Happy Sunday!
In this week's brief:
- Chinese state actors just pulled off the first largely autonomous AI-driven cyber espionage campaign, letting Claude Code handle 80-90% of their attack operations from start to finish
- 77% of organizations dealt with insider-driven data loss in the past 18 months, yet most still can't see how their own users are handling sensitive data
- Amazon's honeypot service caught an APT exploiting Cisco and Citrix zero-days before they were publicly known, using sophisticated custom web shells with advanced evasion techniques
A quick note before we dive in.

Industry News
Amazon Discovers APT Exploiting Cisco and Citrix Zero-Days
-
Amazon's MadPot honeypot service detected an APT exploiting CVE-2025-5777 (Citrix Bleed Two) and CVE-2025-20337 (Cisco ISE) as zero-days before public disclosure, indicating sophisticated vulnerability research capabilities.
-
The threat actor deployed a custom web shell disguised as "IdentityAuditAction" that operated in-memory with advanced evasion techniques including Java reflection, DES encryption, and non-standard Base64 encoding to avoid detection.
-
The campaign targeted critical identity management and network access control infrastructure, demonstrating pre-authentication remote code execution capabilities that provided administrator-level access to compromised Cisco ISE deployments.
DPRK Actors Use JSON Storage Services in Contagious Interview Campaign
-
North Korean threat actors behind the Contagious Interview campaign have evolved their tactics to use legitimate JSON storage services like JSON Keeper, JSONsilo, and npoint.io to host and deliver malware disguised as interview demo projects targeting software developers.
-
The campaign uses social engineering through fake recruiter profiles on LinkedIn to distribute trojanized Node.js projects containing base64-encoded URLs that fetch obfuscated JavaScript code leading to BeaverTail and InvisibleFerret malware deployment.
-
The malware chain includes a new component called Tsunami that establishes persistence, downloads Python if needed, and retrieves additional payloads from Pastebin with over 400 views indicating significant campaign success across multiple platforms including Windows, Linux, and macOS.
Operation Endgame Takes Down 1025 Malware Servers in International Cybercrime Crackdown
-
Law enforcement from 11 countries coordinated by Europol dismantled three major cybercrime enablers including the Rhadamanthys infostealer, VenomRAT remote access trojan, and Elysium botnet between November 10-13, 2024.
-
The operation resulted in one arrest in Greece, 11 location searches across three countries, and the seizure of 20 domains along with over 1,025 servers that had infected hundreds of thousands of victims worldwide.
-
The dismantled infrastructure contained several million stolen credentials and over 100,000 crypto wallets potentially worth millions of euros, with victims now able to check their exposure through dedicated websites established by authorities.

Leadership Insights
Organizations Face Widespread Insider-Driven Data Loss Despite Growing Budgets and Tools
-
77% of organizations experienced insider-driven data loss in the past 18 months, with 41% reporting financial impact between $1M-$10M, yet 72% lack visibility into how users interact with sensitive data across endpoints and cloud applications.
-
While 72% of organizations report increasing budgets for insider risk programs, 51% remain stuck at maturity Level 2 with fragmented tools, and only 14% feel fully confident in their insider threat detection capabilities.
-
Traditional DLP tools are proving inadequate, with only 47% of security professionals agreeing their existing solutions effectively protect sensitive data, while 56% express concern about GenAI tools like ChatGPT but only 12% feel prepared to respond.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
BreachLock Reveals Critical Vulnerabilities from 4,200+ Pentests Across Industries
-
BreachLock's 2025 intelligence report analyzed over 4,200 penetration tests across multiple industries, revealing that 45% of findings were critical or high severity, with broken access control accounting for 32% of high-severity vulnerabilities.
-
The most impacted sectors were technology & SaaS providers (27%) and banking & financial services (21%), with cloud misconfigurations present in 52% of tested systems and widespread authentication failures enabling unauthorized access.
-
Red team engagements demonstrated a median time of just 2.5 hours to achieve lateral movement, highlighting persistent gaps in network segmentation and detection capabilities across tested environments.
62% of Companies Ship Insecure Code Due to False Positives and Resource Constraints Cypress Data Defense Study
-
A survey of 250 IT and security leaders reveals that 62% of organizations knowingly ship insecure code to meet deadlines, while 58% report frequent false positives from security scanners that overwhelm teams and dilute attention from real threats.
-
Only 36% of teams involve security during the planning stage of the SDLC, with 57% waiting until late testing or deployment, missing opportunities to reduce risk and improve release velocity through earlier integration.
-
Despite application flaws accounting for 43% of breaches, 89% of organizations allocate only 11–20% of their security budget to AppSec, while 36% prioritize network security over application-layer protection.
How do you like Mandos Brief?

Career Development
CTF Participation Proves Valuable for Cybersecurity Job Seekers According to Industry Professionals
-
Cybersecurity professionals report that CTF experience was a deciding factor in hiring decisions, with one manager specifically stating an intern was hired because of their participation in local CTFs and national team membership.
-
Red team roles particularly benefit from CTF experience as it serves as a differentiator when choosing between multiple qualified candidates, though the impact is considered less significant for blue team positions.
-
Industry veterans emphasize that CTFs provide essential networking opportunities for young professionals and help demonstrate practical knowledge of attack methodologies, even for defensive security roles.
Cybersecurity Professionals Debate Value of Master's Degrees vs Experience
-
Industry professionals overwhelmingly recommend gaining experience and certifications over pursuing a master's degree immediately after undergraduate studies, with most suggesting 10+ years of experience before considering advanced degrees.
-
Help desk roles serve as common entry points into cybersecurity careers, with professionals typically spending 1-2 years in these positions before transitioning to SOC analyst, incident response, or other specialized security roles.
-
Career progression in cybersecurity often requires job hopping every 2-4 years to advance salary and responsibilities, with hands-on skills and certifications providing better ROI than master's degrees for early-career professionals.
Cybersecurity Professionals Discuss Reality vs Hollywood Stereotypes
-
Cybersecurity professionals describe their work as "cybersecurity janitors" who spend most time on repetitive tasks like investigating false positives, writing documentation, and dealing with user security mistakes rather than dramatic threat interception.
-
The reality is "90% boredom, 10% pure terror" with most excitement coming from incident response scenarios that involve long hours of coordination, forensic analysis, and cleanup rather than real-time hacking battles.
-
While some specialized roles like red teaming, penetration testing, and threat hunting offer more engaging technical work, the majority of cybersecurity involves compliance questionnaires, policy writing, and managing spreadsheets to track security controls.

AI & Security
Chinese State-Sponsored Group GTG-1002 Conducts First AI-Orchestrated Cyber Espionage Campaign
-
Anthropic identified and disrupted a sophisticated cyber espionage operation by Chinese state-sponsored group GTG-1002 that targeted roughly 30 entities including major technology corporations and government agencies, achieving successful intrusions in multiple cases.
-
The threat actors manipulated Claude Code to autonomously execute 80-90% of tactical operations across the entire attack lifecycle, from reconnaissance and vulnerability discovery to credential harvesting and data exfiltration, marking the first documented case of largely autonomous AI-driven cyberattacks at scale.
-
The operation used role-play techniques to bypass AI safety measures by convincing Claude it was conducting legitimate penetration testing, though AI hallucinations during autonomous operations created challenges by fabricating non-existent credentials and overstating findings.
OWASP Releases Security Guide for Third-Party MCP Servers
-
The OWASP GenAI Security Project published a comprehensive guide addressing security risks in Model Context Protocol (MCP) implementations, focusing on tool poisoning, prompt injection, memory poisoning, and tool interference attacks that can lead to unauthorized data access and malicious code execution.
-
The guide outlines critical security controls including enforcing full tool transparency, implementing sandboxed execution environments using Docker containers, and establishing governance workflows with automated scanning and human-in-the-loop approval processes for third-party MCP server deployments.
-
Key recommendations include using OAuth 2.1 for authentication, maintaining trusted registries with version pinning and checksums, and implementing least-privilege policies with granular permissions to minimize attack surfaces when connecting AI applications to external tools and APIs.
Researchers Publish Comprehensive Taxonomy of Agentic AI Security Threats
-
University of South Florida researchers have released a comprehensive survey identifying five major categories of agentic AI security threats including prompt injection, autonomous cyber-exploitation, multi-agent attacks, interface risks, and governance concerns.
-
The research highlights that 94.4% of state-of-the-art LLM agents are vulnerable to prompt injection attacks, with recent real-world incidents including the EchoLeak (CVE-2025-32711) exploit that allowed automatic data exfiltration from Microsoft Copilot.
-
Autonomous agentic systems can now independently execute sophisticated cyberattacks including one-day vulnerability exploitation with 87% success rates using GPT-4, marking a shift from human-directed to fully autonomous threat actors.

Market Updates
Daylight Raises $33 Million Series A Just Three Months After Seed Round
-
Israeli cybersecurity startup Daylight secured $33 million in Series A funding led by Craft Ventures, bringing total funding to $40 million just three months after their $7 million Seed round, highlighting investor urgency around AI-powered security operations.
-
The company develops an AI-native MDR platform that autonomously identifies and contains cyber threats, serving dozens of enterprises including The Motley Fool and McKinsey Investment Office with deployment in under an hour.
-
Founded by Unit 8200 veterans, Daylight will use the funding for U.S. expansion and launching new modules for identity threat response and cloud workload protection as global cyberattacks increase 50% year over year with average breach costs reaching $4.45 million.
RedCarbon Raises €3 Million Series A for AI-Based Cybersecurity
-
Turin-based AI cybersecurity startup RedCarbon secured €3 million in Series A funding led by Azimut Group, with participation from Diapason Prime and FND XI to develop AI agents for managing complex cybersecurity operations.
-
The company plans to use the funding to consolidate its position as a European reference in AI-based cybersecurity and expand into international markets, particularly Europe and the Middle East, with plans to hire 16 strategic roles by 2028.
-
RedCarbon's AI platform aims to transform intensive cybersecurity and risk management activities by automating repetitive tasks, allowing cybersecurity teams to focus on more critical activities and strategic threat response.
Reflectiz Raises $22 Million for Website Security Solution
-
The Series B funding round was led by Fulcrum Equity Partners, bringing Reflectiz's total funding to $28 million since its 2016 founding. The company will use these funds to expand product offerings and establish global headquarters in Boston.
-
Reflectiz's agentless platform provides web exposure management by detecting third-party tools, open source components, and malicious code without requiring code implementation or impacting website performance. The platform can de-obfuscate suspicious JavaScript and monitor vendor behavior from a centralized dashboard.
-
The solution serves global and Fortune 500 enterprises across ecommerce, financial services, healthcare, hospitality, and insurance sectors, addressing risks that enter through third-party components beyond organizations' direct control.

Tools
Trellix Security Platform
AI-powered security platform for detection, response, and threat protection
Hook Security
A security awareness training platform that combines phishing simulations with psychology-based training to help organizations reduce phishing vulnerabilities and build a security-aware culture.
Singularity Identity Detection & Response
Identity threat detection & response for Active Directory and Entra ID.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
Get the Mandos Brief, free.
A free Mandos account gives you our research articles and the Mandos Brief every Monday. Use your work email.
- Research articles
- The Mandos Brief every Monday
Free with your work email. No card. Includes the Mandos Brief every Monday.
