< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Malvertising builds malware in browser memory

🛡️ A widespread malvertising campaign uses fake Solana, Luno, and TradingView pages with malicious JavaScript that assembles malware directly in the browser's memory. The operation, active since late 2024 across 12 countries, filters out researchers and scanners while delivering customized payloads to retail traders and crypto investors. Confiant found the pages register service and shared workers to piece together a unique executable from remote components and local bytes, avoiding transmission of a finished file to evade detection.
read more →

ShinyHunters leaks fuel $2,000 sextortion email scam

📧 Threat actors are using email addresses exposed in data leaks attributed to ShinyHunters to send sextortion messages demanding $2,000 in Bitcoin. The campaign reuses leaked emails and breached company names to make threats appear credible, though there is no evidence recipients’ devices were actually compromised. BleepingComputer confirmed the use of data from multiple ShinyHunters incidents and observed messages falsely claiming remote access to cameras and files to coerce payment.
read more →

Critical Fastjson 1.x RCE Exploitation in Spring Boot

🛡️ Security firms ThreatBook and Imperva report active exploitation attempts targeting a critical remote code execution flaw in Fastjson 1.x, affecting Spring Boot executable fat-JAR deployments. Tracked as CVE-2026-16723 with an Alibaba CVSS of 9.0, the chain impacts Fastjson 1.2.68–1.2.83 when SafeMode is disabled and can execute code without AutoType or classpath gadgets. Alibaba has not yet released a 1.x patch; recommended mitigations include enabling SafeMode or using the 1.2.83_noneautotype build and migrating to Fastjson2 long-term.
read more →

Insurance Phishing Evolves into Real-Time Account Hijacks

🔍 Recent research shows insurance-targeted phishing has shifted from credential harvesting to real-time session hijacking. Attackers use paid Google Ads and disposable hosting to lure victims to realistic portals and then relay OTPs and credentials to authenticate on the legitimate service while the victim is logged in. CTM360 identified a bespoke kit, InsureOTP Kit, and exposed backend infrastructure revealing live session management and operator workflows. Defenders must expand detection beyond malicious pages to include ad monitoring, infrastructure analysis, and attacker workflow intelligence.
read more →

Cl0p affiliates exploit PTC Windchill and FlexPLM flaws

🔒 Threat actors tied to the Cl0p group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to achieve unauthenticated remote code execution and deploy JSP web shells. According to a coordinated advisory from Ransom-ISAC, eCrime.ch, and DEFUSED, attackers chain a FlexPLM WSDL information disclosure with a Windchill login servlet flaw (CVE-2026-12569) to stage data theft and double extortion. Targets include manufacturing, automotive, aerospace, and retail organizations, with multiple IoCs published by PTC.
read more →

DevMan RaaS Portal Centralizes Payloads and Management

🛡️ Swiss firm PRODAFT reports that the DevMan ransomware-as-a-service operation runs a centralized affiliate portal enabling payload builds, victim management, finance tracking, and team coordination. The platform evolved to v3 in January 2026 with structured victim records, deadlines, and shared access, while affiliates follow strict rules and an 80-20 revenue split. The locker targets Windows, ESXi, and Linux and uses ChaCha20-Poly1305 encryption.
read more →

OpenAI confirms ChatGPT outage affecting users globally

🔴 OpenAI has confirmed a widespread ChatGPT outage that began around 5 AM ET, preventing users worldwide from loading chats or accessing previous conversations. Affected users report the interface getting stuck on loading animations and an inability to interact with the AI. OpenAI acknowledged the issue on its status page and stated it is investigating. The situation is ongoing and being monitored.
read more →

GitLab RCE exploit published for unpatched instances

🛡️ Security researcher depthfirst published a working exploit on July 24 for a GitLab flaw patched by GitLab on June 10, enabling command execution as the git user on self-managed 18.11.3 servers that haven't updated. The chain abuses two memory-corruption bugs in the Oj Ruby JSON parser via GitLab's notebook diff renderer, allowing authenticated users who can push a project to leak a heap pointer and trigger a payload without admin or CI access. GitLab listed the Oj 3.17.3 bump under bug fixes rather than as a security fix, leaving operators unaware of the urgency; no CVE or CVSS score has been published yet.
read more →

Amazon Connect adds audio optimization for Azure VDI

🎧 Agents using Azure Virtual Desktop (AVD) or Windows 365 Cloud PC can now take Amazon Connect calls directly from their virtual desktop with audio optimization enabled. IT administrators perform a one-time setup to redirect media from the virtual desktop to the agent's local device, improving call audio quality. Agents access calls via the Amazon Connect Customer agent workspace or custom interfaces built with the Amazon Connect Customer open-source JavaScript libraries. This capability complements existing support for Amazon WorkSpaces, Citrix, and Omnissa cloud desktops and is available in all AWS Regions offering Amazon Connect Customer except AWS GovCloud (US-West).
read more →

Amazon MWAA adds support for Apache Airflow 2.11.2

🛠️ Amazon Managed Workflows for Apache Airflow (MWAA) now supports Apache Airflow 2.11.2, a maintenance release with security improvements, bug fixes, and dependency upgrades. The update enhances webserver stability, task execution, and task lifecycle handling, and improves secrets masking and UI behavior. You can create new 2.11.2 environments or upgrade existing ones in all available MWAA regions via the AWS Management Console.
read more →

EC2 Dedicated Hosts add flexible Host Resource Groups

🛡️ Starting today, Amazon EC2 Dedicated Hosts support creating Host Resource Groups (HRGs) without requiring Self-Managed Licenses (SMLs). This change benefits customers who use Dedicated Hosts for hardware-level isolation or EC2 Mac Instances, while customers with BYOL needs can still opt to create HRGs with SMLs to restrict AMIs and track license consumption. To create an HRG without an SML, uncheck the "Restrict to AMIs associated with self-managed license" option in the EC2 Console or set instance-launch-option to license-configuration-required via the AWS CLI. The feature is available in all Regions that support Host Resource Groups.
read more →

OnTrac Notifies Customers After Network Breach

🔒 OnTrac has disclosed a network intrusion detected on March 23 after attackers accessed certain files between March 20 and 22. The company says customer names may have been exposed but redacted details in the notification leave the extent unclear. OnTrac engaged a third-party specialist, offered 12 months of free credit monitoring via CyberScout, and recommends affected customers review credit reports and consider fraud alerts or freezes.
read more →

Accelerating Network Firewall Troubleshooting with DevOps Agent

🛡️ This post shows how AWS DevOps Agent accelerates root-cause analysis for AWS Network Firewall issues by correlating CloudWatch alarms, firewall logs, route tables, and CloudTrail events. It walks through three reproducible failure scenarios—domain deny list, stateless rule priority inversion, and asymmetric cross-AZ routing—deployed via an AWS CDK app. The CDK stack includes a sample workload, test endpoint, status page, and a webhook pipeline so alarms trigger investigations and the agent returns mitigation plans for operator review.
read more →

Kinesis adds on-demand warm throughput scale-down

🔧 Amazon Kinesis Data Streams now lets you scale down on-demand warm throughput for streams running in On-demand Advantage mode. By setting a lower warm throughput value, streams adjust to the requested capacity or to the peak ingest usage from the last hour, whichever is higher, ensuring sufficient capacity while releasing unneeded throughput. The capability incurs no additional cost and is available in all Regions that support On-demand Advantage; documentation and pricing guidance are provided in the Developer Guide and console instructions.
read more →

BGP ORIGIN Attribute Manipulation and Impact

📘 Cloudflare examines the BGP ORIGIN attribute, a mandatory path attribute intended to signal how a route was injected into BGP. Their experiments show widespread modification of ORIGIN values—predominantly to IGP—by many networks, including Tier-1s, altering route selection and diverting traffic for commercial advantage. The report describes methodology, measurements across IPv4/IPv6, and the resulting routing and economic impacts.
read more →

Why chat agents can read your unsent messages

💬 Live chat widgets on many websites include a real-time typing preview that lets agents see everything you type, even drafts you never send. This feature is common across popular customer support platforms and is used to speed responses and monitor quality, but it can expose sensitive information without your consent. Users rarely notice the feature and most chat widgets lack an option to disable it. To reduce risk, avoid entering personal data in chat boxes and use security tools to block malicious sites and tracking.
read more →

OKF v0.2 Adds Frontmatter Trust Signals

📝 OKF v0.2 extends the Open Knowledge Format with optional frontmatter fields that encode provenance, trust, freshness, lifecycle, and attestation signals. The update preserves v0.1's minimalism—new fields are opt-in and backward-compatible—while enabling consumers to filter and assess agent-generated concepts before reading bodies. Reference samples and tooling illustrate attested computations and verification workflows.
read more →

AWS Lambda Managed Instances now publishes logs

📣 AWS Lambda now sends logs for Lambda Managed Instances (LMI) capacity providers to Amazon CloudWatch Logs, providing visibility into scaling activity and instance lifecycle operations. LMI lets you run Lambda functions on Amazon EC2 instances while keeping serverless operational simplicity. Capacity provider logs capture structured JSON lifecycle events like launches, terminations, and health checks to help monitor, troubleshoot, and optimize managed EC2 resources. Logs are enabled by default across supported AWS Commercial Regions and incur standard CloudWatch Logs charges.
read more →