Happy Sunday!
In this week's brief:
- Red Hat confirms a security incident following claims that hackers breached their GitLab repositories, though details about the scope remain limited
- AI code generation creates more problems than it solves with research showing vulnerabilities increase by 37.6% after just five iterations of AI improvements
- Senior cybersecurity professionals are hitting walls in today's job market, with experienced candidates submitting hundreds of applications and getting nowhere
A quick note before we dive in.

Industry News
Red Hat Confirms Security Incident After Hackers Claim GitLab Breach
-
Red Hat acknowledged a security incident following claims by threat actors that they breached the company's systems and accessed sensitive data from their GitLab repositories.
-
The incident appears to involve unauthorized access to Red Hat's development infrastructure, though the company has not disclosed specific details about the scope or nature of the breach.
-
Red Hat is currently investigating the incident and working to determine what data may have been compromised, while implementing additional security measures to prevent further unauthorized access.
North Korea's Fake Recruiters Feed Stolen Data to IT Workers
-
DeceptiveDevelopment campaign targets cryptocurrency and DeFi developers through fake job offers on LinkedIn and Upwork, deploying malware including BeaverTail, InvisibleFerret, and Tropidoor to steal credentials and infect systems.
-
Stolen developer identities are supplied to North Korean fraudulent IT workers tracked as WageMole, who use this information along with proxy interviewing and AI-generated synthetic identities to obtain remote work at western companies.
-
The operation extends beyond programming roles into civil engineering and architecture, with North Korean workers impersonating legitimate companies and producing falsified engineering drawings with fake approval stamps.
SORVEPOTEL Malware Spreads Through WhatsApp Targeting Brazilian Users
-
The malware spreads via phishing messages containing malicious ZIP files that appear to come from trusted contacts, specifically targeting desktop users with Portuguese messages instructing them to download and open attachments on their PCs.
-
Once executed, SORVEPOTEL establishes persistence by copying itself to the Windows Startup folder and hijacks active WhatsApp Web sessions to automatically send the same malicious ZIP file to all contacts and groups in the victim's account.
-
The campaign has primarily impacted Brazil with 457 of 477 detected cases, focusing on government and public service organizations but also affecting manufacturing, technology, education, and construction sectors through automated propagation rather than data theft.

Leadership Insights
European Energy Sector Faces Rising Cyber Threats From Renewable Transition and Geopolitical Tensions
-
Europe's shift to renewable energy has created new attack vectors for cybercriminals, with successful cyberattacks on UK utilities surging 586% in 2023 and Danish energy companies experiencing the largest cyberattack in the country's history affecting 22 different firms simultaneously.
-
Russian state-backed threat actors are actively targeting European energy infrastructure, disabling over 5,800 wind turbines in Germany and conducting daily cyberattacks against Finnish utility Fortum, exploiting geopolitical tensions following the Ukraine invasion.
-
Phishing attacks drive 34% of energy sector incidents, with large energy companies showing a 47.8% click rate on malicious emails, though comprehensive security awareness training can reduce this to just 4% within one year according to KnowBe4 research.
ENISA Releases 2025 Threat Landscape Report Highlighting Key Cybersecurity Trends
-
The European Union Agency for Cybersecurity published its comprehensive annual threat assessment covering phishing as the primary initial attack vector, increased targeting of cyber dependencies, and continuous threats against mobile devices across five critical sectors.
-
The report analyzes threat convergence patterns where different threat groups are adopting similar tactics, while documenting predictable AI integration in both defensive and offensive cybersecurity operations throughout 2025.
-
ENISA's analysis encompasses cybercrime, state-aligned activities, foreign information manipulation and interference operations, and hacktivism campaigns, providing sector-specific impact assessments for public administration, transport, digital infrastructure, finance, and manufacturing industries.
Netwrix Research Lab Reveals 77% of Organizations Now Operate in Hybrid IT Environments
-
Survey of 2,150 IT professionals across 121 countries shows hybrid adoption rose from 74% in 2024 to 77% in 2025, with 53% of on-premises-only organizations planning cloud migration. Account compromise incidents in the cloud surged from 16% in 2020 to 46% in 2025, while phishing remains the most common threat vector both on-premises and in cloud environments.
-
AI adoption is creating new security challenges as 37% of respondents report that AI-driven threats forced them to adapt their security approach, while only 60% of organizations have implemented AI tools. Attackers are leveraging AI faster than defenders, with cybercriminals using it for more targeted attacks and accelerated data harvesting for social engineering.
-
Financial impact from security incidents is escalating dramatically, with 75% of organizations reporting financial damage in 2025 compared to 60% in 2024. The percentage of organizations experiencing damage exceeding $200,000 nearly doubled from 7% to 13%, while cyber insurance requirements have tightened with PAM and IAM standards becoming more stringent across policies.

Career Development
Senior Tech Professionals Face Unprecedented Job Market Challenges
-
A senior tech professional with 20 years of specialized experience and an MBA has submitted over 200 applications following 2024 layoffs, receiving only 5 HR screening calls with no progression, highlighting the current job market dysfunction for experienced professionals.
-
Companies are increasingly utilizing AI screening tools and posting ghost jobs, creating barriers for candidates while expecting senior-level impact at junior-level costs, effectively pricing out both experienced professionals and entry-level candidates.
-
Networking emerges as the primary solution according to community responses, with direct company applications and cold outreach strategies proving more effective than traditional job board applications in the current market environment.
SOC Analyst Questions Career Ceiling Despite $250K Salary
-
A SOC analyst with 11 years of experience earning $250K annually at a major company questions whether they've reached their career peak, despite having no degree or certifications and working fully remote on a 4-day schedule.
-
Industry professionals in the comments emphasize the exceptional nature of this compensation package, with many certified analysts earning significantly less, highlighting the current challenging cybersecurity job market conditions.
-
The discussion reveals significant salary disparities across the industry, with GRC professionals holding advanced degrees and clearances earning $160K, while Tier 2 analysts with certifications struggle to reach $100K in today's competitive landscape.
Junior Security Team Member Requests Random Script Execution on Production Systems
-
A junior cybersecurity team member casually requested a system administrator to run an untested script from a random blog on three production machines, demonstrating concerning lack of operational awareness and security protocols.
-
The script contained potentially dangerous operations including package installations, file permission changes via chmod, and concluded with a reboot command that could cause significant system downtime.
-
The incident highlights the critical importance of requiring sysadmin experience for cybersecurity roles, as technical understanding of infrastructure is essential to avoid creating security risks while attempting to improve security posture.

AI & Security
Anthropic Develops AI Cyber Defenders for Automated Security Operations
-
Anthropic has developed AI agents capable of performing complex cybersecurity tasks including incident response, threat hunting, and vulnerability assessment without human intervention.
-
The AI cyber defenders demonstrated ability to analyze network traffic, identify malicious activity, and execute remediation actions through integration with existing security tools and SIEM platforms.
-
Initial testing shows the AI agents can reduce mean time to response by up to 60% while maintaining high accuracy in threat detection and classification across various attack vectors.
Second Malicious MCP Server Hides Dual Backdoors in Working Developer Tool
-
The @lanyer640/mcp-runcommand-server npm package was initially legitimate when published September 6, 2025, but was weaponized with malicious code on September 30 after gaining hundreds of installs and establishing trust among developers.
-
Attackers embedded two independent reverse shells – one triggered during package installation via preinstall hook connecting to 45.115.38.27:2333, and another runtime backdoor that creates persistent access whenever the MCP server runs.
-
This represents the second malicious MCP server discovered in one week, indicating a growing supply-chain attack pattern targeting the emerging Model Context Protocol ecosystem where legitimate functionality masks hidden backdoors.
Iterative AI Code Generation Shows 37.6% Increase in Critical Vulnerabilities After Five Iterations
-
University researchers analyzed 400 code samples through 40 rounds of AI improvements using four prompting strategies and found security vulnerabilities increased by 37.6% after just five iterations, with efficiency-focused prompts producing the most severe issues including memory safety problems.
-
The study revealed that even security-focused prompts paradoxically introduced new vulnerabilities while fixing obvious ones, with 21.1% of these attempts resulting in cryptographic implementation errors due to LLM misunderstanding of security contexts and outdated security patterns.
-
Each iteration showed non-linear vulnerability accumulation with later iterations (8-10) averaging 6.2 vulnerabilities per sample compared to 2.1 in early iterations, demonstrating that code complexity increases correlate strongly with security degradation in AI-generated code.

Market Updates
SafeHill Raises $2.6M as It Launches from Stealth to Transform Threat Exposure Management
-
Chicago-based cybersecurity startup SafeHill (formerly Tacticly) has secured $2.6 million in pre-seed funding led by Mucker Capital and Chingona Ventures to launch their AI-powered Continuous Threat Exposure Management platform. The company is co-founded by former blackhat hacker Hector Monsegur, once known as "Sabu," who brings insider expertise to their threat detection capabilities.
-
SafeHill SecureIQ™ combines continuous penetration testing with human validation to provide enterprises with real-time security posture monitoring. The platform offers External Attack Surface Monitoring, AI-assisted threat exposure analysis, and maps findings to compliance frameworks like PCI-DSS, CMMC, NIST, and ISO27001 for streamlined audits.
-
The platform addresses the growing challenge of alert fatigue by using AI to cut through security noise while expert ethical hackers validate findings and prioritize real risks. SafeHill's continuous model helps organizations remediate vulnerabilities before attackers can exploit them, moving beyond traditional point-in-time assessments to always-on threat exposure management.
Prelude Security Raises $16M for Memory Protection Technology
-
Prelude Security secured $16M in funding led by Brightmind Partners, with Sequoia Capital and Insight Partners participating, bringing total funding to $45M to commercialize their runtime memory protection technology that detects and blocks malicious code during execution.
-
The company addresses a critical gap in endpoint security where approximately 75% of advanced attacks now operate entirely in memory, evading traditional EDR platforms that weren't designed to detect memory-resident threats.
-
Their solution uses hardware-level telemetry to identify out-of-context code execution, aligning with Microsoft's Windows Resiliency Initiative and representing what investors call an architectural leap beyond incremental endpoint security improvements.
CISO Global Enters $15 Million Convertible Preferred Equity Facility to Fund Expansion Initiatives
-
CISO Global secured a financing arrangement with B. Riley Securities allowing them to sell up to $15 million of convertible preferred stock over 18 months, with the company retaining full control over timing and amounts with no minimum commitments.
-
The convertible preferred stock has a $1,000 per share stated value with a 4% original issue discount and converts to common stock at varying rates – 105% of the lowest daily VWAP for the initial draw and 95% for subsequent draws, subject to a $0.40 floor.
-
Proceeds will fund expansion initiatives, particularly scaling their cybersecurity software business in the insurance channel through their strategic relationship with CAGI, as the AI-powered cybersecurity firm continues its growth trajectory.

Tools
SimSpace Platform
SimSpace Platform is a cyber range solution that provides realistic environments for cybersecurity training, testing, and optimization of security capabilities.
WPMissionControl
WPMissionControl is a WordPress-focused security and uptime monitoring tool that offers continuous website checks, alerts, and malware cleanup services.
Cyber Cure free intelligence feeds
Intelligence feeds for cybersecurity professionals to stay informed about emerging threats and trends.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz