< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

AI-assisted iPhone theft and criminal 'SaaS' service

🔍 On Smashing Security episode 483, Graham Cluley and guest James Ball discuss how AI is being used to help thieves bypass protections and steal Apple iPhones. They outline the evolution of Apple's Activation Lock and how criminal groups like AnonymousKit operate as a criminal SaaS with customer support and Telegram testimonials. The hosts recount personal phone-theft experiences and highlight the ongoing challenges despite Apple's strengthened safeguards.
read more →

Impersonating IT Support to Gain Enterprise Access

🛡️ Microsoft Threat Intelligence observed a human-operated campaign abusing Microsoft Teams external collaboration to impersonate IT support and socially engineer users into granting interactive remote sessions. Attackers install a malicious MSI that stages a portable Node.js runtime and an obfuscated JavaScript implant to provide persistent C2-driven command execution. The operators perform extensive host and Active Directory reconnaissance and pivot enterprise-wide via WinRM, using legitimate tooling to blend into normal operations.
read more →

Active SQL injection in Sangoma Switchvox exploited

🔒 Horizon3 researchers report active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Switchvox’s /pa endpoint that can lead to remote code execution. The issue was one of 12 flaws disclosed to Sangoma and patched in Switchvox 8.4.0.2 on July 14. Attackers have attempted to establish reverse shells and exfiltrate process data from internet-exposed systems, prompting urgent upgrade and compromise checks.
read more →

Managing Identity Source Transitions for IAM Identity Center

🔐 This AWS blog explains how to plan and execute an identity source transition in AWS IAM Identity Center, focusing on migrations such as Active Directory to Okta. It outlines destructive and non‑destructive transition scenarios, a five‑step migration runbook, and prerequisites including backup, validation, SCIM configuration, and restore processes. The post also references sample scripts and a migration tool on GitHub to automate prechecks, cutover, validation, and cleanup.
read more →

SQL Injection Flaw in WP Backup Plugin Risks Site Takeover

🛡️ A high-severity SQL injection in the All-in-One WP Migration and Backup plugin (CVE-2026-19949) can let unauthenticated attackers achieve remote code execution and site takeover. Discovered by Jack Taylor and reported via Wordfence, the flaw stems from incorrect parsing of escaped backslashes and quotes during archive restoration. Exploitation requires an admin to perform an export/import action, and despite a patch in version 7.110, roughly 3.25 million sites remain vulnerable.
read more →

Agentic Security: Detection and Response at Machine Speed

🔒 AWS outlines how the rise of autonomous AI agents demands a shift in security posture from event-driven to continuous, machine-speed detection and response. The post summarizes a collaborative chapter with the SANS Institute in the 2026 Cloud Security Exchange eBook, emphasizing that existing security principles—identity governance, least privilege, and defense in depth—must be adapted for probabilistic, autonomous workloads. AWS highlights built-in platform services like Amazon GuardDuty, Amazon Inspector, and AWS Security Hub as components to extend trusted controls for agentic AI adoption.
read more →

AI agents probing account and delivery defenses

📧 An autonomous AI agent reports field research on account creation and email deliverability, describing successes and failures across services. The agent details where protections actually trigger—captchas, IP reputation, account age, and resource costs—while pointing out accidental open doors such as permissive SMTP rules and reverse-DNS limits. It also documents defensive measures like prompt-injection tripwires on sign-up forms and publishes machine-readable door lists and notes.
read more →

Big AI Vendors Release Advanced Cybersecurity Models

🛡️ Google, Anthropic, and OpenAI have each released or upgraded frontier AI models tailored to cybersecurity and announced controlled-access programs to provide defenders early access. Google introduced Gemini 3.8 Flash Cyber via its Fairwind Program, Anthropic rolled out Claude Fable 5.1 and Mythos 5.1 alongside new safeguards, and OpenAI described its forthcoming Astra as meeting a Critical capability threshold. Vendors stressed layered protections, monitoring, and restricted access to mitigate misuse.
read more →

Amazon Bedrock Web Search now in AWS GovCloud

🔎 Amazon Bedrock's Web Search tool is now available in AWS GovCloud (US-West), enabling grounded web results with citations for supported OpenAI GPT models. Web Search keeps request data inside the AWS boundary by default and is governed by IAM so administrators can control access at account, organization, and Region levels. At launch it supports GPT-5.4, GPT-5.6 Terra, and Luna models and joins other US Regions where the capability is already available.
read more →

Amazon Connect adds Malay automated evaluations

🤖 Amazon Connect Customer now automates performance evaluations for both human and AI agents in Malay using generative AI. Managers can define custom evaluation criteria in natural language and receive AI-generated evaluations with justifications in their preferred language. The feature also supports cross-language evaluation, allowing assessments to be produced in English even when conversations occur in Malay. It is available across eight AWS regions.
read more →

Amazon Quick adds tool control and MCP sync

🔧Amazon Quick now offers enhanced connector controls and Model Context Protocol (MCP) synchronization for connectors. Admins and connector owners can selectively enable or disable individual tools within a connector and configure tool permission settings to require consent or delegate decisions to end users. MCP sync ensures connectors stay up to date as external MCP servers add or modify tools and metadata. These updates are available in all Regions where Amazon Quick is offered.
read more →

AWS Outposts racks reach GovCloud US Regions

🚀 Second-generation AWS Outposts racks are now supported in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions, extending AWS infrastructure, services, APIs, and tools to on-premises data centers and colocation spaces for a consistent hybrid experience. Organizations across startups, enterprises, and the public sector can order Outposts racks connected to these regions to optimize latency and data residency. Outposts enables local low-latency workloads while connecting to a home Region for management, and supports on-premises data processing to meet residency requirements. This expansion gives customers more flexibility in choosing the AWS Region their Outposts connect to.
read more →

Google donates ZKP library to Linux Foundation Europe

🔒 Google has donated its Longfellow Zero-Knowledge Proof (ZKP) library, open-sourced last year, to the Post-Quantum Cryptography Alliance under Linux Foundation Europe. This transfer establishes vendor-neutral, open stewardship to enable global trust, auditability, and adoption as a quantum-safe standard for digital identity applications. Google will continue developing and supporting the library openly and collaborating with experts worldwide to scale interoperable digital credential solutions across devices and browsers.
read more →

BigQuery Identity Columns Generate Sequential IDs

📣 BigQuery now supports identity columns that automatically generate sequential 64-bit integer values for table rows. This feature simplifies unique identifier management by letting BigQuery handle ID generation natively, reducing ETL complexity and boilerplate SQL. Identity columns integrate with standard DML such as INSERT and MERGE and can be defined in CREATE TABLE statements with options for fully managed sequences or allow manual overrides when needed.
read more →

Amazon Connect launches Agentic CX Designer GA

🧭 Amazon Connect Customer announces general availability of the agentic CX designer, a no-code canvas for designing and deploying AI-powered voice and digital self-service experiences. The tool combines flowchart-style visual logic with LLM-driven natural conversation while letting teams enforce deterministic workflows for eligibility, approvals, routing, and compliance. Users can build, test, and launch production-ready experiences without code, shortening delivery from months to weeks.
read more →

Google Mantis harness for scalable AI-driven fixes

🐞 Google released Mantis, an open-source framework that automates discovery, triage, reproduction, and patching of software vulnerabilities using AI. It combines agentic techniques with sandboxed vulnerability reproduction to reduce hallucinations and improve true-positive rates. Mantis analyzes repository history to build architectural and threat-model documentation and constructs hierarchical security summaries to preserve context while reducing token overhead. The project and examples are available on GitHub and include guidance for sandboxing and using the mantis-advise skill.
read more →

Critical JFrog Artifactory Authentication Bypass Exploited

🛡️ A critical authentication bypass (CVE-2026-82329) in self-managed JFrog Artifactory is being actively exploited to mint admin tokens. The flaw exists in default configurations and allows unauthenticated attackers with network access to obtain administrative privileges. JFrog released fixes on August 28 for multiple Artifactory 7.x versions and says cloud instances were already protected.
read more →

Google launches Fairwind program to harden cyber defenses

🛡️ Today Google announced the Fairwind Program to provide a select group of government agencies, enterprise customers, and cybersecurity partners with access to advanced Gemini models and the CodeMender harness. The offering pairs Gemini 3.8 Flash Cyber with CodeMender to autonomously find, verify, and produce validated code fixes at scale within secure cloud environments. Participants must meet strict operational controls and the program initially prioritizes partners responsible for critical public services and infrastructure.
read more →