Brief #132: Microsoft Defender Bypass, Chinese AI Autonomous Hacking, Salaries Go Down
Shai-Hulud 2.0 compromises 25,000+ npm repositories for credential harvesting. Early AI security adopters see 67% security posture improvement and 70% breach risk reduction.
The Shai-Hulud 2.0 attack compromised over 25,000 npm repositories using sophisticated typosquatting to harvest developer credentials and secrets across multiple package ecosystems
Chinese state actors are using Claude AI to autonomously execute 80-90% of their attack operations, from reconnaissance to exfiltration, with minimal human intervention
Cybersecurity salaries are dropping by approximately $20k across roles as companies capitalize on increased competition from laid-off workers to reduce compensation
SquareX discovered a potential vulnerability in Perplexity's Comet AI browser that could allow attackers to execute local commands through a Model Context Protocol API and two hidden extensions.
The attack requires compromising the agentic extension via XSS, MitM attacks, or gaining access to Perplexity systems, and SquareX demonstrated the exploit using an "extension stomping" technique to deploy ransomware.
Perplexity strongly disputes the findings, calling it "fake security research" and stating the scenario is contrived, though they implemented preventive measures out of caution and claim users must consent to MCP installations.
Threat actors have launched a massive supply chain attack called Shai-Hulud 2.0 that compromises over 25,000 npm package repositories to steal developer credentials and secrets.
The attack involves publishing malicious packages that mimic legitimate libraries, with typosquatting techniques used to trick developers into installing compromised versions that exfiltrate sensitive data.
The campaign demonstrates sophisticated persistence mechanisms and targets high-value organizations by harvesting authentication tokens, API keys, and other secrets from development environments across multiple package ecosystems.
Attackers can create malicious Microsoft 365 tenants without Defender protections and invite victims as guests, completely bypassing Safe Links, ZAP, and malware scanning that exist in the victim's home organization.
Microsoft's MC1182004 feature "Chat with anyone with an email address" is enabled by default and allows threat actors to trivially deliver guest invitations to any email address, making this attack vector easily exploitable.
When users accept guest invitations to external tenants, all security policies apply from the hosting tenant rather than their home organization, creating protection-free zones that attackers can exploit for phishing campaigns and malware distribution.
Modern applications rely on hundreds of third-party components and open-source libraries, creating blind spots where critical vulnerabilities can hide deep within dependency layers that developers may not even know exist.
The Log4Shell vulnerability demonstrated how organizations spent weeks identifying exposure across their environments, a process that could have been reduced to hours with proper SBOM implementation and continuous monitoring.
Supply chain attacks like SolarWinds exploit trusted software vendors by injecting malicious code into routine updates, making comprehensive SBOMs essential for rapid threat identification and risk assessment.
Agentic AI early adopters report 67% positive impact on their organization's security posture, with 88% seeing ROI within the first year compared to 74% across all organizations.
Security operations and cybersecurity represent 46% of AI agent deployments among organizations leveraging these technologies, making it the second most common use case after customer service.
Early adopters achieve significant operational improvements including 50% faster mean time to respond, 65% faster mean time to investigate, and 70% reduction in breach risk and cost.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
Tyler Farrar, CISO at Nextracker, argues that the cybersecurity market has become driven by funding rounds rather than solving real security problems, with vendors creating products that look impressive in demos but fail in production environments.
He emphasizes that effective security still relies on fundamental practices like consistent patching, proper access controls, and network segmentation, rather than the latest AI-powered or autonomous tools that dominate venture capital investments.
Farrar advocates for CISOs to buy selectively based on measurable risk reduction and operational fit, while calling on the industry to focus on reliability over revolution and fund boring but critical work like visibility and identity management.
Traditional entry-level certifications like Security+, Network+, and CCNA provide theoretical foundation but lack practical skills needed for real cybersecurity work, with most focusing on governance rather than hands-on security operations.
Hack The Box Academy defensive and offensive paths offer more realistic and affordable alternatives to expensive training like OffSec OSDA, providing practical lab experience that helps clarify career direction through actual security work rather than theory.
Essential foundational skills include basic programming knowledge (variables, loops, conditions) and strong research abilities, while avoiding over-reliance on AI tools like ChatGPT for solving labs to build critical analytical thinking skills.
Jason from TrustedSec's Targeted Operations Red Team confirms that social engineering now dominates successful compromises of Fortune 500 companies, with purely external technical exploits becoming increasingly rare as organizations improve their security posture.
The team conducts both network and physical red teaming operations, with their physical specialists deploying network-based implants during on-site engagements to simulate real-world attack scenarios.
Legal teams often create significant obstacles during privileged engagements by adding unnecessary overhead, taking adversarial positions against red teams, and filtering critical risk communications to leadership rather than facilitating direct technical discussions.
An experienced analyst with 4.5 years in enterprise security is facing lowball offers 15-20% below market expectations, with companies attempting to negotiate down from already modest salary proposals of 80-90k.
Industry professionals report a widespread salary reduction of approximately 20k across cybersecurity roles, attributed to increased competition from laid-off workers and companies adjusting compensation structures downward.
The current job market shows companies reposting identical positions with reduced salary ranges after initial candidate rejections, indicating employers are prioritizing cost reduction over talent acquisition in the current economic climate.
A survey of 117 security leaders shows 82% of organizations are using or experimenting with AI code assistants, with 32% actively using them in production, while 73% cite introduction of new vulnerabilities as their top concern.
Security teams report lacking visibility into AI usage, with 82% having some or no confidence in their ability to monitor AI-generated code, making visibility a critical gap in current AppSec strategies.
Three-quarters of respondents plan to allocate budget for securing AI-generated code within 12 months, with 62% expecting purpose-built AI security tools integrated into AI IDEs to become the future of application security.
Chinese state-sponsored group GTG-1002 used Claude Code AI toolchain to autonomously execute 80-90% of attack operations including reconnaissance, vulnerability discovery, exploitation, lateral movement, and exfiltration with minimal human intervention.
The AI-driven espionage campaign demonstrated cost asymmetry where attackers can scale operations through compute power while defenders work linearly, with AI agents operating at speeds impossible for human hackers to match.
PwC warns that this represents a paradigm shift requiring defenders to implement AI-driven security operations centers and continuous red teaming to counter increasingly autonomous threats that can operate 24/7 without human limitations.
The guide addresses the rapid expansion of AI tools in enterprise environments, with over 1,000 unique new AI applications discovered in the past year plus AI capabilities being integrated into existing SaaS platforms.
Organizations can choose between DIY approaches using existing tools, dedicated AI security point solutions, or comprehensive SaaS security platforms that include AI discovery as part of broader visibility efforts.
The comparison framework evaluates different discovery methods based on their ability to provide complete visibility across the full SaaS ecosystem, including generative AI tools, machine learning platforms, and AI-enabled applications
RevealSecurity secured $23 million in Series A funding to advance its application detection and response platform that monitors user activities across SaaS, cloud, and custom-built enterprise applications.
The company uses a patent-pending machine learning algorithm to detect suspicious activities and insider threats by analyzing user journeys through various business applications with what they claim is an unprecedented signal-to-noise ratio.
The funding will support global expansion and product development as enterprises face increased security challenges from the shift to SaaS environments, where both external attackers and trusted users pose threats to business-critical functions.
Tel Aviv-based Sweet Security secured $75 million in Series B funding led by Evolution Equity Partners to accelerate global expansion of its runtimeCNAPP and AI security solutions.
The company specializes in real-time protection for cloud environments and production systems, helping enterprises detect adversarial attacks and secure complex cloud workloads including AI agents and models.
Sweet Security serves global Fortune 1000 organizations with headquarters in Tel Aviv and teams across the U.S. and Europe, bringing total funding to $120 million.
Tel Aviv-based consumer cybersecurity company Guardio secured $80M in Series B funding led by Ion Crossover Partners to accelerate product innovation and expand its phishing detection engine capabilities for AI-generated scams.
The company is developing enterprise-grade visibility capabilities similar to DLP and SSPM products specifically designed for individual consumers, marking a shift from traditional enterprise-only security tools to consumer-focused protection.
With three consecutive years of over 100% year-over-year growth, Guardio is positioned to surpass $100M in ARR by early 2026 while expanding protection layers for AI-driven web environments where consumers use AI agents and browsers.
An automated code remediation tool that integrates with source control platforms to automatically fix security vulnerabilities in code through AI-driven analysis and one-click implementations.
Runtime application security platform that provides vulnerability management, patching, and threat detection at the application level during program execution.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.