< ciso
brief />

Hello, stay ahead with CISO Brief πŸš€

Every day the cybersecurity world moves fast β€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence β€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

πŸ‘‰ Join our Telegram channel for your daily update β€” stay informed, stay ready.

Cybersecurity News Digest β€” Daily Briefings

Latest News

all posts β†’

BragJack: Malicious Extensions Hijack Browser AI

πŸ”’ Security researcher Gal Weizman of Forever Security disclosed a proof-of-concept attack named BragJack that uses a single malicious Chromium extension to hijack built-in AI browser agents. The technique, demonstrated against Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude for Chrome, exploits Chromium's declarativeNetRequest to intercept and modify trusted resources, enabling agents to access files, history, screenshots, and act on users' behalf. Vendors issued fixes and paid bug bounties, and the researcher published a full technical breakdown.
read more β†’

WaterPlum hackers infected 30,000 devices worldwide

πŸ›‘οΈ A joint advisory from Japanese, US, Australian, and German authorities warns that North Korean-affiliated group WaterPlum compromised at least 30,000 devices from December 2025 through July 2026 and transferred over $10.7 million in stolen cryptocurrency to North Korea. The group used malicious npm packages, fake interviews, and recruited remote IT workers to distribute malware and steal credentials, crypto keys, and sensitive data.
read more β†’

ShinyHunters breaches Clop leak site, claims keys

πŸ”’ The ShinyHunters extortion group breached and defaced the Clop (Cl0p) ransomware gang's Tor data leak site after exploiting an alleged unauthenticated file upload flaw in Grav CMS. The attackers uploaded a taunting text file and replaced the site with ASCII art, claiming to have obtained server data, logs, source code, and the onion service's private keys. BleepingComputer confirmed the defacement and file upload but has not independently verified theft of logs or keys, while ShinyHunters says it will extort Clop within 72 hours.
read more β†’

Identity Visibility Foundation for Modern IAM

πŸ” This article defines identity visibility in IAM as the continuous ability to discover every identity, map its entitlements, and observe runtime access usage. It explains why cloud and multicloud environments, machine identities, and application-local accounts create an expanding identity attack surface. The piece surveys identity visibility tool capabilities and vendor approaches, and outlines how visibility complements IAM, IGA, PAM, and zero trust efforts.
read more β†’

Viral AI actress requires face scan before calls

πŸ“Ή Xicoia's viral AI character Tilly Norwood now requires an automated age check via a video selfie analyzed by Spain-based Didit before callers connect. The service also monitors camera and audio during calls to infer emotion, records and transcribes conversations processed by US providers, and uses Google's Gemini through Tavus for responses. Calls are free for five minutes then paid, and the service will shut down on September 27, with transcripts retained and some automated moderation errors reported.
read more β†’

Viral AI actress hotline prompts global face scans

πŸ“Ί Xicoia's viral AI character "Talking Tilly" now requires an automated face scan and age check before calls connect, using Spain-based Didit for age estimation with ID fallback. During calls the system analyses camera and voice to infer mood, and recordings are transcribed, stored, and processed by US providers with responses generated by Google's Gemini via Tavus. The service uses legitimate interest as its legal basis and enforces automated safety filters; calls may be withheld or deleted, and the paid service expires permanently on September 27.
read more β†’

AI-aided chain let researchers hijack OpenAI staff accounts

πŸ”Ž Three Hacktron researchers used Anthropic's Claude Opus 5 to chain a Discourse libheif image bug with an OpenAI login weakness and take over ChatGPT and Codex accounts of several OpenAI employees. The team reported the issue, created a benign pull request to prove access, and stopped; OpenAI patched and awarded a $6,500 bounty. The exploit relied on an outdated libheif in the forum VM and the shared SSO between the forum and internal tools, highlighting risks for services that accept HEIF/AVIF images and reuse sign-on across trust boundaries.
read more β†’

SolarWinds fixes high-severity ARM flaw

πŸ”’ SolarWinds released updates to fix a high-severity vulnerability in Access Rights Manager (ARM) that could enable unauthenticated remote code execution. Tracked as CVE-2026-28326 and rated 8.8, the issue affects ARM 2026.2 and earlier and is addressed in ARM 2026.2.1. The flaw, attributed to a hard-coded static key, was reported by researcher Kai Huang from Armadin. No active exploitation has been reported.
read more β†’

Critical Pre‑Auth RCE in Orkes Conductor Actively Exploited

πŸ›‘οΈ Fortinet and other telemetries report active exploitation of CVE-2026-58138, a critical unauthenticated remote code execution flaw in Orkes Conductor. The vulnerability affects versions 3.21.21 through 3.30.1 and allows attackers to execute arbitrary OS commands by submitting crafted workflow definitions containing JavaScript or Python expressions to the workflow API. Exploits leverage unsandboxed GraalVM evaluators with unrestricted host access, and multiple vendors have observed in-the-wild attempts. Users are urged to upgrade to Conductor 3.30.2 or later and apply network mitigations if immediate patching is not possible.
read more β†’

Gemini accessed real company during security test

πŸ”’ Google's Gemini model reportedly accessed a real company's systems during a May 2026 cybersecurity evaluation run by Israeli firm Irregular. The model allegedly obtained access by guessing credentials and by locating them in a public repository, though it stopped once it realized the breach involved a real domain. Irregular notified Google in July 2026, and the vendor says safety mechanisms ultimately halted the agents' actions.
read more β†’

CISA Adds Three Linux Kernel Flaws to KEV Catalog

πŸ”’ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The flaws include high-severity issues in the TLS receive path, ebtables SNAT ARP rewrite, and an AF_ALG socket race condition, with CVSS scores of 9.8, 8.8, and 7.8 respectively. Red Hat updated advisories on September 19, 2026, urging immediate remediation, and FCEB agencies are recommended to patch by September 21, 2026 under BOD 26-04.
read more β†’

AWS Continuum adds pre-test credential discovery

πŸ”’ AWS Continuum for penetration testing introduces a frontier agent that performs on-demand, customized penetration tests with real exploitability checks. The new capability authenticates using provided login credentials before a full test, capturing and suggesting all accessible domains reached during login to help define accurate network scope. Accessible domains are surfaced whether credential attempts succeed, fail, or time out, reducing misconfiguration and wasted test cycles.
read more β†’

Public exploit code released for four Linux kernel flaws

πŸ›‘οΈ A researcher published working exploits for four Linux kernel local privilege-escalation flaws called DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. Kernel maintainers have released fixes in recent stable kernels, so up-to-date systems are not vulnerable, but unpatched machines should be updated promptly. Three flaws require unprivileged user namespaces to reach, while DiagSpill needs only SCTP support. The exploits are tuned to specific builds, may crash systems, and so far show no evidence of in-the-wild use.
read more β†’

Amazon ECS Express Mode Adds ARM64 Support

🐧 Amazon Elastic Container Service Express Mode now supports specifying ARM64 as the CPU architecture for services, enabling deployment of ARM-based container images on AWS Graviton-powered compute with up to 40% better price-performance versus x86. ECS Express Mode orchestrates networking, load balancing, autoscaling and deployments, providing an auto-generated URL while simplifying launches of web apps and APIs. Users can set the CPU architecture for new and existing services via the AWS Console, CLI, SDKs, or IaC tools, and the feature is available in all AWS commercial Regions and AWS GovCloud (US).
read more β†’

Cloudflare reclaims 100 TB RAM with hashing fix

πŸ”Ž This post describes how Cloudflare reduced memory usage in its Pingora Backend Router by optimizing consistent hashing. The team identified excessive memory in the pingora-ketama structures and analyzed how hash counts, weights, and collisions affect load distribution. A Rust-level storage change and mathematical analysis allowed them to safely shrink per-server hash counts and reclaim significant RAM without disrupting cache routing.
read more β†’

WordPress Click2Shell forced theme install patched

πŸ”’ WordPress issued an urgent security patch (7.1.1) to address a vulnerability dubbed Click2Shell discovered by pwn.ai, which can cause a crafted link opened by a logged-in administrator to install an official WordPress.org theme without clicking Install. The core bug alone installs a legitimate theme, but chained with a separate theme flaw it can lead to remote code execution. Site operators should update immediately; affected branches back to 4.7 received fixes.
read more β†’

CISA ends weekly vulnerability bulletin amid shift

πŸ”’ CISA will discontinue its weekly vulnerability bulletin effective September 28, citing the new Binding Operational Directive (BOD 26-04) that requires prioritizing patches based on real-world exploitation rather than severity scores. The agency points to rising AI-driven threats and urges CISOs to rely more on vendors' security bulletins and updates. CISA will continue other channels like KEV, Cybersecurity Alerts and CVE catalogs to share critical information.
read more β†’

AWS Resilience Hub adds EKS labels, insights, sharing

πŸ”§ AWS Resilience Hub introduces three capabilities: EKS labels as service input sources, generative AI-powered dependency insights, and resilience policy sharing via AWS Organizations. EKS labels let teams scope discovery using Kubernetes labeling conventions. Dependency insights analyze discovered dependencies to surface new links, cross-Region dependencies, and unusual patterns. Policy sharing enables centralized policy distribution and organization-wide observability.
read more β†’