Happy Sunday!
Here is what went down this week:
- GitHub token attacks are enabling attackers to move from compromised repositories directly into cloud environments, with most organizations storing cloud credentials in Action Secrets
- 83% of enterprises use AI but nearly half have little visibility into how these systems access their data, creating significant governance blind spots
- Entry-level cybersecurity jobs have become brutally competitive with salaries dropping 20-30% and Security+ certs no longer enough to land most positions
A quick note before we dive in.

Industry News
GitHub PAT Attacks Enable Cross-Cloud Lateral Movement
-
Attackers are leveraging compromised GitHub Personal Access Tokens to discover Action Secrets names through API code search, then creating malicious workflows to execute code and steal cloud credentials from organizations.
-
Threat actors bypass GitHub's secret masking by encoding stolen credentials twice with Base64 or exfiltrating them to external webhook endpoints, allowing them to print raw secret values in Action logs for credential harvesting.
-
The attack enables lateral movement from GitHub repositories directly into victim cloud environments, with 73% of organizations storing CSP credentials in GitHub Action Secrets and 45% keeping plaintext cloud keys in private repositories.
Amazon Confirms 5-Year Russian Cyberattack Campaign Targeting AWS Infrastructure
-
Amazon threat intelligence has confirmed a Sandworm-linked Russian state-sponsored cyberattack campaign targeting AWS-hosted devices since 2021, focusing primarily on Western energy sector infrastructure in North America and Europe.
-
The attacks exploit misconfigured customer network edge devices rather than unpatched vulnerabilities, with threat actors taking advantage of exposed management interfaces and overly permissive identities to maintain persistent access.
-
Amazon's CSO separately disclosed blocking over 1,800 suspected North Korean IT workers since April 2024, who use stolen identities and laptop farms to secure remote positions and funnel earnings back to DPRK weapons programs.
Silent Whisper Vulnerability Allows Covert Tracking of WhatsApp and Signal Users
-
Researchers disclosed a tracking technique that exploits delivery acknowledgments in WhatsApp and Signal, allowing attackers to monitor devices silently using only a phone number without triggering visible messages or notifications.
-
The vulnerability causes significant battery drain during continuous probing, with test devices losing 14-18% battery per hour compared to normal 1% hourly consumption, while also consuming mobile data and disrupting bandwidth-heavy applications.
-
A publicly available proof-of-concept tool enables probing at 50ms intervals to reveal daily routines, sleep schedules, and travel patterns through response time analysis, with the vulnerability remaining exploitable as of December 2025.

Leadership Insights
Sumsub Reports Shift From Volume-Based to Sophisticated Identity Fraud Operations in 2025-2026 Report
-
Identity fraud has evolved from high-volume, low-effort attacks to fewer but more sophisticated operations using deepfake technology, synthetic identity rings, and post-KYC abuse schemes that cause greater financial damage per incident.
-
The report analyzes over 4 million fraud attempts and reveals that while fraud rates appear stable, each successful attack now represents higher preparation costs and longer-term impacts due to fraud-as-a-service platforms becoming more professionalized.
-
Sumsub's research indicates that generative AI has fundamentally changed fraud dynamics by democratizing deception tools while forcing verification systems to innovate at unprecedented speeds to counter increasingly layered attack strategies.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
ENISA 2025 NIS Investments Report Shows Cybersecurity Budget Shift Toward Technology and Services
-
Organizations maintained cybersecurity investment levels at 9% of IT budgets (median 1.5 million euros) but are increasingly directing spending toward technology and outsourcing rather than expanding internal cybersecurity teams.
-
The cyber talent shortage continues to intensify with 76% of EU organizations struggling to attract and 71% struggling to retain cybersecurity professionals, leading to the lowest cybersecurity-to-IT staffing ratio (10.6%) observed to date.
-
NIS2 implementation remains challenging for organizations, with key difficulties in patching (50%), business continuity (49%), and supply chain risk management (37%), while 30% have not conducted cybersecurity assessments in the past 12 months.
Netwrix 2025 Cybersecurity Trends Report Reveals Growing Hybrid IT Adoption and AI Security Challenges
-
Hybrid IT environments now dominate at 77% of organizations (up from 74% in 2024), with 53% of on-premises-only organizations planning cloud adoption and average cloud workload share reaching 49%.
-
AI-driven threats forced 37% of organizations to adapt their security approach, while 60% are already leveraging AI tools in their IT infrastructure, representing a significant shift in the threat landscape.
-
Security incidents with financial damage affected 75% of respondents (up from 60% in 2024), with organizations reporting $200,000+ in damages nearly doubling from 7% to 13%.
How do you like Mandos Brief?

Career Development
Cybersecurity Entry-Level Job Market Faces Severe Saturation and Declining Opportunities
-
The cybersecurity job market has become extremely saturated with entry-level candidates, causing salaries to drop 20-30% and making Security+ certifications insufficient for most positions that now require 2-3 years of experience.
-
Competition has intensified due to multiple factors including fresh graduates, laid-off professionals from the 300,000+ tech workforce reductions, displaced government contractors, and veterans willing to accept lower-paying positions.
-
AI automation is reducing demand for Level 1 analyst roles by handling routine tasks, while the responsibilities are being shifted to higher-level cyber engineers who must now manage multiple functions including AI agent oversight.
Cybersecurity Hiring Manager Faces Criticism for Outdated Interview Tactics
-
A hiring manager complained about declining candidate quality after asking trivia questions like "what did WPA3 introduce," prompting widespread criticism from cybersecurity professionals who called the approach ineffective and outdated.
-
Industry experts argued that memorization-based questions fail to assess real-world problem-solving abilities and recommended scenario-based interviews that evaluate how candidates approach actual security challenges rather than recall certification material.
-
The discussion revealed a broader issue with cybersecurity hiring practices, where interviewers focus on narrow technical trivia instead of assessing candidates' ability to think critically and adapt to evolving threats in their specific roles.
Former Employee Exposes Toxic Work Culture at AI Cybersecurity Startup HydroX AI
-
A former HydroX AI employee revealed experiencing chaotic management, unrealistic KPIs, and 55-60 hour work weeks with no clear guidance on what the company was actually building, highlighting dysfunction common in AI startups.
-
The company allegedly failed to pay previous employees and maintains questionable credibility with a cat listed as their Chief Information Security Officer on their website, raising red flags about their legitimacy.
-
Community members identified the company as Chinese-owned with potential ties to 996 work culture (9am-9pm, 6 days per week), suggesting the toxic environment may stem from cultural management practices incompatible with US employment standards.

AI & Security
Cyera Report Reveals 83% of Enterprises Use AI But Only 13% Have Strong Visibility Into Data Access
-
A survey of 921 IT and cybersecurity professionals found that while AI adoption has become mainstream across enterprises, nearly half have little to no visibility into how AI systems interact with their data, creating a dangerous governance gap.
-
Autonomous AI agents pose the greatest security challenge for 76% of organizations, with 70% also identifying external prompts to public LLMs as high-risk, while two-thirds have caught AI over-accessing sensitive data beyond its intended scope.
-
Only 11% of organizations can automatically block risky AI activity and just 23% have no prompt or output controls in place, leaving most enterprises reactive rather than proactive in managing AI-related data exposure risks.
Cato Survey Reveals 61% of Organizations Found Unauthorized AI Tools in Their Environments
-
Shadow AI presents greater risks than traditional Shadow IT because data gets processed, learned from, and can reappear in outputs where it shouldn't, creating compliance nightmares for enterprises.
-
Only 13% of respondents say their organization is highly effective at managing shadow AI risks, while just 9% feel prepared to defend against AI-generated attacks like deepfakes and prompt injection.
-
69% of organizations lack formal monitoring capabilities for AI tool usage, relying instead on occasional audits or reactive responses to track unauthorized AI adoption across their environments.
Antonio Gulli Releases Comprehensive Guide on Agentic Design Patterns for AI Systems
-
Google's Antonio Gulli has published a 424-page technical guide covering agentic design patterns, providing hands-on implementation guidance for building intelligent AI systems that can perceive, plan, and act autonomously.
-
The book covers 21 core patterns across four parts, including prompt chaining, multi-agent systems, memory management, and safety guardrails, with all author royalties being donated to Save the Children.
-
Industry leaders from Google and Goldman Sachs contributed forewords emphasizing the shift from traditional LLMs to agentic systems that can reason, plan, and execute complex tasks with proper oversight and responsibility frameworks.

Market Updates
Global Cybersecurity Market Projected to Reach $1 Trillion by 2031
-
Cybersecurity Ventures forecasts 15 percent annual growth will drive global cybersecurity spending from $454 billion in 2025 to $1 trillion by 2031, driven by expanding digital infrastructure protection needs across IoT devices, industrial control systems, and emerging AI applications.
-
Nearly 15 percent of corporate cybersecurity spending now comes from outside the CISO organization, with non-CISO cyber budgets expected to grow at 24 percent CAGR over the next three years as cloud, product, and compliance teams drive purchasing decisions.
-
Cybercrime costs are projected to reach $10.5 trillion annually by 2025, making it the world's third largest economy, while Microsoft leads the sector with $37 billion in cybersecurity revenue representing 14 percent of its total business.
Resolve AI Reaches $1 Billion Valuation with Series A Funding
-
Resolve AI, founded by former Splunk executives, secured Series A funding led by Lightspeed Venture Partners with a headline valuation of $1 billion using a multi-tranched structure where investors purchased equity at both the $1 billion valuation and lower prices.
-
The autonomous site reliability engineer platform automates the identification, diagnosis, and resolution of production issues in real-time, addressing the growing shortage of skilled SREs as software systems become increasingly complex and distributed across cloud infrastructure.
-
With approximately $4 million in ARR, the startup competes directly with Traversal, which raised $48 million in Series A funding, highlighting investor interest in AI-powered DevOps automation solutions.
Ciphero Emerges From Stealth With $2.5M in AI Security Funding
-
New York-based Ciphero secured $2.5 million in pre-seed funding co-led by Sovereign's Capital and Chingona Ventures to develop an AI verification layer for enterprise environments.
-
The company's platform captures, verifies, and governs all AI interactions including shadow AI usage, aiming to prevent data loss and attacks while enabling ethical AI adoption.
-
Founded in 2025 by former Fakespot executives Saoud Khalifah (CEO) and Rob Gross (COO), whose previous company was acquired by Mozilla in 2023 for fake review and counterfeit detection technology.

Tools
Crowdstrike Charlotte AI
GenAI assistant that provides faster intelligence for security operations
Cloudflare API Shield
An API security and monitoring platform that automatically discovers, validates, and protects API endpoints while providing comprehensive management and analytics capabilities.
Keeper Privileged Access Management
Cloud-native PAM platform securing privileged access to critical infrastructure
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
Get the Mandos Brief, free.
A free Mandos account gives you our research articles and the Mandos Brief every Monday. Use your work email.
- Research articles
- The Mandos Brief every Monday
Free with your work email. No card. Includes the Mandos Brief every Monday.
