F5 confirms a nation-state breach that exposed BIG-IP source code and undisclosed vulnerabilities, reminding us that even security vendors aren't immune to persistent attacks
AI security incidents more than doubled in 2025 with prompt injection attacks now accounting for 35% of all documented incidents and causing six-figure financial losses
90% of security leaders say managing cyber risk is harder now than five years ago, yet only 19% rate their programs as mature - highlighting the growing complexity we're all facing
RoboShadow is a cybersecurity platform that delivers daily vulnerability scans and automated fixes, helping businesses stay secure and compliant. With powerful integrations and continuous monitoring, it makes managing cyber risks simple and proactive.
F5 disclosed that a nation-state threat actor gained persistent access to their network and stole BIG-IP source code along with information about undisclosed vulnerabilities, with the breach discovered on August 9, 2025.
The attackers accessed F5's product development environment and knowledge management platform, exfiltrating configuration and implementation information affecting a small percentage of customers who will be directly notified.
F5 has engaged Google Mandiant and CrowdStrike for incident response, implemented enhanced security controls, and advises users to apply the latest updates for BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM clients immediately.
Google Threat Intelligence observed UNC5342 using EtherHiding to deliver JADESNOW malware through fake job interviews – marking the first time a nation-state actor has adopted this blockchain-based technique that stores malicious payloads in smart contracts on BNB Smart Chain and Ethereum, making takedowns nearly impossible.
The social engineering campaign targets cryptocurrency developers with fraudulent job interviews, deploying a multi-stage infection chain where JADESNOW downloads INVISIBLEFERRET backdoor from blockchain transactions, ultimately leading to cryptocurrency wallet theft and credential harvesting from browsers and password managers.
While the blockchain storage provides resilience against traditional blocking methods, the attack still relies on centralized API services to interface with blockchains – creating potential mitigation opportunities through Chrome Enterprise policies that block dangerous downloads and enforce managed browser updates.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
Threat actors leveraged CVE-2025-20352, a Cisco SNMP vulnerability in both 32-bit and 64-bit switch builds, to achieve remote code execution and deploy Linux rootkits on unprotected devices, primarily targeting Cisco 9400, 9300, and legacy 3750G series switches.
The rootkit establishes persistent access through a universal password containing "disco" and installs hooks into IOSd memory space, enabling attackers to disable logging, bypass authentication, hide configuration changes, and control network traffic through UDP listeners on any port.
Attackers used sophisticated lateral movement techniques including ARP spoofing to impersonate waystation IP addresses, bypass internal firewalls, and move between network zones while evading detection through log manipulation and configuration hiding capabilities.
PwC's 2026 Global Digital Trust Insights survey of 3,887 executives across 72 countries reveals that 60% are making cyber risk investment a top strategic priority in response to geopolitical uncertainty, while only 6% feel confident they can withstand attacks across all vulnerabilities surveyed.
Organizations struggle with proactive security spending, with 67% maintaining roughly equal spending on proactive and reactive measures, while only 24% achieve the optimal approach of investing significantly more in proactive measures like monitoring and controls rather than incident response.
AI capabilities dominate cybersecurity priorities, with threat hunting ranking as the top AI security capability organizations plan to implement, though knowledge and skills gaps remain the primary barriers to AI implementation for cyber defense, driving 53% to prioritize AI tools to address talent shortages.
Phil Venables and Mike Aiello present a comprehensive framework distinguishing effective security leadership from ineffective approaches. Good CISOs function as business executives who manage technology risk and take full responsibility for organizational resilience, while bad CISOs operate as IT managers focused solely on security tools with excuses for failures.
The analysis emphasizes that successful CISOs build self-reinforcing systems and flywheels that scale security capabilities, communicate in business language about risk and opportunity, and create psychological safety for bad news to travel fast. They focus on enabling teams rather than becoming bottlenecks in security operations.
Key differentiators include strategic vendor management that influences secure product development, deep technical foundations used for empathy rather than control, and long-term relationship building with peers and stakeholders. Good CISOs develop future leaders and create federated security models that can operate independently of their direct involvement.
A survey of 1,000 cybersecurity leaders from companies with 500+ employees reveals that 90% find managing cyber risks more difficult today than five years ago, with AI explosion and widening attack surface being the primary reasons for increased complexity.
Only 19% of organizations rate their cyber risk management practices as very mature, and just 29% have formal programs well-aligned with business objectives, despite 85% deploying attack surface management or continuous threat exposure monitoring solutions.
While continuous monitoring jumped to the top cybersecurity investment priority, only 17% of organizations can regularly map threats across their environments with contextualized risk factors, and just one-third monitor third-party relationships for risk exposure despite 99% assessing vendor cyber risk.
CISOs need extensive security experience to understand why they may not want the CISO role due to challenges like lack of resources, obstruction from other executives, and blame for incidents.
Moving into a CISO role is more about growing into the "C" (executive skills like balancing risk and business velocity) than the "S" (security expertise).
Key advice includes gaining exposure to broader security domains beyond just IAM/PAM, learning how business works, reporting to the board, and developing strong interpersonal skills to navigate organizational politics.
OP, a security engineer, expresses feelings of burnout due to various challenges, including lack of understanding from senior management, other IT teams, and GRC teams, as well as a flooded and burnt-out team.
Commenters suggest prioritizing mental health, seeking professional help, and finding ways to disconnect from work, such as taking restful vacations and engaging in non-computer hobbies like gardening.
Advice includes focusing on what can be changed, starting small with improvements like aggregating alerts, and finding companies with upper management that values and supports cybersecurity.
A Reddit discussion in r/sysadmin highlights concerns that recent graduates entering DevOps and cybersecurity roles without prior IT operations experience lack fundamental knowledge needed to effectively secure systems or bridge development and operations teams, with many commenters noting these professionals often cannot implement fixes beyond reading automated scan reports.
Multiple IT professionals report that cybersecurity teams staffed with inexperienced analysts create problems by running vulnerability scanners and generating tickets without understanding system architecture, business impact, or how to properly harden systems while maintaining operations, leading some to suggest these roles could be replaced by automated Nessus reports sent directly to operations teams.
The consensus among experienced practitioners is that 5-10 years of sysadmin or operations experience should be prerequisite for advanced roles, as understanding how enterprise IT functions in practice including shadow IT, patch management delays, and cross-team coordination cannot be learned from certifications or academic programs alone.
Prompt injection attacks now account for 35.3% of all documented AI security incidents, with simple text-based exploits causing over $100,000 in financial losses through manipulated chatbots and autonomous agents across multiple organizations.
Major companies including Microsoft, Google, Amazon, and Meta experienced significant breaches ranging from data leaks to market value drops, with Google's Bard demo mistake alone causing a $100 billion drop in Alphabet's stock price.
Generative AI systems represent 70.6% of security incidents while Agentic AI accounts for 23.5%, with technology companies facing 35.3% of all documented incidents but no sector remaining immune to AI-related security failures.
Menlo analyzed over 5.6 million GenAI site visits in 30 days, revealing 50% traffic growth to AI tools from February 2024 to January 2025, with ChatGPT dominating usage while most users rely on free tiers that share data with foundational models for training purposes.
Security teams observed 155,005 copy attempts and 313,120 paste attempts to AI sites, with 70% of DLP violations involving sensitive content, 25% restricted data, and 5% personally identifiable information, highlighting significant data leakage risks from shadow AI usage.
Researchers identified nearly 600 phishing sites impersonating legitimate AI tools, alongside compromised browser extensions like "ChatGPT for Google Meet" and "Bard AI Chat" that harvest credentials and inject malicious code, demonstrating how attackers exploit AI hype for credential theft.
Over half (52%) of US employees admit they're willing to use AI tools to make their jobs easier even when it violates company policy, with 28% having already used AI to access sensitive data or documents, creating significant insider threat risks that traditional security measures aren't equipped to handle.
C-level executives show the highest levels of AI ignorance with 38% having no idea what an AI agent is, yet simultaneously demonstrate the most enthusiasm for AI adoption with 67% willing to break policy for convenience, creating a dangerous disconnect between AI governance and leadership understanding.
Despite widespread AI misuse, 84% of employees remain confident their company's CEO or IT team would detect an AI-led breach, revealing a false sense of security that masks the reality that employees are already exposing proprietary information and bypassing security protocols through AI tools.
LevelBlue, the managed security service provider spun out of AT&T, is acquiring Cybereason to expand its XDR, MDR, and forensic capabilities. The deal brings Cybereason's Defense Platform, which uses AI-based MalOp engine for rapid detection and automated remediation, into LevelBlue's portfolio.
This acquisition follows LevelBlue's recent purchases of Trustwave and Aon's risk assessment offerings. Cybereason's Digital Forensics and Incident Response (DFIR) technology will enhance the Stroz Friedberg risk assessment capabilities acquired through Aon, while its research team will merge with Trustwave SpiderLabs.
The deal reunites Cybereason and Trustwave under one company after their previous merger talks collapsed in early 2025 due to disputes among Cybereason board members. Financial terms were not disclosed, and integration plans for Cybereason's XDR platform with Trustwave's Fusion platform remain unclear.
Sheffield-based startup Sitehop secured £7.5m in funding led by Northern Gritstone to scale its hardware-based encryption technology, bringing total funding to £13.5m. The timing aligns with NCSC guidance that post-quantum migration projects should be underway by 2028 and ICO warnings for firms to prepare quantum-proof encryption before 2035.
Sitehop's SAFEseries system performs encryption at the physical layer of the network rather than through software protocols, enabling wire-speed encryption without typical processing overhead. The company claims this approach delivers quantum-resistant security while reducing latency and energy consumption by up to 90% compared to traditional software-based systems.
The startup has completed a proof-of-concept trial at BT's Gemini test facility, reportedly becoming the first external company granted access to the facility. Sitehop is positioning itself as a UK sovereign encryption capability with plans for domestic scaling and international expansion.
Pentera acquired Israeli startup DevOcean for a reported $30 million to address the gap between identifying vulnerabilities through attack simulations and actually remediating them. DevOcean, founded in 2021 by former CyberArk head of security research Doron Naim, employs 15 people and had raised $6 million in funding with sub-$1 million in revenue.
DevOcean's platform integrates with over 100 security tools via APIs and uses AI to automatically triage, prioritize, and route remediation tasks to responsible parties. The system replaces manual processes like emailing findings or creating tickets in Jira with structured ticketing, SLA enforcement, ownership assignment, and escalation workflows.
Customers can immediately use Pentera with DevOcean through API-based integration as of the announcement, with findings from Pentera attack simulations flowing directly into DevOcean's remediation platform. A unified experience is planned for early 2026 to provide seamless workflow from validation to remediation.
A comprehensive threat intelligence platform that monitors cybercrime underground activities and provides actionable intelligence to help organizations detect and prevent cyber threats.
Absolute Security provides a comprehensive cybersecurity platform that offers endpoint-to-network access coverage, automated security compliance, and secure endpoint and access solutions.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.