🎉 Happy Sunday and a Happy New Year!
As we wrap up 2025, I want to thank you for sticking around for Mandos Brief and reflect on this year.
In August, I embarked on a solopreneur journey focusing on two things that I always wanted to work on:
1) Advisory - using my expertise to help organizations improve their security, resilience, and enable business growth
2) Building a product - building CybersecTools into the number 1 destinations for security teams to discover cybersecurity products
The journey is never smooth and full of ups and downs, but the truth is that I love every moment I spend on these two items, learning a lot about sales, marketing, accounting (yes, even that), coding, AI agents, and, of course, catching up with the cybersecurity industry through this Brief.
There is one additional product I am working on currently to truly bring clarity to this crazy, overloaded market of cybersecurity products. This time, helping cybersecurity companies win customers and crush competition through data-based decisions they can't get anywhere else. Coming in Q1 2026, if you work for a cybersecurity company and are interested, let me know.
Wishing you and your loved ones a wonderful holiday season and all the best for 2026! 🥂
And back to the newsletter... Here is what you can expect in this brief:
- Cisco email security appliances are under active attack by UAT-9686 threat actors, with complete rebuilds being the only way to remove persistent backdoors from compromised systems
- NIST published its AI Cybersecurity Framework Profile for public comment, giving us the first structured approach to balance AI adoption with emerging security risks
- Nearly all CISOs now see hybrid infrastructure as their best bet for resilience, with 97% agreeing it beats putting all eggs in one cloud or on-premises basket

Industry News
Cisco Confirms Active Cyberattacks Against Email Security Appliances
-
The UAT-9686 threat actor is actively exploiting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances that have the Spam Quarantine feature exposed to the internet, allowing root privilege command execution.
-
Affected appliances show evidence of a persistence mechanism planted by attackers to maintain ongoing access, with Cisco recommending complete appliance rebuilding as the only viable option to eradicate the threat.
-
The attack specifically targets appliances with both the Spam Quarantine feature enabled and exposed to the internet, assigned CVE-2025-20393 with Critical severity affecting all releases of Cisco AsyncOS Software.