Happy Sunday!
Security budgets hitting a five-year low while threats keep escalating feels like trying to fill a bucket with a bigger hole in the bottom each year.
In this week's brief:
- Cisco patches a maximum severity vulnerability that lets attackers execute remote code on firewall management systems
- New "Man-in-the-Prompt" attacks turn your favorite AI tools into potential data theft machines
- Python skills now showing up in half of all cybersecurity job postings - time to dust off those coding tutorials
A quick note before we dive in.

Industry News
Cisco Warns of Critical CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution
-
Cisco has patched a critical vulnerability (CVE-2025-20265) with maximum CVSS score of 10.0 in Secure Firewall Management Center (FMC) Software, affecting the RADIUS authentication subsystem.
-
The flaw allows unauthenticated, remote attackers to inject arbitrary shell commands during authentication that execute with high privileges when the system is configured for RADIUS authentication.
-
Cisco also released patches for multiple high-severity bugs affecting various Firewall products, including denial-of-service vulnerabilities in Adaptive Security Appliance and Secure Firewall Threat Defense Software.
Top GenAI Tools Vulnerable to "Man-in-the-Prompt" Attack
-
LayerX researchers discovered a new exploit allowing browser extensions to access and manipulate LLM prompts without special permissions, affecting major platforms like ChatGPT (5B monthly visits) and Google Gemini (400M monthly visits).
-
The vulnerability enables attackers to turn LLMs into "hacking copilots" that can extract sensitive data, with malicious extensions able to inject hidden instructions, exfiltrate information, and delete evidence of the attack.
-
Internal corporate LLMs are especially vulnerable as they contain proprietary datasets and often lack hardening against adversarial input, creating significant risks for intellectual property theft and regulatory compliance violations.
Crypto24 Ransomware Targets Large Organizations With Custom EDR Evasion Tool
-
The ransomware group is targeting high-value victims in finance, manufacturing, entertainment, and tech sectors across the US, Europe, and Asia, using a custom variant of RealBlindingEDR to disable security solutions from 12 major vendors.
-
After initial access, attackers escalate privileges by activating default admin accounts, create persistence through malicious Windows services (WinMainSvc keylogger and MSRuntime ransomware loader), and deploy custom tools to systematically evade detection.
-
Crypto24 uses a custom exfiltration tool that leverages the WinINET API to send stolen data to Google Drive before encrypting files and deleting volume shadow copies to prevent recovery.

Leadership Insights
Security Budget Growth Slows to Five-Year Low of 4% Amid Economic Pressures
-
IANS Research and Artico Search's 2025 Security Budget Benchmark Report reveals cybersecurity budget growth dropped to just 4% (from 8% in 2024), with more than half of CISOs reporting flat or shrinking budgets due to global market volatility.
-
Security budget as a percentage of IT spending declined from 11.9% to 10.9%, breaking a five-year upward trend as AI and cloud investments drive IT spending to outpace security allocations.
-
Staffing growth slowed to 7% (lowest in four years) with only 11% of CISOs reporting adequate resources, forcing security leaders to make difficult trade-offs between initiatives while facing expanded program scope.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
CISA Releases Guidance on Microsegmentation for Zero Trust Architecture
-
CISA has published "The Journey to Zero Trust: Microsegmentation in Zero Trust – Part One: Introduction and Planning" document that provides organizations with background and planning guidance for implementing microsegmentation as part of their zero trust strategy.
-
The document explains how microsegmentation is evolving beyond traditional network-based controls to include capabilities implemented at host, application, database, and operating system levels through policy enforcement points (PEPs) that utilize contextual information beyond just IP addresses.
-
This guidance is part of CISA's ongoing effort to support organizations incrementally implementing zero trust principles, emphasizing that zero trust adoption is a journey rather than a wholesale replacement of existing infrastructure or processes.
NIST Releases Initial Public Draft of Guidelines for API Protection in Cloud-Native Systems
-
The National Institute of Standards and Technology (NIST) has published Special Publication 800-228 (initial public draft) providing guidelines for API protection specifically targeting cloud-native systems, acknowledging their critical role in enterprise IT integration.
-
This publication is currently in public comment period from March 25 to May 12, 2025, with feedback being accepted via email at sp800-228-comments@nist.gov or through postal mail to NIST's Computer Security Division.
-
The document authors include Ramaswamy Chandramouli from NIST's Computer Security Division and Zack Butcher from Tetrate, Inc., with the full publication available for free download at https://doi.org/10.6028/NIST.SP.800-228.ipd.

Career Development
Cybersecurity Hiring Manager Shares Resume Advice After 25 Years Of Experience
-
As a cybersecurity hiring manager with 25 years of experience, I reject resumes with AI-generated errors, poor formatting, and excessive length (over 2 pages) as these indicate lack of attention to detail and communication skills.
-
Job hoppers who stay less than 6 months are often passed over because onboarding takes 3 months before new hires become contributors, making short tenures a poor return on investment for employers.
-
Successful applications feature distinctive formatting (like color elements that stand out), concise relevant experience without high school details, and demonstrate multifaceted skills beyond just the current job requirements.
Python Coding Skills Now Required For More Cybersecurity Positions
-
Cybersecurity professionals are reporting an increase in job listings requiring Python scripting skills, with one commenter estimating that over 50% of new listings now demand some type of coding ability.
-
The trend reflects employers' needs for workers who can automate processes, analyze potential threat code, and understand infrastructure-as-code environments where "all the documentation is code, all the DevSecOps guardrails are code."
-
Some industry professionals note this requirement increase coincides with a saturated job market where employers can be more selective, often requiring advanced skills for entry-level positions – creating potential barriers for those without coding experience.
Cisco Layoffs Reportedly Impact Splunk Engineers Following Acquisition
-
Reports on LinkedIn suggest Splunk engineers have been hit hard in the latest round of Cisco layoffs, with former employees confirming significant staff departures including senior roles moving to competitors.
-
Cisco appears to have stopped announcing layoffs publicly after previous negative publicity, while some organizations are migrating away from Splunk due to costs – with one Fortune 500 company planning complete migration by mid-next year.
-
The integration process has accelerated with roles being "consolidated" across the board as of last month, contradicting Cisco's previous promise at last year's conference: "We're not going to fuck this up!"

AI & Security
AI & API Security Report Reveals Rising Threats and Critical Protection Strategies
-
API-related security incidents increased from 22 in 2023 to 26 in 2024, with over 1.6 billion records exposed since 2017, highlighting authorization flaws and authentication weaknesses as primary attack vectors.
-
97% of organizations acknowledge that AI introduces unique security challenges, yet nearly 60% report inadequate visibility into the APIs supporting their AI systems, creating significant vulnerabilities.
-
Key developments shaping the AI and API security landscape include the CIS API Security Guide, TracFone consent decree, OWASP LLM Top 10, and ISO 42001, which together establish important frameworks for security and governance.
OpenAI Releases Practical Guide To Building LLM-Powered Agents
-
OpenAI has published a comprehensive guide defining agents as systems that independently accomplish tasks by leveraging an LLM to manage workflow execution, make decisions, and recover from failures while using tools to interact with external systems.
-
The guide recommends building agents for use cases that have previously resisted automation, particularly those involving complex decision-making, difficult-to-maintain rule systems, or heavy reliance on unstructured data processing.
-
Agent architecture fundamentally consists of three components: the model providing reasoning capabilities, tools enabling system interaction, and instructions defining behavior guardrails – with OpenAI offering a dedicated Agents SDK to simplify implementation.
LevelBlue 2025 Futures Report Reveals Organizations Adapting To AI-Enhanced Cyber Threats
-
Survey of 1,500 C-suite executives across 14 countries shows organizations increasingly implementing cyber-resilience measures throughout their businesses, moving away from the isolated, underfunded security teams observed in 2024.
-
The proliferation of generative AI creates both transformative business opportunities and significantly heightened cybersecurity risks, including more persistent attacks, sophisticated malicious code development, and convincing deepfakes for fraud schemes.
-
The emergence of accessible open-source large language models represents a "new disruptive phase" that enables innovation but simultaneously provides threat actors with powerful, low-cost tools to develop advanced attack techniques.

Market Updates
Ostra Security Extends Series A to $9.5 Million for Managed Security Platform
-
Minnesota-based cybersecurity provider Ostra Security has secured an extension to their Series A funding round, reaching a total of $9.5 million co-led by General Catalyst and Rally Ventures.
-
The funding will accelerate hiring, enhance technical capabilities, and integrate Blackwell Security's MDR platform into Ostra's service offerings.
-
Ostra provides managed security solutions combining advanced XDR capabilities with 24/7 monitoring and human-led remediation through its Ostra Encompass and Ostra Extend product lines.
Accenture To Acquire CyberCX, Expanding Cybersecurity Capabilities In Asia Pacific
-
Accenture is acquiring CyberCX, a leading cybersecurity firm with approximately 1,400 professionals, enhancing its capabilities in offensive security, cyber physical security, and advanced AI-powered platforms for detection and response.
-
The acquisition comes as Accenture's research shows 97% of Australian organizations are unprepared to secure their AI-driven future, with 80% lacking critical data and AI security practices for protecting models and infrastructure.
-
CyberCX brings strong relationships with government and critical infrastructure organizations, along with extensive expertise demonstrated through over 2,600 certifications and partnerships with major security providers like Microsoft, Palo Alto Networks, and CrowdStrike.
Cybersecurity Startup 1Kosmos Secures $57M Series B Funding
-
1Kosmos, a provider of blockchain-based passwordless authentication solutions, will allocate the funding across go-to-market initiatives, R&D with focus on AI capabilities, and global expansion.
-
The company's platform combines identity proofing, credential verification, and strong authentication to prevent account takeover and impersonation-based attacks using live biometrics and phishing-resistant login systems.
-
The firm has tripled its business year-on-year for the past two years, serving clients across financial services, telecommunications, retail, and healthcare sectors with plans to strengthen its position in North America, Asia-Pacific, and expand into the Middle East.

Tools
FutureFeed
A tool for achieving and proving compliance with NIST 800-171 and CMMC cybersecurity requirements
Netskope One Private Access
Netskope One Private Access is a Zero Trust Network Access solution that replaces VPNs with secure, context-aware access to private applications and resources.
Cyera
Cyera is a data security platform that discovers, classifies, and secures sensitive data across various environments, offering features such as DSPM, identity data access, and data privacy compliance.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
Get the Mandos Brief, free.
A free Mandos account gives you our research articles and the Mandos Brief every Monday. Use your work email.
- Research articles
- The Mandos Brief every Monday
Free with your work email. No card. Includes the Mandos Brief every Monday.
