< ciso
brief />

Hello, stay ahead with CISO Brief πŸš€

Every day the cybersecurity world moves fast β€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence β€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

πŸ‘‰ Join our Telegram channel for your daily update β€” stay informed, stay ready.

Cybersecurity News Digest β€” Daily Briefings

Latest News

all posts β†’

WordPress Click2Shell flaw enables remote PHP execution

πŸ›‘οΈ A newly disclosed WordPress CSRF vulnerability named Click2Shell allows pre-authenticated remote code execution by forcing the installation of a theme from the WordPress.org catalog and running arbitrary PHP. The issue, fixed in WordPress 7.1.1, was reported by researcher Paulos Yibelo of pwn.ai and relies on a buggy interpretation of a theme-preview URL combined with JavaScript in the admin browser. An attacker needs no account but requires a logged-in administrator to visit a crafted link, enabling server-side code execution and potential data or file theft. Patchstack notes only administrators can trigger the chain and advises updating or enabling DISALLOW_FILE_MODS as a temporary mitigation.
read more β†’

Microsoft to retire Microsoft 365 companion apps

πŸ“° Microsoft announced that it will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16, 2026, and advised admins to remove them from managed devices. The company previously began auto-installing these taskbar-integrated apps on compatible Windows 11 enterprise devices with the Microsoft 365 desktop client. Admins could opt out via Device Configuration or users disable auto-launch in app settings. Microsoft has stopped installing the apps via Microsoft 365 Apps updates and asked unmanaged users to uninstall them.
read more β†’

North Korean 'Contagious Interview' Campaign Exposed

πŸ›‘οΈ A joint advisory attributes the long-running Contagious Interview campaign to North Korean-linked actors who have compromised at least 30,000 devices across 100+ countries and stolen from over 7,000 cryptocurrency wallets, totaling at least $10.71 million. The campaign targets developers and crypto specialists by posing as recruiters, using coding tests to deploy malware families like BeaverTail, InvisibleFerret, and RATatouille, then exfiltrating data and credentials. Agencies from Japan, the U.S., Australia, and Germany warn the activity is tied to clusters such as WaterPlum and PurpleDelta, and that the operation leverages laptop farms, enablers, and AI-crafted identities to recruit proxies and bypass sanctions.
read more β†’

EU fines Google €403M for mishandling location data

πŸ“Œ The Irish Data Protection Commission fined Google €403 million for GDPR breaches in how three features handled location data between May 2018 and February 2020. The DPC found issues with Web & App Activity, Location History and the Location Accuracy feature, citing failures in lawful processing, transparency and accountability, and excessive data retention. Google says the case concerns historical policies and notes it has updated practices, including introducing auto-delete controls and changing defaults since 2019.
read more β†’

OpenAI security gaps persist despite heavy investment

πŸ”’ Two recent reports reveal security flaws in OpenAI systems that allowed researchers to chain vulnerabilities and bypass sandbox controls. One team leveraged an image library flaw to gain remote code execution and used stolen tokens to access employee accounts and internal repositories; fixes were applied after coordinated disclosure. Another group demonstrated Codex sandbox escapes that enabled the agent to act beyond intended limits; those issues were also patched within days.
read more β†’

Google Cloud enhances Secure Source Manager for CI/CD

πŸ”’ Google Cloud announced two generally available Secure Source Manager (SSM) features to harden CI/CD pipelines: enhanced blocking of unauthorized access across version control, build, and deployment systems, and a new Code Owners system for granular per-file and per-branch approver controls. The Code Owners feature supports nested ownership, branch-specific governance, glob-style path rules, and independent approval sections, while Developer Connect and Private Network Integrations let SSM connect CI/CD and runtimes across private networks with VPC Service Controls and Private Service Connect.
read more β†’

Maximize Apache Spark availability with flexible VMs

πŸ”§ This article explains how Google’s Managed Service for Apache Spark uses flexible VMs to mitigate capacity stockouts that can disrupt Spark pipelines. Flexible VMs let teams specify ordered machine-family preferences for masters and workers, enabling multi-family blending, mixed storage support, and comprehensive cluster coverage. The post gives tiered machine-family and storage recommendations for common shapes (n2d, n1) and highlights the role of Hyperdisk Balanced. It also covers quota, CUDs, testing, and complementary strategies like AutoZone, autoscaling, smaller shapes, and regional fallbacks.
read more β†’

GKE Pod Snapshots: Faster Startup for AI Workloads

πŸš€ GKE Pod snapshots let you capture and restore a running Pod’s full state, including CPU and GPU memory, to dramatically reduce cold-start times for AI inference and sandboxed agent workloads. By persisting snapshots to high-throughput Cloud Storage, new replicas restore directly from a warmed state, cutting startup latency by up to 89% in benchmarks. This enables aggressive autoscaling, lowers idle GPU costs, and replaces complex custom caching solutions with a simple declarative CRD-driven workflow.
read more β†’

Global multi-cluster GKE inference for GPUs and TPUs

🧭 This post describes a layered routing architecture that makes globally scattered accelerator capacity behave like a single pool behind one entry point. The multi-cluster GKE Inference Gateway performs global traffic distribution and high availability while an LLM-d router applies memory-aware scheduling to maximize utilization across GPUs and TPUs. Benchmarks across three regions and 17,000 nodes showed near-linear throughput scaling and <1% routing overhead while maintaining ~99.9% success rates under heavy concurrency.
read more β†’

DPC fines Google €403M for location data breaches

πŸ“Œ Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches tied to processing users’ location data. The investigation, opened in February 2020, reviewed three features β€” Web & App Activity, Location History, and Location Accuracy β€” active during May 25, 2018 to February 4, 2020. The DPC found failures in transparency, lawful processing, and retention practices, and ordered compliance within six months. Google says it has since updated policies and added user controls for location data.
read more β†’

Transform Bedrock Guardrails Events into OCSF

πŸ›‘οΈ This post shows how to capture AWS Bedrock Guardrails intervention events from model invocation logs, transform them into OCSF Detection Finding records, and ingest them into the CloudWatch unified data store for centralized analysis. It explains why guardrail interventions are security-relevant, the limitations of ingestion-time processors, and the need for a dedicated transform step to split and normalize assessments. The end-to-end pipeline uses an AWS Lambda to map fields, assigns severity based on policy type, and writes results to a log group associated with AWS S3 Tables so analysts can query with Athena or CloudWatch Logs Insights.
read more β†’

Irish DPC Fines Google €403M Over Location Data

πŸ“The Irish Data Protection Commission has fined Google €403m for GDPR breaches related to its handling of users' location data across features such as Web & App Activity, Location History and Location Accuracy. The inquiry, covering May 25, 2018 to February 4, 2020, found failures in lawfulness, transparency, accountability and retention practices. The DPC said Google must rectify its processing within six months, while Google contends policies have since changed and tools improved.
read more β†’

Microsoft fixes Excel copy-and-paste bug for users

πŸ› οΈ Microsoft has issued fixes for an Excel paste failure introduced by September 2026 security updates that caused copy-and-paste, autofill, and formula dragging to fail silently in multiple Excel versions and Excel Online. Affected users must manually install specific updates for Excel 2016 and Office LTSC 2019, 2021, and 2024 to resolve the issue. Microsoft noted paste may still fail when workbooks contain conditional formatting and recommended using the Paste Special workaround (Ctrl+Alt+V) until a broader fix is available.
read more β†’

Analysis of Flock ALPR Camera Reverse-Engineering

πŸ” The recovered Flock camera software shows the device runs computer-vision that explicitly detects people, vehicles, license plates, bicycles, and even small graphics such as bumper stickers or patches. While the most sensitive ALPR storage remained encrypted, one unencrypted partition contained the encryption key for another partition, undermining the device's disk encryption. Logs indicate the camera captured more than a million images and can take dozens of frames of a single passing vehicle.
read more β†’

Exvicy ClickFix MaaS Reuses ErrTraffic Code

πŸ›‘οΈ A new ClickFix malware-as-a-service framework named Exvicy has been observed delivering malware via compromised WordPress sites by injecting obfuscated JavaScript and a fake Cloudflare Turnstile lure. Sekoia's Threat Detection & Research team linked Exvicy to active C2 infrastructure after telemetry showed customer hosts communicating with its servers. The actor advertises the service on Exploit.IN, with pricing rising from $1,200 to $2,000 per month and operational panels discovered through a screenshot in the advert. Sekoia assessed Exvicy reuses large portions of ErrTraffic's code, with the main technical difference being Exvicy's hardcoded C2 servers versus ErrTraffic's blockchain-based hiding.
read more β†’

NPM malware evades install-script defenses

πŸ”’ Checkmarx researchers uncovered a campaign in which a malicious npm package, impersonating sorted-btree as β€œindexed-btree,” embeds malware inside a runtime method rather than using lifecycle install scripts. The payload launches a detached Node.js loader that fingerprints hosts and exfiltrates data to hardcoded Slack and Telegram endpoints, while using a Sepolia Ethereum smart contract as a resilient C2 pointer. Multiple related packages with high download counts were removed after discovery.
read more β†’

Weekly Cyber Recap: Active Exploits and AI Risks

πŸ›‘οΈ This week's recap highlights widespread, opportunistic threats affecting trusted software, plugins, and services, from active exploitation of a Cisco ISE auth bypass to novel AI agent supply-chain attacks. It covers high-impact incidents like domain seizures for DDoS services, credential-stealing browser extensions, and ClickFix social-engineering campaigns that weaponize legitimate cloud services. The briefing urges rapid patching, governance for AI agents, and runtime defenses to limit fast-moving attacks.
read more β†’

TASK#STOMP PowerShell Backdoor Steals Data

πŸ›‘οΈ Securonix researchers disclosed a campaign named TASK#STOMP that installs a PowerShell backdoor to harvest business documents, Wi‑Fi credentials, clipboard contents, screenshots and system metadata. The infection begins with an obfuscated VBScript executed via wscript.exe, which establishes multiple persistence mechanisms using Task Scheduler and the Startup folder while hiding and timestomping artifacts. Two hidden PowerShell modules, sys_loader.ps1 and win_conn.ps1, decode payloads and form redundant, token‑authenticated C2 channels that mutually monitor and restart each other. The attackers also open a URL in Chrome and run a cleanup batch script, and the operation relies heavily on native Windows components to evade detection.
read more β†’