Brief #121: Apple Memory Integrity, HybridPetya UEFI Bypass, npm Packages Compromised
AI agents now exploit zero-days in under 10 minutes while energy sector attacks surge 586%. Web3 hackers earn millions as traditional security salaries lag behind.

Happy Sunday!
The renewable energy transition is turning into a cybersecurity nightmare for European utilities, with attacks jumping 586% last year alone - seems like going green comes with some unexpected red flags.
In this week's brief:
- HybridPetya ransomware surfaces with UEFI Secure Boot bypass capabilities, marking the fourth bootkit of its kind we've seen
- Hexstrike-AI drops as a game-changing framework that lets threat actors orchestrate 150+ AI agents to exploit targets in under 10 minutes
- Web3 white hats are making millions from bug bounties while traditional cybersecurity salaries look increasingly modest in comparison
A quick note before we dive in.
MCP Access
Query this dataset from your own AI.
Point Claude, ChatGPT, or Cursor at the Mandos MCP server and ask it about any cybersecurity vendor, product, funding round, or acquisition. Self-serve, pay only for what you pull.
See MCP access

