< ciso
brief />

Hello, stay ahead with CISO Brief πŸš€

Every day the cybersecurity world moves fast β€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence β€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

πŸ‘‰ Join our Telegram channel for your daily update β€” stay informed, stay ready.

Cybersecurity News Digest β€” Daily Briefings

Latest News

all posts β†’

Amazon DocumentDB adds direct major upgrade to 8.0

πŸ”” Amazon DocumentDB now supports in-place major version upgrades directly from engine versions 3.6 and 4.0 to 8.0, preserving data, configurations, and cluster settings. The capability removes the need for intermediate upgrades and is available in all AWS regions where 3.6 and 4.0 are supported. Upgrading to 8.0 brings the latest security patches, performance improvements, and developer features. For detailed guidance, AWS points customers to the MVU documentation and the 8.0 announcement.
read more β†’

AWS expands Partner Revenue Measurement coverage

πŸ” Partner Revenue Measurement's User Agent string now captures additional AWS services, expanding visibility into attributed revenue and product consumption. Partners who already embed the APN User Agent format (APN_1.1/pc_$) receive this expanded coverage automatically with no additional implementation required. The newly measured consumption appears in the Attributed Revenue Dashboard within Partner Analytics in AWS Partner Central. This complements Resource Tagging and AWS Marketplace Metering integrations and is generally available in all commercial regions.
read more β†’

Amazon Quick adds AWS Agent Registry integration

πŸ”— Amazon Quick now integrates with the AWS Agent Registry to let users discover, enable, and share MCP servers and agents directly within their Amazon Quick workspace. Connection details are pre-populated from the registry, enabling quick enablement and distribution for chat, agents, apps, flows, and research. The integration is available in all regions where Amazon Quick and Amazon Bedrock AgentCore are supported, and administrators can connect via Manage account > Permissions > AWS Agent Registry.
read more β†’

Amazon Redshift adds IAM Identity Center via EVR

πŸ”’ Amazon Redshift now supports AWS IAM Identity Center authentication for provisioned clusters and serverless workgroups configured with enhanced VPC routing (EVR). This enables single sign-on using corporate credentials while keeping traffic inside your Amazon VPC and on the AWS network, meeting data residency and network-isolation requirements. Redshift validates and exchanges IAM Identity Center tokens over AWS PrivateLink interface VPC endpoints inside the VPC and supports multi-Region Identity Center replication.
read more β†’

Cronos Restarts After Tectonic $74M Exploit

πŸ”” The Cronos blockchain resumed trading after a rapid price-manipulation attack on the Tectonic lending platform allowed an attacker to borrow $74 million. The attacker inflated the TONIC token price by 100x within 20 minutes and used it as collateral; only about $6 million in ETH was withdrawn while the rest remained on Cronos. Cronos halted the chain, restored state to before the exploit, and resumed block production while investigations continue.
read more β†’

Windows Defender false-off notifications raise risk

πŸ›‘οΈ Microsoft acknowledged a bug causing Windows to display β€œMicrosoft Defender Antivirus is turned off” notifications even though the product is functioning correctly. The vendor says it will issue a fix in a future Defender update and listed affected Windows client and server versions spanning recent and legacy releases. Security experts warn the advisory may train users and SOCs to ignore critical alerts, enabling attacker tradecraft and increasing risk.
read more β†’

Amazon Timestream for InfluxDB expands to 8 regions

πŸ†• Amazon Timestream for InfluxDB is now available in eight additional AWS Regions including Cape Town, Bangkok, Hong Kong, Hyderabad, Melbourne, Seoul, Zurich, and Tel Aviv. Timestream for InfluxDB provides fully managed InfluxDB databases with Multi-AZ high availability, read replicas, enhanced durability, and multi-node scaling to support real-time time-series applications. You can deploy and manage databases via the console, AWS CLI, or AWS SDKs.
read more β†’

AWS partners with Upwind to extend Security Hub

πŸ”’ AWS invited Upwind to join Security Hub Extended after customers repeatedly cited Upwind as a complementary solution. Upwind integrated deeply, offering runtime-first protection, pay-as-you-go pricing, and aligned go-to-market efforts that have driven strong joint deal activity. The integration enables unified findings in OCSF across build-to-runtime tools, simplified procurement on one AWS bill, and no custom integrations for customers.
read more β†’

Amazon Redshift adds Apache Iceberg v3 support

πŸ”” Amazon Redshift now reads from and writes to Apache Iceberg v3 tables in your data lake, adding support for default column values, row lineage, and deletion vectors. Default column values simplify schema evolution by providing initial values when none are supplied. Row lineage exposes pseudo-columns for row identity and update sequence, enabling incremental and CDC workflows. Deletion vectors use compact compressed bitmaps to replace positional delete files, improving read/write performance for frequent updates and deletes.
read more β†’

AWS launches R9g and R9gd Graviton5 memory instances

πŸš€ Amazon EC2 R9g and R9gd instances powered by AWS Graviton5 processors are now generally available, targeting memory-intensive workloads such as databases, in-memory caches, real-time analytics, and containerized applications. R9gd adds local NVMe SSD storage for block-level needs. These instances claim up to 25% better compute performance versus Graviton4-based R8g/R8gd and offer enhanced cache and memory speeds. They run on the sixth-generation AWS Nitro System with the new Nitro Isolation Engine to improve workload isolation and are available in multiple US and EU regions.
read more β†’

Amazon Cognito adds GetClientToken for M2M use

πŸ”’ Amazon Cognito now supports the GetClientToken API, enabling app clients to obtain access tokens for machine-to-machine authorization without requiring a user pool domain. The API lets an app client authenticate with its client ID and secret to receive access tokens for custom scopes on resource servers and integrates with AWS SDKs, AWS WAF, and VPC interface endpoints. The domain-based OAuth 2.0 client-credentials flow remains available, and the feature is live in all regions where Cognito user pools exist.
read more β†’

AWS Lambda recursive loop detection in all regions

πŸ›‘οΈ AWS Lambda recursive loop detection is now available in all commercial AWS Regions. This default-enabled guardrail detects and stops recursive invocations between Lambda functions and supported event sources like Amazon S3, Amazon SQS, and Amazon SNS, preventing runaway workloads and unexpected costs. When a loop is detected, Lambda halts processing and sends an AWS Health Dashboard notification with troubleshooting guidance. You can disable detection per function using the PutFunctionRecursionConfig API if intentional recursion is required.
read more β†’

North Korean job fraud expands beyond IT roles

πŸ›‘οΈ Researchers report DPRK-linked operators have broadened their employment fraud beyond IT into sales, marketing, and healthcare, using stolen and forged identities, VPNs, and proxy services to secure remote jobs at global firms. Investigations found evidence of PiKVM and USB capture hardware, synthetic personas aided by AI, and coordination via multi-account tools and facilitators who provision laptop farms. Agencies and firms are urged to strengthen identity verification and background checks to detect these sophisticated schemes.
read more β†’

Automate IAM Identity Center governance and reporting

πŸ” This post explains how to plan and automate governance for AWS IAM Identity Center across an AWS Organization. It outlines integration with external IdPs, recommended delegation and IAM permissions, and naming conventions to improve discoverability. The article describes a sample solution that uses AWS CDK to deploy reporting and remediation stacks to discover Identity Center applications, generate CSV reports, and optionally enforce assignment policies. It emphasizes cross-team planning, detective controls, and testing before remediation.
read more β†’

Microsoft Exchange Online outage causes email failures

πŸ› οΈ Microsoft is investigating a widespread service issue causing authentication errors and email delays or failures for Exchange Online customers. The incident (EX1464935) was first acknowledged at 5:30 PM UTC after a surge of user reports; Downdetector indicates tens of thousands affected. Reported symptoms include delayed or failed message delivery, authentication errors, administration access issues, and intermittent mailbox operation failures. Microsoft says it has isolated a common failure pattern tied to authentication and protocol connectivity and is analyzing telemetry to determine remediation and scope.
read more β†’

OpenAI confirms ChatGPT outage affecting Work users

πŸ› οΈ OpenAI has acknowledged a partial outage affecting ChatGPT Work that began around 11:04 AM ET on Monday, August 31. Users across multiple subscription plans are seeing elevated latency and errors, with Plus subscribers particularly impacted because Work mode is unavailable for some. The company reported the issue on its status page and said engineers are working on mitigation, with the outage still ongoing as of 12:02 PM ET.
read more β†’

Aurora Serverless performance boosts reach more regions

πŸš€Amazon Aurora Serverless now delivers up to 30% better performance and improved scaling across additional AWS Regions: Asia Pacific (New Zealand), Asia Pacific (Thailand), Africa (Cape Town), Europe (Milan), and Mexico (Central). These upgrades apply to both Aurora PostgreSQL and Aurora MySQL and are provided in platform version 4 at no extra cost. New clusters and restores launch on platform version 4 automatically; existing clusters can upgrade via maintenance actions, restart, or blue/green deployments.
read more β†’

BigQuery Graph: Native graph analytics at scale

πŸ“ˆ BigQuery Graph brings native graph capabilities to the data warehouse, unifying ISO-standard GQL with SQL to run traversals natively at petabyte scale without ETL. Built on BigQuery, it inherits row- and column-level security, integrates with BigQuery ML and Gemini models, and supports cross-cloud Iceberg tables for virtual graphs. GA improves traversal performance, adds CALL and extended subquery support, and includes agentic tooling for modeling, conversational analytics, and auditable context graphs.
read more β†’