Happy Sunday!
The disconnect between C-suite confidence and frontline reality continues to widen, with executives feeling twice as confident about cyber readiness compared to the managers actually dealing with daily threats.
In this week's brief:
- Threat actors are getting creative by exploiting Grok AI on X to spread malicious links through hidden metadata fields
- Shadow AI usage has exploded 200% across enterprises, with companies now juggling an average of 320 AI applications outside IT oversight
- SOC analyst burnout is reaching crisis levels due to chaotic scheduling and toxic management practices at understaffed centers
A quick note before we dive in.

Industry News
Threat Actors Abuse X's Grok AI to Spread Malicious Links
-
Malicious advertisers are exploiting a loophole where they hide malicious links in the "From:" metadata field of video ads on X, which isn't scanned by the platform's security filters.
-
When users ask Grok about these posts, the AI assistant extracts and shares the hidden links as clickable URLs, effectively bypassing X's link posting restrictions while gaining credibility from Grok's trusted system account status.
-
This technique, dubbed "Grokking" by researcher Nati Tal, has helped some malicious ads reach millions of impressions, leading to various scams and information-stealing malware.
GhostRedirector Poisons Windows Servers with Backdoors and SEO Fraud Tools
-
ESET researchers identified a China-aligned threat actor named GhostRedirector that compromised at least 65 Windows servers primarily in Brazil, Thailand, and Vietnam using a passive C++ backdoor (Rungan) and a malicious IIS module (Gamshen) for SEO fraud.
-
The attackers use EfsPotato and BadPotato exploits to create privileged users on compromised servers, ensuring persistent access even if their malware is removed, and deploy various webshells for maintaining access to the systems.
-
GhostRedirector's SEO fraud scheme uses the Gamshen module to manipulate Google search results by hijacking responses only for Googlebot requests, artificially promoting gambling websites without affecting regular visitors of the compromised sites.
VirusTotal Uncovers Undetected Colombian Malware Campaign Using SVG Files
-
VirusTotal's Code Insight detected a sophisticated phishing campaign impersonating the Colombian justice system through SVG files that went completely undetected by all antivirus engines.
-
The malicious SVGs execute embedded JavaScript to render a fake government portal, simulate a document download with progress bar, while secretly downloading a malicious ZIP archive in the background.
-
Investigation revealed 523 samples dating back to August 2025, with attackers using polymorphism techniques and Spanish-language code comments to evade detection while targeting Colombian users via email.

Leadership Insights
GRC Security Professionals Share Tips for Building Influence and Reducing Bureaucratic Perception
-
In this Black Hills Information Security webcast, Kelli Tarala and CJ Cox discuss how GRC professionals can shift from being perceived as obstacles to becoming valued partners by focusing on value creation, relationship building, and effective communication.
-
Resource constraints affect everyone in security—the key is prioritizing effectively and "right-sizing" your GRC program for your organization size rather than attempting to implement Fortune 50-level programs at smaller companies.
-
Leading security professionals recommend leveraging technology and analytics to streamline compliance processes, using AI to help with documentation, and improving dashboards to better communicate risk information to leadership in ways they understand.
Bitdefender Report Reveals Widening Gap Between C-Suite and Security Teams
-
Survey of 1,200 cybersecurity professionals reveals 84% of modern attacks now leverage LOTL techniques that bypass traditional security by using legitimate system tools already present in the environment.
-
Significant perception gaps exist between leadership and frontline teams - 45% of C-level executives report being "very confident" about cyber readiness compared to only 19% of mid-level managers, leading to misaligned priorities.
-
68% of security leaders agree they need to reduce their attack surface by disabling unnecessary tools, while 58% admit they've been told to keep breaches confidential, creating conflicts with compliance requirements.
IBM Cost of Data Breach Report 2025 Highlights AI Security Concerns
-
Global data breach costs declined for the first time in five years to USD 4.44 million, driven by faster containment through AI-powered defenses, while US breach costs surged past USD 10 million due to steeper regulatory penalties.
-
16% of breaches involved attackers using AI in their campaigns, particularly in phishing and deepfake attacks, indicating an escalating arms race between defenders and threat actors.
-
97% of AI-related security breaches involved systems lacking proper access controls, with most breached organizations reporting no governance policies to manage AI or prevent shadow AI use (unauthorized AI applications).

Career Development
Cybersecurity Professionals Discuss Knowledge Gaps And Impostor Syndrome As Part Of Career Journey
-
A Security Architect with 5 years of cybersecurity experience (8 years in IT overall) shares concerns about feeling knowledge gaps despite having advanced education, discovering this is a common experience across the industry.
-
Multiple practitioners across different specialties including GRC and security management confirm experiencing similar feelings, with even a senior professional with 17 years of experience noting that impostor syndrome remains a persistent career challenge.
-
Comments suggest this phenomenon aligns with professional growth rather than incompetence, with recommendations to embrace knowledge gaps, maintain honesty about limitations, and utilize frameworks to quickly address unfamiliar topics when needed.
SOC Analyst Describes Burnout From Chaotic Shift Scheduling and Toxic Workplace
-
A SOC analyst details working irregular shift patterns (including day/night rotations within the same week, double overnights, and weekend work) at an understaffed security operations center, with an hour-long commute to a hybrid office.
-
The challenging work schedule is causing significant mental and physical health issues, exacerbated by a toxic workplace environment that includes bullying from a coworker and degradation from management.
-
Community responses overwhelmingly suggest finding new employment, noting that while 24/7 operations with some weekend work are normal for SOCs, rapidly shifting between different shifts and poor management practices are creating unnecessary burnout and high turnover.
Cybersecurity Community Emphasizes Learning Over Certification Collection
-
The cybersecurity community is discussing how practitioners often overemphasize collecting certifications merely as resume decorations rather than valuing the knowledge gained during the process.
-
Many hiring processes rely heavily on credential verification rather than knowledge assessment, with some companies beginning to value practical demonstrations such as GitHub repositories with relevant projects.
-
Industry professionals advocate for improved hiring practices that include more technical interviews conducted by cybersecurity experts rather than HR personnel with limited understanding of the field.

AI & Security
Cloud Security Alliance Launches AI Safety Initiative With Premier Industry Partners
-
The Cloud Security Alliance (CSA) has established an AI Safety Initiative with a permanent official location, bringing together experts from various organizations to develop best practices for AI safety and security.
-
CSA has announced its initial cohort of Premier AI Safety Ambassadors including Airia, Deloitte, Endor Labs, Microsoft, and Reco – companies that are committed to promoting responsible AI practices and developing pragmatic solutions for managing AI risks.
-
The initiative emphasizes a collaborative approach to addressing AI security challenges, with participating organizations focusing on different aspects such as enterprise AI platform security, professional services, application security, comprehensive threat intelligence, and dynamic SaaS security.
Research Shows LLMs Struggle With Multi-host Network Attacks Without Proper Abstractions
-
Researchers from Carnegie Mellon and Anthropic created MHBench, an open-source benchmark with 10 realistic emulated networks to test LLM capabilities in executing multi-host network attacks.
-
Even advanced models like GPT4o and Gemini 2.5 Pro with security-specific prompting strategies failed to autonomously execute multi-host network attacks when interacting directly with low-level shell tools.
-
The researchers developed Incalmo, a high-level abstraction layer that enables LLMs to specify high-level actions which are translated into lower-level commands, allowing even smaller models to successfully achieve attack goals in multiple test environments.
Enterprise Shadow AI Usage Increases 200% as Organizations Face New Security Challenges
-
The average enterprise now uses 320 AI cloud applications, with a 200% increase in AI app traffic over the past year compared to just 23% growth for non-AI apps, creating significant security blind spots as data uploaded to AI services has grown by 80%.
-
Organizations are experiencing a "Shadow AI" problem with employees using unsanctioned AI tools outside IT oversight, expanding the traditional Shadow IT challenge, with enterprises now using an average of 3,500 cloud services (up from 2,400 in 2023 and 831 in 2014).
-
Top AI applications in enterprise environments include Microsoft Copilot, ChatGPT, Beautiful.AI, Hugging Face, and various other chatbots and content generation tools, raising concerns about data leakage, compliance risks, and LLM-specific security vulnerabilities.

Market Updates
Shift5 Secures $75M Funding to Enhance Defense and Transportation Cybersecurity
-
Washington D.C.-based Shift5 has raised $75 million in Series C funding to expand their operational intelligence capabilities for legacy defense systems and critical transportation infrastructure that were not designed with cybersecurity in mind.
-
The company will use the funding to scale technology in the defense sector while expanding into commercial industries including aviation, rail, and maritime, focusing on protecting systems vulnerable to modern threats like GPS jamming and RF interference.
-
Founded by former military personnel, Shift5 addresses the growing concern that adversaries are increasingly targeting critical infrastructure, providing solutions that convert operational data into predictive maintenance insights rather than relying on static schedule-based maintenance.
Sola Security Raises $35M in Microsoft-Backed Funding Round
-
Tel Aviv-based Sola Security has secured $35 million in funding led by S32 with participation from Microsoft's M12 venture fund, bringing its total funding to $35 million just six months after its seed round.
-
The company offers an AI platform that enables security teams to build custom threat detection apps using prompts, automatically generating SQL queries that search for vulnerabilities in connected systems like AWS environments.
-
Since launching in March, Sola's platform has been adopted by more than 2,000 users who have created over 1,000 cybersecurity apps with features including graph research to determine if vulnerabilities in one system might affect other assets.
Tidal Cyber Raises $10 Million for CTI and Adversary Behavior Platform
-
The Washington, DC-based company, founded in 2022 by former MITRE experts, has now raised a total of $15 million to develop its threat-informed defense platform.
-
Tidal Cyber's platform operationalizes ATT&CK framework by mapping TTPs to provide tailored security strategies focused on adversary behavior, calculating residual risks and security stack effectiveness.
-
The funding will accelerate product innovation and fuel company growth as organizations move beyond CVE-counting and checkbox compliance toward proactive, threat-led defense approaches.

Tools
Vidoc Security
VIDOC is an AI-powered security tool that automates code review, detects and fixes vulnerabilities, and monitors external security, ensuring the integrity of both human-written and AI-generated code in software development pipelines.
Radiflow CIARA
A data-driven OT risk management platform that uses digital twin technology and breach simulations to assess cybersecurity risks, optimize mitigation strategies, and ensure compliance with industry standards.
Mend
An application security platform that combines SCA, SAST, container security, dependency management, and AI model risk analysis with integrated workflows for development and security teams.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz