< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Atlassian Rovo prompt-injection and link flaw fixed

🛡️ Two security teams found ways to make Atlassian's Rovo assistant exfiltrate data a signed-in user can access. One method used a malicious file with hidden instructions to induce Rovo to gather Jira or Confluence content and send it to an attacker-controlled URL; PromptArmor disclosed this on August 5, 2026 and its remediation status after publication is unconfirmed. The second, dubbed RovoBlast by Varonis, preloads attacker instructions via a rovoChatPrompt URL parameter so a single click from an authenticated user could cause data to be sent out; Atlassian fixed this server-side on July 8, 2026. Both issues rely on data the signed-in user can reach, and administrators can limit exposure by restricting which apps and groups can use Rovo and tightening connector permissions.
read more →

New CSS attack chains break webmail boundaries

🔒 New research shows HTML and CSS can escape email message boundaries to interfere with webmail UIs across major providers. PortSwigger researcher Gareth Heyes presented proof-of-concept chains at Black Hat USA 2026 targeting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The techniques can capture passwords, leak tokens, hijack UI actions, and manipulate AI-connected tools; some PoCs remained public as of August 8.
read more →

Metabase zero-day exploited; urgent patches advised

🔒 Metabase disclosed a maximum-severity zero-day vulnerability (CVSS 10.0) affecting versions from x.58.0 through x.63.x that has been actively exploited in the wild. The flaw allows unauthenticated SQL injection into the application database, enabling attackers to gain administrator access, alter configurations, steal stored database credentials, and exfiltrate data. Metabase Cloud has been patched; self-hosted users must apply updates immediately or block the "/api/session/reset_password" endpoint as an interim mitigation.
read more →

N‑able Issues Hotfixes After Active N‑central Exploitation

🔒 N‑able has issued Hotfix 2 for N‑central after detecting active exploitation of a recently disclosed RMM server vulnerability (CVE-2026-18577) first observed on July 31, 2026. The company says Hotfix 2 supersedes Hotfix 1 and provides additional hardening; on-prem customers must update to 2026.3.1.10 immediately. A limited set of customers were affected, and N‑able published IoCs plus a custom service template to scan Windows endpoints, while cautioning that results are not a guarantee of full remediation.
read more →

Critical LoadMaster Command Injection Added to CISA KEV

🔒 CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The flaw, rooted in improper input handling in an escape_quotes() function, allows unauthenticated attackers to execute arbitrary commands on affected appliances. Agencies are urged to apply patches immediately under BOD 26-04 to mitigate ongoing attacks.
read more →

Identity-Driven Attacks and SOC Response Trends

🔐 Unit 42 finds identity compromises underpin most modern incidents, with the 2026 Global Incident Response Report showing identity weaknesses in nearly 90% of investigations and 65% of initial access events. Attackers increasingly use phishing, social engineering, MFA manipulation and third-party account misuse to gain entry, then move laterally, escalate privileges and blend into administrative behavior. Unit 42 recommends correlating identity, endpoint, cloud and network telemetry, applying AI-driven correlation and centralized investigations, and investing in continuous threat hunting and SOC engineering to detect and contain identity-driven intrusions earlier.
read more →

AWS launches R8i and R8i‑flex memory instances

🆕 Amazon EC2 R8i and R8i-flex instances are now available in Europe (Milan), powered by custom Intel Xeon 6 processors exclusive to AWS. These instances provide up to 15% better price-performance and 2.5x memory bandwidth versus prior Intel-based instances, plus up to 20% higher performance than R7i. R8i-flex offers common memory-optimized sizes for cost-efficient workloads, while R8i includes 13 sizes, two bare metal options, and a 96xlarge for the largest applications, with SAP certification and 142,100 aSAPS.
read more →

A decade of AWS Managed Microsoft AD evolution

🔒 Over ten years, AWS Managed Microsoft AD evolved from a basic managed Microsoft Active Directory offering into a foundational enterprise identity service integrated across more than 20 AWS services. The service reduced operational overhead by handling domain controllers, HA, backups, patching, and replication while adding features like schema extensions, gMSA, multi-Region replication, and CRUD APIs. Recent additions include Hybrid Edition, self-service edition upgrades, and integrations for database, file, and remote-access authentication.
read more →

Unlimited Technology Systems Exposes 3.8M Records

🛡️ Unlimited Technology Systems disclosed a data breach affecting 3,803,750 individuals after a server compromise in October 2025. The company, which provides financial and revenue cycle software to specialty healthcare providers, discovered unauthorized access between October 5 and October 10 and notified authorities and patients in July 2026. Affected data may include names, SSNs, dates of birth, contact details, scanned IDs, insurance information, medical records, and diagnosis details. Affected patients were offered identity monitoring through Kroll.
read more →

Timestream for InfluxDB adds backup and restore

🔒 Amazon Timestream for InfluxDB now supports customer-driven backups and restores for InfluxDB 2 and 3 engines. You can trigger one-time on-demand backups, schedule up to four recurring backup configurations per resource with custom frequency and retention, and restore either to a new resource or overwrite an existing one via the Console, CLI, or API. The first backup is full and subsequent backups are incremental, and KMS-managed keys are preserved for encrypted resources.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →

Amazon Cognito added to Agent Toolkit skills

🔧 The Amazon Cognito (aws-auth) skill is now included in the Agent Toolkit for AWS, enabling AI coding agents to set up, configure, secure, and troubleshoot Amazon Cognito using best-practice workflows. The skill supports user pools, app clients, OAuth 2.0 flows, token and JWT authorizer management, passkey/WebAuthn enrollment, threat protection, Lambda triggers, and identity pools. When used with the AWS MCP Server, commands run with IAM guardrails and CloudTrail audit logging; it also works standalone via the AWS CLI.
read more →

BigQuery DTS expands integrations and features

🚀 BigQuery Data Transfer Service (DTS) reduces engineering overhead by automating zero-code data ingestion into BigQuery, enabling teams to shift focus from pipeline maintenance to analytics. Recent additions include Open Lakehouse ingestion to Apache Iceberg, a managed Model Context Protocol (MCP) Server, expanded database connectors (PostgreSQL, MySQL, SQL Server), SaaS connectors (Shopify, Klaviyo, HubSpot, Mailchimp), and a Snowflake migration path. DTS emphasizes free ingestion for many first-party sources, low consumption-based pricing for third-party SaaS, integrated Cloud IAM security, and a 99.99% SLA for resilient data pipelines.
read more →

Securing Amazon S3: Identify and Remediate Over‑Permissions

🔒 This post explains how to detect and remediate over‑permissioned Amazon S3 buckets across single‑ or multi‑account AWS environments. It outlines a five‑phase workflow—setup, detection, remediation, continuous monitoring, and cleanup—while recommending AWS Config, Security Hub, EventBridge, IAM Access Analyzer, and Lambda‑based scanning scripts. The guidance focuses on methodology and customization for security engineers, cloud architects, and DevOps teams.
read more →

One-click multi-Region option for IAM Identity Center

🔒 AWS IAM Identity Center now offers a one-click multi-Region option when creating a new organization instance, simplifying what previously required multiple manual steps. The multi-Region instance choice automatically creates a customer managed multi-Region KMS key and replicates the instance to an additional Region to provide resilient access. Customers can also choose single-Region or custom instances, with custom allowing use of existing customer managed KMS keys and fine-grained Region configuration.
read more →

How Google Cloud detects and contains emerging threats

🔒 Google Cloud outlines its proactive, shared-fate approach to detect and contain emerging threats across AI workloads, cryptomining, credential exposure, supply chain attacks, and account takeover. The post describes detection signals, tailored containment actions like granular throttling and localized identity isolation, and escalation paths including targeted suspensions. It highlights integrations such as GitHub Secret Scanning and details observability tools like Cloud Abuse Event Logging, Cloud Audit Logging, and billing alerts.
read more →

VPC IPAM adds BGP route protection and delegated RPKI

🛡️ Amazon VPC IPAM now supports BGP route protection monitoring and delegated RPKI management for BYOIP prefixes, enabling centralized monitoring of RPKI validity, ROA strength, and route overlap across accounts and regions. Administrators can detect invalid or missing ROAs, identify potential hijacks via overlap detection, and differentiate strict versus permissive ROA configurations. With Delegated RPKI, after a one-time setup with ARIN, RIPE, APNIC, or LACNIC, IPAM automates ROA creation, renewal, and management for both BYOIP and on-premises prefixes. The capability is available in all commercial AWS Regions except AWS GovCloud (US) and the China regions.
read more →

AgentCore adds memory, policy and harness in GovCloud

🛡️ Amazon Bedrock AgentCore is now available in AWS GovCloud (US-West), enabling regulated organizations to build context-aware agents with controls for production scale. AgentCore memory provides short-term conversational context and long-term persistent insights without complex infrastructure. Policy features let teams author natural-language policies that convert to Cedar and enforce tool access at an AgentCore gateway. The managed harness simplifies deployment by declaring models, tools, and instructions via configuration and running agents with a few API calls.
read more →