-
RBAC and identity management remain critical vulnerabilities, with default Kubernetes networking allowing unrestricted Pod-to-Node communication and widespread use of embedded long-lived secrets in container images.
-
Container image security coverage is a major challenge at scale, particularly in tracing vulnerabilities back to source code and ensuring proper signing and scanning policies are enforced before deployment.
-
The rise of AI workloads introduces new risks around model security, with researchers uncovering patterns of lateral movement between AI infrastructure components and resource hijacking for cryptomining activities.
-
100% of organizations have exposed secrets in their development environments, with 36% of secrets found outside source code in tickets, logs, and artifacts. On average, 33% of repositories contain exposed secrets.
-
AI security emerges as a significant concern with 46% of organizations using AI models in source code in risky ways, while misconfigurations affect 89% of organizations' pipelines.
-
Security testing shows major inefficiencies with 78% of organizations having duplicate SCA scanners and 85% having least privilege violations, while compliance rates with security frameworks range from just 33% (OWASP CI/CD) to 76% (ISO).
📖
Discover my collection of industry reports, guides and cheat sheets in ‣
Cyber Strategy OS.
-
BlackFog survey reveals 1 in 4 CISOs contemplate career change due to burnout and challenging work conditions, with most working 16.5 extra hours weekly while facing 24/7 on-call responsibilities
-
Key stressors include lack of authority despite full accountability, limited C-suite visibility, and increasing cyber threats from AI-powered attacks while dealing with resource constraints
-
Industry experts recommend negotiating better employment terms including D&O liability protection, developing business communication skills, and prioritizing mental health to extend CISO careers
-
Software engineering skills are increasingly vital for security roles, with multiple professionals noting that learning to code before transitioning to security provides significant career advantages, particularly in tech companies.
-
Career longevity and advancement are hindered by excessive company loyalty, with multiple respondents reporting 7-17 year tenures ending in layoffs despite dedicated service and strong performance.
-
Professionals emphasize the importance of maintaining proper work-life boundaries, noting that long on-call periods and 60-80 hour workweeks led to burnout without proportional career benefits.
-
Entry-level positions like SOC Analysts and Security Engineer roles range from $75K-95K base salary, with internships around $47K. Most common certifications at this level include Security+ and CySA+.
-
Mid-level positions with 3-5 years experience like Senior Security Engineers and Detection Engineers earn $100K-150K base salary. Common requirements include hands-on experience and certifications like CISSP.
-
Senior and leadership positions like Intelligence Analysts at FAANG companies can reach $300K+ total compensation including base salary, bonuses and stock options. Career progression focuses more on networking and reputation than certifications.
-
Wiz Research discovered an unauthenticated ClickHouse database belonging to DeepSeek AI, containing over 1 million log entries including chat histories, API secrets, and backend details accessible through ports 8123 and 9000.
-
The exposed database allowed full control over operations with no authentication required, potentially enabling attackers to execute arbitrary SQL queries and access sensitive information through the database's web interface.
-
The breach impacted DeepSeek's oauth2callback and dev subdomains, exposing log streams dating from January 6, 2025, before being promptly secured after responsible disclosure by Wiz Research.
-
Google has developed a new methodology to evaluate prompt injection risks in AI systems, focusing on both direct attacks and more sophisticated indirect manipulation attempts.
-
The framework uses a systematic approach to assess potential attack vectors, including analyzing user input boundaries, model behavior patterns, and application-specific vulnerabilities in AI deployments.
-
Research findings emphasize the importance of implementing robust input validation controls and maintaining clear documentation of model interactions to prevent unauthorized prompt manipulation across different deployment scenarios.
-
Autonomous agent ReaperAI demonstrated ability to identify and exploit vulnerabilities on Hack The Box platform by leveraging GPT-4 and task-driven penetration testing frameworks.
-
Research implemented novel approaches including RAG (Retrieval Augmented Generation) for enhanced memory/context and structured task trees to guide decision-making and command generation.
-
While successful in controlled environments, key challenges remain around command parsing, error handling, and maintaining ethical constraints, highlighting areas needed for future enhancement.
-
Company secured Series A funding led by GreatPoint Ventures, with participation from CrowdStrike's Falcon Fund, to expand their browser security solution that protects against zero-day exploits and HTML smuggling attacks.
-
Technology implements a unique JavaScript-based browser agent using Moving Target Defense strategy, working independently of threat intelligence feeds while maintaining user experience and preventing data exfiltration.
-
Solution addresses security gaps in SaaS environments by providing granular admin controls, dynamic data masking, and session watermarking, while supplementing existing security service edge deployments with zero-trust network access principles.
-
Tenable will acquire Vulcan Cyber in a $147M cash and $3M stock deal, expected to close in Q1 2025, strengthening their exposure management capabilities.
-
Integration will provide customers with enhanced risk consolidation across 100+ security products, along with AI-powered prioritization and automated remediation workflows.
-
The acquisition follows Tenable's strategic growth pattern, coming after their $30M purchase of Eureka Security, as part of broader industry consolidation in the exposure management space.
-
Modern cybersecurity startups need to reach $375M in annual recurring revenue before exit - nearly double the COVID-era benchmark of $194M, according to new research from Acrew Capital.
-
Funding requirements have skyrocketed, with current private cybersecurity startups averaging $717M in capital raised compared to $301M during COVID era and just $6M in the Dot-Com era.
-
Despite increased financial demands, the average time to exit remains stable at 11-12 years, while companies must demonstrate both strong revenue growth and innovation to attract acquisition opportunities or achieve IPO.
From Security Expert to Strategic Leader
Stop drowning in operational details. Get the strategic insights, frameworks, and leadership guidance you need to confidently step into your next security leadership role - all in just 10 minutes a week.
I will never spam or sell your information.
A cutting-edge AI-based IT security platform that identifies malware and cyber-attacks within seconds
Mindgard is a continuous automated red teaming platform that enables security teams to identify and remediate vulnerabilities in AI systems, including generative AI and large language models.
Vectra AI offers an AI-driven Attack Signal Intelligence platform that uses advanced machine learning to detect and respond to cyber threats across hybrid cloud environments.
Before you go
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
For more frequent cybersecurity leadership insights and tips, follow me on LinkedIn, BlueSky and Mastodon.
Best,
Nikoloz