< ciso
brief />

Hello, stay ahead with CISO Brief ๐Ÿš€

Every day the cybersecurity world moves fast โ€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence โ€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

๐Ÿ‘‰ Join our Telegram channel for your daily update โ€” stay informed, stay ready.

Cybersecurity News Digest โ€” Daily Briefings

FBI warns of hackers stealing explicit images online

๐Ÿ”” The FBI warns cybercriminals are compromising adults' and children's social media and other online accounts to steal sexually explicit photos and videos for blackmail or sale. Victims risk re-victimization through sextortion, harassment, stalking, and public exposure when attackers post or trade stolen content alongside personal details. Authorities advise not sharing verification codes, avoiding internet-accessible storage for explicit material, using complex passwords, and enabling multi-factor authentication.
read more โ†’

July 2026 Cyber Threats: Ransomware and GenAI Risks

๐Ÿ”’ July 2026 saw a marked uptick in cyber incidents, with weekly attacks averaging 2,336 per organization and ransomware victims rising sharply. Education, Latin America, and Business Services were among the most affected, while GenAI use exposed sensitive data through risky prompts. Email remained a primary entry point as organizations confront multi-vector threats and growing operational exposure.
read more โ†’

NIST Seeks Input to Modernize NVD for AI Era

๐Ÿ›ก๏ธ NIST has issued a request for information to modernize the National Vulnerability Database (NVD) to better address AI-driven challenges and incorporate automation. The RFI, published on August 12, asks stakeholders for forward-looking perspectives and practical recommendations to improve the NVDโ€™s scalability, interoperability, transparency and utility. NIST noted that traditional periodic scanning and manual remediation are becoming inadequate as AI-enabled tools and faster technology cycles increase vulnerability volumes. Responses are invited through October 13, with the aim of creating a more continuous, contextual and automated vulnerability management system.
read more โ†’

PoC for SharePoint JWT Bypass Now Used in Attacks

๐Ÿ”’ A Rapid7 proof-of-concept for a critical SharePoint JWT authentication bypass (CVE-2026-55040) is already being weaponized in attacks, researchers warn. Microsoft patched the flaw in its July 2026 updates for SharePoint Enterprise Server 2016 and SharePoint Server 2019 and cautioned that exploitation can disclose files and modify data. CISA has issued guidance urging teams to avoid exposing SharePoint servers and to apply hardening measures.
read more โ†’

Researchers disclose crossโ€‘session AI reasoning leak

๐Ÿ”’ A new research paper shows a flaw in how OpenAI, Anthropic, and Google carry encrypted reasoning between API calls, enabling recovery of hidden internal reasoning and secrets from session logs. The team demonstrated replay and decoding attacks that recovered API keys, passwords, and other private artifacts from publicly available agent traces. Vendors implemented mitigations and the authors say the main extraction no longer reproduces as of August 2026, but developers are urged to strip opaque reasoning blocks from shared logs.
read more โ†’

Perimeter Recovery Masks Weak Interior Defenses

๐Ÿ” Picus Labs' Blue Report 2026 shows perimeter defenses improved in H1 2026, with prevention rising to 69% and logging at a four-year high of 58%. However, post-compromise prevention inside networks remains weak at 37%, and quiet techniques like reconnaissance and credential theft largely evade controls. The findings highlight signature-dependent gaps and declining IOC-based prevention, urging validation of exposures and stronger detection engineering.
read more โ†’

Fake CCleaner installer enables Chrome credential theft

๐Ÿ›ก๏ธ Researchers discovered a multi-stage Windows malware campaign that uses a fake CCleaner download to install a malicious Chrome extension called GhostDesk. The payload abuses Chrome to capture credentials, cookies, keystrokes, screenshots, and to inject arbitrary JavaScript into active tabs. Variants impersonating 7-Zip and Adobe Acrobat share the same C2 infrastructure and delivery mechanism. Malwarebytes recommends verifying download sources and using up-to-date anti-malware protections.
read more โ†’

Signal adds automatic key verification feature

๐Ÿ” Signal introduced Automatic Key Verification, a new feature within a key transparency system that uses Cloudflare and Trail of Bits as independent auditors to confirm the integrity of encrypted chats. The feature enables users to verify contactsโ€™ public keys automatically via Settings > Privacy > Advanced or by selecting "Verify Automatically" on the safety number screen, showing a green checkmark when successful. Users may disable it and continue with manual safety number checks if they prefer. Signal says this complements existing safety numbers and helps prevent undetected key swaps and man-in-the-middle attacks.
read more โ†’

Adobe issues urgent patches for critical ColdFusion flaws

๐Ÿ”’ Adobe released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. Several flaws carry maximum or near-maximum CVSS scores and could enable arbitrary code execution or privilege escalation. Updates for ColdFusion and Campaign Classic are rated Priority 1, and on-premise Campaign Classic customers must patch promptly; Adobe-hosted instances are already remediated.
read more โ†’

New ShieldBreak zero-day elevates Defender privileges

๐Ÿ”’ A new zero-day named ShieldBreak was published by researcher Nightmare Eclipse after Microsoft's August 2026 Patch Tuesday. The exploit is a bypass for the earlier RoguePlanet privilege escalation flaw and can grant SYSTEM privileges on patched Windows 10, Windows 11, and Windows Server installations. The researcher claims a 100% success rate in tested builds and ties the release to an ongoing dispute over Microsoft's disclosure and bug bounty practices.
read more โ†’

Prompt injections used as defensive mechanism

๐Ÿ›ก๏ธ Researchers from Tracebit report that embedding prompt injections alongside secrets stored on AWS can disrupt AI hacking agents by triggering LLM guardrails. These injected prompts instruct the model to perform forbidden actions, causing the LLM to shut down or stop following prior commandsโ€”a technique the researchers call context bombing. The approach succeeds only when attackers use models with built-in safety filters; locally run or unguarded models remain unaffected.
read more โ†’

Four gaps slowing AI adoption in enterprise SOCs

๐Ÿ” Enterprise SOCs are investing in AI but struggle to convert tools into measurable operational gains. Many initiatives add complexity and fragmented workflows instead of reducing analyst workload. Successful deployments prioritize explainability, augment existing playbooks, and unify access to disparate security tools. Clear governance and incremental automation help turn AI pilots into repeatable operational improvements.
read more โ†’

AI harnesses are the next major attack surface

๐Ÿ” Security researchers say the real risk with AI agents lies less in the model and more in the surrounding harness โ€” the code that turns model output into actions. Vulnerabilities in harness architecture, implementation choices, and the expanding supply chain of skills and plugins have enabled credential theft, code execution, and persistent malware. Experts urge CISOs to inventory harnesses, restrict their permissions, and independently test vendor claims to reduce exposure.
read more โ†’

Microsoft patches 400 vulnerabilities in August update

๐Ÿ”’ Microsoft released its August Patch Tuesday addressing 400 CVEs, including one actively exploited zero-day and two publicly disclosed zero-days. The exploited flaw, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock that can allow local low-privileged attackers to gain system privileges. Other notable fixes include EoP issues in the User Profile Service (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver tampering flaw (CVE-2026-72971). Organizations without automated, risk-based patching will face challenges prioritizing these updates.
read more โ†’

SAP Commerce Cloud flaw lets attackers run code

๐Ÿ”’ SAP released patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) tracked as CVE-2026-58231, rated 10.0, that could allow arbitrary code execution due to insufficient authorization checks and input validation. Onapsis urged customers to update to the fixed release and re-deploy; as a temporary mitigation, apply an IP Filter Set to restrict access to the vulnerable endpoint. SAP's August 2026 update also addressed three other critical flaws across Manufacturing Integration and Intelligence and ABAP platforms.
read more โ†’

Legacy software bugs that lingered for decades

๐Ÿ“ฐ This article reviews a series of long-dormant vulnerabilitiesโ€”some more than 30 years oldโ€”unearthed and finally patched in recent years. It highlights how AI-powered analysis and deep inspections have accelerated the discovery of latent flaws across widely used projects such as libpng, PostgreSQL, Nginx, and the Linux KVM module. The piece explains the origins, exploitation risk, and remediation status of each bug, emphasizing supply-chain and infrastructure impacts and urging administrators to apply available patches.
read more โ†’

Cisco ASA and FTD HTTP DoS Flaw Exploited

๐Ÿ›ก๏ธ Cisco has disclosed a high-severity vulnerability (CVE-2026-20349, CVSS 8.6) in Secure Firewall ASA and Secure Firewall FTD that allows unauthenticated remote attackers to trigger a denial-of-service by sending crafted HTTP requests to the Remote Access SSL VPN service. The flaw affects multiple ASA and FTD versions and configurations (IKEv2 Remote Access VPN, SSL-VPN, Zero Trust Network Access). Cisco released fixes across affected ASA and FTD releases and said it found active exploitation earlier this month; no viable workarounds exist.
read more โ†’

Chrome reduces Android notification abuse by billions

๐Ÿ”” Google reports that Chrome's anti-abuse systems blocked over 7 billion unwanted Android notifications per day in Q1 2026. The company says notification abuse has become a vector for scams, malware, phishing, and fraudulent payment requests, prompting a layered "Swiss cheese" defense model. Chrome now auto-revokes notification permissions from inactive or repeatedly abusive sites and allows users to review and restore access via Safety Hub. The browser also limits message rates for disruptive sites and adjusted permission prompts to be less intrusive on Android.
read more โ†’