< ciso
brief />

Hello, stay ahead with CISO Brief πŸš€

Every day the cybersecurity world moves fast β€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence β€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

πŸ‘‰ Join our Telegram channel for your daily update β€” stay informed, stay ready.

Cybersecurity News Digest β€” Daily Briefings

Latest News

all posts β†’

Anthropic outlines global watermarking plan for Claude

πŸ” Anthropic announced it will apply invisible watermarking to Claude-generated text worldwide to comply with the EU AI Act. The watermark modifies the model's internal randomness during token selection rather than adding visible markers or hidden characters, producing a statistical signature detectable only with a secret key. Anthropic says watermarking has no practical effect on creativity, readability, token costs, or generation speed, and will be omitted where exact outputs or code correctness are required.
read more β†’

Amazon RDS for Oracle Adds APEX 26.1 Support

πŸ”” Amazon RDS for Oracle now supports Oracle Application Express (APEX) 26.1, a low-code platform for building secure, scalable enterprise applications. This managed database service simplifies setup, operation, and scaling of Oracle Database deployments in the cloud. APEX 26.1 is available in all AWS regions where RDS for Oracle is offered; consult the RDS documentation for details on enabling or modifying APEX options.
read more β†’

macOS Screen Sharing flaw exploited to install miner

πŸ”’ The Netherlands' NCSC warns that a macOS Screen Sharing authentication bypass (CVE-2026-65400) is being actively exploited after public exploit code appeared. The flaw affects the built-in VNC-based Screen Sharing service (TCP 5900) and allows network attackers to authenticate without valid credentials. Apple fixed the issue in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9; affected users should update or disable Screen Sharing in System Settings.
read more β†’

ExfilSquad leaks data from 13 organizations

πŸ” New analysis links the ExfilSquad extortion group to leaked data from 13 victims across government, education, finance and manufacturing. Fortra Intelligence and Research Experts (FIRE) validated that public samples contained sensitive information, with published torrents totaling 382.64 GB and 27 million records. Researchers say misconfigured Microsoft Power Pages and unauthorized read access to Microsoft D365/Dataverse exports appear to be the primary cause, not a D365 vulnerability. FIRE identified numerous exposed Power Pages instances and highlighted the risk of the Anonymous Users web role.
read more β†’

Critical SAP Commerce Cloud RCE Now Being Exploited

πŸ›‘οΈ A maximum-severity remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) patched three days ago is already being targeted in attacks, Defused reports. The flaw, in the core Data Hub Adapter extension, allows unauthenticated actors to exploit improper authorization to execute arbitrary code. SAP warned the issue arises from abuse of a default authentication client and insufficient input validation. Threat researchers observed initial exploitation attempts hitting honeypots despite no public PoC existing.
read more β†’

Cloudflare One updates for MCP security

πŸ”’ Cloudflare announces new Cloudflare One capabilities to detect and control Model Context Protocol (MCP) traffic. These features let administrators identify which users and servers are generating MCP requests, distinguish Portal-mediated connections from direct ones, and block unauthorized direct connections on managed network paths. The update combines Gateway protocol signals with MCP Server Portals to help teams find shadow MCP servers and enforce Portal-only access to trusted MCP endpoints.
read more β†’

Oracle launches Database Security Central free trial

πŸ”’ Oracle has introduced Database Security Central, a tool that provides a centralized view of security risk across database environments and will be free through February 2027. It arrives as attackers increasingly target Oracle database flaws and following Oracle’s move to monthly patch releases. The tool assesses posture, detects configuration drift, highlights privileged access risks, monitors sensitive data access, and centralizes policy management and audit evidence collection.
read more β†’

Protect Workers with Cloudflare Access by Default

πŸ” Cloudflare now lets you apply Access directly to a Worker or to all Workers in an account so applications are protected by your company login by default. When enabled, Access enforces authentication before any request reaches Worker code, regardless of domain, route, or preview URL. Policies can be set per hostname, per Worker, or account-wide, with the most specific policy taking priority. Developers can also access authenticated user details through ctx.access.getIdentity() for personalization and logging.
read more β†’

Shell Probes Possible Data Theft After Clop Claims

πŸ”Ž Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. A Shell spokesperson confirmed awareness and said security teams and external experts are examining the matter. Clop listed Shell among 43 victims allegedly targeted via a PTC Windchill and FlexPLM vulnerability tracked as CVE-2026-12569. PTC, CISA, and other authorities have warned of active exploitation and urged urgent patching and mitigations.
read more β†’

DecryptAds reveals who’s tracking you online

πŸ” DecryptAds is a free service that scrapes and correlates public adtech files (ads.txt, app-ads.txt, buyers.json, sellers.json) to reveal which companies can run ads or harvest data from websites and apps. The site presents consolidated profiles, legal dossiers, and geo-risk warnings to help researchers and security teams trace malvertising, ad fraud, and opaque ad-supply chains. Its API and quiet-removals feed enable automation and visibility into removed sellers and reseller relationships.
read more β†’

Why the US should nationalize major AI labs

πŸ“° This essay, coauthored with Nathan E. Sanders and originally published in The Guardian, argues that OpenAI and Anthropicβ€”once founded to restrain reckless corporate AI developmentβ€”have been co-opted by market incentives and investor priorities. Recent market turbulence and questions about long-term profitability suggest these labs may not be viable as private, for-profit companies. The authors propose nationalizing their innovation and compute functions, converting them into publicly governed national labs and utilities to align AI with democratic values and public benefit.
read more β†’

RingCentral Breach Exposes Millions of Account Records

πŸ”’ In July 2026, the ShinyHunters extortion group claimed to have stolen personal data from RingCentral accounts after a reported social engineering intrusion. RingCentral acknowledged a security incident and said remediation steps were taken, noting services continued to operate and only a portion of customers were affected. Have I Been Pwned confirmed leaked data tied to 1.6 million accounts, including names, emails, phone numbers, and addresses.
read more β†’

New macOS infostealer spreads via ClickFix lure

πŸ›‘οΈ Researchers at Jamf warn of a Rust-based macOS infostealer named AmnesiaStealer distributed through ClickFix social engineering. The malware harvests credentials, browser data and live sessions, uses OS version–specific bypasses, and includes a remote-controlled second stage to stealthily control Chromium-family browsers. Jamf recommends enabling threat prevention, advanced threat controls and web protection set to Block and Report.
read more β†’

Reframing cyber backlogs: roles, priorities, and outcomes

πŸ” Security teams should oversee risk rather than perform every remediation task. Assign clear roles: security maintains the authoritative risk inventory, prioritizes findings, escalates missed commitments and verifies closure, while infrastructure, cloud, application and business owners execute fixes. Executives resolve resource conflicts and accept residual risk. Backlogs typically reflect organizational failures in ownership, capacity and decision-making rather than purely technical deficiencies.
read more β†’

Data analyst jailed for $2.5M extortion scheme

πŸ›‘οΈ A former Brightly Software contractor was sentenced to two years in prison after pleading guilty to orchestrating a $2.5 million extortion scheme. He stole payroll and corporate data, emailed employees threatening to leak PII, and demanded ransom in cryptocurrency after his contract ended. Brightly paid a small Bitcoin ransom before involving law enforcement; the FBI recovered devices linking the suspect to the crimes.
read more β†’

How CSOs Turn Cybersecurity into Growth Strategy

πŸ”’ Cybersecurity leaders must shift from proving relevance to demonstrating how security enables innovation and growth. CSOs should embed security into business roadmaps, partner early with operational teams, and translate cyber risk into business impact. Emphasizing resilience, user-centered controls, and seamless protections helps security become a catalyst for transformation rather than an obstacle.
read more β†’

Amazon SES adds custom URL deep linking support

πŸ“£ Amazon Simple Email Service (SES) now supports mobile app deep linking via a new ses:custom-path HTML attribute. When added to an <a> tag, SES preserves the path segment in its tracking URL so iOS Universal Links and Android App Links can route users to the app while keeping engagement tracking enabled. The capability is available in all AWS Regions that offer SES and requires a custom redirect domain with an AASA or Digital Asset Links verification file hosted on that domain. Follow the SES Developer Guide sections on custom domains and email metrics for configuration details.
read more β†’

Five key security takeaways from Black Hat 2026

πŸ” AI dominated Black Hat and DEFCON discussions, highlighting both its value as a defense tool and the risks posed by autonomous agents and malicious AI skills. Speakers urged moving beyond reactive patching toward durable designs, memory-safe languages like Rust, and automated remediation. Researchers revealed AI-based supply-chain attacks, methods to use GitHub telemetry for detections, and human-led AI research uncovering new vulnerabilities. A NAT-based attack class called NatJack was disclosed, prompting vendor patches.
read more β†’