the Preview Environment, and pricing follows the US East (Ohio) Region.
read more →

Aurora PostgreSQL adds direct Iceberg and Parquet query

🚀 Starting today, Aurora PostgreSQL can directly query operational data alongside data stored in data lakes in Apache Iceberg and Parquet formats using your existing PostgreSQL applications and tools. You can create PostgreSQL foreign tables that reference data in Amazon S3, Amazon S3 Tables, or AWS Glue Data Catalog, and queries against those foreign tables use DuckDB’s high-performance engine embedded in PostgreSQL. The capability supports external Iceberg REST Catalog–compatible catalogs federated via AWS Glue Data Catalog, and data can be materialized into native Aurora tables for low-latency workloads. It is generally available on Aurora PostgreSQL versions 17.11, 18.6 and higher across AWS commercial and GovCloud (US) Regions at no extra charge.
read more →

CloudTrail Event Coverage for Data Plane Logging

🔍 AWS CloudTrail has launched Event Coverage, a console feature that displays data plane event logging coverage across accounts and organizations. It highlights which services and resource types have data event logging enabled and which do not, helping teams identify logging gaps without manual scans. The dashboard consolidates supported data event sources and lets users subscribe to data events directly to close coverage gaps quickly.
read more →

Spanner Omni Now Generally Available for Any Infrastructure

🚀 Spanner Omni, the deploy-anywhere edition of Google Cloud Spanner, is now generally available to run in on-premises data centers, other clouds, or local environments. It brings Spanner's distributed SQL capabilities, multi-model features like vector search and graph, and enterprise-grade security and backup to customer-managed infrastructure. Two licensing tiers and enterprise support options are provided, while operational responsibility and some cloud-integrated features remain the customer's.
read more →

Google Cloud CLI remote MCP server enters preview

🛠️ The Google Cloud CLI remote MCP server is now available in public preview, enabling AI agents to run gcloud and bq commands from a secure, network-isolated execution sandbox. This managed server removes the need to install CLI binaries locally, supports hosted agent platforms, and enforces enterprise-grade controls including zero ambient credentials, IAM-based permissions, Model Armor screening, and Cloud Audit Logging. Agents connect via the MCP standard and authenticate through Agent Identity or OAuth 2.0.
read more →

How cybersecurity startups can win CISOs

🔒 In this Cloud CISO Perspectives post, Alicja Cade and Nick Godfrey from Google Cloud’s Office of the CISO offer practical guidance for cybersecurity startups on building trusted relationships with CISOs, evaluating AI security claims, and aligning to sector requirements. They draw on Google for Startups experience and examples to recommend listening-led product design, establishing technical moats, and preparing for due diligence and regulatory needs.
read more →

CISA warns of critical pre-auth RCE in RouterOS

đź”’ CISA has issued an alert about a critical pre-authentication vulnerability (CVE-2026-84411) in MikroTik RouterOS that can lead to remote code execution or denial of service. The flaw is an integer underflow in the web-management HTTP request handling and can be triggered by a single crafted request to achieve root-level code execution. Affected RouterOS releases are reported to be below 7.24, and MikroTik recommends updating to 7.23 or later; the vendor has not yet published its own advisory.
read more →

Critical Cisco SD‑WAN Manager Zero‑Day Alert

🛡️ Cisco warned on September 30 that attackers are actively exploiting a critical zero‑day, CVE‑2026‑76504, in Catalyst SD‑WAN Manager that allows unauthenticated API access as the admin user. The flaw, tied to mishandled URI encoding in session login requests, scored 9.8/10 and has fixed releases available across affected release trains. Cisco confirmed active exploitation and advised upgrades; no workaround exists and internet‑exposed Managers are at highest risk.
read more →

Why Cybersecurity Skills Matter for Tech Students

🔍 Students in technical fields often worry their education lacks practical skills and fear being unprepared for the job market. Experts say this anxiety is normal and can be eased by building identity capital — practical experience, skills, and connections — through internships, courses, and adjacent learning. With digital threats rising and human error driving incidents, basic cybersecurity knowledge is increasingly essential for employers and graduates alike.
read more →

Cisco warns of SD‑WAN authentication bypass zero‑day

đź”’ Cisco released updates to address a critical zero-day in the Catalyst SD-WAN Manager (CVE-2026-76504) that is being actively exploited to gain admin privileges. The flaw affects API session-based authentication and allows unauthenticated remote access by bypassing an authentication rule via improper URI encoding. Cisco published IOCs and log locations for detection and urged customers to upgrade to fixed releases or open TAC cases for investigation. Multiple fixed releases are listed for affected versions.
read more →