< ciso
brief />

Hello, stay ahead with CISO Brief πŸš€

Every day the cybersecurity world moves fast β€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence β€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

πŸ‘‰ Join our Telegram channel for your daily update β€” stay informed, stay ready.

Cybersecurity News Digest β€” Daily Briefings

Latest News

all posts β†’

Custom ChatGPT variants used to push RAT malware

πŸ”’ Researchers at Huntress found threat actors publishing malicious custom GPTs on OpenAI that steer users to a Google Sites page hosting a fake Cloudflare check and a PowerShell command. If executed, the command installs an MSI that sideloads a modified DLL to deliver a remote access trojan (RAT) with remote desktop, audio/camera capture, reconnaissance and persistence functionality. OpenAI removed one GPT by September 25, but variants persisted; the campaign leverages legitimate ChatGPT hosting to increase credibility and employs an encrypted custom archive to conceal components.
read more β†’

OpenAI GPT-6.1 Sol now available on Amazon Bedrock

πŸš€ OpenAI GPT-6.1 Sol is now generally available on Amazon Bedrock, offering improved performance for agentic coding, computer use, and professional workflows. The model approaches GPT-6 Astra performance at roughly one-fifth the cost, enabling more cost-effective agent deployments. Amazon Bedrock provides the inference engine, security controls, and reliability needed for production workloads.
read more β†’

FBI urges ShinyHunters members to surrender now

πŸ›‘οΈ The FBI has publicly urged members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested an alleged leader on September 15. Authorities found extensive data on the suspect's laptop, including details about planned murders, and the suspect remains in pre-trial detention for at least 90 days. The FBI says ShinyHunters has breached over 140 organizations and extorted at least $70 million, often targeting SSO, third-party vendors, and cloud SaaS platforms.
read more β†’

Ex-Air Force Members Sentenced for BEC Fraud

πŸ”’ Two former U.S. Air Force airmen were sentenced to a combined 189 months in federal prison for conducting multi-year business email compromise (BEC) and phishing campaigns while stationed at Dover Air Force Base. They stole employee email credentials, used spoofed addresses to redirect corporate payments, and laundered funds through accomplices in the U.S. and abroad. The pair diverted millions in wire transfers and were also ordered to pay substantial restitution and serve supervised release after prison.
read more β†’

France tax portal breach exposed weak access controls

πŸ›‘οΈ A data theft at France's tax administration (DGFIP) in June–July exposed contact and tax-related messages for roughly 350,000 individuals and 250,000 businesses after attackers used stolen staff passwords. ANSSI's report finds the incident relied on weak login protection, poor network segregation and gaps in monitoring, with the attacker scraping E-Contact and other portals via compromised accounts and partner systems. Remediations include stronger MFA, extended SIEM coverage, session revocation on password resets and blocking personal-device access to government systems.
read more β†’

Windows 11 2026 Update rollout and key details

πŸ›ˆ Microsoft has begun broad rollout of the Windows 11 2026 Update (26H2), but most users will see incremental changes since many features were already delivered via monthly updates. The update installs as a small enablement package for systems on 24H2 or 25H2, making it more like a regular cumulative update. Devices that shipped with 26H1 cannot upgrade directly to 26H2, and installing 26H2 resets the support lifecycle (24 months for Home/Pro, 36 months for Enterprise/Education).
read more β†’

Star Blizzard uses event lures to deploy CosmicPulse backdoor

πŸ›‘οΈ Microsoft says Russian-linked actor Star Blizzard has used fake event invitations and replying email threads to trick targets into running a Windows backdoor installer. Campaigns since January have targeted organizations tied to Ukraine, mainly in the U.S. and U.K., using hacked WordPress and cPanel accounts and a technique called RedFlick to install the CosmicPulse backdoor via scheduled tasks.
read more β†’

New Spectre v2 Variant Leaks Linux Root Hash

πŸ›‘οΈ Researchers disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that can recover root password hashes from Intel-based Linux systems within minutes by exploiting stale branch predictor information after just-in-time (JIT) code reuse. The attack manipulates leftover predictions to trigger transient execution of attacker-controlled instructions, producing cache traces that reveal memory contents. VUSec and Scuola Superiore Sant'Anna reported practical exploits against Linux cBPF and evaluated exposure in SpiderMonkey and GraalVM, leading to CVE-2026-64507 and CVE-2026-64508 and kernel fixes.
read more β†’

Amazon Connect expands data table limits and tools

πŸ“£ Administrators can now store up to 20,000 values per data table in Amazon Connect Customer to define contact center configurations such as operating hours, escalation rules, AI prompts, and queue assignments. The update enables export, bulk editing, instance-to-instance table moves, and loading data from sources like Excel and DynamoDB. Business teams can maintain reference data themselves to adjust configurations in real time without relying on technical staff, and the feature is available in all AWS commercial and GovCloud regions where Amazon Connect Customer is offered.
read more β†’

New Spectre‑v2 BTR Variant Targets JIT Engines

πŸ”’ A team from VUSec and Scuola Superiore Sant'Anna has disclosed a new Spectre‑v2 variant called Branch Target Reuse (BTR) that impacts JIT engines in browsers, language runtimes, and the Linux kernel across multiple CPU vendors. Researchers demonstrated exploitation against SpiderMonkey, GraalVM, and cBPF JIT, producing kernel exploits that can recover root password hashes on patched Intel systems. Mitigations have been merged into the Linux kernel under CVE‑2026‑64507 and CVE‑2026‑64508, while vendors pursue code‑cache randomization and site isolation approaches.
read more β†’

GKE Agent Sandbox Optimized for Agentic Reinforcement Learning

πŸš€ Google Cloud announces GKE Agent Sandbox and the Agent Sandbox RL orchestration SDK, now generally available, to address infrastructure bottlenecks in large-scale agentic reinforcement learning. The solution integrates SandboxWarmPool with GKE Image Streaming to eliminate cold-starts, reduce GPU idle time, and support thousands of large images with low TTFC. Native integrations with popular RL tools and an async Python SDK simplify orchestration and warm-pooling strategies for researchers.
read more β†’

Amazon Aurora PostgreSQL adds multiple minor updates

πŸ”” Amazon Aurora PostgreSQL-Compatible Edition now supports PostgreSQL versions 18.6, 17.11, 16.15, 15.19, and 14.24, delivering community bug fixes and Aurora-specific enhancements. We recommend enabling automatic minor version upgrades to receive these fixes and address known CVEs. Use scheduled maintenance windows or the AWS Organizations Upgrade Rollout Policy to orchestrate phased upgrades across environments. Aurora continues to offer high performance, global resilience, serverless options, and security-focused features.
read more β†’

Amazon RDS for PostgreSQL extended support announced

πŸ›ˆ Amazon RDS for PostgreSQL announces Extended Support minor versions 13.23-rds.20260514, 12.22-rds.20260514, and 11.22-rds.20260514. This Extended Support provides up to three additional years of fixes for critical CVEs and bugs beyond a major version's end of standard support date. You can upgrade via Blue/Green Deployments, in-place upgrade, or restore from a snapshot. Use the Amazon RDS Management Console or AWS CLI to create or update managed PostgreSQL instances.
read more β†’

Graph Workflows in ADK: Patterns and Practices

πŸ”Ž This post explains how the Agent Development Kit (ADK) turns graph engineering into executable workflows using a refund example. It covers fan-out and fan-in, deterministic and agent routers, human-in-the-loop pauses, parallel workers, and dynamic orchestration. The article contrasts static graphs against Python-driven scheduling and shows when to use each approach.
read more β†’

Compromised Identity Leads to Broad DevOps and Cloud Access

πŸ”’ Microsoft DART investigated an incident where the Storm-3068 actor turned a self-service password reset into persistent access across Azure DevOps, development pipelines, and Kubernetes. The actor used legitimate identity and cloud services to enumerate repositories, create malicious pipelines to harvest kubeconfig files, and deploy remote access tools like Atera and Chisel. DART worked with the customer to contain the intrusion, reconstruct activity from audit logs and Git history, and provide remediation guidance to reduce future identity-driven risks.
read more β†’

Partners Deliver Security Agents and AI Defenses

πŸ”’ Google Cloud announced an expanded catalog of partner-built security agents and integrations for Gemini Enterprise, enabling firms to orchestrate multi-step, AI-powered security workflows from a single interface. The partners provide protections spanning deception, identity containment, runtime LLM safety, data discovery, application and cloud risk assessments, and SOC orchestration. These agents let organizations apply context-aware defenses across identity, endpoint, cloud, and agentic AI workloads while reducing containment time and operational friction. The ecosystem supports both vendor agents and protections for agentic workloads to help secure AI-driven operations.
read more β†’

Automated AI agent breaches Dutch cybersecurity nonprofit

πŸ” The Dutch Institute for Vulnerability Disclosure (DIVD) reported an autonomous, AI-driven intrusion that it described as β€œloud and very, very messy.” Evidence suggests a technical vulnerability was exploited to gain access, after which an automated AI agent carried out post-exploitation actions, often making obvious errors. DIVD has launched an investigation, notified authorities, and will publish further details on October 1 while working to identify and inform other potential victims.
read more β†’

Star Blizzard adopts RedFlick to streamline malware delivery

πŸ›‘οΈ Since January 2026, Microsoft observed Russian state-affiliated actor Star Blizzard refine large-scale phishing, use compromised-site accounts, and adopt a novel malware delivery technique called RedFlick. RedFlick leverages scheduled tasks to deploy the actor’s Python backdoor CosmicPulse, reducing required user interaction to a single response and improving evasion. Microsoft details observed TTPs, IOCs, mitigations, and detection guidance to help organizations defend against this evolving threat.
read more β†’