< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Rails fixes critical Active Storage flaw with RCE risk

🛡️ The Rails project patched a critical Active Storage vulnerability (CVE-2026-66066) that can let unauthenticated attackers read arbitrary files and potentially achieve remote code execution when libvips is used. The flaw affects multiple Rails branches before specified patch releases and requires accepting uploads from untrusted users. Administrators should upgrade libvips to 8.13+, apply Rails updates, and rotate exposed secrets. ImageMagick users are not affected by this vector.
read more →

Adform ad script tampering swaps crypto wallet addresses

🔍 Attackers modified Adform's JavaScript advertising resource to rewrite cryptocurrency wallet addresses in visitors' browsers. Adform discovered the issue on July 27, 2026, removed the malicious code, notified clients, and urged users to clear caches and verify wallet addresses before sending funds. The compromised file, trackpoint-async.js served from s2.adform.net, contained two appended payloads that intercepted clipboard and form input events to replace Bitcoin, Ethereum, and Tron addresses.
read more →

Adobe fixes CVSS 10.0 flaw in Campaign Classic

🛡️ Adobe released updates for Campaign Classic (ACC) to patch a maximum-severity authorization vulnerability (CVE-2026-48449, CVSS 10.0) that could enable arbitrary code execution without user interaction. The fixes, delivered in ACC v7.4.3 build 9398 for Windows and Linux, also address a high-severity SQL injection (CVE-2026-48448, CVSS 8.6) enabling arbitrary file reads. Adobe additionally remediated eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and code execution, crediting multiple external researchers. Users are urged to apply the updates promptly for protection.
read more →

Amgen confirms cloud data breach exposed sensitive files

đź”’ Amgen disclosed a cloud data breach after threat actors exfiltrated corporate and patient information from third-party cloud environments. The company detected unauthorized activity in July 2026, activated its incident response plan, and engaged independent forensic experts to investigate. Amgen says stolen data includes proprietary data and patient protected health information, and it is assessing the scope, regulatory requirements, and potential notifications.
read more →

HIPAA Security Rule Technical Safeguards on AWS

🔒 This new guidance helps covered entities and business associates implement and evidence compliance with the HIPAA Security Rule Technical Safeguards (45 CFR §164.312) when building healthcare workloads on AWS. It explains the five standards and nine implementation specifications for access control, audit controls, integrity, authentication, and transmission security. The document also addresses proposed 2025 NPRM changes—such as mandatory encryption, MFA, and new network and configuration controls—and recommends treating all specifications as required for new workloads.
read more →

OpenAI cuts prices for GPT‑5.6 Luna and Terra

🤖 OpenAI has reduced API prices for two GPT-5.6 models, cutting Luna by 80% and Terra by 20% to improve cost efficiency. Luna now costs $0.20 per million input tokens and $1.20 per million output tokens, down from $1 and $6; Terra’s rates dropped to $2 per million input and $12 per million output. OpenAI also updated usage accounting for Codex and ChatGPT Work and upgraded Auto-review to GPT-5.6 Luna, yielding significant cost savings. Additionally, GPT-5.6 Sol gains a Fast API option that is up to 2.5× faster at twice the price for latency‑sensitive workloads.
read more →

New OctLurk and SilkLurk Campaign Targets Central Asia

🛡️ Kaspersky attributes a sustained campaign since January 2025 to a suspected Chinese-speaking threat actor targeting government and public-sector organizations across Central Asia and Syria. The attacker toolkit includes two memory-resident backdoors, OctLurk and SilkLurk, plus a proxy utility dubbed LurkProxy, enabling credential theft, keylogging, remote access, network scanning and plugin-based expansion. Initial access remains unknown, and infrastructure links were observed to a previous campaign using a C++ implant called SilentRaid. Victim-specific payload encoding and in-memory operation complicate detection and analysis.
read more →

Amazon Aurora DSQL Adds Multi-Region Clusters

🚀 Starting today, Amazon Aurora DSQL supports multi-Region clusters in four additional AWS Regions: Europe (Stockholm), Europe (Spain), Asia Pacific (Mumbai), and Asia Pacific (Singapore). Aurora DSQL is a serverless, distributed SQL database offering active-active high availability and multi-Region strong consistency. Each multi-Region cluster exposes writable endpoints in both peered Regions and provides a single logical database that stays available if one Region becomes unavailable.
read more →

Anthropic’s Opus 5 Improves Prompt Injection Defense

🔒 The post reports benchmark results showing Anthropic’s Opus 5 better resists prompt injection than Opus 4.8 and most other evaluated models. Opus 5 reduced attacker success rates on the IPI benchmark to 2.0% within 15 attempts and 0.2% on a single attempt, outperforming non-Claude models like Muse Spark and several GPT 5.6 variants. The author notes that while prompt injection cannot be fully prevented in general, targeted improvements are making models substantially more robust.
read more →

CISA warns of attacks on US water and wastewater systems

🚨 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert after hackers disrupted over 30 Minnesota community water systems by targeting internet-exposed programmable logic controllers (PLCs). The attacks included password changes that locked operators out, IP alterations that severed internet connectivity, and other actions that impaired operations. CISA urges owners and operators to remove publicly exposed PLCs and OT from the internet, use VPNs or gateway devices for access, change default passwords, and implement IP allow-lists. Security vendor research from Censys found thousands of internet-reachable PLC hosts and highlighted undocumented cellular modems as a common blind spot.
read more →

HollowFrame loader deploys Matryoshka backdoor

🛡️ Cybersecurity researchers disclosed a novel Go-based loader called HollowFrame and a Rust backdoor family named Matryoshka, revealed after a phishing intrusion against a law firm. The attack begins with an encrypted archive containing a malicious LNK that triggers a staged chain, uses DLL side-loading with a rogue python311.dll, weakens Defender, and establishes persistence via scheduled tasks. Matryoshka variants communicate over HTTP or via a GitHub-based C2 to receive commands, exfiltrate data, and deliver secondary payloads.
read more →

Monthly updates on Google Cloud AI infrastructure

đź”” Google Cloud summarizes recent AI infrastructure launches, enhancements, and resources across compute, storage, networking, orchestration, and developer tooling. Highlights include GA releases for Managed Lustre and C4N VMs, scaling improvements for GKE Dataplane V2, new cooperative time-slicing for llm-d, and open-sourced AI supply-chain tooling in k8s-aibom. The post also links to technical blueprints, how-to guides, benchmarks, and customer stories illustrating performance and optimization techniques.
read more →

DefCon bans smart glasses with recording features

🕶️ DefCon has added smart glasses to its banned list, prohibiting audio- or video-recording eyewear because organizers say there is no reliable way to tell if they are recording, which undermines trust and privacy. Attendees are required to wear non-smart corrective lenses if needed. The ban supplements strict photography rules that limit group shots and encourage portrait settings to blur backgrounds. Growing market activity from Google, Samsung, and Apple has heightened concerns among conferences and CISOs about privacy and data security.
read more →

Amazon RDS for Oracle adds R8i and M8i Reserved Instances

🚀 Amazon RDS for Oracle now offers 1-year and 3-year Reserved Instances for R8i and M8i instances, delivering up to 53% savings versus On-Demand pricing. These instances use custom Intel Xeon 6 processors exclusive to AWS, offering improved performance and memory bandwidth over prior Intel-based instances. Reserved Instance benefits apply across Multi-AZ and Single-AZ configurations and include size flexibility for BYOL licensing. Purchase options are available via the AWS Console, CLI, or SDK in supported regions.
read more →

Monthly Security roundup with Tony Anscombe

📰 Tony Anscombe, ESET Chief Security Evangelist, reviews July's major cybersecurity stories and highlights lessons for defenders. He discusses an unprecedented OpenAI incident that led to autonomous access to Hugging Face, Sysdig’s report on JADEPUFFER as the first agentic end-to-end ransomware operation, and a new LLM-driven domain interception technique called "phantom squatting." Tony outlines mitigation strategies and points viewers to related resources including the June 2026 roundup and ESET white papers.
read more →

ESET H1 2026 report: AI skills and adaptable malware

🔍 ESET's H1 2026 Threat Report examines how attackers are scaling operations by adapting established techniques to new platforms and leveraging AI. The vendor analyzed nearly 900,000 AI skills and found tens of thousands of suspicious instances and thousands of malicious ones. AI is appearing inside malware, exemplified by Android PromptSpy using Google’s Gemini to interpret UIs and adapt behavior. The report also highlights social engineering trends like ClickFix, rising quishing, and persistent ransomware tactics such as EDR killers.
read more →

Amazon Location adds GrabMaps Search Nearby

📍Amazon Location Service now supports proximity-based point of interest discovery using GrabMaps data in the Asia Pacific (Singapore) and Asia Pacific (Malaysia) AWS Regions. Developers can call SearchNearby to return places within a specified radius and rank results by distance, with optional category filters such as fuel stations, hospitals, or restaurants. This enables localized discovery use cases for delivery, ride-hailing, and travel apps using hyperlocal data validated by millions of daily Grab journeys.
read more →

AWS Lambda: Java runtimes now on AL2023

🛠️ AWS Lambda now supports Java 8, Java 11, and Java 17 runtimes on Amazon Linux 2023 (AL2023), available as managed runtimes and container base images. These AL2023-based runtimes let customers migrate from Amazon Linux 2 (AL2) without having to upgrade their Java version immediately. AL2 reached end of life on June 30, 2026; AL2-based Java runtimes will receive critical and selected important patches until June 30, 2027 to assist migration.
read more →