< ciso
brief />

Hello, stay ahead with CISO Brief πŸš€

Every day the cybersecurity world moves fast β€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence β€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

πŸ‘‰ Join our Telegram channel for your daily update β€” stay informed, stay ready.

Cybersecurity News Digest β€” Daily Briefings

Latest News

all posts β†’

miniOrange SAML plugin under active auth bypass attacks

πŸ” Attackers are exploiting two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On WordPress plugin to forge SAML responses and gain administrator access. The plugin, used to integrate WordPress with corporate IdPs like Microsoft Entra ID, Okta, and Google Workspace, improperly accepts the incoming signature algorithm and mishandles OpenSSL verification errors. Fixes were released in July for free and paid editions, but incomplete vendor disclosure left many paid installations unpatched and exposed to exploitation.
read more β†’

SageMaker MLflow Adds Support for Customer Keys

πŸ” SageMaker MLflow now supports customer-managed keys (CMK) via AWS Key Management Service (KMS). This enhancement lets organizations with strict security or compliance needs manage encryption keys themselves and gain enhanced control and auditing through AWS CloudTrail. Customer-managed keys must be symmetric and created in the same AWS account and region as the MLflow App. The feature is generally available in all Regions where MLflow App is offered.
read more β†’

Cloudflare Blog migration to EmDash CMS

πŸ“ Cloudflare migrated its blog to EmDash, a CMS built for Astro and Cloudflare, moving on August 12. The redesign added dark mode, Kumo-aligned frontend patterns, and improved caching and performance. A staged rollout with a proxy Worker ensured zero downtime while enabling new agent-friendly features like a Model Context Protocol (MCP) server.
read more β†’

TikTok Agrees to $400M COPPA Settlement with DOJ

πŸ“’ The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliates over alleged violations of the Children’s Online Privacy Protection Act (COPPA). The suit, filed in 2024, accused TikTok of allowing users under 13 to create regular accounts outside a restricted Kids Mode, collecting and retaining personal data without parental consent, and failing to delete data upon request. The settlement resolves those allegations while acknowledging that TikTok has since made compliance and privacy changes.
read more β†’

Amazon Aurora adds minor PostgreSQL updates

πŸ”” Amazon Aurora PostgreSQL-Compatible Edition now supports PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 bringing community bug fixes and Aurora-specific improvements. Automatic minor version upgrades can be applied during scheduled maintenance windows and can be orchestrated across accounts using the AWS Organizations Upgrade Rollout Policy. Enable automatic upgrades to address known CVEs and simplify large-scale operations. Aurora continues to offer high performance, global resilience, serverless scale-to-zero compute, and improved I/O price-performance.
read more β†’

New TCG Guidance to Verify Quantum-Safe TPMs

πŸ”’ The Trusted Computing Group (TCG) published guidance on August 24 to help organizations verify that trusted platform modules (TPMs) meet post-quantum cryptography (PQC) requirements. The guidance complements the TCG PC Client Platform TPM Profile (PTP) 1.07, developed with contributions from major vendors, and defines two readiness categories: TCG PQC-ready TPM and TCG PQC-upgradable TPM. TCG also plans to extend its certification programs to cover PQC readiness.
read more β†’

NIST outlines risks and challenges of multi‑cloud use

πŸ” The US National Institute of Standards and Technology (NIST) has warned organisations about unique cybersecurity and compliance challenges in multi-cloud environments, where using multiple cloud service providers complicates consistent policy enforcement, controls and authentication. The report, published on August 21, identifies 23 specific challenges across identity and access, vulnerability management, incident response and data protection. NIST calls for improved governance, automation and standardisation and is seeking public comment until October 5, 2026.
read more β†’

ReliaQuest confirms failed data-theft attempt after breach

πŸ”’ ReliaQuest disclosed that an employee was targeted by a social engineering campaign in which attackers impersonated a security team member and hosted a fake SSO page. The actor obtained temporary, view-only access after the employee entered credentials and approved an MFA push, but device-trust controls prevented further access. ReliaQuest revoked sessions, reset tokens, and found no evidence of application, system, or customer data access.
read more β†’

Malicious Firefox Add‑Ons Target Crypto Wallets

πŸ”’ Security researchers at Socket uncovered a campaign of linked Firefox add‑ons designed to steal cryptocurrency wallet seed phrases and browser credentials. Dubbed the "Offside Wallet Theft Factory," the operation has been active since at least March 2026 and uses minimal‑permission extensions that switch behavior via a Supabase backend. Some extensions pose as wallets, VPNs, or utilities while others impersonate sports score tools, and attackers remotely toggle malicious pages to harvest recovery phrases and passwords. Out of 77 linked add‑ons, 40 were confirmed to steal data, illustrating how shared code and infrastructure enable rapid weaponization.
read more β†’

SageMaker HyperPod adds Ray support for AI workloads

πŸ› οΈ Amazon SageMaker HyperPod now integrates Ray with built-in observability, resilient distributed training, accelerated inference, and managed development environments. Data scientists can create and manage Ray clusters from SageMaker Studio, attach JupyterLab or a local IDE for interactive iteration, and use Grafana and Amazon Managed Service for Prometheus for one-click observability. HyperPod provides node auto-recovery, hung job detection, tiered checkpointing, and task governance to improve GPU utilization and reliability, plus a tiered KV cache and JumpStart model deployment for faster Ray Serve inference.
read more β†’

Amazon Connect Customer adds automated information extraction

πŸ” Amazon Connect Customer now supports automated information extraction from voice and chat interactions, capturing verbatim data like account numbers and derived insights such as reason for contact and next steps. Administrators define conversational analytics rules and extraction runs on raw content before redaction, enabling capture of sensitive items while still supporting redaction in recordings and transcripts. Extracted values appear to agents in After Contact Work, are searchable by supervisors, and are available to developers via APIs, Kinesis Data Streams, and S3 outputs.
read more β†’

Weekly Recap: AI-Enabled PLC Exploits Rise

πŸ” U.S. agencies warn that threat actors are using AI to craft exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs), posing risks to water, energy, manufacturing, and other critical infrastructure. Attackers leverage public scanning services to locate vulnerable PLCs and deploy AI-generated tools that masquerade as legitimate monitoring software to probe and prepare for disruptive write operations. The advisory stresses this is an active, not theoretical, threat and highlights the need for improved segmentation, monitoring, and remediation.
read more β†’

Microsoft Teams adds admin controls to block external bots

πŸ›‘οΈ Microsoft is introducing a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings. This builds on a June update that flagged detected bots for organizer approval; the new policy prevents such bots from joining without confirmation. Rolling out in targeted release through August and GA by late September, the setting is off by default and must be enabled and assigned via the Teams admin center.
read more β†’

AWS ParallelCluster 3.16 Adds On-Node Diagnostics

πŸ› οΈ AWS ParallelCluster 3.16 is now generally available and introduces pcluster-diag, an on-node diagnostics tool included in ParallelCluster AMIs that produces structured reports to simplify issue identification. The release also improves cluster lifecycle resilience with more robust creation, updates, and image builds. The HPC and AI/ML software stack receives updates to NVIDIA drivers, CUDA, EFA installer, and Slurm.
read more β†’

OpenAI GPT-5.6 Terra and Luna arrive on Bedrock GovCloud

🀝 Amazon Bedrock now offers OpenAI's GPT-5.6 family β€” Terra and Luna β€” in AWS GovCloud (US-West) and (US-East), delivered via Bedrock's next-generation inference engine for security and high performance. Terra balances capability and cost while Luna prioritizes fast, low-cost inference; both support 1 million token context windows and prompt caching with explicit breakpoints for reduced billing on repeated context. Use the Bedrock Console or Responses API on the bedrock-mantle endpoint to get started.
read more β†’

Doubloon Dredger abuses Notion to harvest tokens

πŸ“„ Sublime's Threat Intelligence team identified a financially motivated actor, tracked as Doubloon Dredger, abusing free Notion accounts and malicious PDFs in July 2026 to harvest authentication tokens. Fake notifications from compromised Notion accounts bypassed DKIM/SPF/DMARC checks and steered victims to intermediary PDFs that redirected to an EvilTokens device-code phishing page. If users entered the provided code on Microsoft's legitimate device-code entry, attackers obtained authorization tokens and could access accounts and inboxes via tools like MailVault.
read more β†’

August .NET updates break WPF printing and PDF export

πŸ› οΈ Microsoft confirmed that August 2026 .NET Framework cumulative updates are causing some Windows Presentation Foundation (WPF) applications to fail with a System.IO.FileFormatException when printing or generating PDF/XPS content using certain fonts such as Calibri. The issue affects multiple client and server Windows releases, and Microsoft provided a temporary AppContext switch workaround that must be added to the application config file. The company warns this workaround disables protections added in the update and should be used only temporarily while a permanent fix is developed.
read more β†’

Critical Keycloak password reset vulnerability patched

πŸ”’ Red Hat and the Keycloak project released patches to fix a critical flaw (CVE-2026-18963) that allows an unauthenticated remote attacker to take over user accounts by forcing a password reset. Upstream Keycloak users should update to 26.7.2 (released Aug 19, 2026); Red Hat build customers must apply fixes for 26.4.15 and 26.6.6. Red Hat rates the issue 9.1 CVSS and recommends disabling the "Forgot password" feature as a temporary mitigation while upgrading.
read more β†’