Brief #139: AWS SDK Supply Chain Flaw, AI Cuts Breach Time to 25 Min, CrowdStrike Buys Seraphic
Microsoft patches actively exploited Windows flaw enabling ransomware bypass. 99% of organizations running production AI experienced attacks. Change Healthcare breach cost $1.15B, exposed 190M records.
Welcome to the Mandos Brief: Strategic insights to help you stay ahead of threats and the market.
In this week's analysis:
AWS SDK Supply Chain (CodeBreach): Researchers found a way to compromise the JavaScript SDK powering 66% of cloud environments. Action: Review your GitHub ACTOR_ID filters and regex patterns in CI/CD pipelines before someone else finds your gaps.
AI Attack Explosion: Daily cyberattacks jumped from 2.3 million to 9 million in one year thanks to AI tools making attacks faster and easier. Reality Check: Your security team is now racing against AI-powered adversaries who can breach systems in 25 minutes instead of 44 days.
CrowdStrike Buys Seraphic: The endpoint giant is moving into browser security, signaling the platform consolidation trend is accelerating. Strategic Insight: Security vendors who don't evolve into unified platforms will get squeezed out as customers demand fewer vendors, not more tools.
A flaw in AWS CodeBuild authentication controls created systemic supply chain risk, where compromise of a single CI/CD pipeline could have cascaded into widespread customer impact through the AWS Console and SDKs used across the enterprise cloud ecosystem.
The vulnerability enabled unauthenticated privilege escalation, allowing attackers to steal GitHub credentials and potentially inject malicious code into trusted software dependencies, representing a high-impact scenario for software integrity, regulatory exposure, and customer trust.
The incident highlights the need for CISO oversight of CI/CD security governance, including third-party build systems, identity validation controls, and approval gates, as cloud-native development pipelines remain a prime target for nation-state and criminal actors.
The volume and severity of vulnerabilities underscore persistent endpoint risk across enterprise Windows environments, reinforcing the importance of disciplined patch governance and executive visibility into remediation timelines.
The actively exploited Desktop Window Manager flaw demonstrates how low-level information disclosure can be weaponized to bypass modern defenses, increasing the likelihood of ransomware, espionage, or lateral movement attacks if left unpatched.
Secure Boot and driver-related fixes highlight firmware and trust-chain weaknesses that CISOs must factor into risk assessments, especially for regulated industries relying on device integrity assurances.
The aggregation of multiple breach datasets into a single exposed repository illustrates the long-tail risk of third-party data brokers, where legacy incidents continue to amplify impact years after initial compromise.
The combination of healthcare, financial, and government registry data represents high regulatory and reputational risk, particularly under GDPR, with downstream consequences for organizations whose data feeds such ecosystems.
This incident reinforces the need for CISO-led data lifecycle and vendor risk management, including strict data minimization, contractual controls, and monitoring of how organizational data may be resold or recombined by external entities.
Cyberattacks have surged from 2.3 million to nearly 9 million daily in one year due to AI tool adoption, with breach times reduced from 44 days in 2021 to as little as 25 minutes using AI assistance.
Over half of production workloads now run in cloud environments across an average of six providers, with 61% of organizations operating at extensive cloud integration or fully cloud-native states, and APIs experiencing a 41% year-over-year increase in attacks.
While 99% of organizations use GenAI for coding support and 75% run AI in production, 99% have experienced at least one AI system attack in the past year, with one in five organizations reporting high or critical issues remaining in production longer than 30 days.
The Mandos Brief
Get this kind of analysis every week. Subscribe to the Mandos Brief.
IDC surveyed 925 organizations across nine countries and found that only 10% achieved "exceptional" application security maturity, with these organizations being 1.9x less likely to experience data breaches and 3.6x more likely to see 20%+ improvements in app availability.
The research reveals that midsize organizations with 1,000–2,499 employees or $500M–$999M revenue have the highest concentration of exceptional programs (35.5% and 38.7% respectively), suggesting they have optimal resources without the complexity challenges of larger enterprises.
Exceptional organizations demonstrate integrated security approaches with automated CI/CD pipeline controls, unified platform strategies combining WAF, API, and runtime protections, and embedded security culture where development teams own security outcomes rather than treating it as an external function.
Agentic AI represents the next evolution beyond current generative AI tools, promising autonomous agents that can plan, act, and use tools independently, potentially transforming both cybersecurity defense and attack capabilities in 2025.
Ransomware attacks increased 13% year-over-year in 2024 with the largest payment ever recorded at $75 million to Dark Angels group, while the USA became the target of 51% of all known attacks.
The Change Healthcare attack exposed 190 million people's health information and cost an estimated $1.15 billion, demonstrating the devastating impact of supply chain attacks on critical infrastructure.
Stanford and Yale researchers demonstrated that major LLMs including GPT, Claude, Gemini, and Grok can reproduce near-complete texts of copyrighted books like Harry Potter and The Great Gatsby, contradicting AI companies' claims that models don't store copies of training data.
The research supports describing AI models as lossy compression algorithms rather than learning systems, with models functioning as databases that store tokens and contexts from training materials and can reproduce original content through strategic prompting.
This memorization capability creates significant copyright liability risks for AI companies, potentially resulting in billions in infringement judgments, court-ordered product removal, or requirements to retrain models from scratch with properly licensed content.
Varonis Threat Labs discovered the Reprompt vulnerability that allows attackers to steal personal data from Microsoft Copilot Personal users with a single click on a malicious link, bypassing all safety controls.
The attack uses three techniques including Parameter-to-Prompt injection via the 'q' URL parameter, double-request methods to bypass safeguards, and chain-request techniques for continuous data exfiltration.
Microsoft has patched the vulnerability as of January 14, 2026, and enterprise customers using Microsoft 365 Copilot are not affected by this attack vector.
Security researcher discovered that Claude's "Package managers only" network setting allows attackers to upload files to their own Anthropic accounts using indirect prompt injection, enabling exfiltration of up to 30MB of user data per upload.
The attack works by tricking Claude into reading sensitive data (like chat histories), saving it to a file in the Code Interpreter sandbox, then uploading it via the Files API using the attacker's API key instead of the victim's account.
Anthropic initially dismissed this as a model safety issue rather than a security vulnerability, though their documentation acknowledges data exfiltration risks and recommends monitoring Claude's behavior when network access is enabled.
CrowdStrike signed a definitive agreement to acquire Seraphic Security, the leader in browser runtime security, to extend Falcon platform protection directly into any browser without forcing users to change their preferred browser.
The acquisition will integrate Seraphic's in-session browser protection with CrowdStrike's endpoint telemetry and SGNL's continuous authorization to create unified Next-Gen Identity Security across endpoints, browsers, and cloud environments.
Key capabilities include protecting enterprise AI applications from data exfiltration, enforcing zero trust controls during active browser sessions, and securing unmanaged devices through browser-layer protection without requiring full endpoint agents.
The funding round was led by Sound Ventures with participation from Fin Capital, Samsung Ventures, Qualcomm Ventures, and Forgepoint Capital Partners, supporting WitnessAI's mission to provide visibility and control over enterprise AI interactions across LLMs and autonomous agents.
WitnessAI announced two new platform capabilities to secure AI agents: monitoring agent activity including MCP server access and data sharing, plus extending application protection to block attacks and malicious prompts before they reach agents.
The company reported 500% ARR growth in the past 12 months and expanded headcount by 5x, with deployments across leading financial services firms, utilities, airlines, automakers, retailers, and telecoms globally.
The Belgian cybersecurity startup secured $60 million in Series B funding led by DST Global to develop autonomous self-securing software that addresses the security challenges created by AI-generated code and continuous deployment cycles.
Aikido has become the fastest European cybersecurity company to reach unicorn status, experiencing 5x revenue growth and nearly 3x customer growth while serving over 100,000 teams including Premier League, Revolut, and SoundCloud.
The company recently launched Aikido Attack, an AI penetration testing tool that deploys specialized agents to hunt vulnerabilities and validate exploitability, as part of their unified platform covering code, cloud, and runtime security.
API-based email security platform for Microsoft 365 environments
Thank you for reading this week's brief.
If you found this brief valuable, please forward it to one peer who is currently building or securing a B2B startup.
I’m constantly refining this intelligence for you. Was this week's market analysis useful?
Just hit Reply and let me know, I read every message.
P.S. Whenever you’re ready, there are two ways I can help you:
Founders: Need a Fractional CISO to unblock enterprise deals or lead your cybersecurity maturity journey? Book a Discovery Call
Vendors: Want to get your product in front of 15k+ security researchers on CybersecTools? Submit Your Product
Talk to you in the next one.
Nikoloz
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.