Search expert security insights...
Nikoloz Kokhreidze

Nikoloz Kokhreidze

Fractional CISO & Founder of CybersecTools | Strategic Security Advisor for B2B Scale-Ups & Cybersecurity Vendors

205 Security Leadership Insights

Security Insights from Nikoloz Kokhreidze

Brief #142: VMware ESXi Ransomware Exploit, GPT-4o Prompt Injection, Mesh Security's $12M Raise

Brief #142: VMware ESXi Ransomware Exploit, GPT-4o Prompt Injection, Mesh Security's $12M Raise

77% of advanced email threats bypass Microsoft E3/E5 defenses. LLMjacking marketplace sells stolen AI access at 60% discount.

Feb 8 8 min read
mandos brief cybersecurity newsletter

Brief #141: 65% Abandon Prevention Strategy, Gemini Calendar Injection, Nike Breach

VS Code malware installs ScreenConnect RAT with Rust fallback mechanisms. AI cybercrime subscriptions start at $30/month enabling novice attackers. Automotive security market hits $28B by 2036.

Feb 1 7 min read
Brief #140: 6K Palo Alto Firewalls Exposed, $217K Email Breach Costs, Rapid7-ARMO Deal

Brief #140: 6K Palo Alto Firewalls Exposed, $217K Email Breach Costs, Rapid7-ARMO Deal

First AI-generated malware framework VoidLink built in under a week with rootkit capabilities. 50% of SMBs already breached while only 34% have incident response plans. FortiGate SSO exploits create persistence accounts.

Jan 25 7 min read
Brief #139: AWS SDK Supply Chain Flaw, AI Cuts Breach Time to 25 Min, CrowdStrike Buys Seraphic

Brief #139: AWS SDK Supply Chain Flaw, AI Cuts Breach Time to 25 Min, CrowdStrike Buys Seraphic

Microsoft patches actively exploited Windows flaw enabling ransomware bypass. 99% of organizations running production AI experienced attacks. Change Healthcare breach cost $1.15B, exposed 190M records.

Jan 18 7 min read
mandos brief cybersecurity newsletter

Brief #138: 41% Hired AI Deepfake Candidates, Zestix Breaches 50+ Enterprises, CrowdStrike $740M Deal

AI-generated code contains 1.7x more security vulnerabilities and 75% more logic errors than human-written code. Defense contractors leaked ITAR-controlled blueprints due to missing MFA enforcement.

Jan 11 9 min read
mandos brief cybersecurity newsletter

Brief #137: Chrome Extension Supply Chain Attack, MCP Servers Expose AWS Keys, Record CVE Year

15.28% of employees run unverified MCP servers accessing credentials with zero visibility. Experienced CISSP holders apply to 100+ jobs for single interview as AI screening dominates. Manufacturing hit hardest by Google Cloud phishing at 19.6% of targets.

Jan 4 8 min read
Mandos brief Newsletter

Brief #136: Cisco Gateway Attacks Require Full Rebuild, 97% CISOs Adopt Hybrid, MongoDB Critical Patch

Anthropic's Deputy CISO forces AI chatbot on community despite votes, causing mass exodus. Actor lands consultant role in 2 years, CompTIA certs beat traditional degrees.

Dec 28 9 min read
mandos brief cybersecurity newsletter fractional CISO

Brief #135: GitHub Enables Cross-Cloud Attacks, AI Agents Risk 76% of Orgs, Entry Salaries Drop 30%

WhatsApp Silent Whisper flaw enables covert tracking with just phone numbers. Security incidents with $200K+ damages doubled to 13% as hybrid IT adoption hits 77%.

Dec 21 8 min read
cybersecurity newsletter leading fractional CISO practice in Europe

Brief #134: Google Drive Backdoor, AI Beats Human Pen Testers, Worst Job Market in 15 Years

NANOREMOTE blends attacks through Google's API undetected. AI agents now surpass most human security testers in live enterprise assessments.

Dec 14 8 min read

Learn from Nikoloz

Join security leaders who receive knowledge and resources on becoming a more effective security leader. One actionable newsletter every week.

Trusted by CISOs, Founders, and Cybersecurity Builders