< ciso
brief />

Hello, stay ahead with CISO Brief ๐Ÿš€

Every day the cybersecurity world moves fast โ€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence โ€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

๐Ÿ‘‰ Join our Telegram channel for your daily update โ€” stay informed, stay ready.

Cybersecurity News Digest โ€” Daily Briefings

Active scans target Rejetto HFS critical RCE flaw

๐Ÿ”Ž Researchers report active probes targeting CVE-2026-61500 in Rejetto HFS, a session-cookie signing weakness that can enable account takeover and remote code execution. Horizon3 linked discovery to Anthropic's Mythos model and released a PoC, prompting small-scale scans from a China Telecom IP. Administrators are urged to upgrade to Rejetto HFS 3.2.1 or preferably 3.3.4 to mitigate exploitation.
read more โ†’

AWS Builder Center adds availability and filtering

๐Ÿ”” AWS announces feature-level availability notifications and enhanced filters in AWS Builder Center for AWS Capabilities by Region. Builders can subscribe to service- or feature-level notifications and receive in-app alerts and a weekly email digest for selected Regions, including an 'All regions' option that covers future Region launches. New filters let users view API operations and CloudFormation resources by availability status and compare Regions by shared or differing availability across more than 19,000 API operations and 5,000 resource types.
read more โ†’

Italy fines IQVIA โ‚ฌ7M for inadequate data anonymization

๐Ÿ”’ Italy's Data Protection Authority fined IQVIA โ‚ฌ7 million over insufficient anonymization and data-processing practices affecting about one million patient records. The GPDP found that pseudonymous codes plus detailed health and location data could enable re-identification, and that some records included full personal identifiers. Authorities also cited lack of legal basis, failure to inform patients, and missing retention policies, ordering compliance within 120 days.
read more โ†’

AWS releases advanced Ruby driver wrapper for RDS/Aurora

๐Ÿš€ The AWS Advanced Ruby Driver Wrapper is now generally available for Amazon RDS and Amazon Aurora PostgreSQL and MySQL-compatible databases. It reduces RDS Blue/Green switchover, Aurora Global database switchover and failover times to improve application availability and supports authentication via AWS Secrets Manager and token-based AWS IAM. Built on the community pg and mysql2 drivers, it integrates with Aurora/RDS to detect cluster status and reconnect to promoted writers, and provides aws_postgresql and aws_mysql2 ActiveRecord adapters so applications require no code changes.
read more โ†’

Microsoft Exchange privilege escalation advisory

๐Ÿ”’ Microsoft issued out-of-band updates for a high-severity flaw in Microsoft Exchange Server that can allow an authenticated attacker to elevate privileges and access other users' mailboxes within the same organization. Tracked as CVE-2026-96940 with a CVSS score of 8.8, Microsoft applied a service-side fix for Exchange Online, while on-premises customers must install provided updates for specified Exchange Server builds. The company named researcher Jan Mitchell as the reporter and rated exploitability as "Exploitation More Likely."
read more โ†’

Google Cloud Modernize: AI-Driven Enterprise Transformation

๐Ÿš€ Google Cloud announces Google Cloud Modernize, an end-to-end portfolio that consolidates migration and modernization tools to accelerate enterprise transformation with AI. The offering centers on Modernization Hub, an in-console experience for analyzing code and mapping dependencies for Java, .NET, and mainframe apps. New Gemini-powered capabilities in Migration Center provide rapid TCO estimates and interactive cost modeling. Purpose-built compute, VMware support, and agentic migration tools (EKS-to-GKE) help organizations modernize infrastructure and application estates with enterprise-grade controls.
read more โ†’

AWS Batch adds EKS access entry authentication

๐Ÿ› ๏ธ AWS Batch now supports Amazon EKS access entry authentication for compute environments. EKS access entries provide an API-driven way to grant IAM principals access to Kubernetes clusters, complementing the existing aws-auth ConfigMap. To enable, set accessEntry.desiredState to ENABLED via the CreateComputeEnvironment or UpdateComputeEnvironment APIs; AWS Batch creates one access entry per cluster and attaches the AWSBatchClusterPolicy. This feature is available in all Regions where AWS Batch is offered.
read more โ†’

Denmark CPR breach exposes records of 8.8M people

๐Ÿ”’ The Danish Central Population Register (CPR) disclosed a data breach that exposed personal information for approximately 8.8 million registered individuals, including residents, expatriates, and deceased persons. Threat actors abused a private company's legitimate access and used brute-force enumeration of CPR numbers to extract names, addresses, dates of birth, marital status, and CPR identification numbers. The breach occurred in September 2026, was discovered on October 2, and affected about 80% of records held in the CPR system. Authorities have blocked the third party's access, launched a police investigation, and enacted extra security measures while urging citizens to remain vigilant.
read more โ†’

Critical Dell DSU Flaw Lets Attackers Gain Root

๐Ÿ›ก๏ธ Dell warned customers to update the System Update (DSU) CLI after a critical path traversal vulnerability (CVE-2026-86360) was disclosed that can allow unauthenticated attackers to execute code with root privileges. The company released DSU 2.3.0.0 to patch this and four other high-severity issues, and urged immediate upgrades. U.S. agencies previously warned vendors to eliminate path traversal weaknesses, and organizations should patch promptly to reduce risk.
read more โ†’

ClingSTUN backdoor exploits unpatched IoT flaws

๐Ÿ” FortiGuard Labs has identified a Linux proxy backdoor named ClingSTUN that leverages unpatched internet-facing IoT vulnerabilities to turn devices into remotely controlled proxy nodes. The malware abuses legitimate public STUN servers to keep NAT bindings open and blend its traffic with normal VoIP/WebRTC communications. Operators deployed the campaign in three waves, expanding exploited vulnerabilities to at least 24 CVEs and adding hard-coded exploits to aid propagation. FortiGuard urges device inventory, prioritised patching and compensating controls where updates are unavailable.
read more โ†’

South Korea probes bank breaches amid AI suspicions

๐Ÿ”Ž South Korea's Financial Services Commission convened an emergency meeting after a string of cyberattacks affected major banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. Authorities confirmed data leaks โ€” reportedly affecting tens of thousands of customers โ€” and launched on-site investigations while coordinating with KISA and other agencies. Financial firms were ordered to inspect externally accessible systems, tighten access controls, share threat intelligence, and submit security inspection results promptly.
read more โ†’

Weekly Recap: NetScaler, FortiMail, and Major Threats

๐Ÿ“ฐ This weekโ€™s recap highlights multiple actively exploited vulnerabilities, high-profile arrests, and evolving malware techniques that take advantage of small oversights. Notable items include Citrix NetScaler and FortiMail zero-days, arrests tied to ShinyHunters and KillSec operations, and novel attack methods like RedFlick delivering the CosmicPulse backdoor. The report stresses urgent patching and improved basic hygiene to reduce exposure.
read more โ†’

Citrix NetScaler zero-day prompts emergency guidance

๐Ÿ”’ Citrix has disclosed a high-severity zero-day, CVE-2026-88779, affecting NetScaler ADC and NetScaler Gateway that can lead to denial of service when specific SAML-related configurations are present. The vendor urged customers on affected versions to review SAML authentication entries and install updates; temporary signatures and NetScaler Global Deny List rules are available to reduce exposure. Citrix stated customer data integrity was not impacted and is monitoring the situation while CISA added the flaw to its KEV catalog.
read more โ†’

Alleged Ploutus ATM Malware Author Appears in Court

๐Ÿ”’ The U.S. Department of Justice says the alleged developer of Ploutus malware, accused of orchestrating ATM jackpotting that stole millions, has appeared in U.S. court following his arrest. Known as "Prometheus" or "The Engineer," 50-year-old Anibal Alexander Canelon Aguirre faces multiple federal charges tied to attacks from February 2024 to December 2025. Authorities allege the stolen funds were laundered and transferred to accounts controlled by the Tren de Aragua criminal gang, which has been designated by U.S. agencies.
read more โ†’

Cloudflare Birthday Week 2026: Platform and Security

๐ŸŽ‰ Cloudflare recapped its 16th Birthday Week, detailing 46 announcements spanning open source, application security, developer tools, monetization, data platforms, and observability. Highlights include a new cf CLI and Forge pipeline, EmDash CMS, post-quantum cryptography efforts, plans to become a certificate authority, Monetization Gateway and Pay Per Use, and GA launches for Basin and K2. The company emphasized support for agents, developer ecosystems, intern contributions, and commitments to open tools and civic programs.
read more โ†’

Citrix NetScaler memory-overflow DoS vulnerability alert

โš ๏ธ Citrix has warned of a new high-severity memory-overflow vulnerability (CVE-2026-88779) affecting NetScaler ADC and NetScaler Gateway appliances, rating it 8.7 under CVSS 4.0 and reporting observed targeted exploitation. The flaw can cause repeated denial-of-service conditions when SAML authentication is configured and used with Gateway or AAA virtual servers. Citrix provided fixed build numbers and a temporary virtual-patching mitigation via Global Deny List signatures, and warned that affected customers who already patched earlier in the week may need to upgrade again. CISA added the vulnerability to its KEV catalog with an October 7 remediation deadline for US federal agencies.
read more โ†’

Expanding Credential Layer: Visibility and Risk

๐Ÿ”’ GitGuardian outlines why the credential layer deserves immediate attention and how detection is the first essential step. The article explains that credential sprawl spans repositories, endpoints, collaboration tools, and AI agents, increasing attack surfaces and making discovery urgent. It highlights research showing rising hardcoded secrets and explains the need for context โ€” validity, ownership, permissions, and dependencies โ€” to prioritize remediation. The piece argues security teams must connect multiple discovery sources to measure coverage and reduce exposure.
read more โ†’

Cling botnet leverages STUN to hide C2 activity

๐Ÿ” Nozomi Networks observed attackers exploiting a patched critical Realtek Jungle SDK RCE (CVE-2021-35394) starting around September 5, 2026, to deploy a botnet named Cling. The malware repurposes ordinary STUN traffic as a covert command-and-control channel, enabling propagation, proxying, tunneling and denial-of-service actions while resembling legitimate NAT-traversal activity. Samples embed multiple exploit payloads targeting routers and DVRs from various vendors and use persistence techniques like replacing wget and modifying init scripts.
read more โ†’