ServiceNow acquires Veza for $1B+ to expand identity security. Security leaders face burnout managing cloud, AI, and compliance with understaffed teams and limited autonomy.
React and Next.js applications are facing immediate exploitation risk through newly discovered RCE vulnerabilities that affect default configurations and require urgent patching
AI agents are now capable of autonomously exploiting smart contracts for millions in profit, with their success rate doubling every 1.3 months in recent research
Supply chain security programs are failing spectacularly, with 97% of organizations experiencing breaches despite increased spending and established TPRM initiatives
CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) are critical unauthenticated remote code execution vulnerabilities affecting React Server Components through insecure deserialization in the RSC "Flight" protocol with near-100% exploitation reliability.
Default configurations of Next.js applications created with create-next-app are immediately vulnerable, requiring only a crafted HTTP request for exploitation without any developer code changes needed.
Wiz Research data reveals 39% of cloud environments contain vulnerable instances, with patches now available for React versions 19.0-19.2 and Next.js versions 14.3.0-canary through 16.x requiring immediate updating.
Threat actors are exploiting device code phishing to obtain access tokens while bypassing MFA checks, with less than 50% of customers implementing Conditional Access policies to block these flows.
ROPC (Resource Owner Password Credentials) authentication is being weaponized for credential stuffing attacks, with only 0.2% of attempts blocked by CA rules despite being a legacy protocol that skips modern security controls.
Attackers chain successful token acquisition to register devices and configure Windows Hello for Business, creating 90-day persistence through Primary Refresh Tokens that satisfy high-assurance authentication requirements.
Researchers discovered Albiriox, a new Android malware family offered as Malware-as-a-Service for $650-720 monthly by Russian-speaking threat actors who use VNC-based remote access and overlay attacks for on-device fraud.
The malware targets over 400 financial applications including banks and cryptocurrency wallets through a two-stage deployment using dropper applications and social engineering lures that bypass static detection methods.
Albiriox enables complete device takeover through accessibility services that circumvent Android's FLAG_SECURE protections, allowing attackers to perform fraudulent transactions while displaying black screen overlays to hide malicious activity.
Functional security leaders are experiencing increased burnout from managing expanded responsibilities including cloud, AI, and regulatory compliance while dealing with understaffed teams and 24/7 operational demands.
Many midlevel security managers lack autonomy over critical decisions like budgets and staffing despite being held accountable for risk outcomes, creating unsustainable pressure without corresponding authority or career advancement opportunities.
CISOs can address this crisis by implementing clear RACI frameworks, providing meaningful delegation with real autonomy, and creating alternative career paths beyond traditional CISO roles to retain talent and maintain organizational security resilience.
Akira, Qilin, and INC ransomware groups represented 65% of all ransomware cases in Q3, with Akira alone accounting for 39% of incidents primarily through exploiting SonicWall VPN vulnerabilities using credential stuffing attacks.
SEO poisoning campaigns surged as attackers increasingly used search engine manipulation to distribute trojanized productivity tools like PDF editors, bypassing traditional email security filters and directly compromising endpoints.
SonicWall experienced a catastrophic quarter with widespread Akira ransomware attacks against their devices followed by a MySonicWall cloud service breach that compromised backup configurations for all customers using the service.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
Despite 95% of organizations increasing TPRM spending and 46% reporting established programs, 97% experienced at least one supply chain breach – a dramatic increase from 81% in 2024.
Organizations prioritize compliance over risk reduction, with only 16% identifying risk reduction as a primary driver while focusing on cyber insurance requirements and contractual obligations instead.
Internal resistance remains the top challenge, with 60% citing lack of organizational support and only 24% briefing senior leadership monthly, creating a widening gap between program maturity and effectiveness.
A newly appointed CISO at a scale-up company with no existing security team is planning to build a SOC by Q3 and seeks advice from experienced cybersecurity professionals on Reddit.
The overwhelming consensus from commenters is to avoid building an in-house SOC and instead use MSSP services or managed detection and response (MDR) solutions due to cost-effectiveness and resource constraints for smaller organizations.
Multiple experts recommend starting with the MITRE 11 Strategies for SOC framework, focusing on identifying crown jewels and threat landscape before selecting tools, and prioritizing foundational security controls over SOC operations.
A veteran CISO with 15 years of experience across 5 industries finds it increasingly difficult to provide relevant entry-level career advice as traditional paths into cybersecurity have fundamentally changed since the early days when degrees and certifications weren't required.
The hiring manager emphasizes looking for candidates with genuine passion and practical experience through home labs, AWS experimentation, and demonstrable problem-solving skills rather than focusing solely on formal credentials or certifications.
Discussion reveals a broader industry challenge where newcomers face unrealistic expectations of "easy money" and quick entry, while the job market has shifted to require more substantial hands-on experience and business acumen beyond technical skills.
Compliance and basic audit roles face the highest automation risk, with professionals noting that checkbox-style work and policy generation are already being handled by AI tools like Drata and Vanta.
Human-centric roles including incident response, threat hunting, security architecture, and red team operations are considered safe due to their requirements for creativity, judgment, and real-world context interpretation.
GRC positions may see workforce reduction but will retain human oversight for stakeholder management, risk interpretation, and executive communication that requires nuanced decision-making and relationship building.
AWS introduced the Agentic AI Security Scoping Matrix that categorizes four distinct autonomous AI architectures based on connectivity and agency levels, addressing security gaps that traditional AI frameworks cannot cover.
The framework defines four scopes ranging from no-agency systems requiring human approval to fully autonomous agents that can initiate activities and execute complex tasks without human intervention, each requiring progressively more sophisticated security controls.
Organizations should implement progressive deployment strategies starting with lower-risk scopes and advancing gradually while establishing layered security architecture, continuous validation loops, and graceful degradation mechanisms for when security events are detected.
Anthropic researchers created SCONE-bench to evaluate AI agents' ability to exploit smart contracts, finding that frontier models collectively produced exploits worth $4.6 million on contracts exploited after March 2025.
The study revealed that exploit revenue from AI agents doubled every 1.3 months over the past year, with GPT-5 and Claude Sonnet 4.5 discovering two novel zero-day vulnerabilities worth $3,694 at an API cost of only $3,476.
Beyond retrospective analysis, the agents successfully identified previously unknown vulnerabilities in 2,849 recently deployed contracts, demonstrating that profitable autonomous exploitation is technically feasible today.
OpenAI's reasoning models GPT-5 Mini (72%) and GPT-5 (70%) set new security benchmarks, while non-OpenAI models remained clustered in the 50-59% security pass-rate range.
The improvement appears linked to reasoning capabilities rather than general model upgrades, as OpenAI's non-reasoning GPT-5-chat scored only 52% compared to the reasoning variants.
Security gains were most pronounced in C# and Java enterprise languages and showed improvement against SQL injection vulnerabilities specifically.
ServiceNow announced it will acquire identity security startup Veza in a deal reportedly worth at least $1 billion, significantly expanding its cybersecurity portfolio with advanced identity risk visualization capabilities.
Veza's Access Graph technology will be integrated with ServiceNow's AI Control Tower and agentic workflows to provide customers with a unified view of identity risks across SaaS, cloud, and on-premises environments.
The 230-employee startup, valued at $808 million in its April Series D round, specializes in simplifying complex permissions management and has been recognized multiple times as a channel-friendly security vendor.
The cybersecurity startup founded by former Cybereason executives raised the largest Series A round in cybersecurity history, bringing total funding to $166 million after emerging from stealth just 10 months ago.
Their AI agents have processed over 2.5 million alerts and completed more than 650,000 security investigations, with customers reporting time savings of 30 minutes to 2.5 hours per investigation and up to 99% reduction in false positives.
Major clients including Fortune 500 companies like DXC Technology are using 7AI's agentic AI platform in production, with investors betting that AI-autonomous workflows will transform security operations at scale.
The cybersecurity startup, co-founded by CyberGRX founder Fred Kneip, raised $9 million from SYN Ventures and WhiteRabbit Ventures to build an end-to-end platform securing agentic AI communication infrastructure.
Their solution focuses on securing the Model Context Protocol (MCP), which serves as the underlying layer for connections between AI agents and software/data systems.
The platform automatically scans, monitors, and logs all MCP traffic while integrating with existing EDR tools to identify and block noncompliant connections as new communication paths emerge.
API Security is a comprehensive solution that provides continuous discovery, vulnerability assessment, threat detection, compliance monitoring, dynamic testing, and remediation capabilities to protect APIs against various threats and vulnerabilities.
Deep Instinct is a predictive prevention platform that uses deep learning to prevent unknown threats, including ransomware and zero-day malware, from infiltrating storage environments, applications, and endpoints.
Data privacy management platform for compliance with DPDPA, GDPR, and CCPA
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.