Happy Sunday!
The Qantas CEO taking an $800K pay cut for a data breach feels like a turning point - finally seeing real accountability at the top instead of security teams taking all the heat.
In this week's brief:
- A critical Azure flaw that could have given attackers silent access to any Microsoft tenant worldwide - thankfully patched quickly
- Deepfake losses hit $347M this quarter alone, with incidents doubling every six months
- Industry veterans are calling out the cybersecurity job shortage myth, saying most openings are just backfills
A quick note before we dive in.

Industry News
Verified Steam Game Steals Streamer's Cancer Treatment Donations
-
A verified Steam game called BlockBlasters was updated with a cryptodrainer component that stole $32,000 from a cancer patient's wallet during a fundraising livestream for his treatment.
-
Security researchers report the malware affected approximately 261-478 Steam users, stealing a total of $150,000, with victims being specifically targeted based on their cryptocurrency holdings.
-
The game contained sophisticated malware components including a Python backdoor and StealC payload that collected Steam login information and uploaded it to command and control servers.
Actor Tokens Vulnerability Allowed Complete Access to Every Entra ID Tenant
-
A critical vulnerability in the Azure AD Graph API failed to properly validate tenant origins when processing undocumented impersonation "Actor tokens" used by Microsoft for service-to-service communication, allowing attackers to access any Entra ID tenant globally with no logs or evidence.
-
The impact was catastrophic – an attacker could impersonate any user (including Global Admins) in any tenant, bypass Conditional Access policies, and make any modification to the directory without generating logs in the victim's tenant, effectively allowing complete Microsoft 365 and Azure resource compromise.
-
Microsoft fixed the issue within days of receiving the report on July 14, 2025, rolled out additional mitigations preventing applications from requesting these tokens, and issued CVE-2025-55241 to address this flaw that Microsoft's telemetry indicates was not exploited in the wild.
State-Sponsored Threat Actor Exploits Multiple Zero-Day Vulnerabilities in Cisco ASA and FTD Software
-
Cisco identified a state-sponsored threat actor actively exploiting multiple zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software for data exfiltration from government networks.
-
The three critical vulnerabilities (CVE-2025-20333, CVE-2025-20362, CVE-2025-20363) allow attackers to execute arbitrary code, with the first two already under active exploitation in the wild and the third at high risk of imminent exploitation.
-
The U.K.'s NCSC identified RayInitiator (multi-stage bootkit) and LINE VIPER (shellcode loader) malware families being used in these attacks, with the malware designed to survive reboots and firmware upgrades.

Leadership Insights
CSA Survey: Organizations Prioritize SaaS Security Despite Persistent Visibility and Access Challenges
-
SaaS security is now a high priority for 86% of organizations with 76% increasing budgets, though many rely on fragmented approaches including vendor-native tools (69%), CASBs (43%), and manual audits (46%).
-
Data remains at risk with 63% reporting external oversharing and 56% noting sensitive data uploads to unauthorized apps, while 55% of employees adopt SaaS without security team involvement.
-
Organizations face significant identity management challenges, with 58% struggling to enforce privileges and 46% unable to properly monitor non-human identities, while 56% express concerns about over-privileged API access.
Qantas Cutting CEO Pay Signals New Era of Cyber Accountability
-
Qantas Airways board penalized CEO Vanessa Hudson by deducting A$800,000 from her bonus following a June cyber breach that exposed nearly 6 million passengers' personal information.
-
This decision comes amid growing regulatory trends, with US agencies like the SEC and FTC increasingly holding executives personally liable for cybersecurity failures through fines and legal actions.
-
The shift represents a welcome change for CISOs, as accountability for breaches moves from security teams to C-suite executives who define company culture, risk tolerance, and security investments.
2025 CISO Survey Reveals AI as Both Security Threat and Defense Tool for Organizations
-
The survey of 404 security leaders shows data breaches (84%), ransomware (83%), and third-party supplier breaches (80%) as top concerns, with significant regional differences – US organizations prioritizing internal data breaches (88%) while UK counterparts focus more on phishing attacks (84%).
-
AI adoption has increased dramatically with 34% now using it for customer service (up from 19% in 2024) and 28% for content creation (up from 15%), creating new security concerns including data exposure risks (60%) and AI-powered attacks, while 87% plan to implement AI-powered security tools to combat these threats.
-
Despite 91% of respondents reporting successful security awareness training, creating a strong security culture remains the top organizational challenge (80%), indicating a disconnect between training methodologies and actual behavior change in environments where traditional security perimeters have dissolved.

Career Development
Industry Veterans Question Perceived Cybersecurity Demand
-
Industry veterans are challenging the narrative of massive cybersecurity job demand, with hiring managers reporting that most positions are backfill roles rather than new growth positions, and internal candidates are typically prioritized over external hires.
-
The perceived job shortage is being attributed to artificial promotion by educational institutions, boot camps, certification bodies, and social media influencers who market quick-transition programs promising cybersecurity careers in 12 months.
-
Many professionals advocate for establishing a regulatory licensing system similar to other professions like electricians or attorneys, which would standardize qualifications and reduce the need for extensive interview processes while addressing the gap between certification and practical experience.
Senior Sysadmin Terminated After Accidental Production Outage
-
A senior system administrator with seven years of service and consistently strong performance reviews was terminated immediately after accidentally executing a data migration script that caused a 20-minute production system outage.
-
The employee immediately reported the incident to management and took full responsibility for the misclick error, which occurred due to lack of confirmation prompts in the admin console interface.
-
Despite the employee's transparency and history of excellent performance, management classified the incident as "unauthorized activities" and terminated employment without discussion, highlighting potential gaps in change management processes and employee protection policies.
Cybersecurity Professionals Share Alternative Job Board Recommendations Beyond LinkedIn and Indeed
-
Hiring.cafe emerges as the most frequently recommended alternative platform, with multiple security professionals reporting successful job placements and positive experiences compared to traditional job boards.
-
ClearanceJobs.com is highlighted as the go-to platform for cybersecurity professionals with Top Secret clearance or higher, specifically targeting government and defense contractor positions.
-
Industry veterans emphasize that LinkedIn remains effective when used strategically, with CISOs and security managers recommending direct recruiter outreach and avoiding "easy apply" features for better response rates.

AI & Security
Resemble AI Q2 2025 Deepfake Incident Report Shows 487 Cases and $347M in Losses
-
Q2 2025 documented 487 verified deepfake incidents representing a 41% quarterly increase and 312% year-over-year growth, with attacks now doubling every six months and causing $347.2 million in direct financial losses from scams alone.
-
Women face disproportionate targeting with 84% of deepfake attempts targeting females, including over 25 high-profile women subjected to explicit deepfakes, while at least 15 incidents involved AI-generated CSAM using real children's images.
-
Romance fraud operations reached industrial scale with sophisticated cases like Anne losing €830,000 to Brad Pitt impersonators over 18 months, while streaming platform Deezer discovered 18% of daily uploads were completely AI-generated content.
AI-Driven Security Automation Survey Reveals Implementation Delays Despite Strategic Priority
-
BlinkOps surveyed 1,000 security leaders revealing that 45% of organizations took up to three months to implement their most recent automation project, while only 15% deployed in under one month, creating a critical gap when attackers can move in seconds.
-
Despite implementation delays, 81% of security leaders rate AI-driven automation as very important or critically important to their 3–5 year strategy, with 53% planning to adopt AI-led threat detection without human involvement and 52% expecting AI to make complex decisions with oversight.
-
The primary barrier to automation adoption is lack of internal expertise (cited by more than half of respondents), with 44% struggling to hire people with automation experience and 35% lacking skills to build or maintain workflows, driving 45% of organizations to establish centralized automation teams.
Enterprise AI Usage Surges 200% With Significant Security and Compliance Risks
-
Enterprise AI adoption has increased dramatically with traffic to AI apps up 200% compared to just 23% for non-AI apps, while the average organization unknowingly uses 320 AI applications, creating a substantial "Shadow AI" problem.
-
Security concerns are mounting as 94% of AI services are vulnerable to Large Language Model (LLM) risks including prompt injection, malware generation, and bias, while 11% of files uploaded to AI applications contain sensitive corporate content.
-
Organizations are responding by implementing governance controls through Security Service Edge (SSE) solutions, with 78% of enterprises now deploying private AI applications and 82% using Microsoft Copilot (up from 18% last year) as their primary sanctioned AI tool.

Market Updates
Cyberbit Acquires RangeForce to Enhance SOC Readiness
-
Cyberbit, a leader in hyper-realistic attack simulation, has acquired RangeForce to create an integrated operational cyber readiness platform powered by AI that spans from entry-level training to advanced SOC team exercises.
-
The combined platform enhances capabilities through AI-driven content creation, personalized learning, and expanded Live-Fire Exercises for commercial, enterprise, and government sectors across the US and EU.
-
This acquisition unites two recognized leaders in the Forrester Wave for Cybersecurity Skills & Training Platforms, with both companies focused on preparing defensive teams for real-world cyber threats through realistic environments.
Proofpoint Launches Agentic AI Cybersecurity Solution
-
Proofpoint just announced new tools that are designed to secure the agentic workspace, where people and AI agents collaborate side by side.
-
Proofpoint Data Security Complete enables organizations to locate their sensitive data, classify it correctly, control who has access to it, and monitor how people interact with it across endpoints, email, the web and the cloudt
-
Attackers have learned to embed malicious prompts in email to manipulate Al assistants such as Microsoft Copilot and Google Gemini.
Mycroft Raises $3.5 Million for AI-Powered Security and Compliance Platform
-
Toronto-based Mycroft emerged from stealth with autonomous AI agents that function as an AI Security and Compliance Officer, providing cloud security, application security, device management, and automatic remediation capabilities for organizations.
-
The company secured $3.5 million in seed funding led by Luge Capital with participation from multiple venture firms, enabling accelerated product development and operational expansion after attracting over 50 customers within six months.
-
Mycroft's platform specifically targets startups and SMBs by delivering enterprise-grade security and compliance without requiring large security teams, positioning AI agents as operational enhancers rather than simple task automation tools.

Tools
SOCRadar Digital Risk Protection Platform
A digital risk protection platform that combines threat intelligence, dark web monitoring, attack surface management, brand protection, and supply chain intelligence to detect and respond to external cyber threats.
Seemplicity
A remediation operations platform that streamlines vulnerability management by connecting security findings to fixing teams through automated workflows.
Entersoft Web Application Security
A comprehensive application security service provider offering manual penetration testing, vulnerability assessment, and security solutions across various industries.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz