Brief #128: Windows WSUS RCE Exploited, Claude AI Data Leak, CISO Budget Gaps
100,000 WSUS exploitation attempts in 7 days demand immediate patching. CISOs running 25+ security tools face 50% higher incident rates. Entry-level cybersecurity roles see 5,000 applications per position as market contracts.
YouTube's become a malware playground with over 3,000 malicious videos targeting gamers and software crackers - Check Point found this network has been operating since 2021 and attacks tripled this year
AI-generated code is creating serious security headaches with 70% of organizations finding vulnerabilities in AI-written code, which now makes up nearly a quarter of all production code
The cybersecurity job market is brutal right now - even experienced professionals from major tech companies are struggling to land new roles, with some positions getting 5,000 applications in 72 hours
RoboShadow is a cybersecurity platform that delivers daily vulnerability scans and automated fixes, helping businesses stay secure and compliant. With powerful integrations and continuous monitoring, it makes managing cyber risks simple and proactive.
Check Point Research discovered a sophisticated YouTube malware distribution network operating since 2021, using over 3,000 malicious videos to distribute infostealers like Rhadamanthys and Lumma. The network employs compromised accounts with specialized roles – video uploaders, community post managers, and engagement manipulators – to create false legitimacy through positive comments and likes.
The network primarily targets users seeking game hacks (especially Roblox with 380 million monthly users) and software cracks (particularly Adobe products like Photoshop). The most viewed malicious video garnered 293,000 views promoting cracked Adobe Photoshop, while actors frequently update payloads every 3-4 days and rotate C2 servers to evade detection.
Malicious videos tripled in 2025 compared to previous years, with threat actors shifting from Lumma to Rhadamanthys infostealer following Lumma's disruption by law enforcement. Videos redirect users to phishing pages on Google Sites or file-sharing platforms, distributing password-protected archives that commonly instruct victims to disable Windows Defender before execution.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
Socket's Threat Research Team discovered 10 malicious npm packages using typosquatting to mimic popular libraries like TypeScript, discord.js, and ethers.js. The packages automatically execute via postinstall hooks, spawn new terminal windows to avoid detection, and use four layers of obfuscation including XOR encryption and control flow obfuscation to hide their payload.
The malware displays a fake CAPTCHA prompt for social engineering, performs IP fingerprinting against the C2 server at 195.133.79.43, then downloads a 24MB PyInstaller-packaged information stealer called data_extracter. This cross-platform stealer harvests credentials from system keyrings, browsers, SSH keys, and authentication tokens across Windows, Linux, and macOS.
Published by threat actor andrew_r1 on July 4, 2025, the packages remained live for over four months and accumulated 9,900+ downloads. Organizations should audit dependencies immediately, assume compromised systems, reset all stored credentials, revoke authentication tokens, and implement Socket's supply chain protection tools to prevent similar attacks.
Google's Threat Intelligence Group reports UNC6512 threat actor actively exploiting CVE-2025-59287 across multiple victim organizations, with attackers conducting reconnaissance and exfiltrating data from compromised hosts.
The vulnerability affects Windows Server Update Services with an unauthenticated remote code execution flaw stemming from insecure deserialization – Microsoft's initial October patch was incomplete, requiring an emergency fix last Thursday.
Researchers observe approximately 100,000 exploitation attempts in seven days targeting publicly exposed WSUS instances on default TCP ports 8530/8531, with attackers using PowerShell commands to gather network intelligence before data exfiltration.
Survey of 300+ cybersecurity leaders shows 85% of organizations increased security spending since last year, with 88% planning further increases for 2026, despite 56% believing current budgets are insufficient to counter sophisticated threats and cloud complexity being the top inhibitor to program success.
Personnel costs remain the largest budget allocation at 23% of total cybersecurity spending, followed closely by cloud security products at 21%, while 88% of organizations plan to increase their security team's focus on cloud over the next two years as it currently consumes up to half of team resources.
Tool sprawl affects 58% of organizations running 25+ cybersecurity tools, with AI-powered security solutions driving 54% of spending decisions as 99% of respondents believe AI will transform cloud security, though complexity and resource sprawl remain the biggest barriers to effective cloud security programs.
Google Cloud published a detailed defender's guide outlining a three-pillar framework for securing privileged accounts: prevention through proper PAM implementation and credential hardening, detection via behavioral analytics and high-fidelity session monitoring, and response including coordinated enterprise password resets and recovery planning.
The guide emphasizes that privileged access extends beyond traditional domain admins to include developers, service accounts, and API keys, recommending organizations implement tiered access models (T0/T1/T2) with segregation of duties, just-in-time access, and dedicated privileged access workstations to reduce attack surface.
Mandiant research cited in the guide shows stolen credentials now account for 16% of intrusions in 2024, surpassing email phishing as the second-most common initial access method, with attackers increasingly targeting backup infrastructure and virtualization platforms as high-value targets for ransomware deployment.
Ransomware attacks jumped 36% to 3,649 incidents in the first half of 2025, with Cl0p overtaking LockBit as the most active group following law enforcement disruptions, while healthcare remains the most targeted sector with 341 reported breaches affecting nearly 30 million individuals.
Zero-day exploitations increased 46% to 63 vulnerabilities, with network infrastructure devices comprising 21% of newly exploited CVEs, highlighting persistent gaps in perimeter security as 47% of exploited vulnerabilities were published before 2025.
Iranian hacktivist groups are shifting identities and tactics to target OT/ICS systems, with APT IRAN representing an evolution from previous personas like CyberAv3ngers, as threat actors increasingly use opportunistic scanning against industrial control systems receiving over 16,000 daily requests on PLC honeypots.
A 28-year-old Indian cybersecurity professional with a Masters degree, multiple certifications (CCNA, MCSA, CEH, eJPT, BTL1), and 3 years of sysadmin experience is leaving the field after failing to secure a dedicated security role despite extensive preparation and daily job applications for months.
The individual achieved top rankings on training platforms (top 0.5% on TryHackMe, 19th nationally on Blue Team Labs Online) and followed standard career advice including gaining IT experience first, but still couldn't break into dedicated cybersecurity roles, leading to complete career burnout and abandonment of security aspirations.
Community responses reveal widespread similar experiences with toxic leadership, frequent layoffs, discrimination, and a challenging job market where entry-level positions are scarce while companies demand senior-level expertise, suggesting systemic issues within the cybersecurity hiring landscape.
Market conditions vary significantly by region, with Sweden reporting strong demand and active recruiter outreach, while the US and Italy face oversaturation and limited opportunities for quality positions.
Industry professionals report widespread hiring of unqualified junior candidates who lack fundamental skills, leading to salary depression and reduced overall security effectiveness across organizations.
Companies increasingly prioritize cost savings over security expertise, with some organizations turning to AI automation for SOC functions and offshore resources, while others downsize security teams despite growing cyber threats.
The cybersecurity job market is experiencing severe challenges with practitioners reporting difficulty finding positions, particularly for entry-level candidates. Experienced professionals from major tech companies are struggling to find new roles after layoffs, with one LinkedIn post showing 5,000 applications for a single position within 72 hours.
Entry-level positions have become extremely scarce, with industry veterans recommending alternative career paths like nursing, trades, or healthcare. Many suggest starting in IT support or help desk roles first, then transitioning to cybersecurity after gaining experience and obtaining certifications like Security+ and Network+.
The market shows regional variations, with some areas like Australia reportedly having better opportunities due to government investment ($600 million allocated for 50,000 new cybersecurity jobs), though practitioners debate whether these initiatives will materialize into actual hiring opportunities for newcomers to the field.
Researchers discovered that Claude's Code Interpreter can be exploited through indirect prompt injection to exfiltrate user data by uploading files to an attacker's Anthropic account using the victim's sandbox environment and the attacker's API key.
The vulnerability leverages the default "Package managers only" network setting, which allows access to api.anthropic.com, enabling attackers to upload up to 30MB of stolen data including chat histories and sensitive information through the Files API.
Anthropic dismissed the report as a model safety issue rather than a security vulnerability, though the attack demonstrates clear data exfiltration capabilities that could compromise user confidentiality in enterprise environments.
Aardvark is an autonomous AI agent that continuously monitors source code repositories to identify vulnerabilities, assess exploitability, and propose targeted patches using GPT-5's reasoning capabilities rather than traditional program analysis techniques like fuzzing.
The tool operates through a multi-stage pipeline including threat modeling, commit scanning, validation in sandboxed environments, and integration with OpenAI Codex for automated patching, achieving 92% detection rate in benchmark testing on known vulnerabilities.
Currently in private beta, Aardvark has already discovered vulnerabilities across OpenAI's internal codebases and partner organizations, with ten findings in open-source projects receiving CVE identifiers through responsible disclosure practices.
Nearly 70% of organizations have discovered vulnerabilities introduced by AI-generated code, with 1 in 5 suffering serious incidents directly tied to it. AI tools now write 24% of production code (29% in US, 21% in Europe), creating new security challenges as 92% of teams express concern about AI-generated code risks.
Security tool sprawl significantly increases incident rates, with teams using 5+ vendor tools experiencing 50% more security incidents than those using fewer tools. Organizations waste an average of 6.1 hours weekly triaging alerts, costing approximately $20,000 per developer annually in lost productivity, with 72% of that time spent on false positives.
Teams using separate AppSec and CloudSec tools report 50% higher incident rates (31% vs 20%) compared to integrated platforms. One in four CISOs admit that losing a single top security engineer could directly cause a serious breach, highlighting the critical shortage of skilled security professionals in an increasingly complex threat landscape.
Funding dropped 33% sequentially to $3.3 billion in Q3 2025, but remained 33% above year-ago levels, with largest rounds including Quantinuum's $600 million Series B and Ontic's $230 million Series C.
IPO activity showed strength with Netskope raising over $900 million in its September debut, while M&A saw Mitsubishi Electric acquiring Nozomi Networks for approximately $1 billion.
Sequential decline appears temporary rather than indicative of broader market weakness, with public cybersecurity indexes performing well and Google's pending $32 billion Wiz acquisition still under regulatory review.
Conceal secured $26 million in Series B funding led by Two Bear Capital to advance its Browser-Native Security Service Edge platform, which provides proxy-less Zero Trust Network Access directly within standard browsers without requiring VPNs or virtual desktops.
The company's platform eliminates traditional network infrastructure by using intelligent browser extensions and cloud-based management consoles to apply policy-driven access controls, aiming to reduce costs and administrative complexity for hybrid environments.
Led by CEO Eric Cornelius, a former BlackBerry Cylance executive, Conceal integrates with SIEM platforms like Splunk and SOAR to stream telemetry data into existing monitoring workflows, positioning itself in the growing Zero Trust security market.
UK cybersecurity startup raised funding from Fuel Ventures, D11Z Ventures, and others to advance its persistent per-file encryption solution that maintains protection as data moves across systems and locations.
The platform enables granular access controls and compliance checking on individual documents, helping enterprises meet new regulatory standards including Defence Cyber Certification (DCC) and Cybersecurity Maturity Model Certification (CMMC).
Investment will complete platform version 1 and expand customer base as the company prepares for commercial launch, targeting enterprises seeking to reduce data breach risks through document-level security controls.
A cloud-native web application and API security solution that uses contextual AI to protect against known and zero-day threats without signature-based detection.
Sangfor Technologies is a leading cybersecurity, cloud, and infrastructure vendor providing effective cybersecurity and efficient enterprise cloud solutions.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.