Brief

Brief #85: Windows LDAP Exploit, Tenable Nessus Outage, Security Leadership Pay

Critical vulnerabilities in Windows Domain Controllers enable remote attacks, while VW subsidiary exposes 460,000 EV locations. RAND reveals AI security gaps

9 min read
mandos brief cybersecurity newsletter covering week 1 of 2025

Happy New Year!

Hope you're having a great start to 2025! While we were all busy with holiday celebrations and new year resolutions, the cyber world didn't take a break (does it ever? ). I've rounded up some interesting stories that caught my eye, and I thought you might want to know about them too.

Plus plenty more insights on AI security, market moves, and practical tools to make your security work easier. Let's dive in!

Your feedback shapes Mandos Brief and I'd love to hear your thoughts about the content I share.

INDUSTRY NEWS

Volkswagen Subsidiary Cariad Exposes Location Data of 460,000 EV Vehicles

Tenable Nessus Agent Outage Caused by Faulty Plugin Updates

Critical Windows LDAP Vulnerabilities Enable DoS and RCE on Domain Controllers

LEADERSHIP INSIGHTS

Cost-Saving Strategies for Enterprise Cybersecurity Budgets Revealed

AWS OIDC Integration Security: Critical Conditions Required to Prevent Unauthorized Access

Mastercard Report Shows Small Businesses Score Low on Cybersecurity Readiness

Discover my collection of industry reports, guides and cheat sheets in Cyber Strategy OS.

CAREER DEVELOPMENT

Security Professional Returns to SOC Role Due to Executive-Level Burnout

Entry-Level Cybersecurity Certifications Guide: Top 12 Options for Career Launch

AI & SECURITY

RAND Report Outlines Framework for Securing AI Model Weights Against Theft

AI Factory Security Requires API Protection as Foundation

AI Application Security Blueprint Outlines Six-Layer Defense Framework

MARKET UPDATES

Major Cybersecurity M&A Deals in 2024 Topped by $28B Cisco-Splunk Transaction

Digital ID Startup Ver.ID Raises €2M to Support EU eIDAS 2.0 Compliance

Rubrik Gains FedRAMP Approval and Expands Cloud Security Services

TOOLS

Syft

A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

Grype

Grype is a vulnerability scanner for container images and filesystems that scans for known vulnerabilities and supports various image formats.

Anchore Enterprise

Anchore Enterprise is a platform that protects and secures software supply chains end-to-end.


Before you go

If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!

For more frequent cybersecurity leadership insights and tips, follow me on LinkedInBlueSky and Mastodon.

Best, 
Nikoloz

Share This Post

Check out these related posts

Brief #86: BeyondTrust API Exploit, Microsoft vs AI Hackers, OWASP Non-Human Identity Risks

  • Nikoloz Kokhreidze
by Nikoloz Kokhreidze | | 8 min read

Brief #84: Chrome Extension Attacks, Amazon Redshift Vulns, PAN-OS DoS

  • Nikoloz Kokhreidze
by Nikoloz Kokhreidze | | 9 min read

Brief #83: TP-Link Ban, LastPass Breach Impact, SOC Analyst Crisis

  • Nikoloz Kokhreidze
by Nikoloz Kokhreidze | | 9 min read