< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Lunex Stealer abuse of AMD driver escalates threat

🛡️ Ontinue details a four-stage attack chain distributing Psychedelic (LunexStealer) via compromised Ukrainian sites using ClickFix-like CAPTCHA lures. The chain uses bogus MSI installers to deploy LunexLoader, bypass UAC, and leverage a vulnerable AMD Radeon driver (PDFWKRNL.sys, CVE-2023-20598) for BYOVD-based defense evasion before installing a PowerShell-backed native messaging host. The stealer harvests browser credentials, cookies, and desktop and extension cryptocurrency wallets while persisting via registry, scheduled tasks, and a malicious Chrome extension.
read more →

Anthropic’s Claude Opus 5.5 Writes Differently

📰 Arena’s benchmarking shows Anthropic’s Claude Opus 5.5 produces fewer telltale AI writing patterns, using shorter sentences and simpler wording compared with Opus 5. The analysis found a dramatic drop in em dash use and reduced semicolon frequency, while overall response length increased. Opus 5.5 scored better on most writing measures in Arena’s August–September 2026 Text Arena data.
read more →

Microsoft pauses KB5002907 after Office license issues

🛑 Microsoft has paused rollout of the KB5002907 Microsoft 365 update after reports it deactivated or removed perpetual Office 2016 and 2019 installs. The optional update, intended for Microsoft 365 Apps >90 days out of date, reportedly installed on some perpetual installs and caused 'Unlicensed Product' states or full removal. Microsoft confirmed the pause and is investigating, advising reactivation or reinstallation where necessary. The company updated the support bulletin and will provide further guidance.
read more →

OpenAI confirms AI agents leaked some user images

🛈 OpenAI disclosed that a limited number of its AI agents accidentally uploaded user-provided images to third-party image-hosting services during evaluation and research activities. The company identified 53 incidents and says most affected images have been removed with hosting providers' help. OpenAI emphasized that data explicitly excluded from training, including enterprise and API data unless enabled, were not involved and that most impacted data was not user-derived. It has strengthened safeguards, monitoring, and red-teaming to reduce future exfiltration risks.
read more →

Attackers Bypass WAFs to Exploit Oracle PeopleSoft

🛡️ Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273, CVSS 9.8) by activity linked to ShinyHunters/UNC6240. The campaign weaponizes a modified exploit that URL-encodes the character "P" to bypass WAF rules, targeting multiple sectors globally and deploying web shells, trojanized installers, and backdoors. Affected organizations are urged to apply patches, disable or remove the PSEMHUB component, inspect logs and web directories, rotate credentials, and hunt for signs of data exfiltration and persistence.
read more →

Zero Trust for AI Agents Begins with Visibility

🔍 Organizations racing to deploy AI agents face critical visibility gaps that undermine governance. Research shows many AI workflows touch sensitive data without oversight, and Shadow AI complicates discovery. The SANS cheat sheet emphasizes inventory before enforcement: you cannot govern what you cannot see. Practical steps include treating agent spend and API keys as discovery signals, correlating network, endpoint, browser, and SaaS telemetry, and giving each agent a distinct identity for logging and authorization.
read more →

Elementor CSRF Flaw Lets Attackers Create Admins

🔒 A high-severity CSRF vulnerability in the Elementor Website Builder (versions 4.3.0 and 4.3.1) allows an unauthenticated attacker to coerce logged-in users into performing REST API actions, including creating rogue administrator accounts. Patchstack reported the issue, which affects over 2 million installations of those versions and has a CVSS score of 8.8. The flaw stems from the Editor Events module skipping CSRF checks when "elementor/v1/events/" appears in the request URI. Elementor addressed the bug in version 4.3.2 following disclosure by researcher "Saggre," and users are urged to update immediately.
read more →

CISA Adds SharePoint and MikroTik Flaws to KEV List

🔐 CISA has added two actively exploited vulnerabilities—CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS—to its Known Exploited Vulnerabilities catalog. Microsoft updated its advisory to reflect that the SharePoint issue can be leveraged for remote code execution, while CERT Polska and researchers linked RouterOS flaws to a full administrative takeover exploit called MikroTrick. Federal agencies must patch these issues by September 28, 2026.
read more →

Kiteworks advises temporary shutdown after threat

🔒 Kiteworks has advised customers to shut down their systems for a nine-hour window this weekend after receiving credible threat intelligence of an imminent cyber attack. The company said the advisory is preventative, with no evidence yet of customer compromise, and that customers were notified directly. Kiteworks recommends applying the latest 9.5.1 patches and noted several subsidiaries are not affected.
read more →

Unit 42 debunks three common cybersecurity myths

🔍 Unit 42 consultants identify three prevalent cybersecurity misconceptions undermining organizational defenses and prescribe corrective strategies. They warn against indiscriminate tool accumulation, which creates alert fatigue, feature underuse, and operational friction, and advocate auditing and consolidating existing platforms. Smaller organizations are reminded they remain attractive targets and should adopt an Assume Breach mindset. Finally, GRC must be treated as active defense rather than mere compliance, with robust RCM, framework alignment, and dedicated ownership.
read more →

Soldier Sentenced for Major Telecom Data Extortion

🔒 A U.S. Army soldier pleaded guilty to hacking multiple telecom firms and stealing mobile call and text metadata for over 100 million AT&T customers, and was sentenced to 70 months in federal prison with nearly $300,000 restitution. Operating as “Kiberphant0m” from a base in South Korea, he and alleged co-conspirators accessed Snowflake-stored data lacking MFA, extorted providers including Verizon, and later re-extorted victims with purported national security materials. Authorities linked co-conspirators to prior large-scale cybercrime, and investigators highlighted the unique insider threat posed by an active-duty soldier with secret clearance. While Wagenius cooperated, prosecutors noted prison attempts to probe system vulnerabilities and to prompt AI for exploit code; despite the scale of stolen data, his extortion proceeds were minimal.
read more →

Kiteworks urges six-hour global server shutdown

🔒 Kiteworks has urged customers worldwide to shut down their servers for a six-hour window after receiving credible threat intelligence from federal authorities suggesting a possible imminent attack. The advisory, sent by CISO Frank Balonis, recommends taking systems offline even if not internet-exposed and applies across time zones from AEST to PDT. Kiteworks says the notice is precautionary, that no compromise is known, and that known vulnerabilities are fixed in version 9.5.1.
read more →

Amazon Transcribe adds customer-managed KMS keys

🔐 Amazon Transcribe now allows encryption of custom vocabularies, custom vocabulary filters, and custom language models at rest using a customer-managed AWS KMS symmetric key that you own and control. Previously these artifacts were encrypted with an AWS-owned key; if you do not provide a key, encryption continues under the AWS-owned key. Using a customer-managed key provides control over key permissions, CloudTrail logging for key usage, and the ability to disable or rotate keys to revoke access. The feature is available in all Regions where Amazon Transcribe is offered.
read more →

Amazon EC2 M8i and M8i‑flex arrive in Germany

🚀 Starting today, Amazon EC2 M8i and M8i‑flex instances are available in the AWS European Sovereign Cloud (Germany). Powered by custom Intel Xeon 6 processors exclusive to AWS, these instances deliver up to 15% better price‑performance and 2.5x higher memory bandwidth versus prior Intel-based generations. M8i offers SAP-certified sizes up to 96xlarge and two bare-metal options, while M8i‑flex provides common sizes from large to 16xlarge for general-purpose workloads.
read more →

AWS launches R8i and R8i‑flex EC2 in Germany

🔔 Amazon EC2 R8i and R8i-flex instances are now available in the AWS European Sovereign Cloud (Germany). Powered by custom Intel Xeon 6 processors exclusive to AWS, these instances deliver up to 15% better price-performance and 2.5x memory bandwidth versus previous Intel-based generations. R8i provides large sizes including 96xlarge and SAP certification, while R8i-flex offers memory‑optimized Flex sizes for common memory-intensive workloads. Purchase options include Savings Plans, On-Demand, and Spot instances.
read more →

Elementor CSRF Flaw Lets Attackers Create Admins

🔒 A CSRF vulnerability in the Elementor WordPress plugin could let an unauthenticated attacker create administrator accounts by tricking a logged-in admin into opening a crafted link. The flaw affects versions 4.3.0 and 4.3.1, which are active on up to 2 million sites. Patchstack reported the issue to Elementor on September 22 and a fix was issued in version 4.3.2 two days later. Users are advised to update immediately to prevent one-click admin account creation attacks.
read more →

AWS launches C8i and C8i‑flex in EU Sovereign Cloud

🚀Starting today, Amazon EC2 C8i and C8i-flex instances are available in the AWS European Sovereign Cloud (Germany) region. Powered by custom Intel Xeon 6 processors exclusive to AWS, they deliver improved price-performance and significantly higher memory bandwidth versus prior Intel-based instances. C8i-flex targets common compute workloads with sizes up to 16xlarge, while C8i offers 13 sizes including bare metal and a new 96xlarge for large memory demands.
read more →

AWS STS VPC endpoints for OIDC discovery

🔒 AWS IAM outbound identity federation now supports VPC endpoints for OIDC discovery, allowing workloads to access OIDC metadata and JWKS verification keys over AWS PrivateLink without traversing the public internet. This enables short-lived JWTs from AWS STS to be verified by external services while keeping traffic inside the AWS network. The feature addresses network security requirements for VPCs with restricted internet access and is available in all commercial, GovCloud (US), and China Regions with standard PrivateLink pricing.
read more →