AI-generated code contains 1.7x more security vulnerabilities and 75% more logic errors than human-written code. Defense contractors leaked ITAR-controlled blueprints due to missing MFA enforcement.
Zestix threat actors compromised 50+ major enterprises using stolen credentials from old infostealer infections, highlighting how basic MFA gaps continue to enable massive breaches
AI-generated code contains 1.7x more security vulnerabilities than human-written code, particularly struggling with error handling and password security implementations
41% of large enterprises accidentally hired fake candidates created with AI deepfakes, with nearly all organizations experiencing some form of AI impersonation attempts
RoboShadow is a cybersecurity platform that delivers daily vulnerability scans and automated fixes, helping businesses stay secure and compliant. With powerful integrations and continuous monitoring, it makes managing cyber risks simple and proactive.
Threat actor Zestix (alias Sentap) has compromised approximately 50 major global enterprises by exploiting credentials harvested from infostealer malware infections on employee devices, targeting ShareFile, OwnCloud, and Nextcloud platforms across aviation, defense, healthcare, and government sectors.
The breaches occurred due to organizations failing to enforce Multi-Factor Authentication (MFA), allowing attackers to access corporate file-sharing portals using valid username and password combinations extracted from years-old infostealer logs without requiring sophisticated exploits or session hijacking techniques.
Notable victims include Iberia Airlines (77GB of aircraft maintenance data), Intecro Robotics (11.5GB of ITAR-controlled defense blueprints), Maida Health (2.3TB of Brazilian Military Police medical records), and Pickett & Associates (139GB of critical utility infrastructure LiDAR files).
Get this kind of analysis every week. Subscribe to the Mandos Brief.
The CVE-2026-21877 vulnerability affects both self-hosted and cloud versions of the n8n workflow automation platform, allowing authenticated users to execute untrusted code and potentially achieve full system compromise.
Impacted versions include n8n >= 0.123.0 and < 1.121.3, with the fix available in version 1.121.3 released in November 2025, discovered by security researcher Théo Lelasseux.
Administrators can mitigate the risk by disabling the Git node and restricting access for untrusted users if immediate patching to version 1.121.3 or later is not feasible.
Cloudflare investigated a BGP route leak by Venezuelan ISP CANTV (AS8048) on January 2nd, finding it was likely caused by insufficient routing export policies rather than malicious intent, with the leaked routes being heavily prepended making them less attractive for traffic routing.
Analysis revealed CANTV has experienced eleven route leak events since December, all following the same pattern of redistributing customer routes to providers, indicating systemic configuration issues rather than targeted attacks despite speculation about government surveillance capabilities.
The incident highlights the need for better BGP security mechanisms like ASPA (Autonomous System Provider Authorization) and RFC9234 implementation, as traditional RPKI Route Origin Validation would not have prevented this path-based anomaly affecting Venezuelan telecom prefixes.
A survey of 668 IT and cybersecurity leaders shows that nearly all organizations (99%) have experienced AI deepfake or impersonation attempts, with 45% encountering them frequently and 41% admitting to hiring fake candidates only discovered after onboarding.
While 85% of leaders believe deepfake incidents would cause significant reputational damage, many overestimate their detection capabilities and rely on vulnerable authentication methods like voice/video calls without proper verification protocols.
Organizations are struggling to adapt their identity and access management strategies, with only half implementing authentication requirements for video conferences despite 80% using voice/video calls for identity verification in business processes.
Phishing attacks (51%) and DDoS attacks (49%) were the most common threats experienced by organizations, with 83% of security leaders reporting increased cyberattacks over the past 12 months.
AI-powered social engineering attacks emerged as the top concern (55%), yet only 35% of leaders feel their defenses are highly effective against these threats, creating a significant preparedness gap.
Organizations are increasing cybersecurity headcount by more than 20% over the next 2–3 years (55% of respondents) while 67% are partnering with IT services providers to address talent shortages and enhance capabilities.
A survey of 540 software security leaders found that 95% of organizations use AI tools for software development, but only 24% perform comprehensive IP, license, security, and quality evaluations for AI-generated code, exposing organizations to significant supply chain risks.
Organizations with effective dependency tracking and management show 85% preparedness for securing open source software compared to 57% across all respondents, while those implementing automatic continuous monitoring remediate critical vulnerabilities within a day 60% of the time versus 45% overall.
The study reveals that 65% of organizations experienced a software supply chain attack in the past year, with malicious dependencies (30%), unpatched vulnerabilities (28%), and zero-day vulnerabilities (27%) being the most common attack vectors driving increased compliance requirements.
A candidate was rejected for an IT support role after expressing long-term cybersecurity ambitions, with the hiring manager stating "this role is not for you" and citing concerns about employee retention.
The rejection occurred despite positive feedback from initial interviews with HR and the IT team, highlighting disconnect between different levels of management regarding candidate career goals and organizational needs.
Community responses emphasized the importance of tailoring interview answers to focus on the immediate role rather than future aspirations, with many suggesting candidates should frame cybersecurity interests as value-adds rather than primary objectives when applying for entry-level positions.
A laid-off senior cybersecurity analyst with 8 years experience discusses pivoting to engineering roles due to widespread analyst position eliminations and offshoring to India, Canada, and UK markets.
Industry professionals report that cybersecurity analyst roles are increasingly automated through AI agents while engineering positions show greater job stability and resistance to outsourcing trends.
Multiple commenters confirm the market saturation stems from bootcamp graduates with no IT experience, university programs producing unqualified candidates, and big tech layoffs flooding the mid-senior level job market.
Experienced cybersecurity professionals with advanced certifications like CISSP and OSCP are reporting months of unemployment, with some candidates applying to hundreds of positions without success due to economic uncertainty and reduced corporate spending on security roles.
HR departments and AI-powered resume screening systems are creating a significant barrier between qualified candidates and hiring managers, often filtering out experienced professionals while struggling to identify truly qualified applicants for technical cybersecurity positions.
The market has become oversaturated with entry-level candidates from bootcamps and degree programs, while companies simultaneously demand senior-level experience for most roles and increasingly outsource positions to lower-cost international markets.
OpenAI's enterprise customer base grew to over 1 million businesses with ChatGPT message volume increasing 8x year-over-year and API reasoning token consumption per organization rising 320x, indicating deeper workflow integration through Custom GPTs and Projects.
Enterprise workers report saving 40-60 minutes per day using AI tools, with 75% of users completing new technical tasks like coding and data analysis previously outside their role boundaries, demonstrating measurable productivity and business impact.
Growth accelerated globally across industries with the median sector expanding over 6x year-over-year, led by technology (11x), healthcare (8x), and manufacturing (7x), while a widening gap emerges between AI leaders and laggards in adoption intensity.
The OWASP Agentic Security Initiative has published the first comprehensive security framework for AI agent applications, identifying 10 critical threat categories including agent goal hijack, tool misuse, and privilege escalation risks.
Key vulnerabilities include supply chain attacks through poisoned tools and models, insecure inter-agent communication that enables message tampering, and cascading failures where a single compromise can spread across interconnected agent systems.
The framework addresses emerging risks like rogue agents that can self-replicate and act as autonomous insider threats, plus human-agent trust exploitation where attackers manipulate users into approving unsafe actions through deceptive agent outputs.
Analysis of 470 GitHub pull requests revealed that AI co-authored code contains 1.7x more issues overall compared to human-written code, with logic and correctness problems showing a 75% higher prevalence and security vulnerabilities appearing 1.5x more frequently.
AI-generated code particularly struggles with error handling (2x higher), improper password handling (1.9x higher), and excessive I/O operations (8x higher), creating risks that are directly tied to real-world production outages and incidents.
Code quality issues like readability problems (3.2x higher) and formatting errors (2.7x higher) significantly increase review time and technical debt, while critical and major severity findings occur 1.4–1.7x more often in AI-authored submissions.
Cisco is reportedly in advanced negotiations to acquire New York-based cybersecurity startup Axonius for $2 billion, though Axonius has denied being in talks and stated their strategy is to remain independent.
This would mark Cisco's third security acquisition in five months, following purchases of Aura Asset Intelligence and NeuralFabric, as the company continues expanding its cybersecurity portfolio.
Axonius provides an asset management and security platform that covers cyber assets, software, SaaS applications, and identities from a single cloud-based interface for enterprise security teams.
CrowdStrike is purchasing identity management startup SGNL for nearly $740 million to enhance identity security capabilities on its Falcon platform as AI-powered cyberattacks become more sophisticated.
The acquisition is part of a broader industry trend where cybersecurity providers are consolidating capabilities, following major deals like Palo Alto Networks' $25 billion CyberArk purchase and Google's $32 billion Wiz acquisition.
SGNL, founded in 2021 with backing from Cisco and Microsoft, specializes in managing human and AI identity access requests and real-time risk assessment, addressing what has become one of the most significant attack vectors in modern cybersecurity.
Data security startup Cyera secured $400 million in Blackstone-led Series F funding, reaching a $9 billion valuation to develop security controls for autonomous AI agents that traditional user authentication and static permissions cannot adequately protect.
The company is transitioning from data discovery and protection to building a unified control plane that governs how AI systems access, use, and behave with sensitive enterprise data through behavioral analysis and granular access controls.
Cyera plans to use the funding to accelerate product innovation in agentic AI security, strengthen competitive positioning against legacy vendors, and leverage Blackstone's connections to expand strategic partnerships across multiple platforms and cloud environments.
Identity admin platform with virtualized control plane for access mgmt
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
How do you like Mandos Brief?
TerribleBadOkayGoodExcellent
Thank you!
Your input helps me make Mandos even better.
P.S. I am working with select B2B companies on the exact challenges covered above. Calendar link here if you'd like to chat.
Talk to you in the next one.
Best,
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.