< ciso
brief />

Hello, stay ahead with CISO Brief ๐Ÿš€

Every day the cybersecurity world moves fast โ€” new incidents, evolving AI risks, changing regulations, and critical vendor updates. We cut through the noise to deliver only what matters most for your business and security strategy.

CISO Brief brings you a daily digest of high-signal news: major breaches, hyperscaler security releases, AI and compliance shifts, and the latest threat intelligence โ€” all in one concise update.

Built for CISOs, CTOs, and architects, our goal is to save you time, reduce distraction, and keep you always on pulse with the risks and opportunities that shape tomorrow.

๐Ÿ‘‰ Join our Telegram channel for your daily update โ€” stay informed, stay ready.

Cybersecurity News Digest โ€” Daily Briefings

MacSync uses iCloud calendars to load payloads

๐Ÿ“Œ A new MacSync variant for macOS now leverages public iCloud calendar events to deliver follow-on payloads. Kaspersky found the Swift-based infostealer being distributed via ClickFix-style social engineering and fake apps, with a downloader extracting commands from calendar DESCRIPTION fields to fetch archives hosted on iCloud. The malware retains broad credential-stealing capabilities and added an Objective-C backdoor that persists via LaunchAgents, .zshrc changes, and Git hooks.
read more โ†’

WordPress critical RCE flaw patched; rapid attacks follow

๐Ÿ”’ WordPress released a security update fixing a critical remote code execution vulnerability (CVE-2026-87902) that allows unauthenticated attackers to include and execute readable local PHP files outside active theme directories. The flaw, reported by researcher Robert Ressl, has been backported to versions as far back as 4.7 and has already seen exploitation in the wild. Security firms observed reconnaissance within hours and active payload delivery within a day, prompting urgent calls for fast, verified patch rollouts and increased visibility of forgotten WordPress instances.
read more โ†’

Carbonato malware hijacks exposed Docker hosts

๐Ÿ›ก๏ธ A new botnet named Carbonato targets unsecured Docker daemons to install the Hermes Agent AI framework and seize control. Researchers from Malwarebytes ThreatDown found evidence from October 2024 to August 2026 showing worm-like spreading via unauthenticated Docker APIs on port 2375. The malware launches privileged containers, opens reverse SSH tunnels, installs operator keys, and establishes persistence mechanisms while reporting deployments over Telegram.
read more โ†’

Google Named a Leader in 2026 Container Management

๐Ÿš€ Google Cloud was named a Leader in the 2026 Gartnerยฎ Magic Quadrantโ„ข for Container Management, ranking highest for Ability to Execute. The accompanying Gartner Critical Capabilities report placed Google Cloud first across all evaluated use cases, including AI training and inference. Google highlights recent GKE and Cloud Run innovationsโ€”like predictive latency boosts, rapid startup times, serverless GPU scale-to-zero, and Agent Substrate/Sandboxโ€”to support enterprise and AI workloads at scale. The post invites users to try the open-source Agent projects and explore Cloud Run and GKE enhancements.
read more โ†’

AWS Lambda Durable Functions Reach European Sovereign Cloud

๐Ÿ›ก๏ธ AWS Lambda durable functions are now available in the AWS European Sovereign Cloud, enabling developers to build reliable multi-step applications and AI workflows within the Lambda developer experience. These functions introduce primitives like step and wait to checkpoint progress, recover from failures, and pause executions without incurring on-demand compute charges. Support covers new Python (3.13, 3.14), Node.js (22, 24), and Java (17+) runtimes, and activation is possible via the AWS Lambda API, Console, SDKs, and IaC tools such as AWS CloudFormation, AWS SAM, and AWS CDK.
read more โ†’

Unpatched OnePlus flaws let installed apps gain root

๐Ÿ”’ A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app that requests no special permissions. Researcher Rasmus Moorats chained two vendor services to gain root: one that accepts arbitrary calls and injects text into system commands, and another that executes shell instructions when invoked as root. OnePlus confirmed the flaws in May, claimed exclusive control over disclosure, and had not released a patch when Moorats published on September 24.
read more โ†’

Trust Risks in Consultancy Scams and AI Malware

๐Ÿ” In this Threat Source briefing, Talos warns practitioners about social engineering that leverages flattering offers โ€” such as paid consultancy or fake recruitment โ€” to coax security professionals into abusing trusted access. The piece describes a staged consultation that escalates to requests for internal insights and special reports, and highlights emerging AI-integrated malware research from Talos. It outlines CAIRN, an open-source toolkit for hunting AI artifact tradecraft, and summarizes recent threats and notable incidents.
read more โ†’

Weekly ThreatsDay: AI Search Poisoning and Malware

๐Ÿ›ก๏ธ This ThreatsDay bulletin outlines a steady stream of deceptively mundane threats leveraging AI, poisoned trusted paths, and social engineering to bypass defenses. Highlights include an AI-assisted Android banking trojan, AI code privacy concerns from Z.ai, and FBI/CISA guidance on ICS integrator access. Also covered are super-app surveillance findings, browser-in-the-browser phishing, novel EDR evasion, and large-scale AI search poisoning campaigns targeting major brands.
read more โ†’

Exposed GitLab email tokens enable malicious pushes

๐Ÿ“ง Researchers found that private GitLab incoming-email addresses, generated by the Email work item to this project feature, are being published in public READMEs and guides. These addresses include long-lived tokens that let anyone create issues or merge requests if they modify the address suffix, potentially bypassing IP restrictions. Aikido reported instances affecting popular open-source projects and urges token resets and removal from public docs.
read more โ†’

GKE agentic migration for safer cloud modernizations

๐Ÿ”ง Google Cloud released the open-source GKE agentic migration plugin to simplify migrations from AWS EKS to Google Kubernetes Engine. The tool combines LLM-driven translations with deterministic server-side validation and GitOps PR workflows to avoid direct changes to live clusters. It persists long-running migration state for multi-persona handoffs and produces runbooks for stateful transport, enabling human-in-the-loop approvals and safer, auditable migrations.
read more โ†’

September 2026 Microsoft Security updates and features

๐Ÿ”’ This post summarizes September 2026 security updates across Microsoft Security, highlighting new controls for local AI agents, expanded Zero Trust for agentic traffic, and SOC improvements. It covers AI-powered detonation summaries for emails, Purview and Entra integration for data protection, Purview auto-labeling and eDiscovery enhancements, data lifecycle management for SharePoint, and new GCC High capabilities for Intune and PKI.
read more โ†’

Storm-2570: Cross-ecosystem ransomware tradecraft

๐Ÿ” Microsoft details activity attributed to the Storm-2570 ransomware affiliate, showing how the actor operates across multiple RaaS ecosystems (Qilin, DragonForce, Anubis, BERT) while using consistent post-compromise tooling and techniques. The report highlights repeated use of remote management software like MeshAgent, tunneling utilities, credential theft tools, lateral movement methods, and cloud exfiltration utilities. It emphasizes analyzing actor behavior across the attack chain to detect and disrupt intrusions before payload deployment, and provides detection and defense recommendations.
read more โ†’

Scribd scales document classification with Gemini

๐Ÿ“„ Scribd, Inc. used Gemini Enterprise to classify over 400 million user-uploaded documents (12+ billion pages) across Scribd and SlideShare. Native PDF input allowed more than 99% of the corpus to be processed without OCR or rendering, and batch prediction at a 50% discount made large-scale LLM classification economically viable. Google Cloud partnered on planning and scaling throughput, enabling the backfill to complete in months and converting the process into a continuous pipeline.
read more โ†’

Amazon RDS Adds Postโ€‘Quantum TLS for PostgreSQL

๐Ÿ” Amazon RDS for PostgreSQL now supports post-quantum TLS (PQ-TLS) key exchange to provide post-quantum cryptography options for data in transit. RDS for PostgreSQL versions 18 and higher allow modification of the ssl_groups parameter so administrators can pick cryptographic groups from the RDS allow list. Customers can deploy or update managed PostgreSQL instances through the Amazon RDS Console or the AWS CLI to enable these options.
read more โ†’

Amazon RDS MySQL extended support for minors

๐Ÿ”” Amazon RDS for MySQL announces Extended Support minor releases 5.7.44-rds.20260902 and 8.0.46-rds.20260908. RDS Extended Support offers up to three extra years of fixes for critical CVEs and bugs beyond standard support end dates. Customers can upgrade using Blue/Green Deployments, in-place upgrades, or restore from snapshots, and migrate with AWS Database Migration Service.
read more โ†’

Amazon RDS Adds PostgreSQL 19 Beta 4 Preview

๐Ÿš€ Amazon RDS now offers PostgreSQL 19 Beta 4 in the Amazon RDS Database Preview Environment, enabling evaluation of the pre-release on RDS. This beta refines query performance and autovacuum management, fixes TOAST table reporting in pg_stat_autovacuum_scores, and rebalances parallel autovacuum cost limits. Preview instances persist up to 60 days, snapshots are limited to the Preview Environment, and standard dump/load tooling is supported.
read more โ†’

Microsoft adds integrated SOC features to Defender

๐Ÿ”’ Microsoft now offers Integrated Security Operations Center (ISOC) capabilities inside Microsoft Defender for Microsoft 365 E5 and E7 customers at no extra license cost during public preview. ISOC combines SIEM-like functions with Defender XDR, threat intelligence, automation and AI in a single portal, and ingests Microsoft product logs without charges. From Oct. 1, third-party data ingestion will be metered at $2.40 per GB, and more advanced features require an ISOC workspace and Azure subscription.
read more โ†’

Placeholder domains weaponized to deliver ClickFix lures

๐Ÿ›ก๏ธ Manifold Security discovered that the documentation placeholder domain third-party[.]com has been registered and weaponized to serve a ClickFix social engineering lure for Windows visitors while showing benign decoys to others. The domain, referenced in over 1,700 public GitHub repositories, poisons the clipboard and prompts users to paste and run a command that fetches a remote PowerShell payload. It has been flagged as malicious on VirusTotal and Google Safe Browsing, and the researchers found a further 13 non-reserved placeholder domains being abused to serve scams and scareware to macOS users.
read more โ†’