Brief #137: Chrome Extension Supply Chain Attack, MCP Servers Expose AWS Keys, Record CVE Year
15.28% of employees run unverified MCP servers accessing credentials with zero visibility. Experienced CISSP holders apply to 100+ jobs for single interview as AI screening dominates. Manufacturing hit hardest by Google Cloud phishing at 19.6% of targets.
Trust Wallet's browser extension was compromised in another Shai-Hulud supply chain attack, draining $8.5 million from over 2,500 wallets and highlighting how even established crypto platforms remain vulnerable
Human risk incidents jumped 90% according to KnowBe4's latest study, with AI applications now the second-fastest growing attack vector as employees struggle with unauthorized AI tool usage
The job market reality check continues as a retired military professional with 12 years of experience and a CISSP can't land interviews, reflecting broader workforce challenges many of us are witnessing
Attackers sent 9,394 phishing emails from legitimate Google address by abusing Google Cloud's Application Integration Send Email task to impersonate routine enterprise notifications like voicemail alerts and file access requests.
The campaign used a multi-stage redirection flow starting with trusted storage.cloud.google.com links, then filtering through fake CAPTCHAs on googleusercontent.com, before ultimately directing victims to fake Microsoft login pages hosted on non-Microsoft domains.
Primary targets included manufacturing (19.6%), technology/SaaS (18.9%), and finance/banking/insurance (14.8%) organizations across the United States (48.6%), Asia-Pacific (20.7%), and Europe (19.8%), with the attack leveraging legitimate cloud infrastructure to bypass traditional sender reputation controls.
CloudSEK researchers discovered a nine-month RondoDoX botnet campaign that recently shifted to exploiting a critical Next.js vulnerability, deploying malicious payloads including cryptominers and the "React2Shell" backdoor through six confirmed C2 servers.
The threat actors have conducted over 40 exploitation attempts within six days targeting Next.js Server Actions through prototype pollution attacks, while simultaneously maintaining automated campaigns against IoT devices including routers and cameras.
The campaign demonstrates three distinct phases from March to December 2025, with attackers deploying multi-architecture binaries across x86, ARM, and MIPS systems while implementing aggressive persistence mechanisms that terminate competing malware and establish cron-based backdoors.
Trust Wallet's GitHub secrets were exposed during the second iteration of the Shai-Hulud supply chain attack, allowing threat actors to gain Chrome Web Store API access and push a malicious version 2.68 of their browser extension on December 24, 2025.
The trojanized extension contained a backdoor that harvested wallet mnemonic phrases from all configured wallets during every unlock attempt, exfiltrating the data to a domain hosted on bulletproof hosting provider Stark Industries Solutions.
The attack resulted in $8.5 million in cryptocurrency being drained from 2,520 wallet addresses, with Trust Wallet now processing reimbursement claims while implementing additional monitoring controls to prevent future supply chain compromises.
Protecting sensitive data tops cybersecurity priorities for 2026 with 44% ranking it first, followed by threat detection and response (36%) and AI enablement (25%).
MDR (Managed Detection and Response) emerges as the leading priority for both organizational investment and automation efforts, while threat hunting gains importance specifically for automation initiatives.
Mobile devices represent the largest visibility gap (51%) in cybersecurity landscapes, with cloud workloads (40%) and BYOD environments (39%) following as major blind spots.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
Security researcher Jerry Gamblin's annual analysis reveals 48,185 CVEs were published in 2025, marking a 20.6% increase from the previous year and bringing the total CVE count to over 308,000 since 1999.
The cybersecurity landscape saw a dramatic shift with WordPress security firms Patchstack and Wordfence now publishing more CVEs than tech giants like Microsoft and Google, reflecting the growing focus on third-party plugin vulnerabilities.
Cross-site scripting (CWE-79) dominated the weakness landscape with over 8,000 entries, while 39.4% of all CVEs received Critical or High severity ratings, indicating a substantial attack surface requiring immediate attention.
Organizations face escalating attacks as more targets become compromised across all sectors, requiring baseline security improvements including stronger authentication, prioritized patching, and network segmentation to reduce blast radius.
AI security emerged as a core discipline in 2025 with organizations rapidly adopting AI while security teams scramble to ensure secure deployment, compliance, and governance through agent identity management and posture monitoring solutions.
The convergence of AI for security acceleration and a growing wall of vulnerabilities will define the next chapter, as synthetic content proliferation creates a global search for authenticity requiring verification of people, content, software, and brands.
A retired military cybersecurity professional with 12 years of experience, a CISSP certification, and a Master's degree cannot secure job interviews despite applying for GRC positions at entry level.
Community feedback reveals that modern hiring processes require tailoring resumes for each specific job posting, with some professionals reporting the need to apply to 100+ positions for a single interview opportunity.
The discussion highlights broader workforce challenges in cybersecurity, with multiple experienced professionals expressing similar frustrations and considering career changes due to market saturation and AI-driven screening processes.
A senior threat hunter specializing in data science and machine learning seeks insights from hiring managers about whether these skills make candidates stand out in cybersecurity roles, noting that most job postings don't explicitly mention DS/ML requirements outside of specialized positions.
The discussion reveals mixed perspectives, with some professionals viewing DS/ML skills as valuable differentiators for anomaly detection and advanced analytics, while others suggest these capabilities are rarely needed outside of research or product development roles.
Industry practitioners highlight the practical application of techniques like clustering, time series analysis, and graph networks for threat hunting, emphasizing that custom-built models can uncover threats missed by traditional SIEM tools and commercial AI solutions.
A Deputy CISO reports handling all strategic responsibilities including incident ownership, board preparation, and team direction while their CISO focuses on conferences and external engagements rather than day-to-day operations.
The cybersecurity community identifies this as a common pattern where some CISOs act more like professional speakers on the convention circuit than hands-on executives, leaving technical staff to manage actual security operations.
Industry professionals recommend the Deputy CISO leverage this experience to transition into a full CISO role elsewhere, noting that accountability ultimately falls on the CISO during major incidents despite the Deputy carrying operational responsibility.
The 2025 State of Human Risk report surveyed 4,200 professionals across 14 countries and found that 90% of cybersecurity leaders experienced an increase in incidents involving the human element, with email remaining the primary attack vector at 64% of external attacks but AI applications showing the second-highest growth at 43%.
Only 16% of organizations have a well-established Human Risk Management program despite 97% of cybersecurity leaders wanting more budget to secure people, while 47% of employees believe data belongs to them rather than their organization, creating significant ownership and accountability gaps.
AI threats now rank as cybersecurity leaders' top concern for behavioral risk, with 86% of employees expressing concern about deepfakes and 17% admitting to using unauthorized AI tools at work, highlighting the urgent need for organizations to extend security frameworks beyond traditional human risk to include AI agents.
Clutch Security found 15.28% of enterprise employees are running MCP servers locally with 38% being unofficial implementations from unverified sources that have direct access to AWS keys, GitHub tokens, and database passwords.
The Model Context Protocol ecosystem exploded from 3 servers in October 2024 to 6,878 servers by November 2025 – a 2,200% growth rate with developers installing arbitrary code from npm, GitHub, and PyPI without security review.
In a typical 10,000-person organization, 3,056 total MCP server installations connect to 115 enterprise services including AWS, Atlassian, and Snowflake, with 95% running on endpoints where security tools have no visibility and 3% containing hardcoded credentials.
Google published a comprehensive technical paper mapping SAIF (Secure AI Framework) security controls to specific Google Cloud capabilities, providing enterprise customers with actionable guidance for securing AI systems throughout their lifecycles using services like Vertex AI and foundation models.
The paper covers seven control categories including data controls, infrastructure controls, model controls, application controls, assurance controls, governance controls, and agentic AI risks, with each control analyzed through "what we do" (built-in protections) and "what you should consider" (optional configurations) approaches.
Key security capabilities highlighted include differential privacy in BigQuery, federated learning with TensorFlow Federated, Confidential Space for trusted execution environments, and Sensitive Data Protection for detecting and sanitizing PII in training datasets.
The enterprise cybersecurity giant acquired the Germany-based Microsoft 365 security provider for $1.8 billion, significantly exceeding initial $1 billion estimates to expand into the SMB market and strengthen European presence.
Hornetsecurity will operate as a dedicated business unit serving over 12,000 MSPs and 125,000 customers, bringing nearly $200 million in annual recurring revenue with 20% year-over-year growth.
The acquisition centers around Hornetsecurity's 365 Total Protection platform, a cloud-native solution that complements Proofpoint's enterprise-grade offerings to protect Microsoft 365 environments across both enterprise and small business segments.
Google acquired Wiz Security for $32 billion and Palo Alto Networks announced a $25 billion deal for CyberArk, driving total M&A activity to surpass 2024 levels by more than 10% and approach the 2021 record of $75 billion.
The market shifted from acquiring high-growth startups to strategic consolidation focused on reducing vendor sprawl, with buyers prioritizing integrated platforms over point solutions to deliver simplicity, automation, and AI governance.
Identity security emerged as a critical control plane for AI, with acquisitions targeting privileged access management, workforce identity, and ITDR capabilities to manage both human and machine identities in zero trust environments.
Saudi Arabia-based cybersecurity company DSShield raised $54 million from Merak Capital to expand operations and develop proprietary technology for government entities, critical infrastructure, and financial institutions.
The funding comes as Saudi Arabia's cybersecurity market reached $4 billion in 2024 with 14% growth, driven by accelerated digital adoption and cloud migration across the Kingdom's public and private sectors.
DSShield will use the investment to scale managed security services, strengthen advisory capabilities, and establish a pathway toward a public listing while serving environments where availability and compliance are critical.
End-to-end email encryption with enterprise features like revocation & policies
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.