Brief

Brief #87: AWS S3 Ransomware, Google's 97% Automated Threat Detection, Microsoft AI Red Team Report

Critical AWS S3 ransomware campaign discovered. Snyk uploads suspicious NPM packages. Microsoft UEFI vulnerability enables Secure Boot bypass.

9 min read
Mandos Brief week 3 of 2025 - newsletter for cybersecurity professionals and leaders

Happy Sunday!

Hope you're having a relaxing weekend! While you were busy wrapping up another week, the cybersecurity world has been buzzing with some fascinating developments that I think you'll want to hear about.

- Snyk stirred up controversy with suspicious NPM packages targeting Cursor AI (drama in the DevSec world!)
- A clever new ransomware technique is using AWS's own encryption against S3 buckets
- Google shared how they automated 97% of their threat detection (and yes, it's as cool as it sounds)

Plus plenty more stories about AI security, career trends, and new tools that caught my attention this week. Let's dive in!

Your feedback shapes Mandos Brief and I'd love to hear your thoughts about the content I share.

INDUSTRY NEWS

Snyk Uploads Suspicious NPM Packages Targeting Cursor AI Code Editor

New Ransomware Campaign Encrypts AWS S3 Buckets Using Native SSE-C Feature

Microsoft-Signed UEFI Application Vulnerability Enables Secure Boot Bypass (CVE-2024-7344)

LEADERSHIP INSIGHTS

Google Reveals Internal Threat Detection Framework Built on Automation and Engineering

2025 World Economic Forum Report Highlights Growing Cyber Complexity and Inequity

CISO Role Evolution Shows Growing Strategic Influence and Career Opportunities in 2025

Discover my collection of industry reports, guides and cheat sheets in Cyber Strategy OS.

CAREER DEVELOPMENT

Current Cybersecurity Job Market Demands Higher Qualifications and Technical Skills

Threat Hunting Role Varies by Organization Size and Security Maturity

OSINT Skills Offer Growing Career Opportunities in Cybersecurity

AI & SECURITY

Microsoft AI Red Team Shares Key Lessons from Testing 100+ Generative AI Products

Databricks Develops AI System for Automated Vulnerability Detection and Prioritization

Deep Instinct Launches AI-Powered Malware Analysis Tool Using Amazon Bedrock

MARKET UPDATES

Cisco Launches AI Defense Tool to Secure Enterprise AI Systems

Orca Security Launches Agentless eBPF-Based Sensor for Cloud-Native Security

Czech Startup Wultra Raises €3M to Develop Post-Quantum Authentication for Banks

TOOLS

FutureFeed

A tool for achieving and proving compliance with NIST 800-171 and CMMC cybersecurity requirements.

Darktrace

Darktrace is a cyber security solution that uses AI to detect and prevent cyber attacks in real-time.

InfinityAI

Infinity Platform / Infinity AI is an AI-powered threat intelligence and generative AI service that combines AI-powered threat intelligence with generative AI capabilities for comprehensive threat prevention, automated threat response, and efficient security administration.


Before you go

If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!

For more frequent cybersecurity leadership insights and tips, follow me on LinkedInBlueSky and Mastodon.

Best, 
Nikoloz

Share This Post

Check out these related posts

Brief #86: BeyondTrust API Exploit, Microsoft vs AI Hackers, OWASP Non-Human Identity Risks

  • Nikoloz Kokhreidze
by Nikoloz Kokhreidze | | 8 min read

Brief #85: Windows LDAP Exploit, Tenable Nessus Outage, Security Leadership Pay

  • Nikoloz Kokhreidze
by Nikoloz Kokhreidze | | 9 min read

Brief #84: Chrome Extension Attacks, Amazon Redshift Vulns, PAN-OS DoS

  • Nikoloz Kokhreidze
by Nikoloz Kokhreidze | | 9 min read