< ciso
brief />

Hello, stay ahead with CISO Brief 🚀

Every day the cybersecurity world moves fast — new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence — all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

👉 Join our Telegram channel for your daily update — stay informed, stay ready.

Cybersecurity News Digest — Daily Briefings

Latest News

all posts →

Amazon Cognito adds admin TOTP reset API

🔐 Amazon Cognito introduces an admin API operation to reset a user's time-based one-time password (TOTP) multi-factor authentication configuration. Administrators can remove the TOTP device association for users who lose access to their authenticator, enabling users to enroll a new device on next sign-in. This avoids recreating accounts to recover locked-out users and preserves enforced MFA policies. The feature is available in all AWS Regions and is accessible via the AdminDeleteSoftwareToken API through the AWS CLI, SDKs, or APIs; see the developer guide for details.
read more →

Critical Avada WordPress Theme Zero-Click RCE

🛡️A chain of six vulnerabilities in the Avada WordPress theme and Fusion Builder plugin allows an unauthenticated attacker to execute arbitrary PHP code via a zero-click exploit. Tracked as CVE-2026-18431 with a 9.8 score, the attack requires a precise sequence of authorization, input-validation, trust-boundary, and file-handling failures. ThemeFusion released patches in Avada 7.16.1 and Fusion Builder 3.16.1 after disclosure by Wordfence, which withheld full details to allow administrators time to update.
read more →

Amazon Connect adds unplanned shrinkage to schedules

🛠️ Managers can now record unplanned shrinkage directly in Amazon Connect Customer agent schedules, capturing unscheduled absences like late logins or sudden sick leave. Uploaded assumptions update scheduling metrics instantly, showing adjusted scheduled headcount, net staffing, and projected service level. This allows teams to see, for example, how a 10% unavailability at 8 AM reduces projected service level from 90% to 85%, helping workforce managers proactively address staffing gaps.
read more →

AWS Security: July 2026 updates and guidance

🛡️ This recap highlights AWS Security blog posts, new capabilities, code samples, and guidance published in July 2026. Topics include AI agent security, data protection, network and infrastructure protections, threat detection enhancements, compliance guidance, and 21 security bulletins addressing vulnerabilities. Vendors and practitioners can use the code samples and workshops to implement recommended controls and apply patches promptly.
read more →

GPUThor Rowhammer Bypasses NVIDIA ECC Protections

🛡️ Researchers from the University of Toronto disclosed GPUThor, a Rowhammer variant that defeats SECDED ECC on Ampere-class NVIDIA GPUs, enabling DoS and root privilege escalation. The attack achieves far higher bit-flip rates than prior GPU Rowhammer concepts by exploiting undocumented memory request coalescing and TRR behavior. Tested on RTX A4000–A6000 cards, GPUThor produced thousands of flips per GB and demonstrated both device resets and corrupted page tables leading to host root access. NVIDIA issued guidance recommending SYS-ECC, IOMMU/DMA isolation, telemetry monitoring, and restrictions on untrusted workloads.
read more →

Mountpoint for S3 adds configurable memory limits

🧩 Mountpoint for Amazon S3 now supports configurable memory usage limits, either set manually or determined automatically based on the runtime environment. This change lets Mountpoint coexist with memory‑intensive workloads such as machine learning training or analytics by reserving memory for applications and slowing operations under memory pressure. The feature detects container budgets in environments like Amazon EKS and is available in all AWS Regions. Upgrade details and configuration guidance are available in the Mountpoint GitHub repository.
read more →

Detecting Multi‑Stage Attacks on AWS with Correlation

🔍 This post explains how correlating signals across AWS services and your business context reveals multi-stage attacks that single alerts miss. It outlines five attack phases and the three primary log sources—CloudTrail, VPC Flow Logs, and Route 53 Resolver logs—used to surface each phase. The guide emphasizes enabling and tuning AWS detection services such as Amazon GuardDuty, then layering custom queries that encode your environment-specific knowledge. It includes CloudWatch Logs Insights queries and operational guidance for thresholds, multi-account setups, and automating detection pipelines.
read more →

Amazon Connect adds points-based evaluation scoring

🔔 Amazon Connect Customer now offers points-based scoring to evaluate human and AI agent performance, giving managers greater flexibility to assign importance to individual criteria. With this model, scores are the sum of points earned rather than percentages that must total 100. Managers can combine criteria, exclude items from scoring, or award bonus points to reflect business priorities. The feature is available in all regions where Amazon Connect Customer is offered.
read more →

Securing AI Gateways and Control Plane Targets

🔒 Microsoft describes attacks targeting AI infrastructure components such as gateways, retrieval platforms, orchestration services, and container runtimes that centralize credentials and execution privileges. Observed intrusions against LiteLLM, RAGFlow, and Kestra aimed to harvest secrets, persist on hosts, and monetize compute. The advisory emphasizes inventorying exposed AI surfaces, restricting administrative access, and monitoring gateway-originated execution and secret access to mitigate risk.
read more →

FBI Disrupts China-Linked QTFY Botnet Operations

🔒 The U.S. Department of Justice and FBI announced the disruption of two hacking platforms, QScan and QTRouter, used by the China-linked group QTFY to target U.S. critical infrastructure and sensitive networks. Lumen Black Lotus Labs, which tracked the group since 2018, collaborated with the FBI after observing extensive targeting of research and public sector organizations. QScan infected IoT devices to build a proxy mesh while QTRouter and associated services obfuscated attack origins using compromised routers, commercial proxy services, and leased VPSs. The court-authorized seizure of hard-coded domains caused the platforms to cease operations.
read more →

Meta Agrees to Proposed $18B Settlement Over Teen Harms

📰 Meta has reached a proposed settlement of up to $18 billion with a bipartisan coalition of 52 state attorneys general resolving a 2023 lawsuit alleging Facebook and Instagram were designed to encourage compulsive use by children and teens. The agreement, pending court approval, requires new protections for under-18 users including default time limits, nighttime restrictions, hidden like counts, stronger parental tools, and expanded age verification. An independent auditor will oversee compliance and Meta is barred from making misleading safety claims.
read more →

AWS Glue 5.1 Arrives in European Sovereign Cloud

🔔 AWS Glue 5.1 is now available in the AWS European Sovereign Cloud Region, bringing core engine upgrades to Apache Spark 3.5.6, Python 3.11, and Scala 2.12.18 for improved performance and security. The release updates open table format support for Apache Hudi 1.0.2, Apache Iceberg 1.10.0, and Delta Lake 3.3.2, and adds Iceberg format 3.0 features such as default column values and row lineage tracking. Lake Formation now enforces fine-grained access control for write DML and DDL operations in Spark DataFrames and Spark SQL, and full-table access control is added for Hudi and Delta Lake tables.
read more →

Reducing AI agent costs with runtime optimizations

🔍 This post explains how Microsoft Foundry helps reduce the cost per successful AI outcome by optimizing each model request at runtime. It outlines four levers—model routing and deployment choices, caching, prompt and agent optimization, and observability—that teams can apply, measure, and reverse if necessary. The guidance emphasizes matching model and deployment choices to task complexity, using caching and fine-tuning to lower repeated costs, and relying on observability and evaluation to validate savings without degrading quality.
read more →

Scaling OKF Bundles Using Knowledge Catalog

📘 This article explains how to publish and govern Open Knowledge Format (OKF) bundles across an organization by mapping OKF concepts onto Google Cloud's Knowledge Catalog. It outlines a one-time setup and a single push workflow using sample code and the kcmd CLI to register EntryGroups, EntryTypes, and an okf AspectType carrying OKF v0.2 signals. The approach makes bundles discoverable, searchable, and governed by existing IAM policies alongside BigQuery, Cloud Storage, and other cataloged resources.
read more →

Uber reduces hybrid AI risk with Cloud Interconnect

🚦Uber adopted application awareness on Cloud Interconnect to prioritize business-critical traffic across its hybrid networks. As an early design partner, Uber deployed the feature in multiple locations to classify and queue application traffic using DSCP marking, protecting low-latency services during congestion. The approach improved bandwidth utilization, reduced the need for costly overprovisioning, and enabled safer migration of strategic workloads to Google Cloud.
read more →

Google Cloud introduces Fault Injection Testing (Preview)

🛠️ Google Cloud announces Fault Injection Testing (FIT) in public preview to help teams automate failure testing and validate application resilience. FIT lets you create experiment templates to inject targeted faults such as Cloud SQL failovers and degraded Layer 7 traffic, with an automated dry run to verify affected resources and permissions. Experiments run for a defined duration with stop-and-revert controls, and Google recommends using FIT in non-production during preview. Access is via the Cloud console, gcloud CLI, or REST API; request preview through your account team.
read more →

Boston Scientific hit by cyberattack disrupting operations

🔒 Boston Scientific reported a cyberattack detected on August 25 that disrupted IT systems and caused global operational impacts, including difficulties processing and shipping customer orders. The company activated its incident response plan and engaged external cybersecurity experts to investigate and contain the intrusion. Boston Scientific said it does not yet know when all affected systems will be fully restored and continues to assess the scope and consequences of the incident. The SEC filing offered no details on the attacker, initial access, or whether data was exposed.
read more →

Attackers Target SharePoint RCE Chain and PoC Exploits

🛡️ Defused warns attackers are chaining two Microsoft SharePoint flaws — CVE-2026-55040 and CVE-2026-63520 — to achieve remote code execution on unpatched servers. Public proof-of-concept exploits were published in August and were quickly weaponized, with probes observed against honeypots and large-scale internet-exposed SharePoint instances. CISA has issued directives to secure SharePoint servers while Microsoft monitors exploitation activity.
read more →