-
Enterprises are hesitant to adopt security startups due to data sensitivity concerns, leading companies to choose between massive VC funding, server-hosted products, or the open source route.
-
Companies can monetize open source security tools through three main approaches: selling centralization features, offering SaaS versions, or providing support and consultancy services.
-
Real-world success stories include Workbrew's enterprise version of Homebrew, Fleet and Kolide building upon osquery, demonstrating how open source projects can evolve into commercial security products.
-
A total of 768 CVEs were reported as exploited in the wild in 2024, marking a 20% increase from 2023's 639 cases, with 112 unique sources providing initial evidence.
-
Analysis shows that 23.6% of Known Exploited Vulnerabilities (KEVs) were exploited on or before their CVE disclosure date, slightly down from 27% in 2023, challenging the focus on zero-day threats.
-
Monthly exploitation reports maintained a baseline of 30-50 vulnerabilities, with notable spikes occurring during specific industry events and following the introduction of new reporting resources.
📖
Discover my collection of industry reports, guides and cheat sheets in ‣
Cyber Strategy OS.
-
Wiz introduces new certification program starting with Cloud Fundamentals exam, designed to validate expertise in Wiz Cloud technology deployment and management for customers, partners, and security professionals.
-
Program addresses growing demand for cloud security expertise, citing research showing 57% of companies use multiple cloud platforms and 50% have exposed databases or storage buckets.
-
Future specialized exams will build upon the Cloud Fundamentals certification, creating a comprehensive professional development path for cloud security practitioners seeking to demonstrate their expertise.
-
Practical experience and infrastructure knowledge are more valuable than degrees or certifications alone, with SOC Analyst and Support roles serving as foundational stepping stones for advanced positions.
-
Current market is experiencing oversaturation at entry-level, particularly for SOC analysts without infrastructure experience, while security engineering positions remain in high demand.
-
Alternative pathways include starting in help desk or IT roles, leveraging internal transfers, and focusing on industries outside tech - such as retail and state finance housing authorities which are actively recruiting for junior security positions.
-
Candidate with years of SOC experience was dismissed during interview primarily due to lack of knowledge in a specific tool, despite broader security expertise and transferable skills.
-
Community response emphasizes this as a red flag, noting that strong SOC leaders should be evaluated on leadership capabilities and fundamental security knowledge rather than tool-specific expertise.
-
Multiple security professionals shared similar experiences, suggesting some organizations use undisclosed tool requirements as a pretense for having pre-selected internal candidates or attempting to find exact replicas of departing SMEs.
-
ReversingLabs discovered "nullifAI" attack technique using broken Pickle files to distribute malware through ML models, bypassing Hugging Face's security scanning by exploiting file validation weaknesses.
-
The malicious models contained reverse shell payloads that execute before the corrupted Pickle file fails to load, connecting to hardcoded IP addresses while evading detection from Hugging Face's Picklescan security tool.
-
After responsible disclosure, Hugging Face removed the malicious models within 24 hours and updated their scanning tools, but researchers warn that Pickle's inherent security weaknesses make it fundamentally risky for collaborative platforms sharing untrusted code.
-
Four key locations for sensitive data management in GenAI apps: LLM training, vector databases, tools, and agents - each requiring distinct authorization approaches.
-
RAG implementations should enforce authorization before sending data to LLMs, with options for both application-level and metadata filtering to control access to sensitive information.
-
Data governance across visibility, access control, quality and ownership is critical, with AWS services like DataZone and Lake Formation helping manage sensitive data authorization.
-
OpenAI introduces data residency options in Europe for ChatGPT Enterprise, ChatGPT Edu, and API Platform, allowing organizations to meet local data sovereignty requirements while maintaining zero data retention for API requests.
-
The platform implements enterprise-grade security measures including AES-256 encryption for data at rest and TLS 1.2+ for data in transit, with a strict policy of not training models on customer data unless explicitly opted in.
-
The service supports GDPR compliance and includes a comprehensive Data Processing Addendum, currently serving major European organizations like Booking.com, BBVA, Zalando, and Oxford University.
-
Company founded by creator of syslog-ng launches platform to automatically discover, classify, parse, normalize, and enrich security data, promising over 50% reduction in data volume and associated costs.
-
Platform focuses on improving data quality through automated data curation pipeline, eliminating need for manual coding while preventing "invisible data loss" - a critical concern for compliance in regulated industries.
-
Solution targets enterprises with hybrid environments, supporting both cloud and on-premises deployments, with early adoption by large enterprise customers and demonstrations planned for RSA Conference and Gartner Risk and Security Summit.
-
Company secured funding from multiple investors including Craft Ventures and Alumni Ventures to develop their adaptive security platform that quantifies and manages employee-related security risks.
-
Platform uses artificial intelligence to identify high-risk users and automatically implement tailored security controls and training interventions based on individual behavior patterns.
-
Solution integrates with existing security infrastructure to help enterprises address the human element of cybersecurity through behavioral analytics and dynamic risk assessment.
-
The Delaware-based startup's platform leverages artificial intelligence to provide enterprise-grade cyber protection specifically designed for MSPs serving small to medium-sized businesses, offering comprehensive visibility through a single dashboard.
-
Platform capabilities include automated penetration testing, risk scoring, dark web monitoring, and asset discovery, with multi-tenant design enabling MSPs to monitor internal, external, and cloud environments.
-
Investment led by Top Down Ventures' Founders Fund I will accelerate product development and expand go-to-market operations, with additional backing from Blu Ventures and Runtime Ventures.
From Security Expert to Strategic Leader
Stop drowning in operational details. Get the strategic insights, frameworks, and leadership guidance you need to confidently step into your next security leadership role - all in just 10 minutes a week.
I will never spam or sell your information.
Drata is a cloud-based platform that automates security and compliance processes, evidence collection, and audit preparation for various industry standards and regulations.
A cloud-native SIEM platform that provides security analytics, intuitive workflow, and simplified incident response to help security teams defend against cyber threats.
Tessian is an AI-powered cloud email security solution that protects against advanced phishing, account compromise, data exfiltration, and helps coach users on email security.
Before you go
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
For more frequent cybersecurity leadership insights and tips, follow me on LinkedIn, BlueSky and Mastodon.
Best,
Nikoloz