Happy Sunday and Happy Holidays!
Before diving into today's Brief, I want to express thank you all for your incredible support and engagement throughout 2024.
This year has been remarkable – Mandos community has grown more than 450%, thanks to your active participation and valuable feedback, which has helped me shape the format and enhance the value I want to deliver to you.
Your continued input remains invaluable, and I'm truly honored to serve our community of cybersecurity leaders, professionals and enthusiasts.
Thank you!
Now, let's get into this week's Brief. I hope you're energized and ready for the challenges and opportunities in the new year!
In this edition, I am covering:
- A widespread Chrome extension compromise affecting 140,000+ users through supply chain attacks
- New research on emerging threats for 2025, including AI-driven attacks and evolving ransomware tactics
- Concerning findings about security team burnout, with 25% of leaders considering leaving the field
And much more.
Your feedback shapes Mandos Brief and I'd love to hear your thoughts about the content I share.
InfoSecHired
Cybersecurity job market is hyper-competitive and standing out is harder than ever.
InfoSecHired's AI-powered platform helps you break through the noise with perfectly tailored resumes and applications in just 60 seconds. Built by cybersecurity hiring managers, InfoSecHired delivers 4x higher interview success rates by optimizing every application for ATS systems while highlighting your most relevant skills and experience.

INDUSTRY NEWS
Chrome Extension Supply Chain Attack Impacts Multiple Security Tools
-
Cyberhaven's Chrome extension was compromised through a phishing attack on an admin account, allowing attackers to publish a malicious version that steals session data and cookies through cyberhavenext[.]pro domain.
-
Investigation revealed four additional compromised extensions (Internxt VPN, VPNCity, Uvoice, ParrotTalks) affecting over 140,000 users combined, all containing similar malicious code for data exfiltration.
-
Affected users should upgrade to versions released after December 26, reset passwords, clear browser data, and consider complete extension removal if uncertain about security status.




