< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Amazon ECS adds automatic agent connectivity repair

🔧 Amazon Elastic Container Service now automatically detects and repairs container instances with impaired agent connectivity across all compute options. It surfaces a new AGENT_CONNECTIVITY health change event for AWS Fargate, Amazon ECS Managed Instances, and Amazon ECS on EC2. For ECS Managed Instances and Fargate, ECS will automatically drain tasks and launch replacement capacity while deregistering impaired instances; ECS on EC2 users can use the event to trigger replacements. This capability is available at no additional cost in all AWS Commercial and GovCloud (US) Regions.
read more →

Unpatched Calix NAT bypass risk exposes internal devices

🔒 An unpatched authentication flaw in Calix GS7 XGS (GS5239XG) residential gateways running EXOS/6.6.47 lets remote unauthenticated attackers create and manipulate port-forwarding rules via the MiniUPnPd control endpoint on TCP port 5000. Researcher Brian Khan Quintana reported the issue as CVE-2026-75501 after failed vendor notification and worked with CERT/CC for disclosure. Exploitation can permanently open firewall rules that expose internal cameras, NAS, IoT devices, and admin interfaces; users are advised to disable UPnP or contact their ISP if the setting is locked.
read more →

miniOrange SAML plugin under active auth bypass attacks

🔐 Attackers are exploiting two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On WordPress plugin to forge SAML responses and gain administrator access. The plugin, used to integrate WordPress with corporate IdPs like Microsoft Entra ID, Okta, and Google Workspace, improperly accepts the incoming signature algorithm and mishandles OpenSSL verification errors. Fixes were released in July for free and paid editions, but incomplete vendor disclosure left many paid installations unpatched and exposed to exploitation.
read more →

SageMaker MLflow Adds Support for Customer Keys

🔐 SageMaker MLflow now supports customer-managed keys (CMK) via AWS Key Management Service (KMS). This enhancement lets organizations with strict security or compliance needs manage encryption keys themselves and gain enhanced control and auditing through AWS CloudTrail. Customer-managed keys must be symmetric and created in the same AWS account and region as the MLflow App. The feature is generally available in all Regions where MLflow App is offered.
read more →

Cloudflare Blog migration to EmDash CMS

📝 Cloudflare migrated its blog to EmDash, a CMS built for Astro and Cloudflare, moving on August 12. The redesign added dark mode, Kumo-aligned frontend patterns, and improved caching and performance. A staged rollout with a proxy Worker ensured zero downtime while enabling new agent-friendly features like a Model Context Protocol (MCP) server.
read more →

Amazon EKS adds support for multiple OIDC providers

🔒 Amazon Elastic Kubernetes Service (Amazon EKS) now lets you associate up to 10 external OpenID Connect (OIDC) identity providers with a single cluster. This enables distinct user populations—employees, contractors, CI/CD systems—to authenticate directly without consolidating providers or using an identity broker. Each provider is configured and managed independently and coexists with existing IAM authentication. You add providers via the AWS Management Console or the AssociateIdentityProviderConfig API at no extra cost in all EKS regions.
read more →

TikTok Agrees to $400M COPPA Settlement with DOJ

📢 The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliates over alleged violations of the Children’s Online Privacy Protection Act (COPPA). The suit, filed in 2024, accused TikTok of allowing users under 13 to create regular accounts outside a restricted Kids Mode, collecting and retaining personal data without parental consent, and failing to delete data upon request. The settlement resolves those allegations while acknowledging that TikTok has since made compliance and privacy changes.
read more →

Weedhack malware spread via fake Minecraft clients

🛡️ McAfee Labs found ongoing campaigns distributing the Weedhack malware by impersonating popular Minecraft clients and hosting convincing lookalike sites. The attacks use SEO poisoning, Discord and file-hosting links to redirect victims and deploy multi-stage JAR payloads that collect system data and disable security protections. Threat actors even used an AI site builder to create believable malicious domains that outrank legitimate sources.
read more →

Amazon Aurora adds minor PostgreSQL updates

🔔 Amazon Aurora PostgreSQL-Compatible Edition now supports PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 bringing community bug fixes and Aurora-specific improvements. Automatic minor version upgrades can be applied during scheduled maintenance windows and can be orchestrated across accounts using the AWS Organizations Upgrade Rollout Policy. Enable automatic upgrades to address known CVEs and simplify large-scale operations. Aurora continues to offer high performance, global resilience, serverless scale-to-zero compute, and improved I/O price-performance.
read more →

New TCG Guidance to Verify Quantum-Safe TPMs

🔒 The Trusted Computing Group (TCG) published guidance on August 24 to help organizations verify that trusted platform modules (TPMs) meet post-quantum cryptography (PQC) requirements. The guidance complements the TCG PC Client Platform TPM Profile (PTP) 1.07, developed with contributions from major vendors, and defines two readiness categories: TCG PQC-ready TPM and TCG PQC-upgradable TPM. TCG also plans to extend its certification programs to cover PQC readiness.
read more →

NIST outlines risks and challenges of multi‑cloud use

🔍 The US National Institute of Standards and Technology (NIST) has warned organisations about unique cybersecurity and compliance challenges in multi-cloud environments, where using multiple cloud service providers complicates consistent policy enforcement, controls and authentication. The report, published on August 21, identifies 23 specific challenges across identity and access, vulnerability management, incident response and data protection. NIST calls for improved governance, automation and standardisation and is seeking public comment until October 5, 2026.
read more →

ReliaQuest confirms failed data-theft attempt after breach

🔒 ReliaQuest disclosed that an employee was targeted by a social engineering campaign in which attackers impersonated a security team member and hosted a fake SSO page. The actor obtained temporary, view-only access after the employee entered credentials and approved an MFA push, but device-trust controls prevented further access. ReliaQuest revoked sessions, reset tokens, and found no evidence of application, system, or customer data access.
read more →

Malicious Firefox Add‑Ons Target Crypto Wallets

🔒 Security researchers at Socket uncovered a campaign of linked Firefox add‑ons designed to steal cryptocurrency wallet seed phrases and browser credentials. Dubbed the "Offside Wallet Theft Factory," the operation has been active since at least March 2026 and uses minimal‑permission extensions that switch behavior via a Supabase backend. Some extensions pose as wallets, VPNs, or utilities while others impersonate sports score tools, and attackers remotely toggle malicious pages to harvest recovery phrases and passwords. Out of 77 linked add‑ons, 40 were confirmed to steal data, illustrating how shared code and infrastructure enable rapid weaponization.
read more →

SageMaker HyperPod adds Ray support for AI workloads

🛠️ Amazon SageMaker HyperPod now integrates Ray with built-in observability, resilient distributed training, accelerated inference, and managed development environments. Data scientists can create and manage Ray clusters from SageMaker Studio, attach JupyterLab or a local IDE for interactive iteration, and use Grafana and Amazon Managed Service for Prometheus for one-click observability. HyperPod provides node auto-recovery, hung job detection, tiered checkpointing, and task governance to improve GPU utilization and reliability, plus a tiered KV cache and JumpStart model deployment for faster Ray Serve inference.
read more →

Amazon Connect Customer adds automated information extraction

🔍 Amazon Connect Customer now supports automated information extraction from voice and chat interactions, capturing verbatim data like account numbers and derived insights such as reason for contact and next steps. Administrators define conversational analytics rules and extraction runs on raw content before redaction, enabling capture of sensitive items while still supporting redaction in recordings and transcripts. Extracted values appear to agents in After Contact Work, are searchable by supervisors, and are available to developers via APIs, Kinesis Data Streams, and S3 outputs.
read more →

Weekly Recap: AI-Enabled PLC Exploits Rise

🔍 U.S. agencies warn that threat actors are using AI to craft exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs), posing risks to water, energy, manufacturing, and other critical infrastructure. Attackers leverage public scanning services to locate vulnerable PLCs and deploy AI-generated tools that masquerade as legitimate monitoring software to probe and prepare for disruptive write operations. The advisory stresses this is an active, not theoretical, threat and highlights the need for improved segmentation, monitoring, and remediation.
read more →

Microsoft Teams adds admin controls to block external bots

🛡️ Microsoft is introducing a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings. This builds on a June update that flagged detected bots for organizer approval; the new policy prevents such bots from joining without confirmation. Rolling out in targeted release through August and GA by late September, the setting is off by default and must be enabled and assigned via the Teams admin center.
read more →

AWS ParallelCluster 3.16 Adds On-Node Diagnostics

🛠️ AWS ParallelCluster 3.16 is now generally available and introduces pcluster-diag, an on-node diagnostics tool included in ParallelCluster AMIs that produces structured reports to simplify issue identification. The release also improves cluster lifecycle resilience with more robust creation, updates, and image builds. The HPC and AI/ML software stack receives updates to NVIDIA drivers, CUDA, EFA installer, and Slurm.
read more →