< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Smashing Security Ep 486: Vibe‑Coded Shops Risk

📰 Smashing Security episode 486 features Graham Cluley and guest Dave Bittner discussing misconfigured AI-built websites, notably a New Zealand store using Base44 that left its site editable by anyone. The episode covers humorous consequences (crusty socks, Princess Diana plates, a Laser Kiwi) and broader concerns about low‑expertise users adopting AI site builders without proper security settings. The hosts also mention past Base44 flaws and consider the risks to small businesses adopting these tools.
read more →

AWS August 2026 Security Update Digest

🔒 August’s AWS Security digest highlights new service capabilities, compliance updates, and hands-on resources across identity, data protection, AI security, detection, and governance. It summarizes 20+ blog posts, security bulletins, and 17 code samples focused on agent governance, credential protection, and automated compliance. The update emphasizes prompt patching and practical deployment guidance for enterprise security teams.
read more →

Kinesis adds service‑managed partition keys for on‑demand

🔔 Amazon Kinesis Data Streams now offers service-managed partition keys for On-Demand Standard and On-Demand Advantage streams, automatically distributing records across shards so customers don’t need to supply partition keys when ordering isn’t required. This simplifies ingestion for use cases such as log aggregation, metrics, and IoT telemetry, eliminating hot keys and reducing time to production. The feature is available today in all AWS commercial regions at no extra cost; customers can adopt it by upgrading to the latest AWS SDK or Kinesis Producer Library.
read more →

Placeholder domain abused to deliver ClickFix attacks

🛡️ The commonly used placeholder domain third-party.com is serving a fake Cloudflare verification page that attempts to trick Windows users into running PowerShell commands. The site copies a malicious command to the clipboard and instructs victims to paste and execute it, a technique known as ClickFix. Researchers found the domain referenced across public developer docs and confirmed the malicious behavior; the current payload host was not resolving during testing.
read more →

RemControl Android banking MaaS targets Europe, Canada

🛡️ Researchers at Group-IB have uncovered a new Android malware-as-a-service called RemControl, distributed via malvertising that impersonates the TVTap IPTV app. The dropper starts a VPN to block Google Play services and requests Accessibility permissions to deploy full-screen phishing overlays and steal banking credentials. Targets include users in Europe, Canada, and parts of the Middle East, and the operation dynamically fetches C2 data via Telegram.
read more →

F5 patches critical BIG-IP APM zero‑day flaw

🔒 F5 released fixes for a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) that was actively exploited in the wild. The heap-based buffer overflow, tracked as CVE-2026-94127 and rated 9.8, affects deployments configured as OAuth authorization servers and can also impact appliance-mode systems when both APM and an OAuth authorization server profile are enabled. F5 published hotfixes for the 21.x, 17.5.x and 17.1.x branches and provided an iRule mitigation while patches are applied.
read more →

Check Point warns of Security Gateway VPN RCE exploit

🔒 Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate-handling of its Security Gateway product, and warned of active abuse of CVE-2026-93616 affecting the Management web service. The company reported attacks beginning September 12, 2026, originating from anonymization services, and advised administrators to apply LivePatch Take 26 or specified Jumbo Hotfixes, update Spark firewalls, and follow temporary VPN rule restrictions if updates are not possible.
read more →

Critical WordPress flaw exploited for remote code execution

🔍 Threat actors have progressed from scanning for CVE-2026-87902 to actively exploiting the vulnerability to write files that execute shell commands when accessed. Patchstack observed initial reconnaissance less than five hours after WordPress 7.1.2 was released, with malicious activity increasing tenfold as attackers began delivering payloads. The flaw, discovered by Robert Ressl, is an unauthenticated path traversal that can lead to RCE under specific theme and server conditions. Administrators are urged to update to WordPress 7.1.2 and review logs for indicators of compromise.
read more →

Amazon Bedrock adds Salesforce and Zendesk connectors

🔗 AWS announced native Salesforce and Zendesk data source connectors for Amazon Bedrock Managed Knowledge Base, enabling direct synchronization of Salesforce knowledge articles and Zendesk help center articles and community posts. The connectors remove the need for custom ingestion pipelines by handling crawling, metadata extraction, and incremental sync using instance credentials. This streamlines building RAG-based AI agents and assistants grounded in up-to-date support and product knowledge.
read more →

Leaked GitLab email token enables commits and CI

📧 GitLab issues each user a persistent incoming-email address for filing work items; that address contains a token tied to the account and does not expire. Researchers at Aikido Security found the token is shared across a user's project addresses and allows anyone who holds the address to create issues, open merge requests by email, commit patches to branches (including main) and trigger CI/CD jobs that run as the account holder. GitLab currently does not verify the sender address, and incoming email bypasses IP allowlists and two-factor requirements.
read more →

MikroTrick RouterOS SSH Chain Grants Full Access

🔒 CERT Polska details a two-bug chain named MikroTrick that lets attackers gain full administrative control of Internet-exposed MikroTik RouterOS devices without a password. The chain combines an SSH state-machine flaw (CVE-2026-67279) and an argument-injection bug in the login process (CVE-2026-86060); exploitation traces predate vendor patches. Administrators are urged to apply updates and inspect devices for indicators such as a '-2' login, unexpected 'ops' accounts, and suspicious network activity.
read more →

Amazon Connect adds routing step data to data lake

📊 Amazon Connect Customer now delivers routing step data into its analytics data lake, enabling easier insight generation from routing decisions. Using the data lake, customers can use Amazon Athena and Amazon Quick to analyze trends like contacts queued and contacts joined at each routing step without building complex pipelines. Analysts can report on contact progression, pinpoint where agent matching criteria were relaxed, and measure routing impacts on wait times and agent utilization.
read more →

Reimagining the SOC for the agentic era

🔐 Microsoft announces an Integrated Security Operations Center (ISOC) in Microsoft Defender to unify SIEM and threat protection into a single platform. ISOC provides combined signals, context, and actuators so humans and agents can operate as one system, enabling faster detection, investigation, and automated response. The preview is available now.
read more →

GKE Adds Native Scale-to-Zero Capabilities

🚀 GKE 1.37 introduces native scale-to-zero so workloads can fully scale down to zero replicas and stop consuming compute while idle. The feature uses HPA with the new AutoscalingMetric CRD and KEP-2021 support for minReplicas: 0 to wake workloads based on external signals such as Pub/Sub or Cloud Monitoring. Capacity buffers provide pooled warm capacity to eliminate cold-start latency and balance cost with instant responsiveness.
read more →

Autonomous optimization for real‑time video pipelines

🎯 This article explains how AlphaEvolve pairs cloud-based Gemini code generation with local evaluation to accelerate real-time video processing. It outlines the split-loop architecture—managed generation on Google Cloud and customer-run evaluators on target hardware—and emphasizes constructing robust quality gates like SSIM to prevent benchmark gaming. The post includes practical guidance on evaluator design, multi-frame state, and measuring hardware floors versus software overhead to set realistic optimization targets.
read more →

GKE Adds Native Prometheus Metrics for Autoscaling

🔔 Google Cloud announced built-in Prometheus metrics processing for GKE, enabling HPA to use PromQL queries directly via Google Managed Service for Prometheus. This removes the need for third-party adapters, reduces latency, and simplifies autoscaling configuration. The controller runs in the control plane and only deploys pods on nodes when PromQL metrics are actively requested, minimizing resource use. The feature is in preview with plans to add self-hosted Prometheus support before GA.
read more →

Leaked GitHub App keys risk organization takeover

🔐 GitGuardian discovered hundreds of publicly exposed GitHub App private keys that remain valid unless manually revoked. Their testing found many keys granted read or write access to private repositories and some allowed organization administration, enabling potential takeovers. The exposed keys included apps used by multiple organizations and internal one-off bots, increasing supply-chain risk. Experts recommend routine key rotation and prompt revocation to limit long-lived exposure.
read more →

Amazon EMR on EKS adds IPv6 support

🚀 Amazon announces that Amazon EMR on EKS now supports running Spark and Flink workloads on IPv6 Amazon EKS clusters. This enables teams to use the larger IPv6 address space to scale high-executor analytics jobs without IPv4 workarounds. Support starts with EMR releases emr-7.14.0 and emr-spark-8.0.0 and is available in regions where IPv6 EKS clusters are offered.
read more →