-
Survey reveals 80% of respondents lack high confidence in identifying high-risk data sources, with 31% reporting insufficient tooling to identify their riskiest data sources.
-
Misalignment exists between management and operational teams, with executives focusing on strategic goals while staff struggle with resource constraints—54% rely on semi-automated processes and 22% on entirely manual processes.
-
Organizations are shifting toward risk-based approaches, prioritizing vulnerability identification (7.06/8) and vulnerability prioritization (6.15/8) over compliance-driven strategies, with 54% using four or more tools to manage data risks.
-
Attackers used LinkedIn and WhatsApp to target key development staff, convincing them to run malicious code that harvested access keys and credentials from corporate laptops.
-
The threat actor bypassed MFA by stealing session tokens, gaining access to Microsoft 365 and AWS environments through both direct API access and web console via compromised Entra ID.
-
The sophisticated attack demonstrates how threat actors can chain together minor permission gaps to achieve privilege escalation, highlighting critical weaknesses in identity governance and cloud security monitoring.
-
"SneakThief" malware employs multi-stage infiltration techniques including process injection, encrypted communications, and boot persistence to remain hidden while stealing valuable data.
-
Top ten MITRE ATT&CK techniques account for over 90% of observed malicious activity, with Process Injection (T1055), Command and Scripting Interpreter (T1059), and Credentials from Password Stores (T1555) being most prevalent.
-
Modern infostealers now perform an average of 14 malicious actions per sample, while ransomware groups have evolved to multi-stage extortion campaigns that combine data theft with traditional encryption tactics.
📖
Discover my collection of industry reports, guides and cheat sheets in ‣
Cyber Strategy OS.
-
The partnership introduces a structured learning program designed to equip cybersecurity professionals with skills to evaluate, test, and defend AI systems against adversarial threats like data poisoning and model evasion.
-
The curriculum aligns with Google's Secure AI Framework (SAIF) and provides hands-on labs focused on red teaming methodologies specifically for AI security challenges.
-
Target audiences include penetration testers expanding into AI security, AI engineers developing secure models, and developers working with AI-integrated applications, with plans to expand coverage of MITRE Atlas and OWASP LLM/ML frameworks.
-
Most respondents indicate entry-level SOC analyst positions start at $50-60K, with some reporting increases to $60-70K after probationary periods or in higher cost-of-living areas.
-
True entry-level cybersecurity positions are relatively rare, with many employers preferring candidates who have 2-5 years of prior IT experience, which can push salaries toward the $70-90K range.
-
Location significantly impacts salary ranges, with coastal and high cost-of-living areas offering higher compensation (up to $90-100K), while specialized roles in consulting, engineering, or finance sectors may command premium starting salaries.
-
The cybersecurity job market has evolved from "hire anyone who can spell cybersecurity" to a more competitive landscape, with generalists facing potential oversupply while specific skill shortages persist in areas like operational technology and zero-trust expertise.
-
HR practices are complicating the hiring process through "ghost jobs" (advertised positions that don't exist), AI-based resume filtering that rejects qualified candidates, and unrealistic job requirements that don't match actual needs or compensation levels.
-
Industry experts recommend employers work with existing security staff to create realistic job descriptions, focus on hiring for aptitude rather than experience for junior roles, and note that networking has become increasingly critical for job seekers in the security field.
-
OWASP researchers found that while LLMs can technically perform hacking tasks, they require extensive supervision from experts and are impractical for low-skill threat actors due to high time investment (82 developer hours for just five tasks).
-
GPT-4o outperformed Claude and local DeepSeek models (which failed completely), suggesting that advanced LLM hacking requires credentials for commercial APIs, increasing both cost and risk of detection for malicious actors.
-
LLMs demonstrated significant limitations including rigid goal-following (missing obvious vulnerabilities), installation loops creating "cycles of spend," and noisy fallback behaviors that would likely trigger detection in real environments.
-
AI is entering the "Agentic" phase, where autonomous AI systems can perceive environments and take actions to achieve specific goals without constant human input.
-
Five types of AI agents are emerging: simple reflex, model-based reflex, goal-based, utility-based, and learning agents - with applications across customer support, online shopping, education, healthcare, and business decision-making.
-
While promising increased productivity, the shift raises concerns about job displacement and control problems, with experts predicting AI will affect nearly 40% of all jobs in coming years.
-
Security researcher Joseph (rez0) has released a detailed guide covering methodologies for hacking AI applications, focusing on systems that use language models as features.
-
The guide explores various attack vectors including prompt injection, traditional web vulnerabilities triggered through AI, and multimodal attacks that use invisible Unicode characters or image-based techniques.
-
The researcher includes a responsibility model for AI security, explaining how vulnerabilities should be attributed between model providers, application developers, and users, along with potential mitigations for the identified security issues.
-
CalypsoAI has launched the first comprehensive security ranking system for major GenAI models, using their new Inference Red-Team solution that successfully compromised all tested models through automated attacks and "Agentic Warfare" techniques.
-
The CalypsoAI Security Index (CASI) shows Anthropic's Claude 3.5 Sonnet leading with a 96.25 score, while popular models like OpenAI's GPT-4o scored significantly lower at 75.06, revealing substantial vulnerabilities across even the most advanced AI systems.
-
The index provides critical metrics beyond security scores, including Risk-to-Performance ratio and Cost of Security, giving organizations essential data to make informed decisions about which AI models can be safely deployed in enterprise environments.
-
Rapid7's expanded offering provides continuous visibility into sensitive data across multicloud environments, integrating with AWS Macie, Google Cloud DLP, and Microsoft Defender for automated data classification.
-
New AI-driven vulnerability scoring enhances risk prioritization by generating intelligence-driven risk scores, helping security teams focus on critical exposures with greater accuracy.
-
Updates to Remediation Hub streamline the remediation process by embedding guidance directly within asset inventory pages, eliminating platform switching and accelerating mean-time-to-remediate.
-
The endpoint management platform raised funding led by ICONIQ Growth and CapitalG to drive R&D in autonomous management, patching, and vulnerability remediation while supporting its pending $262M acquisition of Dropsuite.
-
NinjaOne remains founder-led with co-founders Sal Sferlazza and Chris Matarese maintaining majority control of the company, which serves over 24,000 customers including Nvidia, Lyft, and Porsche.
-
The company plans to expand its AI capabilities and IT use cases while maintaining its commitment to customer support, having recently launched NinjaOne AI for Patch Sentiment, Mobile Device Management, and free Warranty Tracking.
From Security Expert to Strategic Leader
Stop drowning in operational details. Get the strategic insights, frameworks, and leadership guidance you need to confidently step into your next security leadership role - all in just 10 minutes a week.
I will never spam or sell your information.
CloudDefense.AI is a Cloud Native Application Protection Platform (CNAPP) that safeguards cloud infrastructure and cloud-native apps with expertise, precision, and confidence.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Anomali is an AI-Powered Security Operations Platform that delivers speed, scale, and performance at a reduced cost, combining ETL, SIEM, XDR, SOAR, and TIP to detect, investigate, respond, and remediate threats.
Before you go
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
For more frequent cybersecurity leadership insights and tips, follow me on LinkedIn, BlueSky and Mastodon.
Best,
Nikoloz