-
CloudTrail network activity events provide visibility into API calls passing through VPC Endpoints, helping troubleshoot endpoint policies and detect potential exfiltration attempts.
-
Currently supports five AWS services (CloudTrail, EC2, KMS, S3, and Secrets Manager) with the same pricing structure as Data Events ($0.10 per 100,000 events).
-
At minimum, organizations should enable logging for VpceAccessDenied events, which offers critical visibility into denied requests without significant cost implications.
-
Cloudflare's new algorithm uses AI to analyze context around potential data leaks, adapting to an organization's unique traffic patterns and learning from administrator feedback to reduce false positives.
-
The system leverages Workers AI for text embeddings and Vectorize for similarity searches, comparing new potential matches against previously reported true and false positives to improve detection accuracy.
-
Currently in closed beta with approximately 400ms added latency for matching requests, the feature will expand beyond HTTP traffic to include CASB and Email Security by the end of 2025.
-
Organizations manage an average of 41,605 service accounts compared to just 915 human users, with machine identities being exponentially more numerous and difficult to secure.
-
Real-time threat detection and response is now achievable within the "555 Benchmark" (5 seconds to detect, 5 minutes to investigate, 5 minutes to respond), with organizations initiating response actions in under 4 minutes on average.
-
The adoption of automated security responses has nearly tripled over the past year, with more organizations implementing preventive actions like container kill, stop, or pause functions when drift is detected.
📖
Discover my collection of industry reports, guides and cheat sheets in ‣
Cyber Strategy OS.
-
Ankit Masrani, a 36-year-old software engineer, successfully pivoted to cybersecurity at Microsoft after 6.5 years at AWS, where he gained experience with customer-managed key encryption and data security practices.
-
Now a principal software engineer on Microsoft's Security Platform, Masrani develops sovereignty controls ensuring sensitive customer information remains within geographic boundaries, applying his background in IT, computer science, and data experience.
-
For others looking to make similar transitions, Masrani recommends developing skills in big data technologies, cloud services, and security fundamentals including data governance, regional regulations like GDPR, and best practices for handling sensitive information.
-
Today's cybersecurity leaders increasingly come from finance, law, and corporate strategy backgrounds, bringing risk-management perspectives that complement traditional technical approaches.
-
The evolving threat landscape requires security executives who can navigate regulatory compliance, financial risk management, and operational resilience while communicating effectively with boards.
-
Cybersecurity must be approached as an enterprisewide risk rather than just a technical challenge or compliance checkbox to drive long-term organizational resilience.
-
Overworked manager handling international support alone for 4 months, working split shifts (8am-4pm and 8:30pm-11pm) while team members resist late meetings.
-
Manager feels adequately compensated (mid $100-200K range) but acknowledges competitors offer $20-50K more plus bonuses for similar positions.
-
Current workload includes multiple security functions (threat hunting, logging, forensics, pen testing) with nightly logging fixes that often fail by morning, suggesting unsustainable work patterns.
-
Organizations are increasingly adopting AI technologies, with workloads using AI/ML packages growing by 500% over the past year.
-
Despite this massive growth, public exposure of AI workloads decreased by 38%, indicating that organizations are prioritizing security in their AI implementations.
-
The adoption of GenAI security tools is accelerating, with 45% of Sysdig customers enabling their AI security analyst within four months of its release, primarily used by SecOps teams for alert triage and investigation.
-
74% of IT leaders confirmed AI breaches in 2024 (up from 67% last year), with 87% able to identify the source, while 45% of companies have concealed AI security incidents due to potential public backlash.
-
Organizations face significant governance challenges with 72% acknowledging shadow AI issues (up from 61%), while only 32% deploy technology solutions to address AI threats and just 16% secure models with red teaming.
-
Despite concerns, positive trends include 96% of companies implementing formal AI security frameworks, 81% establishing AI governance committees, and 95% increasing their budgets for AI security in 2025.
-
Pillar Security researchers discovered a new supply chain attack vector that allows hackers to inject malicious instructions into configuration files used by AI coding assistants, manipulating them to generate compromised code.
-
The attack exploits hidden Unicode characters in rule files that remain invisible during code reviews, effectively weaponizing the AI assistant itself as an attack vector that can silently propagate through projects.
-
With 97% of enterprise developers using AI coding tools, this vulnerability creates significant risk as neither GitHub nor Cursor consider this their responsibility, leaving organizations to implement their own mitigation strategies like rule file validation.
-
Google has agreed to purchase cloud security startup Wiz for $32 billion in an all-cash transaction, marking the largest acquisition in Google's 26-year history and the biggest-ever cybersecurity deal.
-
The acquisition aims to strengthen Google Cloud division, which has seen significant growth with revenue jumping 64% to $43.2 billion last year, as the company competes with Microsoft and Amazon in the AI-driven cloud computing market.
-
The deal faces potential regulatory scrutiny amid Google's ongoing antitrust battles, including a recent ruling that its search engine is an illegal monopoly, with both companies expecting the acquisition to close in 2026.
-
Orion Security's platform creates a comprehensive map of organizational data flows, using AI to distinguish between legitimate business activities and potential risks, addressing the growing threat of data exfiltration.
-
The startup's approach moves beyond traditional manual policies and rigid rules-based systems, using proprietary reasoning algorithms and LLM-powered classification to understand the context of data movement.
-
Data exfiltration has become increasingly costly (averaging $5 million per breach) and sophisticated, with threats ranging from North Korean hackers posing as contractors to accidental leaks through generative AI tools.
-
VulnCheck raised $12 million in Series A funding led by Ten Eleven Ventures, bringing total funding to nearly $20 million for international expansion and platform enhancement after achieving 3x year-over-year ARR growth.
-
The company's 2024 Trends in Exploitation Report revealed 768 vulnerabilities were publicly reported as exploited in the wild, a 20% increase over 2023, with 23.6% of known exploited vulnerabilities being exploited on or before CVE disclosure.
-
VulnCheck's platform collects data from nearly 500 channels and over 400 million records across all CVEs, refreshing every eight hours to help security teams prioritize and remediate critical vulnerabilities before attackers strike.
From Security Expert to Strategic Leader
Stop drowning in operational details. Get the strategic insights, frameworks, and leadership guidance you need to confidently step into your next security leadership role - all in just 10 minutes a week.
I will never spam or sell your information.
The Upstream Security Platform is a cloud-based solution for monitoring and securing connected vehicles and mobility IoT devices, offering features such as cybersecurity detection, API protection, and fraud detection.
TrojAI is an AI security platform that detects vulnerabilities in AI models and defends against attacks on AI applications.
Cyera is a data security platform that discovers, classifies, and secures sensitive data across various environments, offering features such as DSPM, identity data access, and data privacy compliance.
Before you go
If you found this newsletter useful, I'd really appreciate if you could forward it to your community and share your feedback below!
For more frequent cybersecurity leadership insights and tips, follow me on LinkedIn, BlueSky and Mastodon.
Best,
Nikoloz