🎉 Happy Sunday and a Happy New Year!
As we wrap up 2025, I want to thank you for sticking around for Mandos Brief and reflect on this year.
In August, I embarked on a solopreneur journey focusing on two things that I always wanted to work on:
1) Advisory - using my expertise to help organizations improve their security, resilience, and enable business growth
2) Building a product - building CybersecTools into the number 1 destinations for security teams to discover cybersecurity products
The journey is never smooth and full of ups and downs, but the truth is that I love every moment I spend on these two items, learning a lot about sales, marketing, accounting (yes, even that), coding, AI agents, and, of course, catching up with the cybersecurity industry through this Brief.
There is one additional product I am working on currently to truly bring clarity to this crazy, overloaded market of cybersecurity products. This time, helping cybersecurity companies win customers and crush competition through data-based decisions they can't get anywhere else. Coming in Q1 2026, if you work for a cybersecurity company and are interested, let me know.
Wishing you and your loved ones a wonderful holiday season and all the best for 2026! 🥂
And back to the newsletter... Here is what you can expect in this brief:
- Cisco email security appliances are under active attack by UAT-9686 threat actors, with complete rebuilds being the only way to remove persistent backdoors from compromised systems
- NIST published its AI Cybersecurity Framework Profile for public comment, giving us the first structured approach to balance AI adoption with emerging security risks
- Nearly all CISOs now see hybrid infrastructure as their best bet for resilience, with 97% agreeing it beats putting all eggs in one cloud or on-premises basket

Industry News
Cisco Confirms Active Cyberattacks Against Email Security Appliances
-
The UAT-9686 threat actor is actively exploiting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances that have the Spam Quarantine feature exposed to the internet, allowing root privilege command execution.
-
Affected appliances show evidence of a persistence mechanism planted by attackers to maintain ongoing access, with Cisco recommending complete appliance rebuilding as the only viable option to eradicate the threat.
-
The attack specifically targets appliances with both the Spam Quarantine feature enabled and exposed to the internet, assigned CVE-2025-20393 with Critical severity affecting all releases of Cisco AsyncOS Software.
MongoDB Warns Admins to Patch Severe Vulnerability Immediately
-
CVE-2025-14847 is a high-severity memory-read vulnerability affecting multiple MongoDB versions that allows unauthenticated attackers to exploit the server's zlib implementation remotely without user interaction.
-
The flaw stems from improper handling of length parameter inconsistency in zlib compressed protocol headers, potentially allowing attackers to read uninitialized heap memory and gather sensitive information from targeted systems.
-
MongoDB strongly recommends immediately upgrading to patched versions (8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30) or disabling zlib compression on MongoDB servers as a temporary workaround until patches can be applied.
Fortinet Warns of Active Exploitation of CVE-2020-12812 LDAP Bypass Vulnerability
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
-
Fortinet has observed recent exploitation of CVE-2020-12812 (FG-IR-19-283) in FortiGate devices where attackers bypass two-factor authentication by exploiting case-sensitive username handling differences between FortiGate and LDAP directories.
-
The vulnerability allows attackers to authenticate using alternate case variations of usernames (e.g., "Jsmith" instead of "jsmith") which causes FortiGate to fail local user matching and fall back to LDAP group authentication, bypassing 2FA requirements entirely.
-
Organizations can mitigate this issue by upgrading to FortiOS 6.0.10, 6.2.4, or 6.4.1 and setting "username-case-sensitivity disable" on all local accounts, or removing unnecessary secondary LDAP group configurations that enable the authentication bypass.

Leadership Insights
CISOs Embrace Hybrid Infrastructure as Foundation for Cyber Resilience
-
Nearly all CISOs (97%) agree hybrid infrastructure provides greater resilience and risk management capabilities than relying solely on cloud or on-premises environments, with 89% of organizations already operating in a hybrid model distributing workloads across multiple platforms.
-
The top driver for hybrid adoption is improving resilience and business continuity (36%), followed by enhancing cybersecurity (31%) and reinforcing supply-chain integrity (26%), while 96% say hybrid is essential for meeting evolving regulatory and compliance requirements.
-
Despite complexity challenges including integrating OT and IT security (41%) and threat analysis across hybrid boundaries (37%), CISOs are doubling down on investments with cybersecurity (43%), OT/IT convergence (40%), and cloud expansion (38%) as top priorities for the next 12 months.
CISOs Focus on Strategic Transformation Through AI and Human-Centered Security
-
Modern CISOs are shifting from reactive firefighting to proactive strategic planning, leveraging AI to clear tactical debt like unpatched systems and incomplete projects that consume resources and create security gaps.
-
Security leaders prioritize breaking down organizational silos between AppSec, CloudSec, and GRC teams through automated workflows that integrate disparate tools and provide unified risk visibility across all security functions.
-
The new CISO agenda emphasizes human-led business enablement over traditional gatekeeping, focusing on talent development, cross-functional collaboration, and building security programs that drive innovation rather than just prevent attacks.
CISOs Discuss Hidden Workplace Challenges in Reddit Forum
-
CISOs report working 14-16 hour days at large companies with constant pressure from executives and board members, leading many to reconsider career advancement into these roles due to work-life balance concerns.
-
Many organizations hire CISOs primarily for liability management rather than true security authority, creating situations where they bear responsibility for incidents without having sufficient budget control or decision-making power.
-
Security leaders struggle with geopolitical risks and communicating that cybersecurity is a permanent problem requiring ongoing management rather than a solvable issue, especially when executives expect definitive solutions.
How do you like Mandos Brief?

Career Development
Cybersecurity Professionals Share Daily Work Experiences Across Multiple Roles and Industries
-
Security professionals reveal their day-to-day work ranges from log analysis and alert triage in SOC environments to compliance documentation and vulnerability management, with many emphasizing the repetitive nature of monitoring tasks punctuated by urgent incident response.
-
Incident frequencies vary significantly by organization size, with major corporations experiencing newsworthy breaches annually while smaller incidents like phishing clicks and malware infections occur daily across most environments.
-
Work-life balance generally remains favorable in most cybersecurity roles, though incident response teams face extended hours during active breaches, and automation through scripting has become essential for managing routine security tasks efficiently.
Former Actor Transitions to Cybersecurity Consultant Role at Global Finance Firm in Two Years
-
A professional actor with no degree or prior IT experience successfully transitioned to cybersecurity by obtaining CompTIA Security+ and Network+ certifications while working entry-level IT positions at Best Buy and help desk roles.
-
The individual leveraged networking skills developed through acting experience to build relationships at a cybersecurity convention, leading to direct contact with hiring managers and ultimately securing a cybersecurity consultant position.
-
The career progression included strategic moves from Geek Squad technician to help desk analyst to system administrator, demonstrating how soft skills and persistence can overcome traditional qualification gaps in cybersecurity hiring.
Cybersecurity Professionals Share Success Stories Despite Industry Pessimism
-
A security engineer with 5 years of experience and no formal certifications or degree reports consistent job interview success, receiving interviews for 3-4 positions out of every dozen applications.
-
Multiple professionals emphasize that networking events and industry conferences are crucial for career advancement, with approximately half of job opportunities coming through personal connections rather than traditional applications.
-
Recent cybersecurity graduates are successfully securing entry-level positions including internships at major companies like Cisco and direct hires as IAM analysts and SOC/IR analysts, contradicting widespread pessimism about degree value in the field.

AI & Security
Researchers Propose Five-Level Framework for AI Agent Autonomy
-
University of Washington researchers introduced a framework defining five escalating levels of AI agent autonomy, ranging from user as operator (L1) to user as observer (L5), treating autonomy as a deliberate design decision separate from capability.
-
The framework proposes autonomy certificates issued by third-party governing bodies to communicate agent behavioral characteristics, enabling better risk assessment and multi-agent system coordination.
-
Each autonomy level addresses different tradeoffs between utility, efficiency, accountability, and cost, with higher levels not necessarily meaning better agents but requiring more sophisticated governance mechanisms.
NIST Releases AI Cybersecurity Framework Profile for Public Comment
-
NIST published a preliminary draft of its Cybersecurity Framework Profile for Artificial Intelligence, seeking public feedback through January 30, 2026, to help organizations manage AI cybersecurity risks while leveraging AI for enhanced defensive capabilities.
-
The profile addresses three focus areas: securing AI system components, conducting AI-enabled cyber defense operations, and building resilience against AI-enabled attack vectors using the CSF 2.0 framework structure.
-
Organizations can use this framework to strategically adopt AI technologies while prioritizing emerging cybersecurity risks, with NIST specifically requesting input on informative references, implementation examples, and risk management approaches.
Anthropic Exec Forces AI Chatbot on Gay Discord Community, Members Flee
-
Jason Clinton, Anthropic's Deputy CISO and Discord moderator, overrode community votes to force Claude AI chatbot deployment across all channels despite member protests.
-
The gay gaming Discord community that was once vibrant has become a ghost town after members fled following Clinton's actions and behavior after the bot launch.
-
Community members had initially voted to restrict the Claude chatbot to its own dedicated channel, but Clinton used his moderator privileges to bypass their democratic decision.

Market Updates
IoT Security Firm Exein Raises €100 Million
-
Italian IoT security company Exein secured €100 million in Series B funding led by Blue Cloud Ventures, bringing their total 2025 funding to €170 million ($200 million).
-
The company's AI-powered embedded security platform provides runtime protection and vulnerability analysis for IoT device firmware, currently protecting over one billion devices globally.
-
Exein plans to use the investment for global expansion, M&A activities, and developing next-generation runtime security technology for the embedded systems market.
Adaptive Security Raises $81M Series B to Combat AI-Powered Cyber Threats
-
Adaptive Security secured $81 million in Series B funding led by Bain Capital Ventures, bringing total funding to $146.5 million as deepfake incidents grew 17 times from 2023 to 2024 with over 100,000 occurring in the U.S. alone.
-
The company has rapidly scaled to more than 500 enterprise customers including PayPal, Xerox, and Figma in under a year by using AI to simulate social engineering attacks across voice, video, text, and email channels.
-
Their platform combines impersonation simulations with risk scoring and tailored security training to address the fact that social engineering accounts for more than 95% of successful cyber breaches in an era where AI-powered threats are becoming mainstream.
Cybersecurity Market Projected to Reach $556 Billion by 2032 With 12% Growth Rate
-
The global cybersecurity market grew from $224.55 billion in 2024 and is expected to reach $555.98 billion by 2032, driven by a 41.5% increase in data breaches affecting over 422 million people in 2022.
-
Major acquisitions dominated 2025, including Google Cloud's $32 billion purchase of Wiz Security and Palo Alto Networks' $3.35 billion acquisition of Chronosphere, consolidating cloud security capabilities.
-
North America leads with 40% market share while Asia-Pacific shows the fastest growth at 13% CAGR, though the industry faces a critical talent shortage with 4 million unfilled cybersecurity positions globally.

Tools
Inlyse
A cutting-edge AI-based IT security platform that identifies malware and cyber-attacks within seconds
Traceable AppSec
Platform for API & app security with discovery, testing, and protection
Alkira Zero Trust Network Access
Cloud-based ZTNA solution providing identity-based access control for users and apps
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
Get the Mandos Brief, free.
A free Mandos account gives you our research articles and the Mandos Brief every Monday. Use your work email.
- Research articles
- The Mandos Brief every Monday
Free with your work email. No card. Includes the Mandos Brief every Monday.
