AWS suffered a major outage when a DNS race condition in DynamoDB brought down multiple services across US-EAST-1, showing how cascading failures can impact entire cloud regions
GlassWorm malware is targeting VS Code extensions using invisible Unicode characters and an unkillable blockchain-based command structure that's nearly impossible to take down
Microsoft deployed 14 Deputy CISOs to handle security across their massive organization, offering insights into how large enterprises are restructuring security leadership
RoboShadow is a cybersecurity platform that delivers daily vulnerability scans and automated fixes, helping businesses stay secure and compliant. With powerful integrations and continuous monitoring, it makes managing cyber risks simple and proactive.
A race condition in DynamoDB's automated DNS management system caused the regional endpoint to resolve to an empty record, preventing new connections to the service from 11:48 PM on October 19 to 2:40 AM on October 20, 2025. The bug occurred when two DNS Enactors processed plans simultaneously, with one applying an outdated plan that was then deleted by cleanup processes, leaving the system in an inconsistent state requiring manual intervention.
The DynamoDB outage cascaded to cause EC2 instance launch failures lasting until 1:50 PM on October 20 due to the DropletWorkflow Manager's dependency on DynamoDB for maintaining server leases. When leases timed out, the system entered congestive collapse and couldn't establish new droplet leases, requiring engineers to throttle incoming work and selectively restart DWFM hosts to recover capacity.
Multiple AWS services including Lambda, ECS, EKS, Fargate, Connect, STS, IAM authentication, Redshift, and Support Console experienced significant disruptions, with some services like Connect experiencing busy tones and failed connections, while Redshift clusters remained in "modifying" states that prevented query processing even after DynamoDB recovery.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
Researchers discovered the first self-propagating worm targeting VS Code extensions on OpenVSX marketplace, affecting 10,711 installations across seven compromised extensions. The malware uses invisible Unicode characters to hide malicious code that becomes completely transparent in code editors and bypasses traditional code review processes.
GlassWorm employs an unkillable command and control infrastructure using the Solana blockchain as its primary C2 server, with Google Calendar as backup. This immutable, decentralized approach makes takedowns impossible while enabling dynamic payload updates for less than a penny per transaction.
The final payload transforms infected developer workstations into criminal infrastructure through SOCKS proxy servers, hidden VNC access, and peer-to-peer communication channels. The worm harvests credentials from 49 cryptocurrency wallet extensions, NPM tokens, and GitHub credentials to automatically spread to additional packages and extensions.
Researchers found that a single weaponized URL can hijack Perplexity's Comet AI browser to steal sensitive data from connected services like Gmail and Calendar without requiring credential phishing, simply by tricking users into clicking a malicious link.
The attack exploits URL parameters to force the AI to prioritize user memory over web searches, then instructs it to encode stolen data in base64 format and POST it to attacker-controlled servers, effectively bypassing Perplexity's built-in exfiltration protections.
Despite LayerX's responsible disclosure in August 2025, Perplexity marked the findings as "Not Applicable," highlighting the emerging security risks of agentic browsers where AI assistants have trusted access to personal and corporate data sources.
Microsoft deployed 14 Deputy CISOs in 2024 under its Secure Future Initiative, each reporting to corporate CISO Igor Tsyganskiy and handling specialized security domains across products like Azure, Windows, and Linux. The structure includes product-aligned dCISOs who also report to their respective business leaders, creating dual accountability for both security posture and business outcomes.
The dCISO model addresses the impossibility of a single CISO managing security across Microsoft's scale and complexity, with each deputy effectively functioning as a full CISO for their domain. Ann Johnson leads the Customer Security Management Office handling external engagement, while Mark Russinovich covers Azure, core operating systems, and engineering systems as CTO and dCISO.
Both leaders identify nation state actors and artificial intelligence as primary emerging threats, with AI enabling automated probing and attacks at unprecedented scale. They emphasize that while attack methods evolve, core threat motivations remain consistent: financial gain through ransomware and BEC, plus espionage and intelligence gathering by nation states.
Hacktivists adapted to platform disruptions by migrating from Telegram to X (formerly Twitter), with pro-Russian groups showing increased decentralization and DDoS attacks remaining the primary tactic across 3,662 tracked victims in H1 2025.
Ransomware groups evolved multi-extortion strategies, with Scattered Spider affiliates targeting major retailers like Marks & Spencer and Co-op, while Qilin's attack on Lee Enterprises exposed personal data of 40,000 individuals and cost over $2 million in recovery.
Infostealers infected 2.67 million machines and compromised 204 million credentials, with Lumma, Redline, and Racoon2 accounting for 85% of infections and serving as entry points for advanced persistent threats targeting high-value organizations.
Cloud intrusions increased by 136% in the first half of 2025 compared to all of 2024, with China-nexus adversaries showing a 40% year-over-year increase in cloud-focused attacks. Interactive intrusions grew 27% overall, with 81% being malware-free operations.
Vishing attacks have already surpassed 2024 totals in just the first half of 2025, following a 442% increase from first to second half of 2024. SCATTERED SPIDER accelerated operations, moving from account takeover to ransomware deployment in just 24 hours.
FAMOUS CHOLLIMA IT workers infiltrated over 320 companies in 12 months using GenAI for résumé creation, deepfake video interviews, and code assistance – representing a 220% year-over-year increase in their insider threat operations.
Reddit discussion reveals that transitioning from IAM management to CISO requires broader business skills rather than deep technical expertise, with experienced professionals emphasizing that C-suite security roles focus more on stakeholder management, risk communication, and politics than hands-on security work.
Multiple current and former CISOs warn that the role often involves taking blame for security incidents while struggling for resources and executive support, leading some to transition to consulting roles that offer better compensation ($250-300/hour) and reduced organizational stress.
Career progression advice centers on gaining exposure to GRC domains, developing executive presence, and understanding that CISO success depends more on business acumen and interpersonal skills than technical certifications, with networking and timing playing crucial roles in reaching executive positions.
Community discussion reveals cybersecurity professionals are seeking additional income streams beyond traditional employment, with bug bounty programs, consulting work, and virtual CISO services being popular options despite varying success rates and time investment requirements.
Multiple professionals report success with consulting side hustles, particularly offering virtual CISO services to small and medium businesses, requiring LinkedIn optimization, industry specialization, and partnerships with MSPs or vendors for lead generation.
Discussion highlights broader industry concerns about job market saturation and layoffs affecting cybersecurity professionals, with some noting the influx of government workers into private sector creating increased competition for available positions.
A major local university CISO position posting at $161K has generated significant discussion about whether this compensation is adequate for the role's responsibilities and potential liability exposure.
Higher education consistently pays below market rates compared to private sector cybersecurity roles, with professionals reporting salary gaps of $30K or more, though institutions often compensate with better work-life balance, comprehensive benefits, and tuition assistance programs.
Many cybersecurity professionals view university CISO roles as valuable stepping stones for career advancement, providing essential executive experience and title recognition that can lead to higher-paying positions in the private sector.
Soft guardrails operate within the agent's loop to intercept and moderate thoughts, prompts, and responses but remain vulnerable to jailbreak techniques and probabilistic reasoning failures. OpenAI's AgentKit demonstrates these limitations as guardrails can be bypassed through clever encoding or multi-turn manipulation.
Traffic screening provides runtime inspection of data in motion between agents and their environment, catching threats that escape agent-level control through proxy monitoring and API gateway integration. This layer focuses on actual data transmission patterns rather than model intent, enabling detection of encoded payloads and data exfiltration attempts.
Hard boundaries enforce immutable restrictions at the infrastructure level through sandboxed execution, IAM controls, and tool validation that cannot be bypassed by any prompt or reasoning trick. These deterministic controls act as the system's physics, making unsafe actions physically impossible to perform regardless of model behavior.
Noma Security released the Agentic Risk Map platform to address the growing security challenge of autonomous AI agents operating across enterprise environments, providing comprehensive discovery, posture management, and runtime monitoring for agents deployed in SaaS platforms, cloud infrastructure, and endpoint applications.
The platform maps complex agent-to-agent connections and tool relationships to identify dangerous risk combinations like agents with code execution capabilities connected to public channels or agents authorized to send external emails without human approval, creating potential vectors for remote code execution and data exfiltration.
Runtime monitoring overlays real-time activity visualization to detect security events including indirect prompt injections, tool abuse, risky actions, data leakage, and privilege escalation, enabling immediate response through automated agent isolation or permission revocation.
Researchers found that 43% of tested MCP server implementations contain command injection flaws, with 30% allowing unrestricted URL fetching, creating significant attack surfaces for autonomous AI agents.
Tool poisoning attacks embed malicious instructions in tool metadata or descriptions, enabling prompt injection that can bypass LLM guardrails and lead to data exfiltration without user awareness.
Cross-tool orchestration attacks leverage multiple MCP tools simultaneously, including name collision exploits and coordinated data theft using legitimate tools like grep_search to extract sensitive information such as API keys.
LevelBlue, the managed security service provider spun out of AT&T, will acquire Cybereason to expand its global managed services portfolio, adding the company's Defense Platform with AI-based MalOp engine that provides rapid detection, response, and automated remediation capabilities.
The acquisition enhances LevelBlue's offensive and defensive capabilities by integrating Cybereason's XDR platform and Digital Forensics and Incident Response (DFIR) services with existing offerings from recent acquisitions of Trustwave and Aon's Stroz Friedberg risk assessment unit.
This deal reunites Cybereason and Trustwave under one company after their previous merger talks fell apart due to board disputes, with LevelBlue planning to combine research teams from Cybereason and Trustwave SpiderLabs for enhanced threat intelligence capabilities.
Dataminr announced plans to acquire threat intelligence firm ThreatConnect for $290 million in cash and equity, combining Dataminr's AI-powered public data signals platform with ThreatConnect's internal data analysis capabilities.
ThreatConnect serves 250 enterprises and government organizations including Nike, Wells Fargo, and agencies across the US, UK, and Australia, providing platforms for security teams to aggregate and analyze cyber threat intelligence.
The acquisition aims to create AI-powered Client-Tailored intelligence that fuses external public data with internal client data to provide real-time, actionable insights tailored to each customer's specific risk profile and needs.
Veeam Software agreed to buy data privacy management company Securiti AI for $1.73 billion to integrate Securiti's Data Command Center product with Veeam's backup and recovery software, targeting customers using AI applications across multiple cloud services.
The acquisition aims to help Veeam better compete with rivals like Rubrik and Commvault Systems as cybersecurity incidents and ransomware attacks continue to surge, particularly by combining data security with immutable backup capabilities.
Securiti AI CEO Rehan Jalil will join Veeam as president of security and AI after the transaction closes in Q4, with Morgan Stanley advising Securiti and JPMorgan providing financing to Veeam for the deal.
A security platform that automates the deployment and management of security canaries across cloud infrastructure to detect potential intrusions and unauthorized access.
An API security platform that provides automated security testing, runtime protection, and lifecycle management for APIs through integrated tools and controls.
A comprehensive application security service provider offering manual penetration testing, vulnerability assessment, and security solutions across various industries.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.