< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Cisco alerts on exploited ISE authentication bypass zero-day

🔒 Cisco has issued urgent updates for a maximum-severity Identity Services Engine vulnerability being actively exploited in the wild. The flaw (CVE-2026-76460) allows remote attackers to bypass authentication via a vulnerable API in Cisco ISE and ISE-PIC, enabling unauthorized access to the web-based management interface. Cisco PSIRT recommends immediate upgrades to fixed releases, and no workarounds are available.
read more →

Anthropic tests Claude Money for personal finance

💡 Anthropic is trialing a new feature called "Claude Money" that lets users link bank accounts to Claude to analyze spending, plans, and more. The capability appeared in the iOS app alongside other sections, but it's not widely available yet and details remain limited. It's likely to mirror existing offerings like ChatGPT Finances and may be restricted regionally due to privacy laws.
read more →

Amazon Corretto 27 Feature Release Now Available

🟢 Amazon Corretto 27, a Feature Release (FR) of the no-cost, production-ready OpenJDK distribution, is now available for Linux, Windows, and macOS. Corretto 27 will be supported through April 2027 and introduces G1 as the default garbage collector, post-quantum hybrid key exchange for TLS 1.3, compact object headers, and JFR in-process data redaction. Several preview and incubator features are continued, including enhanced pattern matching, structured concurrency, lazy constants, and the Vector API.
read more →

Smashing Security Podcast Episode 485 Recap

🎧 Researchers tested LG smart TVs for security risks but bypassed restrictive terms by arguing intoxication voids consent. They discovered concerning capabilities that change how viewers view their devices. The episode also covers the rise of audacious Android malware targeting users and a featured interview with Andy Hornegold on mid-market ransomware dynamics and AI-assisted attack escalation.
read more →

SageMaker Adds Serverless Fine‑Tuning for Nemotron 3.5

🔧 Amazon SageMaker AI now supports serverless model customization for the NVIDIA Nemotron 3.5 Lightning model, enabling supervised fine‑tuning (SFT), Direct Preference Optimization (DPO), and reinforcement fine‑tuning (RFT). The hybrid Mixture‑of‑Experts model has 3B active parameters and 30B total parameters. SageMaker handles infrastructure and orchestration so teams can focus on data and evaluation. Serverless customization is available in US East, US West, Asia Pacific (Tokyo), and Europe (Ireland).
read more →

Architecting a Secure Landing Zone in EUSC

🔒 This post explains how to design a secure, scalable landing zone for the AWS European Sovereign Cloud (aws-eusc), a partitioned AWS environment operated within the EU. It covers account structure and governance, identity as IaC, centralized logging to a SIEM, data protection, perimeter and network design, CI/CD and artifact distribution, and incident response. The guidance maps to the AWS Security Reference Architecture and the AWS Well-Architected Framework, and highlights which behaviors are partition boundaries versus configurable choices.
read more →

Windows 11 update breaks domain trust for some

🔒 Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust on some enterprise systems, preventing valid domain logins. Administrators report that affected devices lose their secure channel with Active Directory after reboot and observed Kerberos and NTLM failures. The issue may be linked to the Machine Identity Isolation setting, especially when set to enforcement mode, and some have restored access by adjusting registry values and repairing the secure channel.
read more →

Iranian CHOSEN BRICK Windows malware targets dissidents

🛡️ Joint advisories warn that Iranian state-linked hackers deploy a Windows malware called CHOSEN BRICK to spy on dissidents, activists, and journalists. The malware harvests email, Telegram, and WhatsApp data, captures screenshots and audio, and establishes persistence via Registry Run keys while adding Microsoft Defender exclusions. Attacks begin with social engineering on WhatsApp or Telegram and malicious files masquerading as trusted apps. Stolen data is exfiltrated via Telegram or cloud services and sometimes published on pro-Iranian leak sites.
read more →

Client-side security uncovers four malicious campaigns

🔍 Cloudflare describes how its Page Shield Client-Side Security ML uncovered four distinct malicious JavaScript operations running on storefronts. The post explains that automated GNN analysis (with LLM second opinions) detected eight payloads in live traffic that other scanners missed, and details how the scripts siphoned affiliate revenue, hijacked clicks, suppressed analytics, and conditionally loaded remote code. It highlights delivery via tag managers, typosquatted hosts, time- and browser-gated execution, and the need for sustained browser visibility to catch cloaked threats.
read more →

LinkedIn Pushes Limits on Secrecy in Government Subpoenas

🛡️ Microsoft’s chief legal officer argued that secrecy orders accompanying government subpoenas should be the exception, not the rule. LinkedIn, owned by Microsoft, is challenging broad government demands that bar notifying customers when their data is sought, urging courts to impose meaningful limits and oversight. The company acknowledged law enforcement needs while asserting providers and users deserve adversarial review and notice. Legislative reforms in the House aim to constrain secrecy orders and strengthen notice protections.
read more →

KREMLIN malware forces browser extension installs

🔒 Researchers at Elastic Security Labs uncovered a banking malware toolkit called KREMLIN that has been active since mid-2025 and installs malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive data. The infection begins with a malicious JavaScript file posing as banking documents, which downloads Node.js, establishes persistence, and retrieves payload locations from an Ethereum smart contract. KREMLIN copies extensions into browser profile directories, regenerates integrity HMACs using browser keys, and enables them without user consent, while also operating as an info-stealer and delivering RATs like REMCOS.
read more →

Radaris Loses Domains After New Jersey Privacy Case

📰 A New Jersey judge ordered radaris.com and more than a dozen related domains transferred to plaintiffs after finding the data broker repeatedly ignored removal requests under Daniel’s Law. Atlas Data Privacy Corp sued Radaris in 2024, alleging the company published personal data for state law enforcement and other officials and employed evasive shell-company tactics. The transfer follows extensive litigation, investigative reporting and documentary evidence tying multiple sites to a common operator.
read more →

AWS Client VPN Adds macOS 27 Golden Gate Support

🖥️ AWS Client VPN now supports macOS 27 Golden Gate with client versions 6.0 and later. The AWS-supplied desktop VPN client can be run on the latest macOS releases and remains available free of charge. Client VPN is a managed service that securely connects remote users to AWS and on-premises networks and supports macOS, Windows (x64 and Arm64) and Ubuntu Linux clients.
read more →

AWS launches simplified Builder experience

🔧 Builders can now sign up for a simplified experience that speeds turning ideas into running code on AWS. The new flow reduces setup effort by auto-configuring an initial project with sensible defaults and supports sign-in via Google, GitHub, Apple, or Amazon credentials. New customers may receive up to $200 in free credits and no credit card is required for most signups. Projects include automated IAM role management, team invites, per-project spend limits, and easy upgrades to advanced features without downtime.
read more →

Spain’s data agency reports first AI-powered breach

🔒 The Spanish Data Protection Agency (AEPD) was notified of an alleged attack carried out by an AI agent powered by a known large language model. The agent reportedly searched for flaws, logged into systems, probed applications, modified personal data, and accessed financial documents. The AEPD has not yet verified the incident but warns that AI-related breaches are now realistic and urges revised risk and response measures.
read more →

Amazon Connect imports evaluation form PDFs with AI

🤖 Amazon Connect Customer now supports importing evaluation form PDFs from third-party quality management applications and uses AI to recreate them within Connect. The service extracts sections, questions, answer options, and scoring into a draft form after you choose percentage or points-based scoring. You can provide natural language instructions to refine the import, reducing manual edits before activation. This feature is available in multiple AWS Regions including N. Virginia, Oregon, Singapore, Sydney, Tokyo, Frankfurt, and Canada (Central).
read more →

Amazon WorkSpaces adds NVIDIA Blackwell G7 bundles

🚀 Amazon WorkSpaces Personal and Core now offer Graphics G7 bundles powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs and Intel Xeon 6 processors. These bundles deliver up to 2.1x better graphics performance versus Graphics G6 and come in four sizes from 8 vCPUs/32 GB/1 GPU to 48 vCPUs/192 GB/2 GPUs. Graphics G7 supports demanding professional workloads, Windows licensing options, AlwaysOn and AutoStop modes, and is initially available in three US Regions with broader rollout planned.
read more →

Amazon Connect Customer adds tag-based access control

🔐 Amazon Connect Customer now supports tag-based access control for custom metrics, enabling administrators to govern who can view, create, or modify each metric. This lets teams tag metrics and assign permissions so they retain full control over their own metrics, have view-only access to other teams’ metrics, or are prevented from seeing restricted metrics. Search results respect these access controls. The feature is available in all Regions where Amazon Connect Customer is offered.
read more →