Happy Sunday!
In this week's brief:
- NANOREMOTE backdoor is using Google Drive API for command and control, blending malicious traffic with legitimate cloud services in a way that's pretty clever
- Stanford researchers proved their AI agent outperformed 9 out of 10 human penetration testers in live enterprise testing, which should make us all think about where this industry is heading
- The cybersecurity job market has hit its worst point in 15 years, with seasoned professionals reporting they can't even get interviews despite strong credentials
A quick note before we dive in.

Industry News
Elastic Security Labs Discovers NANOREMOTE Windows Backdoor Using Google Drive API
-
Elastic Security Labs identified a fully-featured Windows backdoor called NANOREMOTE that shares code similarities with FINALDRAFT and REF7707 malware, likely developed by the same espionage threat actor for reconnaissance and data theft operations.
-
The malware leverages the Google Drive API for command and control communications, enabling file transfers and payload staging through legitimate cloud services that blend with normal network traffic and evade traditional detection methods.
-
NANOREMOTE features 22 command handlers providing comprehensive capabilities including system enumeration, command execution, custom PE loading using libPeConv library, and task management for file operations with pause/resume functionality.
Zscaler ThreatLabz Analyzes BlackForce Phishing Kit
-
BlackForce is a new phishing kit first observed in August 2025 with five distinct versions that enables Man-in-the-Browser attacks to steal credentials and bypass MFA through real-time operator interaction.
-
The kit has been used to impersonate over 11 brands including Disney, Netflix, DHL, and UPS, and is actively sold on Telegram forums for €200–€300 with sophisticated evasion techniques including ISP and security vendor blocklists.
-
BlackForce evolved from a stateless to stateful architecture across versions, implementing persistent session storage and dual-channel communication that separates phishing servers from Telegram data exfiltration to ensure resilience.
MITRE Releases 2025's Top 25 Most Dangerous Software Weaknesses
-
MITRE analyzed 39,080 CVE Records from June 2024 to June 2025, identifying the most critical software weaknesses that enable threat actors to compromise systems and steal data.
-
Cross-Site Scripting (XSS) retains the top spot while Missing Authorization, NULL Pointer Dereference, and Missing Authentication showed the biggest upward movement in rankings.
-
Six new entries joined the list including Classic Buffer Overflow, Stack-based Buffer Overflow, Heap-based Buffer Overflow, and Improper Access Control, highlighting evolving threat landscapes.

Leadership Insights
Trellix Detects 272,512 OT/ICS Threats Across 572 Customers in Six-Month Period
-
From April to September 2025, Sandworm Team dominated industrial threat activity with nearly one-third of observed OT intrusions, deploying Industroyer2 against Ukrainian power substations and multiple destructive wipers including CaddyWiper and NikoWiper.
-
Manufacturing emerged as the primary target representing 41.5% of all detections, followed by transportation and shipping at 27.6%, with attackers leveraging PowerShell (96,061 detections) and Cobalt Strike as primary attack vectors to pivot from IT to OT environments.
-
Critical vulnerabilities in Cisco ASA/FTD devices (CVE-2025-20333 & CVE-2025-20362) and SAP NetWeaver systems enabled threat actors to compromise network boundaries and manufacturing execution systems, with average OT patching cycles extending beyond 180 days compared to 30 days for IT systems.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
Wiz Releases CISO Org Chart Playbook for Cloud Security Teams
-
The playbook provides templates for three organizational models: centralized, hybrid, and federated structures with role-by-role breakdowns for cloud security functions including product security, detection response, and GRC.
-
Wiz emphasizes that organizational design directly impacts developer velocity and risk posture, noting that poor structure creates bottlenecks and slow releases while the right model reduces firefighting through clear ownership.
-
The resource targets CISOs scaling cloud security teams and organizations moving through different growth stages, offering adaptation guides to strengthen current structures without requiring full reorganizations.
GSMA Report: Mobile Operators Spend $15-19bn Annually on Cybersecurity With Costs Rising
-
Global mobile operators currently spend between $15bn and $19bn annually on core cybersecurity activities, with projections showing costs will rise to $40bn-42bn by 2030 as threat complexity increases.
-
The report identifies six key principles for effective cybersecurity policy including harmonisation with international standards, risk-based approaches, and collaborative regulatory culture to avoid unnecessary compliance burdens.
-
Fragmented regulatory frameworks across multiple jurisdictions create operational inefficiencies and duplicate reporting requirements, particularly impacting operators in low- and middle-income countries where high fixed cybersecurity costs must be recovered from lower revenue customer bases.
How do you like Mandos Brief?

Career Development
Cybersecurity Job Market Faces Worst Conditions in 15 Years According to Industry Professionals
-
Industry veterans report the cybersecurity job market is experiencing the worst conditions in 15 years, with professionals struggling to secure interviews even with extensive experience and certifications.
-
The market saturation has reached critical levels, prompting some cybersecurity professionals to pivot to entirely different fields like nursing or consider trades such as general contracting.
-
Corporate practices including extensive use of H1-B visas and immigration firms to circumvent visa caps are being cited as significant contributing factors to the challenging job market conditions, rather than AI displacement alone.
Cybersecurity Company Requires Employee To Use Personal Device With Pirated Software For Work
-
A new remote employee at a cybersecurity company discovered they must use their personal Windows laptop containing pirated games and software for work duties, raising significant security concerns about malware exposure and data protection.
-
Security professionals unanimously criticized the company's BYOD policy as extremely risky, with many questioning the legitimacy of any cybersecurity firm that would allow such practices without proper isolation or virtual desktop infrastructure.
-
Recommended mitigation strategies include complete system reformatting, dual-booting with a clean Linux distribution, or physical drive separation, though experts emphasized that no solution fully eliminates the inherent risks of mixing personal and corporate data on compromised systems.
ISC2 Finds Skills Shortages Eclipse Staffing Concerns as Economic Pressures Stabilize
-
A record 16,029 cybersecurity professionals reported that skills shortages (59% citing critical or significant needs) now outweigh headcount concerns, with AI (41%) and cloud security (36%) leading the most pressing competency gaps.
-
Economic pressures from budget cuts (36%) and hiring freezes (39%) have stabilized rather than worsened, though 72% of respondents believe reducing cybersecurity personnel significantly increases breach risk.
-
Despite workforce challenges, 73% view AI as creating more specialized cybersecurity roles rather than eliminating jobs, with 63% of current AI tool users reporting significant productivity boosts.

AI & Security
AWS Launches Security Agent for Automated Application Security Testing (Preview)
-
AWS Security Agent provides context-aware automated application security reviews and on-demand penetration testing throughout the development lifecycle, addressing the gap where 81% of organizations knowingly deploy vulnerable code to meet delivery deadlines.
-
The service includes three core capabilities: design security review for architectural documents, code security review for GitHub pull requests checking OWASP Top Ten vulnerabilities, and penetration testing that executes sophisticated attack chains across 13 risk categories.
-
Currently available in preview at no charge in US East (N. Virginia) Region, the agent creates customized attack plans informed by source code and business documentation, reducing penetration testing time from weeks to hours.
Security Researcher Details Critical AI Agent Vulnerabilities With 100% Attack Success Rate
-
Greyswan AI and UK AI Security Institute achieved 100% attack success rate against all tested AI agents in public competition, with some requiring only ten probes or less to compromise through prompt injection attacks.
-
AI agents suffer from fundamental security flaws where the LLM cannot distinguish between system instructions and user data, creating a "lethal trifecta" when agents process untrustworthy inputs, access sensitive systems, and perform consequential actions simultaneously.
-
Security architects can mitigate risks using design patterns like CaMeL (Capabilities for Machine Learning) that separate privileged and quarantined LLMs, implementing the Principle of Least Autonomy to constrain agent decision-making capabilities.
Stanford Research: AI Agent ARTEMIS Outperforms 9 of 10 Cybersecurity Professionals in Live Penetration Testing
-
Stanford researchers conducted the first comprehensive comparison of AI agents versus human cybersecurity professionals in a live enterprise environment, testing on 8,000 hosts across 12 subnets, where their new ARTEMIS framework discovered 9 valid vulnerabilities with an 82% valid submission rate.
-
ARTEMIS demonstrated cost-effectiveness at $18/hour compared to $60/hour for professional penetration testers, while showcasing advantages in systematic enumeration and parallel exploitation through its multi-agent architecture that can run up to 8 concurrent sub-agents.
-
The study revealed key capability gaps where AI agents exhibited higher false-positive rates and struggled with GUI-based tasks, while excelling at CLI-based exploitation that humans often abandoned due to browser compatibility issues.

Market Updates
Imper.ai Emerges From Stealth Mode With $28 Million in Funding
-
The New York-based startup, founded by Israeli intelligence veterans, focuses on detecting AI-driven impersonation and social engineering attacks across video, voice, and chat platforms like Zoom, Teams, and Slack.
-
The company's agentless platform analyzes behavioral markers, device telemetry, and network diagnostics to provide real-time risk scoring and block attacks at the first point of contact.
-
Funding came from Redpoint Ventures, Battery Ventures, Maple VC, Vessy VC, and Cerca Partners, with investors positioning the solution as a foundational layer for enterprise security against deepfakes and voice clones.
ServiceNow Near Deal to Buy Cybersecurity Startup Armis for Up to $7 Billion
-
ServiceNow is in advanced talks to acquire Armis, a cybersecurity startup specializing in IoT device protection, for up to $7 billion, though discussions could still fall through or attract competing bidders.
-
The acquisition would represent a significant premium over Armis's current $6.1 billion valuation from its November funding round, where the company raised $435 million.
-
Armis provides real-time security for connected devices and serves over 40% of Fortune 100 companies, positioning ServiceNow to capitalize on surging demand for advanced cybersecurity solutions following costly global cyberattacks this year.
CYBRET AI Emerges From Stealth With Nordic VC Backing for Autonomous Cyber Defense
-
Norwegian cybersecurity startup CYBRET AI launched from stealth mode with undisclosed funding from Nordic VCs including Skyfall, Inception Fund, and Wave Ventures to develop autonomous security systems that operate at machine speed.
-
The company is building AI systems that understand real-world attack behavior and can reason across complex environments in real-time, moving security operations beyond human-only capabilities.
-
Founded by 19-year-old Adrian De Gendt, Norway's youngest cybersecurity analyst in history, the startup aims to become a global category-defining company with strong Nordic roots but worldwide ambitions.

Tools
iScan Advanced Scanning Tool
Scans repositories for exposed secrets, API keys, and credentials for bug bounty
Netskope One Private Access
Netskope One Private Access is a Zero Trust Network Access solution that replaces VPNs with secure, context-aware access to private applications and resources.
ManageEngine Endpoint DLP Plus
An endpoint data loss prevention solution that discovers, classifies, and protects sensitive data while controlling data transfer methods and mitigating insider threats.
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
Get the Mandos Brief, free.
A free Mandos account gives you our research articles and the Mandos Brief every Monday. Use your work email.
- Research articles
- The Mandos Brief every Monday
Free with your work email. No card. Includes the Mandos Brief every Monday.
