Brief #122: CrowdStrike npm Attack, SonicWall Cloud Breach, ChatGPT Zero-Click
Ransomware payments dropped to $115K median but hit 44% of all breaches. Cybersecurity pros can't find jobs despite 10+ years experience.
Founder at Mandos Cyber, CybersecTools and CybersecRadars
Ransomware payments dropped to $115K median but hit 44% of all breaches. Cybersecurity pros can't find jobs despite 10+ years experience.
AI agents now exploit zero-days in under 10 minutes while energy sector attacks surge 586%. Web3 hackers earn millions as traditional security salaries lag behind.
Colombian malware campaign using SVG files went completely undetected by all antivirus engines. C-suite executives show dangerous overconfidence compared to frontline security teams.
Most B2B companies build cybersecurity programs backwards - starting with compliance instead of real security. Learn why this approach fails and how fractional CISO services can help you build effective security that actually prevents breaches while achieving compliance.
Netskope files IPO with $707M ARR amid cybersecurity M&A surge. Industry training decline leaves newcomers struggling despite credentials and certs.
Initial Access Brokers surge 90% targeting smaller US companies. Machine identities now outnumber humans 80 while most orgs lack AI security controls.
LayerX researchers expose "Man-in-the-Prompt" attacks turning AI assistants into hacking copilots. CISA releases zero trust microsegmentation guidance as Python skills become mandatory for 50%+ of cyber jobs.
RomCom exploits WinRAR zero-day for malware deployment. North Korean UNC4899 steals millions in cryptocurrency through sophisticated cloud attacks.
Auto-Color backdoor exploits SAP NetWeaver via CVE-2025-31324 targeting US chemicals company. Cursor IDE vulnerability enables full RCE through prompt injection attacks.
Join security leaders who receive knowledge and resources on becoming a more effective security leader. One actionable newsletter every week.