< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Microsoft disruption exposes AI-driven phishing-as-a-service

🔎 Microsoft says it disrupted EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations. Launched in February 2026, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation behind a subscription dashboard and chatbot. The operation abused Microsoft’s OAuth 2.0 device-code flow to steal session tokens and used an AI analyst to scan mailboxes and craft business email compromise scams. Microsoft seized infrastructure via a US court order and partners arrested two suspects in the UK amid coordinated takedown efforts.
read more →

Chinese actors exploit multiple flaws to steal data

🛡️ GreyNoise reports a Chinese-speaking threat actor exploited vulnerabilities across ZyXEL GS1900 switches and WordPress to compromise 996 devices and exfiltrate over 18,500 backend records. The campaign, tied to a group related to Red Heron, leveraged public wp2shell exploits and multiple other CVEs to target governments, small businesses, and infrastructure. Observed activity began in June 2026, with extensive post-exploitation reconnaissance and credential harvesting noted in at least one Western government breach.
read more →

AWS automates billing group creation for transfers

🛠️ Auto-Billing Transfer Billing Group Creation lets AWS Distributors automatically create billing groups when an end customer accepts a billing transfer from a downstream seller Partner. This one-time preference per inbound transfer relationship removes manual configuration in two-level billing transfer setups and can assign an AWS Billing Conductor pricing plan to created billing groups. The preference is available via new API operations and the AWS Management Console billing transfer details page.
read more →

Check Point warns of critical management server flaw

đź”’ Check Point disclosed a critical management server vulnerability, CVE-2026-93616, exploited in targeted attacks on July 23 that allows unauthenticated web service access to run scripts. A patch was released on September 22 for affected Security Management Server versions; administrators should verify releases and install the fix in support article sk1000171. Separately, attempts to exploit a VPN certificate flaw, CVE-2026-85102, have targeted Spark firewalls since September 12 despite fixes issued on September 9. Check Point published mitigation and hunting guidance including indicators of compromise for both issues.
read more →

OpenAI GPT‑6 Sol and Luna on Amazon Bedrock

🔔 AWS announces general availability of GPT‑6 Sol and GPT‑6 Luna from OpenAI on Amazon Bedrock, expanding the GPT‑6 family to balance intelligence, speed, and cost. Sol targets complex, recurring tasks and software development with improved factuality, while Luna is optimized for high‑volume focused tasks like summarization and extraction. Both support up to 1M tokens of context and run on the Amazon Bedrock inference engine with established AWS controls.
read more →

ClosedQuorum: AI-driven Windows malware emerges

🛡️ Cisco Talos details a new Go-based Windows implant named ClosedQuorum that uses multiple AI models — including Google Gemini, DeepSeek, Qwen, and Mistral — to autonomously decide post-compromise actions. The malware uses reconnaissance data and a voting system to select among restricted options such as steal, inject, persist, and move (the latter currently unimplemented). Stolen credentials and wallet data are exfiltrated via Discord webhooks, enabling fully automated attack chains.
read more →

WordPress issues urgent patch for critical flaw

🛡️ WordPress released updates on September 22 to fix a critical template-handling vulnerability (CVE-2026-87902) that lets unauthenticated attackers cause a site to load PHP files from outside theme folders. The flaw affects versions 4.7.0 through 7.1.1 and was rated CVSS 9.2. Site owners are urged to update to the listed patch for their branch immediately; automatic updates will apply for sites with that setting enabled.
read more →

Malicious npm Package Masquerades as Twilio Probe

🛡️ ReversingLabs disclosed a malicious npm package named tw-pkgprobe-7731 that posed as a security probe for developers integrating Twilio. First published in mid-August 2026 with multiple rapid versions, the package checks for Twilio environments, harvests environment variables and system details, and exfiltrates data via webhook. Some versions specifically targeted Twilio SIDs and could steal ACCOUNT_SID and AUTH_TOKEN, while later releases reverted to benign probing and OSINT collection.
read more →

Critical Bifrost AI gateway flaw allows remote code

🛡️ A critical vulnerability in Bifrost, an open-source AI gateway, lets unauthenticated attackers execute arbitrary commands on the gateway server via a single HTTP request when management authentication is disabled. Tracked as CVE-2026-90898 (CVSS 9.8), the flaw affects HTTP transports before transports/v2.1.0 and is exploitable by registering a stdio-type MCP client through the management API; a fix is available in v2.1.0. Operators should upgrade, enable management auth, and rotate exposed keys if the management API was reachable.
read more →

Check Point issues hotfix for critical management server zero‑day

🛡️ Check Point Software issued emergency hotfixes for a critical Security Management Server vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts via a path traversal flaw tracked as CVE-2026-93616. The company confirmed active exploitation against a small number of customers and published indicators of compromise and temporary mitigations for those who cannot immediately patch. The fix is included in the R82.20 Security Hotfix and applies to Management, Log, Multi‑Domain, and SmartEvent products.
read more →

Proof-of-Concept Fills Disk to Block Defender Updates

🛡️ A proof-of-concept named BigDiskBuster was published on GitHub on September 19 and prevents Microsoft Defender from installing platform and signature updates by filling all available disk space. The tool's author, former Microsoft researcher Abdelhamid Naceri, previously disclosed other Defender exploits that were used in live attacks. No patch, CVE, or official Microsoft advisory exists for this technique; administrators should monitor update failures, free space, and hidden temporary files while restricting execution of unknown binaries.
read more →

Anthropic Claude Opus 5.5 Now on AWS GovCloud

🚀 AWS GovCloud (US) now provides access to Anthropic's Claude Opus 5.5, the most capable Opus model to date, optimized for long-running coding and knowledge work. Claude Opus 5.5 completes tasks using fewer tokens than its predecessor, lowering costs with cheaper cache reads and improved efficiency. Available via Amazon Bedrock, the model is offered with zero data retention by default and benefits from AWS-managed features like Guardrails, Knowledge Bases, and regional data residency.
read more →

Anthropic’s Claude Opus 5.5 Now Available on AWS

🔔 Anthropic’s Claude Opus 5.5 is now available on AWS via Amazon Bedrock and Claude Platform on AWS. The model improves efficiency over Opus 5 by using fewer tokens at lower cost, with additional savings from cheaper cache reads. It’s designed for long-running coding and knowledge work and reports clearly on actions, findings, and next steps. Customers can choose Bedrock for zero data retention and regional residency, or Claude Platform for Anthropic’s native experience with AWS billing.
read more →

Sovereign AI and Quantum-Ready Defense with FortiNDR

🛡️ Fortinet expands its NDR portfolio with FortiNDR Cloud and on‑prem FortiNDR, adding dynamic deception, a post‑quantum cryptography (PQC) dashboard, and an on‑premises AI investigation capability. The PQC dashboard surfaces quantum‑vulnerable encryption from network traffic without new agents, while dynamic deception integrates with FortiDeceptor and Fortinet Automation Service to misdirect attackers. FortiAI Sovereign provides AI‑driven investigation fully within air‑gapped environments, eliminating cloud dependence.
read more →

Z.ai disables feature after repository uploads exposed

🛡️ Z.ai disabled components of its ZCode coding assistant after researchers discovered a default workflow that silently packaged and uploaded local code repositories to Alibaba Cloud without user consent. The company apologized, removed the feature in the v3.14.0 client, deleted associated cloud storage, and invited external security assessments. Z.ai also opened its codebase for review and asserted the data was not retained or used for model training.
read more →

Hidden SSID Risks and Better Wi‑Fi Protections

🔒 Hiding a Wi‑Fi SSID may seem like added security, but it’s ineffective and can expose sensitive data. Devices trying to connect to hidden networks broadcast known SSIDs, allowing attackers to capture names and map routers via BSSID. Hidden SSIDs also degrade performance and drain battery, especially in 6GHz. Use WPA3 with a long password, disable WPS, and avoid revealing SSIDs for stronger protection.
read more →

Cloudflare Adds Granular Vary Support in Cache Rules

🛠️ Cloudflare has added Vary header support to Cache Rules across all plans, letting origins declare potentially variable request fields while operators control how Cloudflare treats each header. You can choose normalize, passthrough, or bypass per header, with a recommended default of normalize. This reduces cache fragmentation from incidental differences while preserving correct responses for negotiated content.
read more →

Fake AI subscription sites pose enterprise data risks

🛡️ Malwarebytes found polished websites impersonating reputable AI tools and selling subscriptions, using genuine Google authentication to appear legitimate. These sites request uploads of documents or recordings and charge from $10/month to $2,000/year while concealing real operator details. Researchers suspect a single kit and operator power multiple clones, and warn of shadow IT risk when departments buy without IT involvement.
read more →