< ciso
brief />

Hello, stay ahead with CISO Brief ๐Ÿš€

Every day the cybersecurity world moves fast โ€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence โ€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

๐Ÿ‘‰ Join our Telegram channel for your daily update โ€” stay informed, stay ready.

Cybersecurity News Digest โ€” Daily Briefings

macOS Screen Sharing flaw exploited to install miner

๐Ÿ”’ The Netherlands' NCSC warns that a macOS Screen Sharing authentication bypass (CVE-2026-65400) is being actively exploited after public exploit code appeared. The flaw affects the built-in VNC-based Screen Sharing service (TCP 5900) and allows network attackers to authenticate without valid credentials. Apple fixed the issue in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9; affected users should update or disable Screen Sharing in System Settings.
read more โ†’

ExfilSquad leaks data from 13 organizations

๐Ÿ” New analysis links the ExfilSquad extortion group to leaked data from 13 victims across government, education, finance and manufacturing. Fortra Intelligence and Research Experts (FIRE) validated that public samples contained sensitive information, with published torrents totaling 382.64 GB and 27 million records. Researchers say misconfigured Microsoft Power Pages and unauthorized read access to Microsoft D365/Dataverse exports appear to be the primary cause, not a D365 vulnerability. FIRE identified numerous exposed Power Pages instances and highlighted the risk of the Anonymous Users web role.
read more โ†’

Critical SAP Commerce Cloud RCE Now Being Exploited

๐Ÿ›ก๏ธ A maximum-severity remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) patched three days ago is already being targeted in attacks, Defused reports. The flaw, in the core Data Hub Adapter extension, allows unauthenticated actors to exploit improper authorization to execute arbitrary code. SAP warned the issue arises from abuse of a default authentication client and insufficient input validation. Threat researchers observed initial exploitation attempts hitting honeypots despite no public PoC existing.
read more โ†’

Cloudflare One updates for MCP security

๐Ÿ”’ Cloudflare announces new Cloudflare One capabilities to detect and control Model Context Protocol (MCP) traffic. These features let administrators identify which users and servers are generating MCP requests, distinguish Portal-mediated connections from direct ones, and block unauthorized direct connections on managed network paths. The update combines Gateway protocol signals with MCP Server Portals to help teams find shadow MCP servers and enforce Portal-only access to trusted MCP endpoints.
read more โ†’

Oracle launches Database Security Central free trial

๐Ÿ”’ Oracle has introduced Database Security Central, a tool that provides a centralized view of security risk across database environments and will be free through February 2027. It arrives as attackers increasingly target Oracle database flaws and following Oracleโ€™s move to monthly patch releases. The tool assesses posture, detects configuration drift, highlights privileged access risks, monitors sensitive data access, and centralizes policy management and audit evidence collection.
read more โ†’

Protect Workers with Cloudflare Access by Default

๐Ÿ” Cloudflare now lets you apply Access directly to a Worker or to all Workers in an account so applications are protected by your company login by default. When enabled, Access enforces authentication before any request reaches Worker code, regardless of domain, route, or preview URL. Policies can be set per hostname, per Worker, or account-wide, with the most specific policy taking priority. Developers can also access authenticated user details through ctx.access.getIdentity() for personalization and logging.
read more โ†’

Shell Probes Possible Data Theft After Clop Claims

๐Ÿ”Ž Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. A Shell spokesperson confirmed awareness and said security teams and external experts are examining the matter. Clop listed Shell among 43 victims allegedly targeted via a PTC Windchill and FlexPLM vulnerability tracked as CVE-2026-12569. PTC, CISA, and other authorities have warned of active exploitation and urged urgent patching and mitigations.
read more โ†’

DecryptAds reveals whoโ€™s tracking you online

๐Ÿ” DecryptAds is a free service that scrapes and correlates public adtech files (ads.txt, app-ads.txt, buyers.json, sellers.json) to reveal which companies can run ads or harvest data from websites and apps. The site presents consolidated profiles, legal dossiers, and geo-risk warnings to help researchers and security teams trace malvertising, ad fraud, and opaque ad-supply chains. Its API and quiet-removals feed enable automation and visibility into removed sellers and reseller relationships.
read more โ†’

Why the US should nationalize major AI labs

๐Ÿ“ฐ This essay, coauthored with Nathan E. Sanders and originally published in The Guardian, argues that OpenAI and Anthropicโ€”once founded to restrain reckless corporate AI developmentโ€”have been co-opted by market incentives and investor priorities. Recent market turbulence and questions about long-term profitability suggest these labs may not be viable as private, for-profit companies. The authors propose nationalizing their innovation and compute functions, converting them into publicly governed national labs and utilities to align AI with democratic values and public benefit.
read more โ†’

RingCentral Breach Exposes Millions of Account Records

๐Ÿ”’ In July 2026, the ShinyHunters extortion group claimed to have stolen personal data from RingCentral accounts after a reported social engineering intrusion. RingCentral acknowledged a security incident and said remediation steps were taken, noting services continued to operate and only a portion of customers were affected. Have I Been Pwned confirmed leaked data tied to 1.6 million accounts, including names, emails, phone numbers, and addresses.
read more โ†’

New macOS infostealer spreads via ClickFix lure

๐Ÿ›ก๏ธ Researchers at Jamf warn of a Rust-based macOS infostealer named AmnesiaStealer distributed through ClickFix social engineering. The malware harvests credentials, browser data and live sessions, uses OS versionโ€“specific bypasses, and includes a remote-controlled second stage to stealthily control Chromium-family browsers. Jamf recommends enabling threat prevention, advanced threat controls and web protection set to Block and Report.
read more โ†’

Reframing cyber backlogs: roles, priorities, and outcomes

๐Ÿ” Security teams should oversee risk rather than perform every remediation task. Assign clear roles: security maintains the authoritative risk inventory, prioritizes findings, escalates missed commitments and verifies closure, while infrastructure, cloud, application and business owners execute fixes. Executives resolve resource conflicts and accept residual risk. Backlogs typically reflect organizational failures in ownership, capacity and decision-making rather than purely technical deficiencies.
read more โ†’

Data analyst jailed for $2.5M extortion scheme

๐Ÿ›ก๏ธ A former Brightly Software contractor was sentenced to two years in prison after pleading guilty to orchestrating a $2.5 million extortion scheme. He stole payroll and corporate data, emailed employees threatening to leak PII, and demanded ransom in cryptocurrency after his contract ended. Brightly paid a small Bitcoin ransom before involving law enforcement; the FBI recovered devices linking the suspect to the crimes.
read more โ†’

How CSOs Turn Cybersecurity into Growth Strategy

๐Ÿ”’ Cybersecurity leaders must shift from proving relevance to demonstrating how security enables innovation and growth. CSOs should embed security into business roadmaps, partner early with operational teams, and translate cyber risk into business impact. Emphasizing resilience, user-centered controls, and seamless protections helps security become a catalyst for transformation rather than an obstacle.
read more โ†’

Five key security takeaways from Black Hat 2026

๐Ÿ” AI dominated Black Hat and DEFCON discussions, highlighting both its value as a defense tool and the risks posed by autonomous agents and malicious AI skills. Speakers urged moving beyond reactive patching toward durable designs, memory-safe languages like Rust, and automated remediation. Researchers revealed AI-based supply-chain attacks, methods to use GitHub telemetry for detections, and human-led AI research uncovering new vulnerabilities. A NAT-based attack class called NatJack was disclosed, prompting vendor patches.
read more โ†’

AWS introduces managed billing and cost dashboards

๐Ÿ“Š AWS Billing and Cost Management now provides Managed Dashboards: a set of five preconfigured, read-only dashboards that populate with your account data automatically. They include Cost Overview & Trends, Compute and Database breakdowns, and Reservations and Savings Plans performance views. Dashboards are maintained by AWS, can be duplicated for editing, and support widget export via PDF or CSV.
read more โ†’

Apple issues new threat notifications over spyware

๐Ÿ”” Apple sent a fresh batch of threat notifications on August 13 alerting select iPhone users to suspected mercenary spyware attacks. These high-confidence alerts, issued since 2021, target a small set of users such as journalists and activists and do not name specific spyware or attribution. Apple warns users to verify genuine messages via account.apple.com and avoid links or requests for credentials, recommending Lockdown Mode and expert help if affected.
read more โ†’

AWS to End Email Validation for ACM Certificates

๐Ÿ›ก๏ธ AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027, aligning with the CA/B Forumโ€™s March 15, 2028 deprecation of email-based domain validation. Customers must migrate to DNS validation; ACM is updating the UpdateCertificateOptions API to allow in-place switching from email to DNS without changing certificate ARNs. ACM provides a CNAME record for DNS validation and offers a 72-hour window to add it; once validated, ACM will handle automatic renewals. AWS provides console and AWS CLI steps, a migration user guide, and support resources to assist customers through the transition.
read more โ†’