-
Ransomware continues as the primary cybersecurity concern with attacks becoming faster, stealthier, and more numerous in 2024, with the USA accounting for 51% of all known attacks.
-
While current generative AI has had limited impact on the threat landscape, the emergence of autonomous AI agents in 2025 could transform cybersecurity by enabling both defenders and attackers to scale operations dramatically.
-
The ransomware ecosystem is evolving with "dark horse" groups gaining market share as tools become more accessible, while attackers increasingly use legitimate administration tools (Living Off the Land tactics) to evade detection.
-
The 2025 Black Duck Open Source Security and Risk Analysis report reveals that jQuery accounts for 8 of the top 10 high-risk vulnerabilities found in open source components, with 32% of scanned codebases containing this library.
-
Transitive dependencies represent 64% of open source components in applications, creating significant hidden risk as 81% of codebases contain high or critical-risk vulnerabilities, with nearly half introduced through these indirect dependencies.
-
Organizations face maintenance challenges with 90% of codebases containing outdated components and 56% containing license conflicts, highlighting the need for comprehensive Software Bill of Materials (SBOM) tracking.
-
Google Cloud has released quantum-safe digital signatures in preview as part of their Cloud Key Management Service, following NIST's publication of quantum-safe cryptographic standards last summer.
-
Organizations should begin preparing for post-quantum cryptography now, as NIST suggests retiring current public-key cryptosystems by 2030-2035, and implementation will take significant time despite seeming like a distant concern.
-
The primary risks include "harvest now, decrypt later" attacks where adversaries collect encrypted data to decrypt once quantum computing advances, and the potential for CRQC (cryptographically-relevant quantum computers) to break existing cryptographic infrastructure.
📖
Discover my collection of industry reports, guides and cheat sheets in ‣
Cyber Strategy OS.
-
Despite having a cybersecurity degree and multiple certifications (Security+, BTL1, SC-900), this analyst feels their foundational knowledge is poor and struggles to investigate alerts in Microsoft Sentinel.
-
The analyst's learning approach may be ineffective - they spend more time writing notes than understanding concepts, and have difficulty applying information when investigating alerts.
-
Fellow professionals reassure that imposter syndrome is common in cybersecurity, with even industry experts sharing similar experiences throughout their careers, suggesting persistence and continuous learning are key to overcoming these feelings.
-
Solo virtual CISOs typically manage 2-8 clients simultaneously, with one professional recommending a maximum of 20 billable hours per week to avoid burnout while running their consultancy.
-
Successful vCISOs emphasize the importance of prior experience managing information security teams, strong organizational skills, and understanding that the role involves more compliance and governance work than technical security tasks.
-
Most vCISO services operate on a fixed fee model based on estimated monthly hours, with professionals noting that business communication skills and industry-specific experience are crucial for long-term success.
-
The cybersecurity field is experiencing a seismic transformation where traditional skills (endpoints, networks, operating systems) are no longer sufficient in an era of cloud computing, remote work, and AI.
-
Future cybersecurity professionals will need to be solution builders rather than configuration experts, similar to how software engineers operate - creating integrated, scalable security stacks using cloud technologies.
-
The industry parallels early 20th century farming's transformation, where employers increasingly prefer candidates with specialized cloud platform expertise and coding abilities over security generalists, sometimes even promoting software engineers directly into security roles.
-
Modern security systems utilize different AI agent architectures, from basic reflex agents (simple if-then rules) to sophisticated learning agents that adapt over time.
-
Each agent type serves specific security functions - model-based agents maintain internal representations of network states, goal-based agents work toward security objectives, and utility-based agents balance competing priorities like security versus usability.
-
The future of cybersecurity lies in hybrid approaches that combine multiple agent types, allowing organizations to leverage the strengths of each architecture while minimizing their individual weaknesses.
-
Microsoft's low-code AI agent platform has a security flaw allowing attackers to enumerate and access exposed agents through predictable URL patterns derived from tenant IDs and common agent names.
-
Once discovered, unauthenticated agents can serve as knowledge oracles, potentially leaking sensitive financial data from knowledge bases connected to SharePoint, Excel sheets, and other corporate resources.
-
Despite Microsoft updating default settings to warn about "No Authentication" configurations, the researchers believe many of the 100,000 organizations using Copilot Studio will still have misconfigured agents accessible to threat actors.
-
LLM red teaming involves systematically testing AI models to identify vulnerabilities and unwanted behaviors, with two main categories: security red teaming (focusing on traditional security properties) and content-based red teaming (examining unwanted outputs).
-
Red teamers employ various strategies including social engineering, technical manipulation, and context exploitation, motivated by professional requirements, social factors, or personal interest in discovering model weaknesses.
-
NVIDIA uses red teaming as part of their Trustworthy AI process, with findings incorporated into their Model Card++ documentation and the open-source garak toolkit that tests LLMs against over 120 vulnerability categories.
-
The new service consolidates data from multiple sources including Zscaler's Zero Trust Exchange platform (which processes 500 billion security transactions daily) to provide organizations with accurate asset inventory and risk visibility.
-
Asset Exposure Management helps identify security gaps by detecting assets lacking essential protection measures like EDR solutions or running outdated software, while automating remediation workflows.
-
The solution addresses challenges faced by IT teams in regulated industries like healthcare and financial services where asset tracking is crucial to avoid noncompliance penalties.
-
Archipelo has emerged from stealth with a new DevSPM (Developer Security Posture Management) platform that addresses security risks at their source—developer actions and AI-assisted coding workflows—before vulnerabilities reach production environments.
-
The San Francisco-based startup secured $12M in funding led by Dell Technologies Capital with participation from notable investors including Zoom CEO Eric Yuan, creating a new cybersecurity category focused on the 74% of security breaches caused by human error.
-
The platform offers four key capabilities: Developer Detection & Response, AI Code Risk Monitoring, Automated Developer Tool Inventory, and Developer Security Posture Analytics—already serving Fortune 500 enterprises in financial services, technology, and defense sectors.
-
Mimic's SaaS platform detects ransomware in fractions of a second, with former Mandiant CEO Kevin Mandia joining the board and Greg Davison (ex-Mandiant/Google) appointed as Head of Revenue.
-
Seattle-based retailer REI has been announced as a major customer, with their CISO Mike Hughes highlighting Mimic's capabilities in early detection and rapid recovery as vital to their business continuity.
-
The company unveiled its new Signal Generator feature that allows customers to safely simulate ransomware impacts within their networks to test security posture without handling actual malware.
From Security Expert to Strategic Leader
Stop drowning in operational details. Get the strategic insights, frameworks, and leadership guidance you need to confidently step into your next security leadership role - all in just 10 minutes a week.
I will never spam or sell your information.
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Zoho Vault is a secure password management tool that allows you to store and automatically fill in passwords on websites and apps.
CloudDefense.AI is a Cloud Native Application Protection Platform (CNAPP) that safeguards cloud infrastructure and cloud-native apps with expertise, precision, and confidence.
Before you go
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
For more frequent cybersecurity leadership insights and tips, follow me on LinkedIn, BlueSky and Mastodon.
Best,
Nikoloz