Happy Sunday!
I hope this Brief finds you well and ready to tackle the week ahead.
In this edition, I am covering:
- French ISP 'Free' faces massive data breach affecting 19M customers
- Google reveals AI now generates 25% of their new code
- New survey shows concerning CISO burnout trends with 25% considering career changes
And much more.
Fabric by BlackStork
Fabric Platform streamlines cybersecurity reporting processes, offering a comprehensive solution for teams seeking efficiency and consistency.

INDUSTRY NEWS
French ISP 'Free' Hit by Data Breach Exposing 19M Customer Records
-
Threat actor "drussellx" accessed Free's internal management tool and attempted to sell two databases on Dark Web forums containing over 19M customer accounts and 5M international bank account details
-
Free confirmed no passwords, payment cards, emails, SMS, or voicemails were compromised in the breach, though personal data was accessed. The company's services remain unaffected by the intrusion
-
This incident follows a pattern of increasing APT attacks targeting ISPs, with groups like Salt Typhoon and Evasive Panda exploiting these networks to gather customer data and establish persistence for further campaigns
Multiple Critical Vulnerabilities Found in NetIQ iManager Enable Remote Code Execution
-
Yahoo's Paranoid team discovered 11 vulnerabilities in OpenText's NetIQ iManager, including authentication bypass (CVE-2024-3487), command injection (CVE-2024-3483), and arbitrary file upload (CVE-2024-3488) flaws.
-
When chained together, these vulnerabilities allow unauthenticated attackers to compromise iManager instances remotely by tricking users into visiting malicious websites, potentially gaining administrator credentials.
-
The flaws were patched in April 2024, but are particularly concerning as iManager holds a privileged position in managing directory services that maintain user account information and serve as a source of truth for downstream applications.
Critical Authentication Flaws in Mitsubishi and Rockwell Factory Systems Enable RCE
-
CVE-2023-6943 in Mitsubishi Electric automation software allows attackers to bypass authentication and achieve remote code execution through malicious library exploitation, carrying a critical CVSS score of 9.8
-
Rockwell Automation's ThinManager platform contains authentication bypass vulnerability (CVE-2024-10386) enabling database manipulation through crafted network messages
-
Multiple affected ICS products require immediate patching as CISA warns of increased nation-state targeting of smart factories by Russian and Chinese APTs

LEADERSHIP INSIGHTS
CISO Burnout Crisis: 25% Consider Leaving Roles Due to Stress
-
Survey reveals 93% of CISOs and IT Security Decision Makers cite overwhelming stress as primary reason for considering career changes, with most working an additional 9 hours beyond contracted time weekly.
-
Rising concerns about AI-enabled attacks (42%) and ransomware (37%) are key stressors, compounded by insufficient budgets and resources reported by 41% of security leaders.
-
Concerning coping mechanisms emerge with 45% of respondents using substances to manage work pressure, while organizations attempt to address burnout through flexible hours (64%) and remote work options.



