< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Four gaps slowing AI adoption in enterprise SOCs

🔍 Enterprise SOCs are investing in AI but struggle to convert tools into measurable operational gains. Many initiatives add complexity and fragmented workflows instead of reducing analyst workload. Successful deployments prioritize explainability, augment existing playbooks, and unify access to disparate security tools. Clear governance and incremental automation help turn AI pilots into repeatable operational improvements.
read more →

AI harnesses are the next major attack surface

🔐 Security researchers say the real risk with AI agents lies less in the model and more in the surrounding harness — the code that turns model output into actions. Vulnerabilities in harness architecture, implementation choices, and the expanding supply chain of skills and plugins have enabled credential theft, code execution, and persistent malware. Experts urge CISOs to inventory harnesses, restrict their permissions, and independently test vendor claims to reduce exposure.
read more →

Microsoft patches 400 vulnerabilities in August update

🔒 Microsoft released its August Patch Tuesday addressing 400 CVEs, including one actively exploited zero-day and two publicly disclosed zero-days. The exploited flaw, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock that can allow local low-privileged attackers to gain system privileges. Other notable fixes include EoP issues in the User Profile Service (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver tampering flaw (CVE-2026-72971). Organizations without automated, risk-based patching will face challenges prioritizing these updates.
read more →

SAP Commerce Cloud flaw lets attackers run code

🔒 SAP released patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) tracked as CVE-2026-58231, rated 10.0, that could allow arbitrary code execution due to insufficient authorization checks and input validation. Onapsis urged customers to update to the fixed release and re-deploy; as a temporary mitigation, apply an IP Filter Set to restrict access to the vulnerable endpoint. SAP's August 2026 update also addressed three other critical flaws across Manufacturing Integration and Intelligence and ABAP platforms.
read more →

Legacy software bugs that lingered for decades

📰 This article reviews a series of long-dormant vulnerabilities—some more than 30 years old—unearthed and finally patched in recent years. It highlights how AI-powered analysis and deep inspections have accelerated the discovery of latent flaws across widely used projects such as libpng, PostgreSQL, Nginx, and the Linux KVM module. The piece explains the origins, exploitation risk, and remediation status of each bug, emphasizing supply-chain and infrastructure impacts and urging administrators to apply available patches.
read more →

Cisco ASA and FTD HTTP DoS Flaw Exploited

🛡️ Cisco has disclosed a high-severity vulnerability (CVE-2026-20349, CVSS 8.6) in Secure Firewall ASA and Secure Firewall FTD that allows unauthenticated remote attackers to trigger a denial-of-service by sending crafted HTTP requests to the Remote Access SSL VPN service. The flaw affects multiple ASA and FTD versions and configurations (IKEv2 Remote Access VPN, SSL-VPN, Zero Trust Network Access). Cisco released fixes across affected ASA and FTD releases and said it found active exploitation earlier this month; no viable workarounds exist.
read more →

Chrome reduces Android notification abuse by billions

🔔 Google reports that Chrome's anti-abuse systems blocked over 7 billion unwanted Android notifications per day in Q1 2026. The company says notification abuse has become a vector for scams, malware, phishing, and fraudulent payment requests, prompting a layered "Swiss cheese" defense model. Chrome now auto-revokes notification permissions from inactive or repeatedly abusive sites and allows users to review and restore access via Safety Hub. The browser also limits message rates for disruptive sites and adjusted permission prompts to be less intrusive on Android.
read more →

August 2026 Patch Tuesday: Zero‑Day Winsock and SAP CVE

🛡️ Microsoft’s August Patch Tuesday delivers 398 CVE fixes, highlighted by an actively exploited zero‑day in the Windows Ancillary Function Driver for WinSock (CVE‑2026‑68820). The release includes 42 critical and numerous remote code execution flaws that may be exploitable without authentication, plus two additional publicly disclosed zero‑days. SAP released 29 patches, led by a maximum‑severity improper authorization issue in Commerce Cloud’s Data Hub Adapter (CVE‑2026‑58231).
read more →

Zoom patches zero-click RCE and VDI disclosure flaws

🛡️ Zoom has patched four vulnerabilities across its applications, including two zero-click remote code execution issues that allow a meeting participant to execute malicious code on other attendees' systems without any interaction. Three client vulnerabilities affect Zoom versions before 7.1.5 and 7.0.6 and stem from memory corruption in the text annotation feature; a fourth path traversal flaw impacts Zoom Workplace VDI Client and plugins before 7.0.11 and 6.6.15. The annotation bugs were found by A Security using an AI agent, which built a working exploit in under 24 hours, and Zoom has provided mitigations including server-side filtering and guidance to restrict optional features and enforce client version minimums.
read more →

Microsoft Patch Tuesday — August 2026 Update Summary

🛡️ Microsoft released its August 2026 Patch Tuesday with 421 vulnerabilities across many products, including 62 rated critical. One flaw has known exploitation in the wild: CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock. The bulletin highlights numerous RCEs in Windows, Office, SharePoint, Azure services and more, and flags several high-scoring elevation-of-privilege issues.
read more →

DeadLock Ransomware Leverages Blockchain to Resist Takedown

🔒 Microsoft researchers detail a new DeadLock ransomware operation that uses blockchain-backed services and decentralized networks to harden its infrastructure. The group, active since mid-2025, employs double-extortion tactics and hosts leak posts and configuration data on the Polygon blockchain. Victims span multiple European industries, while attackers use Session and Wasabi to protect communications and stolen files, complicating takedown efforts.
read more →

Amazon EC2 R8a instances now in Canada Central

🚀 Amazon EC2 R8a instances are now available in Canada (Central). These instances use 5th Gen AMD EPYC processors with up to 4.5 GHz and deliver up to 30% higher performance and up to 19% better price-performance versus R7a. Built on the AWS Nitro System with sixth generation Nitro Cards, R8a offers 12 sizes (including 2 bare metal) and is SAP-certified.
read more →

Landing Zone Accelerator C5:2020 Assessment Report Now Available

🔒 Landing Zone Accelerator now has an independent assessment report for C5:2020 available on AWS Artifact, evaluating how LZA's baseline implements nearly 200 native security controls. The report, prepared by AWS partner Schellman, maps LZA's Universal Configuration and security control baseline to C5:2020 technical criteria and describes architecture, best practices, and scoping considerations. LZA supports standard multi-account and container deployments in the AWS European Sovereign Cloud and is accompanied by a Compliance Workbook to help customers accelerate evidence collection and assessment preparation.
read more →

Microsoft issues massive August security patch bundle

🔒 Microsoft released updates addressing 398 security vulnerabilities across Windows and related software in its August Patch Tuesday, including one actively exploited zero-day and two publicly disclosed flaws. The company rated 42 of the fixes as critical, and attributed the flood of discoveries to AI-assisted vulnerability research. Experts caution that AI may accelerate bug finding but human oversight remains essential for safe, effective patching.
read more →

Sandworm targets IT pros with trojanized VPN client

🔒 A Ukrainian CERT report details a social-engineering campaign by a Sandworm-linked cluster, UAC-0145, targeting system administrators and IT professionals with fake job offers and interviews. Attackers move conversations to Telegram, conduct Zoom interviews, then instruct candidates to install a trojanized WireGuard client named "SopraVPN" from SourceForge. The modified client includes a nonstandard SymmetricKey option that decrypts and executes embedded PowerShell on Windows and retrieves executables via VPN on Linux, while using a custom Base64 alphabet to hinder analysis.
read more →

Amazon Bedrock adds IAM principal cost allocation

🔒 Amazon Bedrock now supports cost allocation by AWS Identity and Access Management (IAM) principal — including IAM users and roles — for model inference requests made through the bedrock-mantle endpoint. This extends existing support for the bedrock-runtime endpoint and enables customers to attribute inference costs to teams, projects, or applications using IAM principal tags. Activate IAM principal tags in the AWS Billing and Cost Management console to analyze costs in AWS Cost Explorer or include caller identity data in AWS Cost and Usage Report 2.0.
read more →

Microsoft patches 398 vulnerabilities, including active zero-day

🛡️ Microsoft released its August security updates closing 398 CVEs, including one actively exploited Windows kernel privilege-escalation bug in afd.sys (CVE-2026-68820). Four unauthenticated RCEs affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack each score 9.8 and require prioritization based on service exposure. The release also completes a two-part SharePoint remediation started in July by fixing the RCE component.
read more →

Cisco warns of ASA and FTD VPN flaw causing DoS

🔒 Cisco warns of a high-severity DoS vulnerability, CVE-2026-20349, affecting Secure Firewall ASA and Threat Defense (FTD) devices when certain remote access services are enabled. The flaw stems from insufficient error checking in HTTP request processing and can be exploited remotely without authentication to crash affected devices. Cisco has released hotfixes for multiple ASA and FTD releases and urges customers to upgrade, noting no available workarounds. The company reports active exploitation since August 2026 but has not shared exploit details or indicators of compromise.
read more →