Brief #116: Microsoft Exchange RCE, Google Salesforce Breach, AI SOC Market

Nikoloz Kokhreidze

Nikoloz Kokhreidze

9 min read

RomCom exploits WinRAR zero-day for malware deployment. North Korean UNC4899 steals millions in cryptocurrency through sophisticated cloud attacks.

mandos brief newsletter for cybersecurity leaders and professionals

Happy Sunday! 

The North Korean cryptocurrency heist story this week really shows how social engineering remains one of our biggest blind spots. Even sophisticated organizations are falling for fake freelance job offers that lead to multi-million dollar losses.

In this week's brief:

  • Microsoft disclosed a high-severity Exchange vulnerability that lets attackers silently escalate privileges in hybrid cloud setups
  • The AI SOC market is exploding with predictions that AI will handle 60% of SOC tasks by 2028 - but are we ready for that shift?
  • A SOC manager is struggling to transition back to technical work, highlighting a common career dilemma many of us face

Let's dive in.

Member-Only Content

Join Mandos to Continue Reading

Get instant access to this article and the Mandos Brief - your weekly 10-minute security leadership update.

Already a member? Sign in

Nikoloz Kokhreidze

Share With Your Network

Check out these related posts

Brief #149: FortiClient EMS Zero-Day, EU Commission 340GB Breach, LinkedIn BrowserGate
Apr 5, 2026 10 min read

Brief #149: FortiClient EMS Zero-Day, EU Commission 340GB Breach, LinkedIn BrowserGate

Brief #148: Telnyx PyPI Supply Chain Attack, F5 BIG-IP RCE Exploited, Databricks Launches Lakewatch SIEM
Mar 29, 2026 6 min read

Brief #148: Telnyx PyPI Supply Chain Attack, F5 BIG-IP RCE Exploited, Databricks Launches Lakewatch SIEM

Brief #147: Trivy CanisterWorm, Stryker Wiper Attack, XBOW Hits $1B
Mar 22, 2026 10 min read

Brief #147: Trivy CanisterWorm, Stryker Wiper Attack, XBOW Hits $1B