-
First-ever API honeypot deployment across 14 global locations shows new APIs are discovered and targeted in under 2 minutes, with port 80 (19%) being most probed, followed by unexpected port 26657 for blockchain services.
-
Study reveals 54.4% of total attacks specifically target APIs over web applications, with common endpoints like "/status" and "/info" being rapidly discovered. Top attack types include authentication checks (26%) and service discovery attempts (34%).
-
Analysis of 337 unique API requests shows attackers frequently probe for known services like Docker, Grafana, and Prometheus, with 40% of top-50 common API requests attempting to exploit specific CVEs.
-
CISA released BOD 25-01 requiring Federal Civilian Executive Branch agencies to implement specific Secure Cloud Business Applications (SCuBA) configurations by June 20, 2025, focusing on Microsoft 365 services including Azure AD, Defender, Exchange Online, and Teams.
-
The directive mandates strict security controls including blocking legacy authentication, enforcing phishing-resistant MFA, implementing strict external sharing policies, and enabling comprehensive audit logging across cloud services.
-
While mandatory only for federal agencies, CISA strongly recommends all organizations adopt these SCuBA baseline configurations and utilize the provided assessment tools to enhance their cloud security posture and reduce organizational risk.
-
Current CISO responsibilities deemed unsustainable with average tenure under 2 years, facing expectations to be universal security experts while managing limited resources and authority to implement change across organizations.
-
Key survival strategies include ruthless risk prioritization, delegation through strong team building, and shifting focus from complete risk elimination to effective risk management frameworks.
-
Organizations need structural changes including proper budget allocation, strategic involvement of CISOs in planning, and reformed accountability models to prevent CISOs from becoming scapegoats during security incidents.
Discover my collection of industry reports, guides and cheat sheets in Cyber Strategy OS.
-
Most security incidents (approximately 90%) stem from internal mishaps rather than sophisticated attacks - including email disclosures, misconfigurations, lost devices, and users falling for phishing attempts.
-
The role involves significant administrative overhead, with professionals spending considerable time on documentation, attending meetings, and managing routine tasks like incident reports, security assessments, and control reviews.
-
Career success requires constant learning, dealing with limited budgets, and managing stress from repetitive tasks, while many incident response recommendations and root cause analyses may not lead to meaningful organizational changes.
-
Deputy CIO Jerry Cochran of Pacific Northwest National Laboratory advocates for empathy as a crucial leadership principle, emphasizing its importance in both communication with teams and understanding adversarial perspectives.
-
With over 25 years in cybersecurity experience across military, public, and private sectors, Cochran emphasizes that effective defense requires thinking like an attacker to better anticipate and prevent potential threats.
-
In his role overseeing the CISO office and enterprise IT operations at the DOE-managed laboratory, Cochran promotes a balanced approach combining empathetic leadership with data-driven decision-making strategies.
-
High volume of daily alerts and false positives creates unsustainable pressure on SOC analysts, leading to widespread burnout and high turnover rates, with constant fear of missing critical security events.
-
Integration of AI solutions proposed to transform role by automating repetitive tasks, including threat intelligence enrichment, alert triage, and 24/7 monitoring, allowing analysts to focus on proactive threat hunting.
-
Organizations must implement structured career development through mentorship, specialized training, and strategic involvement in decision-making to retain talent and create sustainable career paths for SOC analysts.
-
Initial investigation found suspicious 49-character document IDs that didn't match standard hash lengths, with first characters showing patterns and last digits appearing sequential for identical file uploads.
-
Using Claude 3.5 to analyze 100 generated IDs revealed that first 8 characters contained hex timestamps, enabling prediction of document IDs through timestamp manipulation in a sandwich attack.
-
The vulnerability allowed unauthorized access to other users' documents due to improper authorization mapping between user cookies and document IDs, demonstrating how AI can accelerate pattern recognition in security research.
-
The security startup landscape has seen significant growth in agentic solutions, particularly in three key areas: incident triage automation, code vulnerability analysis, and security copilots. Companies like Dropzone.AI and CommandZero are focusing on SOC automation to reduce manual analysis workload.
-
Code security solutions are emerging to address the increasing volume of machine-generated code, with companies like Pixee AI acting as automated security engineers to identify vulnerabilities and propose fixes. These solutions are expanding to include configuration and deployment script analysis.
-
Major platforms like Microsoft Security Copilot and SentinelOne's Purple AI are leading the natural language security interface movement, while startups like Simbian AI are developing specialized agents for specific security tasks, focusing on ecosystem integration and workflow automation.
-
Aikido Intel, powered by LLMs, has identified 511 undisclosed vulnerabilities in open-source packages since January, revealing that 67% of security patches are implemented without public disclosure, including critical severity issues.
-
Most common unreported vulnerabilities include cross-site scripting (14.8%) and sensitive information exposure (12.3%), with major projects like Axios (56M weekly downloads) and Apache ECharts silently patching security issues.
-
The tool analyzes package changelogs using dual LLM models with human security engineer verification, finding that disclosed vulnerabilities take an average of 27 days from patch release to CVE assignment, with some taking up to 9 months.
-
SnapAttack's threat detection platform will be integrated into Cisco's Splunk security portfolio, combining threat intelligence, attack emulation, and behavioral analytics to identify network vulnerabilities proactively.
-
The platform will enhance Splunk's SIEM capabilities by providing curated detection content discovery prioritized by threat activity and continuous validation of deployed security content.
-
This marks Cisco's fourth acquisition in 2024, following their $28 billion Splunk acquisition in 2023, demonstrating continued focus on security and AI technology investments.
-
Bureau's platform unifies compliance, fraud prevention, and credit risk management into a single solution, leveraging device intelligence and behavioral AI to surpass traditional rule-based systems.
-
The Series B funding round was led by Sorenson Capital Partners, with participation from PayPal Ventures and other investors, bringing total funding to $50.7M across four rounds.
-
Platform capabilities include money mule detection, account takeover prevention, and fraud ring detection, serving banking, fintech, gaming, and e-commerce sectors through a unified API approach.
-
Arctic Wolf will integrate Cylance's AI-powered endpoint protection into their Aurora platform, aiming to reduce alert fatigue and enhance their open-XDR capabilities, with the deal including $80M cash at closing and $40M after one year, plus 5.5M Arctic Wolf shares.
-
The acquisition strengthens Arctic Wolf's position in the security operations market by adding native endpoint security to their portfolio, making them the only provider supporting over 15 endpoint solutions through their open platform architecture.
-
BlackBerry retains its Secure Communications portfolio (including UEM, AtHoc, and SecuSUITE) while gaining benefits as both a reseller for government customers and a stakeholder in Arctic Wolf's future growth.
Improve Your Cybersecurity Leadership
Join security leaders receiving the most critical insights, strategies, and resources to stay ahead in cybersecurity.
I will never spam or sell your information.
A platform that helps companies automate the management of their SaaS identities and applications, providing visibility, security, and compliance across the organization's SaaS ecosystem.
Provides breach and attack simulation products for security control validation, offering three different products to meet the needs of organizations of various sizes and maturity levels.
SerpApi is a Google Search API that allows you to scrape Google and other search engines with ease.
Before you go
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
For more frequent cybersecurity leadership insights and tips, follow me on LinkedIn, BlueSky and Mastodon.
Best,
Nikoloz