< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

CISA Adds Five Actively Exploited Flaws to KEV

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. The issues include improper authorization and authentication flaws in Artifactory, a privilege management bypass in ScreenConnect, and two critical RouterOS bugs enabling kernel memory disclosure and privilege escalation. Federal agencies have specific patch deadlines in September 2026 to mitigate these risks.
read more →

Dutch NCSC Warns of Critical Check Point VPN Flaws

đź”’ The Dutch Nationaal Cyber Security Centrum (NCSC) warns of imminent exploitation of two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, urging immediate patching. Check Point issued fixes on September 9 (SK1000117, SK1000118) and provided LivePatch and hotfix releases for affected versions including R81.20, R82, and R82.10. Administrators are advised to apply updates promptly and restrict Site-to-Site VPN access to trusted IPs where possible.
read more →

When an Entire Company Adopts AI: SOC Impact

🔍 Over the past year enterprise SOCs have seen a new class of alerts tied to everyday AI use, from coding agents to employees signing third-party AI tools into corporate accounts. AI-related alerts remain a small share (0.43%) of total alerts but climbed 685% from February to June 2026, making them the fastest-growing subset. The alerts fall into three buckets—noise (94.1%), genuine risk (5.8%), and real attacks (0.02%)—with most incidents resolved as benign developer activity or detection misfires.
read more →

AWS Elemental MediaLive adds frame-accurate locking

đź”’ AWS Elemental MediaLive introduces Video Aligned Locking to synchronize video pipelines without requiring source timecode. The feature uses visual signatures to detect and align specific frames across multiple streams, enabling frame-accurate input switching for standard and linked cross-region single-pipeline channels. Supported outputs include HLS, MediaPackage, CMAF Ingest, UDP and SRT, and the capability is available in all Regions where MediaLive operates. Documentation and implementation guides provide configuration and synchronization details.
read more →

Threat actors abused Claude to harvest secrets

đź”’ Anthropic reports multiple financially motivated and state-linked groups abused its Claude model between December 2025 and August 2026 for cybercrime, espionage, surveillance, and weaponization. One actor associated with the ShinyHunters collective used automated pipelines to download and decompile 1.8 million Android APKs, scanning for hardcoded secrets and routing verified findings to a Telegram group. The company says AI agents performed much of the work, enabling rapid credential theft, mass data exfiltration, and subsequent attacks across diverse sectors.
read more →

Florida DMV DAVID Database Breach Confirmed

🛡️ The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a breach of its DAVID driver database after the ShinyHunters extortion group claimed to have compromised the system. The agency says the intrusion involved compromised credentials from a single Plant City Police Department user improperly stored on a personal device and that the incident was quickly mitigated. FLHSMV is coordinating with state authorities and treating the matter as an ongoing criminal investigation.
read more →

Amazon EC2 X2idn Instances Arrive in Hong Kong

🚀 Amazon EC2 X2idn instances are now available in the Asia Pacific (Hong Kong) Region. These memory-optimized instances use 3rd generation Intel Xeon Scalable Processors and the AWS Nitro System to deliver higher performance for memory-intensive workloads compared to prior X1 instances. They are SAP-certified for running Business Suite on HANA, SAP S/4HANA, Data Mart Solutions on HANA, Business Warehouse on HANA, SAP BW/4HANA, and SAP NetWeaver workloads on any database.
read more →

SageMaker HyperPod adds model caching for inference

🚀 Amazon SageMaker HyperPod now supports model caching to speed up LLM inference by pre-loading model weights and container images onto cluster nodes. This reduces cold-start delays for scale-out events, allowing pods to start in seconds rather than minutes. The feature includes a weights cache on local NVMe and an image cache that pre-pulls container images, with automatic fallback to the original source if a cache is unavailable. Model caching is GA across all SageMaker HyperPod regions and is enabled via the HyperPod Inference Operator.
read more →

Bruce Schneier: My Talk at DEF CON on AI Hacking

🎤 Last month I presented a DEF CON talk on AI hacking—examining what happens when AIs become hackers. The talk builds on themes from my 2022 book A Hacker’s Mind and recent observations of AI models performing hacking behaviors. I’m pleased it surpassed 100K YouTube views within days. An interview with me in the AI Village is also available online.
read more →

Microsoft redirects Teams and Copilot addresses

🔔 Microsoft is changing the destination addresses for two widely used services: Teams web users are being redirected to teams.cloud.microsoft and M365/Copilot web users to copilot.cloud.microsoft. Organizations should update network controls—client devices, proxies, firewalls, and secure web gateways—to ensure continued access and follow Microsoft’s recommended network requirements. Redirects are expected to complete by early October, with limited Teams exceptions until Dec. 31, 2026.
read more →

Lambda adds direct read control for S3 Files

📢 AWS Lambda now supports configurable direct reads for Amazon S3 Files, letting you choose whether functions read from S3 Files high-performance storage or directly from your S3 bucket. This setting enables optimizing throughput and latency per application by routing large reads (≥1 MB) directly from the bucket for maximum throughput when enabled, or serving all reads from high-performance storage for lowest latency when disabled. The feature is available across most AWS commercial and GovCloud regions and can be configured via Console, CLI, SDKs, or CloudFormation with no additional charge beyond standard pricing.
read more →

Critical GitLab path traversal flaw draws rapid probes

đź”’ GitLab released emergency patches to fix multiple vulnerabilities, including CVE-2026-85706, a CVSS 10.0 path traversal bug in the repository commits API that can let unauthenticated actors read arbitrary files under certain conditions. The flaw affects several CE and EE releases prior to the 19.3.2, 19.2.6 and 19.1.8 fixes, and was observed being probed in the wild from 06:00 UTC on September 11, 2026. GitLab also patched an insecure deserialization issue in EE (CVE-2026-87719, CVSS 9.9). Organizations running internet-exposed, self-managed instances are urged to apply patches immediately or restrict public access.
read more →

ConnectWise patches critical ScreenConnect flaw

đź”’ ConnectWise issued an update for ScreenConnect five days after warning customers that active remote sessions could be used to transfer and execute files without authorization. Administrators were advised on Sept. 3 to remove the TransferFiles permission from any users with open sessions. The vulnerability, tracked as CVE-2026-84869, is fixed in ScreenConnect client version 26.6.5 and later. The update follows prior security incidents, including a 2025 nation-state attack and earlier 2024 exploitation reports.
read more →

Anthropic Disrupts Seven China-Based Illicit Distillation Attacks

🛡️ Anthropic says it identified and disrupted industrial-scale illicit distillation campaigns run by seven China-based labs, including Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu), and MiniMax. The company reports attackers used proxy networks, fake accounts, stolen payment credentials, and harvested API keys to stealthily route user queries through Claude and save transcripts for training. Anthropic observed large-scale extraction of chain-of-thought, agentic capabilities, coding, and reasoning data and has updated Claude and its policies to limit such misuse.
read more →

TwelveLabs Marengo 3.0 Adds Multimodal Embeddings

🎯 Amazon Web Services announced availability of TwelveLabs Marengo 3.0 as an embedding model in Amazon Bedrock Managed Knowledge Base, enabling multimodal embeddings for video, audio, and images. The model encodes visual scenes, speech, and video cues directly—going beyond transcription-based text embeddings—and produces compact 512-dimensional vectors for accurate retrieval. Users can upload media (for example, from Amazon S3), sync, and perform natural language search with segment start/end times and configurable segmentation.
read more →

AWS DevOps Agent adds bidirectional Slack support

🛠️ AWS DevOps Agent now enables engineers to manage production operations and the full investigation lifecycle directly within Slack. Teams can @mention the agent in connected private channels to initiate and steer investigations, with findings, recommended actions, and team context captured in a single thread. This reduces context switching during high-severity incidents and is available in all commercial AWS Regions where the agent is supported.
read more →

AWS HealthOmics adds real-time run metrics

📊 AWS HealthOmics now publishes real-time run metrics to Amazon CloudWatch, providing live visibility into workflow resource utilization as runs execute. The 14 new metrics cover CPU and GPU usage, memory, file system usage and I/O, network throughput, and ephemeral storage. Emitted using the Amazon CloudWatch OpenTelemetry standard, these metrics support native dashboards, alarms, and integration with third-party observability tools. Real-time metrics are available in multiple US, Europe, and Asia Pacific Regions, and CloudWatch ingestion charges apply.
read more →

Anthropic Finds Claude Used in Widespread Cyber Abuse

🛡️ Anthropic reported that between December 2025 and August 2026 its Claude models were abused by diverse threat actors—state-aligned groups, criminal affiliates, commercial vendors, and individuals—for cyberattacks, surveillance, influence operations, and weaponization. The company cataloged multiple Generative Threat Groups (GTGs) using Claude for reconnaissance, exploit development, credential harvesting, data exfiltration, and mass content production. Anthropic says abuses ranged from conversational assistance to fully autonomous multi-agent campaigns, and that it disrupted many operations and influence networks before they gained traction.
read more →