Happy Sunday!
Hope you're enjoying your weekend! While you were busy wrapping up another week, the cybersecurity world has been pretty active (as always!). I've picked some interesting stories that I think you'll want to know about.
- Chinese hackers managed to break into the U.S. Treasury using a stolen API key
- Microsoft is taking hackers to court for abusing their AI services
- A whopping 70% of CISOs are feeling the heat from personal liability risks
And there's plenty more where that came from. Grab your favorite Sunday beverage and dive in!
Your feedback shapes Mandos Brief and I'd love to hear your thoughts about the content I share.

INDUSTRY NEWS
Chinese State Actors Access U.S. Treasury Systems Using Stolen BeyondTrust API Key
-
Threat actors gained unauthorized access to Treasury Department systems through a compromised API key from BeyondTrust's Remote Support service, enabling them to reset passwords and access unclassified workstations and documents.
-
The incident, discovered on December 8th, has been attributed to a Chinese state-sponsored APT group based on evidence gathered during investigations by CISA and FBI.
-
BeyondTrust identified two vulnerabilities in their products, with CVE-2024-12356 receiving a critical CVSS score of 9.8 and being actively exploited in the wild, leading to its addition to CISA's Known Exploited Vulnerabilities catalog.
Azure Airflow Kubernetes Misconfiguration Enables Cluster-Wide Admin Access
-
Discovery of three security flaws in Azure Data Factory Apache Airflow integration allows attackers to gain unauthorized access through DAG files, potentially leading to complete cluster compromise.
-
Initial access requires write permissions to storage accounts via compromised credentials, but exploiting a misconfigured service account with cluster-admin privileges enables full control of the Kubernetes environment.
-
Attackers could leverage root access to deploy malicious pods, modify cluster nodes, and manipulate Geneva service logs, potentially maintaining persistent access while avoiding detection through falsified logging.
Banshee Stealer Malware Targets macOS Users Through GitHub and Phishing Campaigns
-
New stealer-as-a-service malware sold for $3,000 on underground forums targets macOS users, stealing credentials, crypto wallets, and sensitive data while using Apple's XProtect encryption algorithm to evade detection.
-
Malware distributed through phishing sites and malicious GitHub repositories masquerading as legitimate software (Chrome, Telegram, TradingView), with simultaneous campaigns targeting Windows users with Lumma Stealer.
-
Source code leaked in November 2024 leading to shutdown of public operations, but active campaigns continue with removal of Russian language check suggesting geographical expansion of targets.

LEADERSHIP INSIGHTS
OWASP Releases First Top 10 Non-Human Identities Security Risks List
-
The inaugural list focuses on securing service accounts, API keys, and automated system identities, with improper offboarding, secret leakage, and vulnerable third-party integrations identified as the top three risks.
-
Common security challenges include excessive permissions, poor credential management, and inadequate monitoring of non-human identities (NHIs) which can lead to widespread damage if compromised.
-
The rankings were developed using recent breach data, CVE scores, and industry surveys including Datadog's State of Cloud Security and the DBIR 2024 report.



