The 5-Minute Cyber Brief
Good morning. Start with the issue most likely to reshuffle someone's priority list today, then move through the supporting developments that deserve attention.
Lead Story
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embedding hidden prompt injection payloads inside "Ask AI" buttons on marketing and competitor comparison pages.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: This matters because more companies are adding AI referral buttons before they have thought through prompt trust, disclosure, or downstream influence. If marketing pages can quietly steer assistant memory and recommendations, the security problem becomes content integrity, brand risk, and decision manipulation all at once.
Read more on CyberExperts: Read more on CyberExperts
Original source: The Hacker News
Also Worth Your Attention
Swiss government SharePoint breach compromised 200 accounts

Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts.
Why it matters: This matters because a SharePoint compromise that reaches hundreds of accounts is rarely just a server story. It quickly becomes an identity, document access, and downstream trust problem, especially in government or regulated environments.
Read more on CyberExperts: Read more on CyberExperts
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines.
Why it matters: This matters because hardware-side channels do not stay academic once researchers show a practical path to real secrets. Teams running shared Linux infrastructure need to assume mitigation status, workload sensitivity, and isolation design still matter far more than a patch note checkbox.
Read more on CyberExperts: Read more on CyberExperts
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

A newly disclosed KVM issue dubbed Zapscape could let an attacker with kernel privileges inside a nested guest break isolation and execute code on the Linux host, putting environments that expose nested virtualization to untrusted workloads in the spotlight.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: This matters because virtualization boundaries are often treated like settled infrastructure trust. If a privileged nested guest can escape to the host, cloud and lab environments that allow untrusted workloads may need to revisit whether convenience features quietly expanded their blast radius.
Read more on CyberExperts: Read more on CyberExperts
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft says Defender isolated a compromised QNET endpoint in 128 seconds, interrupting a multi-stage ransomware chain before the payload could establish persistence or spread.
Why it matters: This matters because stopping ransomware in 128 seconds is a reminder that endpoint isolation speed and identity containment often decide whether one compromised machine becomes a business outage.
Read more on CyberExperts: Read more on CyberExperts
Go Deeper
Editorial Promise
CyberExperts should help you get the signal fast, understand what actually matters, and know where to go deeper before the day gets noisy.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Coder’s registry infrastructure compromised to push malicious modules
The Coder incident is a supply-chain lesson in miniature: once attackers can tamper with trusted module distribution, defenders are no longer verifying...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The useful lesson in this campaign is not that Node.js is bad. It is that adversaries keep choosing legitimate runtimes defenders already...
HPE patches critical ArubaOS-CX remote code execution flaw
ArubaOS-CX deserves attention because switching software rarely gets treated with the same urgency as identity or edge security until exploitation arrives. A...
The 5-Minute Cyber Brief: September 18, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.