< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Help‑desk vishing fuels Microsoft 365 token theft

📣 Threat hunters warn of a broad data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms via help‑desk vishing, adversary‑in‑the‑middle token theft, and residential‑proxy sign‑ins. Tracked by Arctic Wolf as PREY‑0058 and linked to activity groups like UNC6671 and Cinder, the actors impersonate IT staff to lure executives to authentication‑themed pages and capture MFA approvals. Attacks culminate in SharePoint, OneDrive, Exchange, and Box data exfiltration and extortion without deploying endpoint malware. Organizations are urged to adopt Conditional Access, phishing‑resistant MFA, and tighter SharePoint access controls.
read more →

Weekly cyber recap: zero-days, router exploits

🛡️ This week’s recap highlights active zero-days, credential‑stealing supply‑chain code, and novel attack vectors that bypass simple user precautions. Notable incidents include an actively exploited Chrome V8 zero-day, MikroTik RouterOS exploit chains dubbed "MikroTrick," and a Magento/Adobe Commerce zero-day called StyleSmuggler used to backdoor storefronts. The briefing summarizes patches, observed exploitation activity, and trending CVEs to prioritize.
read more →

NCSC warns of growing shadow AI security risks

🛡️ The UK's National Cyber Security Centre warns that employees using unapproved AI tools can expose corporate data and create hard-to-detect security risks. The NCSC noted that shadow AI use is widespread, citing research showing 71% of UK employees used tools not approved by employers. It urged organizations to reduce risks through positive cybersecurity culture, clear guardrails, and careful adoption of agentic AI services.
read more →

Mathspace data breach exposes over 1 million records

🔒 Mathspace disclosed that attackers exploited a vulnerability in its self-hosted Metabase reporting system, gaining administrator access and stealing personal information belonging to students, staff, and parents in Australia and New Zealand. The company confirmed the intrusion was first leveraged on August 10, with data downloaded on August 27 and a breach confirmed on September 3, 2026. Mathspace says 1,079,819 people were affected but asserts that no passwords, authentication tokens, SSO or API credentials, or academic records were exposed. The firm warned those affected to monitor for suspicious account activity and noted the incident is part of a wider series of Metabase compromises linked to threat actors like ShinyHunters.
read more →

NoName057(16) Relaunches DDoS Campaigns Against Japan

🛡️ On August 24, 2026, pro-Russian hacktivist collective NoName057(16) announced the relaunch of #OpJapan, a DDoS campaign targeting Japanese organizations in response to Japan's support for Ukraine and NATO. The group claimed 66 attacks against 26 entities across maritime, logistics and government sectors between August 24 and 30, using both volumetric floods and targeted requests against costly site functions. Activity has mostly been DDoS, with opportunistic intrusions against small- to medium-sized businesses and no observed data theft or backend compromises. By August 31, activity slowed as attention shifted to #OpEstonia, while coalition partners like Dark Storm Team joined the wave.
read more →

N‑able issues hotfix for critical N-central RCE

🔒 N-able has released a hotfix addressing a critical pre-authentication remote code execution vulnerability, CVE-2026-86218, in its N-central monitoring and management platform. The flaw, given a maximum CVSS score of 10, impacts N-central versions before 2026.3.1.14 and could allow unauthenticated code execution on the server. N-able patched the issue in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) and reports no evidence of in-the-wild exploitation. This follows several recent high-severity vulnerabilities and prior hotfixes.
read more →

Trezor Data Breach Now Affects 81,000 Customers

🚨 Trezor disclosed that an August data breach at its logistics partner ShipMonk has expanded to affect 81,000 customers after an additional 67,000 U.S. customers were found impacted. The exposed data includes full names, shipping addresses, email addresses, phone numbers, and order numbers for customers who ordered during specific periods between 2019 and 2026. Trezor confirmed its own systems and devices were not compromised and warned customers to expect increased phishing and fraud risk. The incident stems from a Metabase vulnerability and extortion attempts linked to the ShinyHunters gang.
read more →

OpenAI’s GPT-6 Astra rollout criticized as messy

🛠️ OpenAI’s GPT-6 Astra launch experienced early access problems, with many paid ChatGPT and API users unable to use the model immediately after announcement. CEO Sam Altman apologized for the “messy” rollout and said the company is expanding access incrementally, prioritizing Pro and enterprise tiers. Initially only Daybreak cybersecurity partners had access, prompting concerns about the gap between model announcement and broad availability. Analysts urge enterprises to verify access, strengthen governance, and temper expectations during the phased rollout.
read more →

Cloud Security Index Shows Provider Risk Divergence

🔍 Intruder's 2026 Cloud Security Index analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles differ dramatically by provider. Weak IAM and missing logging are nearly universal, while exposed services, permissive firewalls, weak encryption, and misconfigured services vary widely. AWS shows high prevalence in exposed services and permissive network controls, Azure's top issues center on storage and identity, and Google Cloud's dominant problems are IAM-related. Larger organizations generally have fewer exposure-style misconfigurations but worse IAM issues, and midmarket firms take the longest to remediate.
read more →

Telerik RadAsyncUpload padding oracle leads to RCE

🔒 Security researcher TantoSec published a proof-of-concept that chains an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution against applications in a specific, non-default configuration. Progress shipped a patch in July (2026.2.708) and published CVEs, and there are no confirmed in-the-wild exploit reports as of September 7. The chain targets RadAsyncUpload versions through 2026.2.519 and relies on an explicit custom encryption key and a server-side handler that reads upload results.
read more →

Lazarus Reorganized Into Six Distinct Cyber Clusters

🔎 Sekoia and Kudelski Security report that North Korea's long-running Lazarus umbrella has been reorganized into six distinct cyber clusters focused on espionage, financial operations and sanctions evasion. The groups—TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima—were identified by TTPs and activity patterns. Researchers note extensive use of fake IT workers, front companies and third-country infrastructure to fund operations and gain access to targets.
read more →

ChatGPT tests feature to mimic your writing style

✉️ OpenAI is testing a new "Writing Style" feature for ChatGPT that can learn a user's voice by referencing examples in connected apps. The trial, limited to a small group, supports examples from Messaging, Documents, and Email, with services like Slack, Google Drive, Notion, and Gmail listed. Once enabled, ChatGPT can use these real examples to draft content that matches a user's natural tone without repeated instruction. OpenAI confirmed the experiment but has not announced a wider rollout timeline.
read more →

MikroTik RouterOS SSH flaws exploited in wild

🔒 Hackers are actively exploiting two recently disclosed MikroTik RouterOS vulnerabilities to hijack routers with internet-exposed SSH. The chain combines an SSH authentication bypass (CVE-2026-67276) that lets attackers log in if they know a username and the public modulus, and an SSH privilege escalation (CVE-2026-86060) that grants full administrative rights via specially crafted usernames. Poland's CERT, aided by GPT-5.5-cyber and GPT-5.6-sol, named the campaign “MikroTrick” and confirmed active exploitation; MikroTik released patches and added compromise-detection measures in recent RouterOS updates.
read more →

Lenovo ID flaw let attackers access Dropbox accounts

🔒 Dropbox confirmed roughly 5,000 accounts were accessed in August after attackers abused a legacy Lenovo ID login integration. The issue involved Lenovo allowing new IDs to be registered with someone else's email without verifying inbox ownership, enabling sign-ins to linked Dropbox accounts without a Dropbox password. Dropbox and Lenovo say they collaborated to mitigate the risk, and Dropbox has revoked Lenovo-ID sessions and now requires Dropbox passwords and 2FA.
read more →

ConnectWise warns of new ScreenConnect file transfer flaw

🔐 ConnectWise has disclosed a new vulnerability in ScreenConnect Remote Access affecting both cloud and on-premises deployments and plans to release a patch later this week. The company provided immediate mitigation steps requiring administrators to remove the TransferFiles (or TransferFilesInSession) permission from session groups via Administration > Security > Roles. Shadowserver currently tracks nearly 6,000 public ScreenConnect instances, and the vendor cautions that these flaws are often targeted by financially motivated and state-backed threat actors.
read more →

Class-action suits follow alleged IDScan.net mega-breach

🔍 Several class-action lawsuits have been filed against IDScan.net after reports of a potential large-scale leak of driver’s license and identity document data. The FBI is investigating following reporting that linked stolen records to a Russian forum listing called “Nexus.” Plaintiffs seek damages and improved security, while law firms are contacting potential victims and advising steps to determine exposure and preserve evidence.
read more →

N‑able issues fourth hotfix for N‑central RMM

🔒 N‑able released Hotfix 4 (build 2026.3.1.14) for its N‑central RMM to fix CVE-2026-86218, a pre-auth remote code execution vulnerability affecting all on‑premises builds prior to 2026.3.1.14. The company says hosted instances are patched and urges on‑premises customers to upgrade immediately; agents do not require updates. Communications diverge on whether the flaw has been observed exploited in the wild, and no indicators of compromise or interim mitigations were provided.
read more →

Zero-day Privilege Escalation Reported in CrowdStrike

🛡️ A security researcher known as “Nightmare Eclipse” published a GitHub proof-of-concept on September 3 for a zero-day privilege escalation called FalconFlank that targets CrowdStrike Falcon Sensor. The exploit abuses the Microsoft Office file malicious macro remediation feature and reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 when specific CrowdStrike settings are enabled. CrowdStrike advised customers to disable the Microsoft Office File Suspicious Macro Removal policy while it investigates and referenced a customer-only tech alert. No CVE has been assigned yet, and the researcher has also published other vendor zero-days previously.
read more →