< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Anubis Claims Responsibility for Fairlife Cyberattack

🛡️ The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, alleging it stole approximately 1 TB of corporate data and encrypted Nutanix systems. Coca-Cola disclosed the incident on July 16 after production at U.S. facilities was suspended; the company said product safety was unaffected and declined to comment on Anubis' claims. Anubis, a RaaS group active since December 2024, has combined data theft, encryption, and destructive wiping in prior attacks.
read more →

AWS WAF dynamic label interpolation for bot signals

🛡️ AWS WAF now supports dynamic label interpolation, allowing labels applied to requests (including managed Bot Control and ATP labels) to be referenced by namespace instead of enumerating individual values. Use the ${namespace:} syntax in custom request/response headers and response bodies to forward matched labels and synthetic values (client IP, request ID, JA3/JA4) to your origin or embed them in challenge and block pages. This reduces rule maintenance, supports hundreds of evolving bot categories, enables per-device signals, and lets applications make nuanced decisions—such as challenges, redirects, or routing—based on WAF classifications.
read more →

Critical wp2shell WordPress flaws exploited widely

🔒 Hackers are actively exploiting the wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) in WordPress Core to install persistent webshells and malicious plugins. The exploit abuses the REST API batch-processing feature to achieve unauthenticated remote code execution. WordPress released emergency patches (7.0.2, 6.9.5, 6.8.6) and forced automatic updates while researchers report mass scanning, plugin abuse, and backdoor deployments.
read more →

Amazon SES launches tiered pricing plans

📣 Amazon Simple Email Service (SES) now offers three hierarchical pricing plans — Essentials, Pro, and Enterprise — that bundle commonly used deliverability and management capabilities. Each plan builds on the prior tier and provides progressively greater features at a discount versus à‑la‑carte purchases. Plans remove the need to evaluate and buy individual add-ons and are available in all AWS Regions where SES operates except the Middle East (UAE) and Bahrain.
read more →

AWS Kiro flaw let hidden web content trigger RCE

🛡️ Hidden text on a web page allowed Kiro, AWS's agentic coding IDE, to rewrite its mcp.json configuration and execute attacker-controlled commands on a developer's machine without a usable approval step. Researchers at Intezer and Kodem Security showed that asking Kiro to summarize or fetch a page could inject setup instructions in one-pixel white text, causing Kiro to register and launch a malicious Model Context Protocol server. AWS patched the vulnerability by protecting sensitive paths and adding platform-enforced approval checks.
read more →

AlloyDB boosts pgvector HNSW performance 4x

🔒 AlloyDB, a PostgreSQL-compatible managed service, now offers columnar engine accelerated HNSW to speed up pgvector vector search. This preview feature pins HNSW indexes in a compressed, in-memory columnar cache to reduce buffer-manager overhead and enable up to 4x higher QPS compared to standard PostgreSQL. The enhancement requires simple flag changes and uses the same pgvector SQL syntax, delivering higher throughput and improved AI recall without application changes.
read more →

Amazon ECS adds Action Logs for deployment visibility

📘 Amazon Elastic Container Service (Amazon ECS) now provides Action Logs, an observability feature that records detailed, timestamped actions ECS performs during service deployments and Managed Daemon updates. These logs surface previously invisible service-side operations to help monitor and troubleshoot workloads without contacting AWS Support. You can enable Action Logs at the cluster level via the console or CloudWatch vended logs APIs and deliver them to CloudWatch Logs, S3, or Kinesis Data Firehose. Amazon Q in the ECS console integrates with Action Logs to detect deployment issues and provide root cause analysis and remediation guidance; standard CloudWatch/S3/Firehose pricing applies.
read more →

ConsentFix: OAuth-based Microsoft 365 account hijacking

🛡️Researchers uncovered a new ClickFix variant called ConsentFix that tricks users into granting OAuth tokens, enabling attackers to access Microsoft 365 accounts without stealing passwords. Attackers use deceptive pages and social engineering—often via phishing emails imitating file-sharing services—to induce victims to drag a tokenized URL onto an attacker-controlled page. Once obtained, the OAuth token can expose Outlook, Teams, OneDrive, SharePoint and other services depending on the organization’s license and privileges, enabling data exfiltration, BEC and lateral movement. The technique is widely shared on cybercrime forums with tutorials and turnkey tools, increasing its prevalence and lowering the barrier for novice threat actors.
read more →

Google unveils Gemini 3.5 Flash Cyber for security

🔒 DeepMind has released Gemini 3.5 Flash Cyber, a lightweight AI specialized in rapid vulnerability discovery, validation, and patching. The model is available only to governments and trusted partners via the CodeMender pilot program and is designed for high-speed, low-cost scanning of code paths. DeepMind reports it outperforms other Gemini variants and rival models in finding unique, confirmed issues across complex projects.
read more →

CodeMender brings AI-driven code scanning and remediation

🛡️ CodeMender is a managed code security agent now available in preview, offering automated scanning and remediation using Google DeepMind–tuned models via the Gemini Enterprise Agent Platform or as part of AI Threat Defense. It prioritizes fixes by exploitability, runs proof-of-concept exploits in customer-managed sandboxes, and generates validated patches that integrate into developer workflows. The agent supports multiple languages, integrates with CI/CD and IDEs, and enforces enterprise-grade governance and data controls.
read more →

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation

🛡️ Microsoft patched a critical SharePoint Server deserialization flaw, CVE-2026-50522 (CVSS 9.8), which is now being actively exploited. DEVCORE researcher splitline reported the issue; Microsoft warned authenticated attackers with Site Owner privileges could execute remote code. Security firms and CISA observed attackers stealing machine keys and urged credential rotation even after patching.
read more →

Qilin ransomware leverages PAN‑OS VPN flaw

🛡️ Arctic Wolf Labs investigated June 2026 intrusions where actors exploited CVE-2026-0257, a patched authentication bypass in Palo Alto Networks PAN-OS, to establish SSL VPN sessions and deploy Qilin (aka Agenda) ransomware. Post-exploitation activity varied from rapid encryption to full double-extortion, but shared tactics included staging payloads in C:\PerfLogs\, using PsExec for lateral movement, harvesting credentials, disabling Defender real-time protection, and clearing event logs.
read more →

Amazon Managed Service for Prometheus scales massively

📈 Amazon Managed Service for Prometheus now supports up to 1.5 billion active metric time series and up to 200,000 recording and alerting rules per workspace, with customers able to create many workspaces per account. Amazon Managed Service for Prometheus is a fully managed, Prometheus-compatible monitoring service that automatically scales ingestion and storage for high-cardinality workloads across containerized, serverless, and hybrid environments. It integrates with AWS security services to provide secure access to monitoring data and lets customers request higher workspace limits via AWS Support Center or AWS Service Quotas.
read more →

Actor Commercializes Claude Jailbreaks into AI Pentest Tool

🔍 A Russian-speaking actor known as Trim moved from posting a Claude jailbreak tutorial to selling a commercial AI pentesting platform in three months. Cato CTRL research shows Trim published six named bypass techniques in March and launched AI Pentest Checker by June, embedding those jailbreaks and using a grey-market Claude API key. The product combines Claude Opus and GLM-5 with conventional scanners to produce rapid vulnerability reports.
read more →

Zimbra issues patch for critical SNMP command flaw

🔧 Zimbra released version 10.1.20 to address nine vulnerabilities, led by a command injection flaw in the SNMP monitoring component when SNMP notifications are enabled. The update also fixes four cross-site scripting (XSS) issues in the Classic Web Client and a mail forwarding restriction bypass (CVE-2026-50055) reported by Jonah Burgess. The vendor limited details per industry best practices and urged customers to apply the fixes promptly.
read more →

Ransomware Landscape Expands with New Groups Weekly

🛡️ The Black Kite Ransomware Report 2026 finds 146 active ransomware groups as of June 2026, up from 105 a year earlier, with 61 new groups emerging in 2026 alone. The study highlights a fragmented ecosystem where groups often have short lifespans—averaging 4.9 months—and a small number of operators still account for a large share of disclosed victims. Black Kite urges organizations to prioritize rapid patching of critical vulnerabilities and strengthen identity and vendor controls to mitigate attacks.
read more →

Global Internet Traffic Shifts During the 2026 World Cup

📈 Cloudflare Radar analyzed HTTP, DNS, and security signals across its global network during the June–July 2026 World Cup to measure how matches changed Internet activity. Using a four-week median baseline and log2 ratios, the study compared per-country deviations by kickoff time, revealing large spikes for overnight matches and smaller evening bumps. The report ranks matches and teams by worldwide impact and examines regional behaviors, streaming effects, and distinct halftime and hydration-break patterns.
read more →

FBI warns of deepfake videos used in IC3 scam

🛡️ The FBI has issued an IC3 public service announcement warning that scammers are escalating a long-running impersonation scheme by deploying deepfake videos of senior FBI officials and spoofed IC3 websites to re-defraud previous victims. Fraudsters combine social media impersonation, AI-generated video and lookalike complaint portals to harvest further data and payments. IC3 stressed it does not communicate via social platforms or request payment, and urged users to verify .gov domains.
read more →