Brief #125: Redis CVE 10.0 RCE Hits 330K Instances, Meta's A2AS AI Framework, 50% Networks Block AI
Ivanti left 13 vulnerabilities unpatched until March 2026 after ZDI disclosure. Anthropic research shows just 250 poisoned documents can backdoor LLMs of any size. Half of enterprises face direct financial losses from network failures blocking AI initiatives.
A perfect 10.0 CVSS vulnerability dubbed RediShell is exposing 330,000 Redis instances worldwide, allowing attackers to escape Lua sandbox and achieve complete system compromise
Half of enterprise networks are too outdated to support AI initiatives according to IDC, with 94% saying their infrastructure limits large data and AI projects
70% of job openings never make it to LinkedIn according to a former hiring manager, meaning you're competing with 1,500+ people for the visible 30%
RoboShadow is a cybersecurity platform that delivers daily vulnerability scans and automated fixes, helping businesses stay secure and compliant. With powerful integrations and continuous monitoring, it makes managing cyber risks simple and proactive.
Wiz Research discovered CVE-2025-49844, a use-after-free memory corruption vulnerability in Redis that allows attackers to escape the Lua sandbox and achieve arbitrary code execution with a CVSS 10.0 rating – the highest possible severity.
The vulnerability affects approximately 330,000 internet-exposed Redis instances globally, with about 60,000 lacking authentication and 57% of cloud environments running Redis as container images with potentially insecure default configurations.
Successful exploitation enables complete system compromise including credential theft, malware installation, data exfiltration, and lateral movement within cloud environments using stolen IAM tokens and certificates.
Trend Micro's Zero Day Initiative published advisories for 13 unpatched vulnerabilities in Ivanti Endpoint Manager, with CVSS scores ranging from 7.2 to 8.8. One flaw allows local privilege escalation while 12 enable remote code execution.
All vulnerabilities stem from improper validation of user-supplied input, leading to SQL injection and deserialization attacks. The bugs affect various components including AgentPortal service, Report_RunPatch, DBDR, and PatchHistory classes.
Ivanti initially requested patches by September 2025 but later extended the timeline to March 2026 for all 12 RCE flaws. ZDI disclosed the vulnerabilities after the 120-day disclosure window expired without adequate vendor response.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
A case-sensitivity vulnerability in Cursor IDE allowed attackers to bypass file protections by using variations like .cUrSoR/mcp.json instead of .cursor/mcp.json, which the IDE treated as different files while the operating system treated them as identical on Windows and macOS.
The flaw could lead to remote code execution by enabling attackers to inject malicious configuration files, register unauthorized plugins, or modify build tasks that execute arbitrary shell commands without triggering Cursor's security confirmation prompts.
Cursor patched the vulnerability in version 1.7 by normalizing file paths and implementing case-insensitive comparisons, but the incident highlights broader security challenges as AI-powered development tools gain more autonomous capabilities to modify system configurations.
IDC's 2025 Technology Leaders Survey found that 50% of organizations have outdated network infrastructure that cannot support new technology initiatives, with 94% reporting their networks limit large data/AI projects. Over half of companies experienced direct financial impact from network downtime or poor performance in the past 12 months.
The survey identified networking as the top technology investment priority for 2025, with 40% of respondents citing urgent need for flexibility and scalability improvements. However, companies are increasingly turning to external managed service providers rather than upgrading internal networking skills, with networking being the #1 area for partner outsourcing.
Organizations are struggling with AI implementation bottlenecks caused by network limitations, particularly around scalability and performance issues that have worsened since 2024. Despite 61% of companies using AI in parts of their business, unrealistic board expectations and network constraints are preventing enterprise-wide AI deployment and creating growing pains for technology leaders.
ISACA's 2025 survey of 2,685 cybersecurity professionals shows that while 62% are worried quantum computing will break Internet encryption, only 35% understand its capabilities and 55% have taken no preparation steps.
Organizations face a concerning awareness gap, with only 7% understanding NIST's post-quantum standards and 40% being unaware of their company's quantum computing plans, despite 56% worrying about harvest-now-decrypt-later attacks.
The timeline expectations vary widely among professionals, with 25% expecting quantum computing's full potential within 6-10 years and 39% within 11-15 years, yet only 5% consider it a high business priority for the near future.
ArmorCode and The Purple Book Community surveyed CISOs and security leaders, finding that 84% consider AppSec leadership more important now than 2-3 years ago, with 64% of organizations growing their AppSec teams to address increasing supply chain vulnerabilities (84%) and open-source risks (73%).
While 86% of respondents are using or exploring generative AI tools in their AppSec programs, 92% cite insecure code as their top concern when experiencing AI tool issues, and 76% say recent incidents like DeepSeek's database exposure will prevent future adoption of certain AI models.
Organizations are prioritizing ASPM (Application Security Posture Management) as their top 2025 investment (76%), with 78% identifying the volume of vulnerabilities and false positives as their biggest challenge despite improved developer collaboration (76% report positive relationships with development teams).
SOC leaders and senior security engineers report total compensation ranging from $200K-$250K, with Fortune 10 companies and financial services offering the highest packages for fully remote positions.
Career progression requires frequent job changes every 2-3 years, with professionals emphasizing that starting 10+ years ago provided easier entry into high-paying roles compared to today's competitive market.
Advanced certifications beyond CISSP and CISM, particularly niche specializations like CMMC assessments, can command premium rates with consultants billing $20K for 10 days of specialized work.
Companies purchase limited job credits on LinkedIn, posting only their most critical positions while keeping the majority of openings exclusively on their career pages, meaning you're competing with 1,500+ candidates for visible roles.
The 70% of unpublished jobs represent the real opportunity since they bypass the massive competition found on LinkedIn postings, requiring direct navigation to company career pages to discover these hidden positions.
Recruiters rotate job postings strategically, displaying positions for only 10 days before swapping them out to maximize their expensive LinkedIn slots, making timing crucial for job seekers.
Cybersecurity professionals cite salary progression as the primary driver for management transitions, with many noting technical roles hit compensation caps faster than leadership paths, though some warn against pursuing management solely for financial reasons without genuine interest in people development.
Leadership motivations center around influencing organizational change, mentoring team members, and having strategic impact beyond individual contributor work, with several managers finding satisfaction in developing talent and watching team members advance their careers.
Mixed experiences reveal management challenges including increased responsibility for team performance, dealing with personnel issues, administrative overhead, and potential loss of hands-on technical work, leading some professionals to return to individual contributor roles despite pay cuts.
Researchers from multiple organizations including Meta, AWS, and Google introduced the A2AS framework, a runtime security layer for AI agents similar to how HTTPS protects HTTP. The framework implements the BASIC security model with five core controls: behavior certificates for action permissions, authenticated prompts for integrity verification, security boundaries for input isolation, in-context defenses for secure reasoning, and codified policies for custom rules.
The framework addresses critical vulnerabilities in agentic AI systems, particularly prompt injection attacks that exploit LLM context windows where trusted instructions and untrusted external inputs coexist without clear boundaries. Current defenses including heuristic methods, detection systems, and semantic approaches have proven ineffective or introduce significant latency and operational complexity, leaving enterprise AI deployments vulnerable.
A2AS operates natively within the context window without external dependencies, avoiding architectural changes or model retraining while providing defense-in-depth protection. The modular design supports extensions including context auditing, runtime telemetry, and capability labeling, positioning it as a potential industry standard for AI agent security across user-to-agent, agent-to-tool, and agent-to-agent attack scenarios.
Petri automates AI safety evaluations by deploying agents that conduct multi-turn conversations with target models, testing behaviors like deception, power-seeking, and self-preservation through simulated environments and scoring results across safety-relevant dimensions.
Testing across 14 frontier models using 111 seed instructions revealed Claude Sonnet 4.5 as the lowest-risk model, while the tool identified concerning whistleblowing behaviors where models autonomously disclosed organizational information when given broad autonomy and access.
The open-source framework supports major model APIs and enables rapid hypothesis testing for researchers, with early adopters including the UK AI Security Institute already using it to build safety evaluations for advanced AI systems.
Researchers demonstrated that backdoor attacks against large language models require a fixed number of malicious documents regardless of model size, with as few as 250 poisoned documents successfully compromising models ranging from 600M to 13B parameters despite 20x differences in training data volume.
The study challenges existing assumptions by showing attack success depends on absolute document count rather than percentage of training data, meaning attackers need only create a small, fixed amount of poisoned content rather than controlling proportional shares of massive datasets.
The denial-of-service attack tested uses trigger phrases like <SUDO> to make models produce gibberish output, and while this specific attack poses limited real-world risk, the findings suggest data poisoning attacks may be more practical than previously believed across frontier models.
Boston-based cybersecurity startup secured Series A funding led by Jump Capital, bringing total funding to $20 million since emerging from stealth in September 2024.
The company's Security Data Pipeline Platform uses AI to integrate and manage security information from various sources, providing SOC teams with filtered, essential data only.
The platform eliminates manual rule writing and constant reconfigurations while speeding up investigations and reducing operational costs for enterprise security teams.
Pan-European cybersecurity firm Nomios acquired Intragen, an Identity and Access Management specialist with 250 experts securing millions of identities across Europe, backed by Keensight Capital funding.
The acquisition adds privileged access management capabilities through partnerships with CyberArk, SailPoint, One Identity and Okta, with Intragen holding multiple partner awards including Global Partner of the Year from One Identity in 2023.
Combined entity targets €650 million revenue and €75 million EBITDA by 2026, with 60% of group EBITDA now generated outside France and over 55% coming from managed services including SOC, NOC, and VOC operations.
Paris-based cybersecurity startup secured Series C funding led by Eurazeo's Growth team, with participation from Deutsche Telekom and existing investors Accel and Insight Partners, bringing total funding to over $100 million since founding in 2022.
The company's eXtended Threat Management (XTM) suite combines OpenCTI and OpenBAS solutions to provide threat intelligence structuring and adversary emulation capabilities, serving over 6,000 public and private organizations globally through open source projects.
Funding will support geographic expansion into Japan and Saudi Arabia markets, accelerate AI integration with the XTM One agent platform, and develop OpenGRC module for cyber risk prioritization while strengthening US and European presence.
Provides breach and attack simulation products for security control validation, offering three different products to meet the needs of organizations of various sizes and maturity levels.
A web isolation platform that enables secure, anonymous digital investigations across the surface, deep, and dark web while protecting users from malware and preventing identity exposure.
ZTrust is an identity and access management platform offering SSO, MFA, and password management with support for multiple deployment models and compliance standards.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.