Happy Sunday!
In this week's brief:
- OWASP's 2025 Top 10 introduces Software Supply Chain Failures as a new #3 category, while social engineering attacks jumped 1,450% in the first half of 2025
- ChatGPT vulnerabilities are enabling attackers to steal private data from hundreds of millions of users through 0-click attacks and memory poisoning techniques
- The "two million cybersecurity jobs" narrative gets debunked with real data showing only 514,000 actual openings, explaining why qualified professionals struggle to find work
A quick note before we dive in.

Industry News
Sturnus Banking Trojan Bypasses WhatsApp, Telegram and Signal Encryption
-
Security researchers discovered Sturnus, an Android banking trojan that bypasses end-to-end encryption by capturing content directly from device screens after decryption, allowing attackers to monitor communications on WhatsApp, Telegram, and Signal in real-time.
-
The malware provides extensive remote control capabilities including full device takeover, credential harvesting through fake banking app overlays, and the ability to black out screens while executing fraudulent transactions without victim knowledge.
-
Currently in development phase with limited deployment, Sturnus targets financial institutions across Southern and Central Europe and uses advanced techniques including AES encryption for C2 communications, VNC protocol for remote sessions, and Android Accessibility Service abuse for comprehensive device monitoring.
Sneaky2FA Phishing Kit Adds Browser-in-the-Browser Attack Capability
-
Push Security researchers discovered that the Sneaky2FA phishing-as-a-service kit has integrated Browser-in-the-Browser (BITB) techniques, creating fake Microsoft login pop-ups that mask the actual phishing URL while using reverse-proxy technology to steal credentials and bypass MFA.
-
The attack chain begins with Cloudflare Turnstile bot protection, followed by a fake Adobe Acrobat document prompt that loads a convincing Microsoft login form in an embedded browser window that adapts to the victim's operating system and browser type.
-
Sneaky2FA employs multiple evasion techniques including conditional loading to block security vendors, heavily obfuscated HTML/JavaScript code, domain rotation with randomized 150-character URLs, and anti-analysis methods that disable browser developer tools.
Azure Neutralizes Record-Breaking 15 Tbps DDoS Attack
-
Azure DDoS Protection automatically detected and mitigated a massive 15.72 Tbps attack on October 24, 2025, targeting a single endpoint in Australia while maintaining uninterrupted service availability for customer workloads.
-
The attack originated from the Aisuru botnet, a Turbo Mirai-class IoT botnet that exploited compromised home routers and cameras across residential ISPs in the United States and other countries.
-
The multi-vector assault involved extremely high-rate UDP floods launched from over 500,000 source IPs with minimal source spoofing and random source ports, making it the largest DDoS attack ever observed in the cloud.

Leadership Insights
Security Providers Expand Compliance Services as Market Demand Surges, Report Shows 87% Now Offer These Services
-
Compliance services are now offered by 87% of surveyed security providers in 2025, representing a 7 percentage point increase from 2024 as organizations face heightened regulatory scrutiny and complex requirements.
-
Providers primarily delivering compliance as a managed service report better business outcomes including greater automation, lower churn rates, and higher recurring revenue compared to those focusing on consulting and advisory work.
-
Despite 90% of providers struggling to stand out in the crowded market, those with highest perceived differentiation use GRC platforms or compliance automation tools, with 66% primarily using such platforms versus only 16% relying on spreadsheets.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
CrowdStrike Reveals Europe Faces 22% of Global Ransomware Attacks in 2025 Threat Report
-
Europe-based victims constitute nearly 22% of entities named on ransomware dedicated leak sites, making it the second most targeted region after North America with big game hunting adversaries leveraging GDPR penalties to pressure victims into paying ransoms.
-
Vishing (voice phishing) campaigns are increasingly targeting European entities, with nearly 1,000 incidents observed globally during the reporting period as eCrime adversaries employ native speakers and sophisticated social engineering to gain initial access for ransomware deployment.
-
The robust Russian-language underground ecosystem continues supporting European cybercrime operations through forums like Exploit and XSS, offering specialized services including malware-as-a-service, initial access brokers, and fake CAPTCHA lures that impacted over 1,000 Europe-based customers in 2024-2025.
Application Detection and Response (ADR) Emerges to Address Runtime AppSec Gaps
-
The average application faces 81 confirmed viable attacks monthly alongside over 10,000 probes, while maintaining 30 serious exploitable vulnerabilities that outpace remediation capacity at 17 new vulnerabilities per month.
-
Traditional EDR and WAF solutions miss application-layer attacks, with SOCs discovering over half of incidents from external sources rather than internal detection capabilities, creating dangerous visibility gaps.
-
Organizations take 84 days to remediate critical vulnerabilities while acquiring new ones at nearly triple the remediation rate, creating exponential growth in security technical debt and ransomware exposure averaging $4.91 million per incident.
How do you like Mandos Brief?

Career Development
CISO Compensation Jumped 6.7% While Security Budgets Grew Only 4%, IANS Study Finds
-
A study of 550 CISOs across the US and Canada reveals compensation increases outpaced security budget growth, with pay rising 6.7% compared to the slowest budget increase in five years at 4%.
-
The top 1% of CISOs earn starting at $3.2 million annually, creating a 20x disparity with bottom earners, while equity-based compensation increasingly comprises up to 50% of pay packages for top performers.
-
CISO turnover reached 15% this year, the highest in six years, though those staying with current employers and expanding responsibilities saw 8.1% pay increases versus 5% for job switchers.
Cybersecurity Senior Job Market Discussion Reveals Hiring Challenges and Candidate Quality Issues on Reddit
-
Senior cybersecurity professionals report difficult job market conditions with hiring managers experiencing floods of unqualified applicants who lack basic technical knowledge despite claiming 5+ years of experience.
-
Multiple recruitment challenges emerge including candidates who cannot demonstrate familiarity with fundamental tools like SIEM, EDR, or MITRE framework despite listing extensive experience on resumes.
-
Industry professionals with 6+ years experience report decreased recruiter outreach since early 2024, with salary ranges of $120-$150k for fully remote positions and growing competition for senior-level roles due to market saturation.
Cybersecurity Beginner Advice: Hands-On Training Over Traditional Certifications
-
Traditional entry-level certifications like Security+, Network+, and CCNA provide theoretical foundation but lack practical skills needed for real cybersecurity work, with most focusing on governance rather than hands-on security operations.
-
Hack The Box Academy defensive and offensive paths offer more realistic and affordable alternatives to expensive training like OffSec OSDA, providing practical lab experience that helps clarify career direction through actual security work rather than theory.
-
Essential foundational skills include basic programming knowledge (variables, loops, conditions) and strong research abilities, while avoiding over-reliance on AI tools like ChatGPT for solving labs to build critical analytical thinking skills.

AI & Security
Google Cloud Study Shows Two-Thirds of Early Adopters See Positive Security Impact from Agentic AI
-
A survey of 3,466 global enterprise leaders found that 67% of agentic AI early adopters report positive impact on their organization's security posture, with 46% of organizations deploying AI agents specifically for security operations and cybersecurity.
-
Organizations are moving beyond basic AI assistance to autonomous AI agents that execute investigation and response workflows within predefined guardrails, enabling security teams to shift from reactive to proactive defense postures.
-
AI agents are being deployed for specialized security functions including malware analysis, detection engineering, alert triage, and incident response workflows, with adoption rates ranging from 44% to 64% across different global regions.
ServiceNow Now Assist AI Agents Exploited via Second-Order Prompt Injection
-
Researchers demonstrated how second-order prompt injection attacks can exploit ServiceNow's Now Assist agent-to-agent discovery feature to perform unauthorized CRUD operations and data exfiltration, even with prompt injection protection enabled.
-
The attack leverages default configurations where agents are automatically grouped into teams and marked as discoverable, allowing malicious prompts embedded in data fields to redirect benign agents to recruit more privileged agents for harmful tasks.
-
Organizations should implement supervised execution mode for powerful agents, disable autonomous overrides, segment agent duties by team, and deploy real-time monitoring solutions like AppOmni's AgentGuard to detect suspicious agent behavior patterns.
CSET Policy Brief Analyzes AI's Impact on Cyber Offense-Defense Balance
-
The Center for Security and Emerging Technology published a comprehensive policy brief examining how AI advancement will reshape cybersecurity, concluding there's no single answer to whether AI will favor offense or defense but identifying five key impact categories including digital ecosystem changes and tactical engagement aspects.
-
AI will likely increase the complexity and scale of digital systems requiring protection while potentially reducing network connections through centralized AI providers, creating both defensive challenges from expanded attack surfaces and opportunities from simplified monitoring requirements.
-
The brief recommends prioritizing AI reliability over originality for defensive applications, funding provable security and live patching capabilities, and maintaining human control options to preserve resilience during cyber crises and prevent over-aggregation of critical system controls.

Market Updates
Sweet Security Raises $75M Series B for AI Security Platform
-
The cybersecurity startup, founded by ex-IDF cyber chiefs, secured Series B funding led by Evolution Equity Partners to expand its cloud-native application protection platform and newly launched AI security capabilities.
-
The company's CNAPP solution provides comprehensive visibility across cloud environments, detecting live attacks, configuration risks, and identity security threats while prioritizing actionable threats over lengthy vulnerability lists.
-
Sweet Security is expanding its AI Security Platform (AISP) to help organizations discover Shadow AI tools, map all AI agents and LLM servers, and assess exposure risks from unknown AI deployments running in enterprise environments.
Israeli Startups Raise Over $800 Million in Mega Funding Week
-
Armis secured a $435 million Series C at $6.1 billion valuation, marking one of the largest private cybersecurity financings of 2025 and led by Goldman Sachs with participation from CapitalG and Evolution Equity Partners.
-
AI companies dominated with Wonderful raising $100 million Series A just four months after a $34 million seed round, while Majestic Labs closed $90 million Series A for compute infrastructure solutions targeting enterprise AI workloads.
-
Cybersecurity remains investor favorite as Sweet Security raised $75 million Series B and stealth startup Tenzai emerged with $75 million seed round led by Battery Ventures, Greylock Partners, and Lux Capital.
Tenzai Raises Record $75M Seed Round for AI-Powered Penetration Testing
-
Israeli cybersecurity startup Tenzai secured the largest seed round in the country's history, raising $75 million to develop an AI-based platform that automates penetration testing and replaces costly human consultants with continuous, scalable vulnerability assessments.
-
The company was founded by five Guardicore veterans who previously built and sold their last company to Akamai for $650 million, giving investors confidence in the team's ability to execute in the rapidly growing cybersecurity market estimated at $8 billion annually.
-
Battery Ventures, Greylock Partners, and Lux Capital led the round, betting on the company's potential to capitalize on the surge in AI-generated code which creates new attack surfaces that require more frequent and comprehensive security testing than traditional methods can provide.

Tools
StepSecurity
StepSecurity is a platform that enhances GitHub Actions security by providing network egress control, risk discovery, action replacement, and security best practices orchestration.
ManageEngine AlarmsOne
IT alert management platform that consolidates alerts from multiple monitoring tools
Cyver Core
A pentest management platform that automates reporting workflows, provides client collaboration tools, and streamlines the entire penetration testing lifecycle from scoping to remediation.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
Get the Mandos Brief, free.
A free Mandos account gives you our research articles and the Mandos Brief every Monday. Use your work email.
- Research articles
- The Mandos Brief every Monday
Free with your work email. No card. Includes the Mandos Brief every Monday.
