It seems we're drowning in our own data - with 61% of security teams overwhelmed by threat intelligence feeds while lacking the skilled analysts to make sense of it all.
In this week's brief:
Initial Access Brokers are shifting their sights to smaller US companies with weaker defenses, while VPN access becomes their new favorite entry point
AI adoption is exploding across enterprises, but security teams can only see about 20% of what's actually being used - creating some serious blind spots
A SOC Lead candidate got rejected mid-interview for not knowing a specific tool, sparking debate about what really matters in security hiring
Initial Access Brokers (IABs) primarily targeted the US (31%) in 2023, while France and Brazil saw increased targeting in 2024, with a 90% increase in accesses for sale across the top 10 targeted countries – suggesting ransomware actors are concentrating on specific geographic regions.
The manufacturing sector has risen into the top 3 targeted industries in 2024, joining business services and retail, while IABs have shifted focus to smaller organizations with revenue between $5M-$50M (60.5% of all listings), potentially due to their weaker security posture.
VPN access has surged in 2024 (33% of listings), challenging RDP access (55%) as the preferred access type sold by IABs, with most access listings priced between $500-$3,000, though high-value targets can exceed $10,000.
A threat actor named "Chucky_BF" is advertising a "Global PayPal Credential Dump 2025" containing 15.8 million plain-text password and email combinations with associated PayPal URLs for just $750.
The 1.1GB dataset likely originated from infostealer malware logs rather than a direct PayPal breach, containing login details collected from infected devices worldwide across multiple email providers.
The data includes specific PayPal endpoints like /signin and /signup, along with Android-specific URIs, potentially enabling automated credential stuffing attacks against both web and mobile services.
HR giant Workday confirmed a data breach after threat actors gained access to their third-party CRM platform through a social engineering campaign, primarily exposing business contact information such as names, email addresses, and phone numbers.
The breach is part of a larger campaign linked to the ShinyHunters extortion group targeting Salesforce instances, with attackers using social engineering and voice phishing techniques to trick employees into linking malicious OAuth apps.
Workday, which serves over 11,000 organizations including more than 60% of Fortune 500 companies, discovered the breach on August 6 and emphasized that no customer tenants or the data within them were accessed during the incident.
Security teams are drowning in data with 61% of respondents overwhelmed by too many threat intelligence feeds and 60% facing shortages of skilled threat analysts, leaving critical security gaps and limiting their ability to effectively respond to threats.
Due to intelligence overload, 72% of organizations remain in a reactive security posture, struggling to prioritize threats and implement timely, effective responses despite having access to multiple threat intelligence sources.
The report recommends overcoming these challenges by focusing on actionable intelligence that is complete, accurate, relevant, and timely, while leveraging both AI technologies and external cyberthreat intelligence experts to bolster internal capabilities.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
71% of security leaders consider threat exposure validation "absolutely essential" in 2025, with organizations conducting monthly validation experiencing a 20% reduction in breaches while 61% admit lacking the ability to identify and remediate cloud exposures.
Security teams can test 230x more threats using automated security validation compared to manual methods, with 89% already implementing AI in their exposure validation processes, reducing testing time for new cyber threats by 24 hours.
98% of security leaders plan to invest in exposure management within the next year, with 90% applying validation at least monthly, though 31% cite lack of resources as a major challenge in remediation efforts.
Machine identities now outnumber human identities by more than 80:1 ratio, with 94% of organizations reporting an increase in machine identities over the past three years, yet 88% of respondents still define 'privileged users' as human-only, creating significant blind spots in security coverage.
AI presents a triple threat – as an attack tool, defense mechanism, and new risk vector, with 94% of organizations using AI for security but 68% lacking proper identity security controls for AI systems, while 47% cannot effectively secure "shadow AI" usage.
Identity silos are undermining security effectiveness with 70% of respondents identifying them as root causes of cybersecurity risk, while 49% lack complete visibility into entitlements and permissions across their cloud environments.
An experienced SOC professional was rejected during a interview for a SOC Lead position after being unable to demonstrate sufficient knowledge of a specific security tool used by the company.
Security community members overwhelmingly suggested this was a "red flag" about the employer, noting that capable security professionals can learn tools quickly and that hiring decisions based primarily on tool familiarity rather than security fundamentals indicate poor organizational priorities.
The incident highlights ongoing tension in cybersecurity recruitment between tool-specific technical requirements and broader security expertise necessary for leadership positions.
Senior tech employee reports sudden termination as company offshores their entire technical department, highlighting increasing vulnerability even for experienced professionals in cybersecurity and IT roles.
Community advice emphasizes financial preparation, including reducing spending immediately, as commenters suggest the job market will worsen before improving, particularly impacting senior-level positions.
Practical recovery steps include claiming unemployment, maintaining professional connections for references, and considering temporary salary reductions while developing side business opportunities using existing technical skills.
Consulting giants like Deloitte, Accenture, and EY were most frequently cited for toxic workplace practices, with many describing them as "puppy mills" that burn through recent graduates by overloading staff while offering below-market compensation.
DXC Technology and Leidos were specifically mentioned for having problematic management cultures, with DXC characterized by high turnover and Leidos criticized for inefficient processes and questionable expertise.
Federal government contracts were noted as potential exceptions, with some professionals reporting positive experiences on government projects that maintained reasonable 40-45 hour workweeks despite working for otherwise poorly-reviewed companies.
The workbook is part of the AI Ethics and Governance in Practice Programme, authored by a team of researchers from the Public Policy Programme at The Alan Turing Institute to help practitioners implement explainable AI systems.
It introduces four key maxims of AI explainability (be transparent, be accountable, consider context, reflect on impacts) and explores six types of explanations – rationale, responsibility, data, fairness, safety, and impact.
Designed for practical application, the workbook includes activities, case studies, and an Explainability Assurance Management Template to help organizations properly document and implement explainability throughout the AI system lifecycle.
OpenAI emphasizes starting with systematic evals – rigorous evaluation processes that measure AI model performance against specific use cases, as demonstrated by Morgan Stanley where 98% of financial advisors now use AI daily.
Enterprise AI adoption delivers measurable improvements in workforce performance, automating routine operations, and powering products with more relevant customer experiences – requiring an experimental mindset unlike traditional software deployment.
The report outlines seven key lessons for enterprise AI implementation, including embedding AI in products, customizing models, and setting bold automation goals to maximize value from AI investments.
Organizations are rapidly adopting AI applications with some using over 100 unique AI tools, but IT and security teams have visibility into less than 20% of these applications, creating significant security and compliance risks.
The report analyzed AI usage across 160+ organizations, 400K+ users, and 3000+ AI applications, revealing that this "AI sprawl" introduces new risks including potential data leakage through unmanaged AI agents and uncontrolled access paths.
ChatGPT leads enterprise AI adoption by a significant margin, followed by tools like Cursor, Google Gemini, and QuillBot, with many organizations lacking proper governance frameworks to manage this widespread adoption.
Berlin-based RedMimicry has secured seven-figure seed funding led by High-Tech Gründerfonds, enabling further development of their platform that realistically emulates complex cyber-attacks for defense testing.
The company addresses regulatory requirements like DORA and NIS-2 by providing repeatable attack emulations that validate defenses against realistic threats, helping organizations improve security while reducing costs.
Upcoming platform enhancements will focus on specific threat scenarios for critical infrastructure (OT environments) and financial services, with plans to expand their partner network for wider market reach.
Exposure action platform Seemplicity secured $50M in Series B funding led by Sienna Venture Capital with participation from Essentia VC and existing investors to enhance their AI capabilities and expand market presence in the US, UK, and Europe.
The company's platform reduces exposure noise by 95% through automated aggregation, prioritization, and remediation of vulnerabilities, processing over 1.5 billion security findings daily across various industries.
Since its Series A funding, Seemplicity has reported an 800% increase in annual recurring revenue and tripled its customer base, with recent product updates introducing AI Insights and Detailed Remediation Steps to simplify vulnerability management workflows.
Innerworks has developed a security platform that identifies AI-generated synthetic interactions with 97% accuracy, already being used to defend national infrastructure and investigate major cryptocurrency hacks including a €1.38 billion theft linked to North Korean operatives.
The company employs "RedTeam," a crypto-bounty program that recruits ethical hackers and AI agents globally to continuously test and improve their system's resilience against sophisticated AI-based attacks.
Nearly €184 billion was lost to bot-related attacks in 2024, with deepfake fraud attempts rising 2,000% since 2022 – Innerworks' platform aims to become "the internet's immune system" by distinguishing authentic human behavior from AI imitations.
A continuous threat exposure management platform that provides automated vulnerability scanning for internet-facing assets with varying service tiers for different organizational needs.
Provides breach and attack simulation products for security control validation, offering three different products to meet the needs of organizations of various sizes and maturity levels.
XAHICO Web Platform is a cloud-based solution for vulnerability detection, penetration testing, and adversary simulation, accessible through web browsers and suitable for various user levels.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.