Happy Sunday!
In this week's brief:
- CrowdStrike's npm packages got hit by the Shai-Hulud supply chain attack, affecting over 526 packages and showing how sophisticated these attacks have become
- 71.7% of workplace AI tools are classified as high or critical risk, with most enterprise data flowing to risky platforms rather than secure alternatives
- Experienced cybersecurity professionals are struggling in an unprecedented job market, with some reporting over 1,000 applications without success
A quick note before we dive in.

Industry News
Shai-Hulud Supply Chain Attack Targets CrowdStrike npm Packages
-
Multiple npm packages published under CrowdStrike's account were compromised in an ongoing supply chain attack called "Shai-Hulud" that previously affected tinycolor and 40+ other packages. The attack uses identical malware that scans systems for tokens/credentials and exfiltrates sensitive data.
-
The malware evolved through seven distinct versions, becoming increasingly stealthy and efficient. It self-propagates by stealing credentials to modify and republish packages, adding a malicious bundle.js file that executes automatically via postinstall scripts.
-
Over 526 packages were affected, with more than 100 packages compromised in a single burst targeting CrowdStrike. Organizations should rotate npm tokens, audit environments that installed affected packages, and monitor for unusual publish events.
ShadowLeak: Zero-Click Attack Exfiltrates Sensitive Data via ChatGPT's Deep Research Agent
-
Researchers discovered a zero-click vulnerability in ChatGPT's Deep Research agent that allows attackers to craft malicious emails that trick the agent into leaking sensitive inbox data with no user action required or visible indication.
-
Unlike previous attacks requiring client-side image rendering, this service-side exfiltration occurs entirely from OpenAI's cloud environment, making it invisible to traditional enterprise security controls and applicable across multiple data connectors beyond Gmail.
-
The attack used sophisticated social engineering techniques embedded in HTML emails to bypass the agent's safety restrictions, achieving 100% success rate by encoding stolen data in Base64 format before exfiltration.
SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers
-
SonicWall detected suspicious activity targeting their cloud backup service, with unknown threat actors accessing encrypted firewall configuration files for less than 5% of customers through a series of brute-force attacks.
-
While credentials within the compromised files were encrypted, the files contained information that could help attackers potentially exploit the related firewalls, prompting SonicWall to urge immediate password resets.
-
The company recommends affected customers take urgent containment actions including limiting WAN access, disabling management services and VPN access, resetting passwords, and importing fresh preferences files provided by SonicWall with randomized credentials.

Leadership Insights
CyberArk Reports 90% of Organizations Suffered Identity-Centric Breaches as Machine Identities Outnumber Humans 80:1
-
CyberArk's report highlights an "AI trifecta" where artificial intelligence simultaneously serves as a tool for attackers, a defense mechanism, and creates new identity-centric risks as organizations integrate AI across their enterprises.
-
The survey of 2,600 security decision-makers across 20 countries reveals machine identities now outnumber human identities by more than 80:1, yet 68% of respondents lack proper controls for AI technologies despite 72% of employees regularly using AI tools.
-
Nation-state actors are increasingly collaborating with cybercriminal groups to conduct sophisticated attacks, including targeting critical infrastructure and financial institutions, as evidenced by a recent $1.5B crypto heist from ByBit and Chinese government hackers gaining access to the U.S. Treasury.
Akamai Reports 311 Billion Web Application and API Attacks in 2024
-
Web application and API attacks increased by 33% year-over-year, with APIs emerging as primary targets and AI-generated kill chains automating the entire attack lifecycle.
-
Organizations face severe financial implications with API security issues currently costing approximately $87 billion annually, projected to exceed $100 billion by 2026 without adequate intervention.
-
Modern applications increasingly depend on APIs for functionality, with organizations expecting a 39% increase in web applications within two years, making shadow and zombie APIs particularly vulnerable attack vectors.
Verizon's 2025 DBIR Reveals Surge in Third-Party Breaches and Ransomware
-
Third-party involvement in breaches doubled to 30% (from 15% last year), with System Intrusion being the dominant pattern. Vulnerable software, leaked credentials in code repositories, and SaaS provider compromises all played significant roles in this trend.
-
Exploitation of vulnerabilities grew 34% as an initial access vector, reaching 20% of breaches and approaching credential abuse levels. Edge device and VPN vulnerabilities grew eight-fold (to 22%), with only 54% of these vulnerabilities being fully remediated within a median of 32 days.
-
Ransomware presence increased 37% from last year, appearing in 44% of all breaches analyzed. Small organizations were disproportionately affected (88% of SMB breaches vs. 39% of large organization breaches), though median ransom payments decreased to $115,000 with 64% of victims refusing to pay.

Career Development
IT Professional With 10 Years Experience Struggles To Enter Cybersecurity Field Despite Qualifications
-
An IT support professional with 9.5 years of experience, home lab setup, and certifications (A+, Sec+, CySA+, AZ900) reports being consistently rejected when applying for entry-level cybersecurity positions despite meeting or exceeding requirements.
-
Industry expert explains current market conditions are extremely challenging due to COVID-related layoffs and AI disruption, creating a situation where experienced professionals are competing for entry-level positions.
-
The recommended strategy for breaking into the field emphasizes networking over certifications, with specific advice to build connections, demonstrate practical skills through labs, and stay current with industry news rather than continuing to "brute force" applications.
Cybersecurity Professionals Facing Unprecedented Job Market Challenges
-
The current IT and cybersecurity job market is being described as "abysmal" – worse than seen in decades, with experienced professionals reporting search periods extending beyond a year compared to weeks in previous years.
-
Cloud migration and WFH trends have reduced the need for on-site IT staff, while AI-powered solutions enable senior professionals to dramatically outperform teams of junior employees, creating further employment challenges.
-
The industry is experiencing a "perfect storm" as companies pull back on IT personnel spending, educational institutions produce more cyber graduates, and certification pathways lower barriers to entry – all amid government sector drawdowns.
InfoSec Professional Shares Job Search Struggles Despite 20 Years of Experience
-
Experienced professional with 15+ years in IT and several years in ransomware remediation describes applying to over 1000 jobs in the past 10 months without success after being laid off without severance.
-
The author transitioned from IT to cybersecurity around 2020, working as a lead for an MSSP handling incidents involving major threat actors like BlackBasta, Conti, and Lockbit, later moving to a consultant role focused on NIST CSF 2.0 audits.
-
They express frustration with current hiring practices, particularly the reliance on ATS systems that may filter candidates based on resume formatting rather than experience, and note that many recruiters openly admit they don't review all applications.

AI & Security
AI Risk Report: 71.7% of AI Tools Used in Workplace Classified as High or Critical Risk
-
A comprehensive analysis of 7 million workers shows AI usage has grown 61x over the past 24 months, with 83.8% of enterprise data going to risky AI tools rather than enterprise-ready alternatives.
-
The report identifies that 34.8% of corporate data sent to AI tools is sensitive, including source code (18.7%), R&D materials (17.1%), and sales/marketing data (10.7%), creating significant data exfiltration risks.
-
Among the top 25 AI tools in the workplace, ChatGPT remains the most used, while Claude has climbed dramatically to second place, reflecting market consolidation around tools offering enterprise-grade capabilities and security features.
Executive-Analyst Divide Emerges in Cybersecurity AI Implementation
-
While 71% of executives believe AI has significantly improved their security team's productivity, only 22% of frontline analysts agree, revealing a substantial perception gap about AI's operational effectiveness.
-
Over half of surveyed organizations have already restructured their security teams in response to AI adoption, focusing not on reducing headcount but on creating new roles around automation oversight and AI governance.
-
The most tangible value of AI in cybersecurity currently lies in threat detection, investigation, and response (TDIR), though only 10% of analysts trust AI to operate autonomously compared to 38% of executives.
AI Integration Transforms Security Operations Centers With 153x Increase In Threat Hunting
-
Adlumin's report reveals AI now automates 70% of incident investigations and threat remediation activities, enabling SOC teams to focus on complex threats while processing over 490,000 alerts between December 2024 and February 2025.
-
Threat origins show 56% of detections come from endpoints and 44% from the cloud, with 95% of proactive threat responses involving password resets and account disablement – demonstrating modern breaches increasingly bypass traditional endpoint security.
-
Despite automation advances, human expertise remains critical – 86% of alerts escalate into tickets requiring validation, and 1 in 10 cases still need MDR team intervention, highlighting the complementary relationship between AI and analysts in effective cybersecurity operations.

Market Updates
CrowdStrike to Acquire Pangea to Secure Enterprise AI
-
CrowdStrike announced plans to acquire Pangea, a leader in AI security, extending the Falcon platform to deliver the industry's first complete AI Detection and Response (AIDR) solution.
-
The acquisition will provide protection against prompt injection attacks with up to 99% efficacy, enabling organizations to control AI conversations and stop risky AI use through governance policies.
-
With this integration, CrowdStrike will secure the entire AI lifecycle from development through deployment, allowing customers to build and scale AI applications with security built-in from the start.
Irregular Secures $80M Series A to Combat AI Model Exploitation
-
San Francisco-based Irregular raised $80M in Series A funding to develop simulation environments that test AI models both as potential attackers and victims, helping identify vulnerabilities in real-world attack scenarios.
-
The startup, led by former IBM AI researcher Dan Lahav, serves top AI labs including OpenAI and Anthropic, creating tools that assess if models can perform malicious actions like evading detection or leaking sensitive data.
-
Irregular plans to convert its research into enterprise-ready products that will help any organization deploying AI to monitor and secure their models against increasingly sophisticated AI-based threats.
Vega Raises $65 Million in Funding to Redefine Security Analytics
-
Vega secured $65 million across seed and Series A rounds led by Accel, with participation from Cyberstarts, Redpoint, and CRV to deliver AI-native security analytics that works across any stack without requiring costly migrations.
-
Founded in 2024 by Shay Sandler and Eli Rozen, the platform addresses limitations of traditional SIEM systems by analyzing data in place rather than requiring all data to be shipped in and indexed, reducing blind spots and investigation delays.
-
The company's federated approach provides global visibility regardless of where data resides – cloud, legacy, or hybrid environments – and is already trusted by Fortune 500 companies, top-tier banks, and major healthcare organizations.

Tools
Falcon ASPM
A cloud security solution that provides agentless application mapping and vulnerability prioritization based on business impact across cloud environments.
Akto
API security platform that combines discovery, testing, and monitoring capabilities to identify and protect against API vulnerabilities throughout the development lifecycle.
Silobreaker
Silobreaker is an intelligence platform that processes unstructured data from open and dark web sources to support cyber threat intelligence, vulnerability management, and risk assessment workflows.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz