Happy Sunday!
Some of you have mentioned that the newsletter has grown in size, and you'd prefer a more condensed version. As someone deeply involved in cybersecurity, I understand how precious your time is. I'm considering condensing Mandos Brief format to help you stay informed even more efficiently.
Below, you'll find this week's newsletter in the new condensed format. Please let me know the version of the newsletter you prefer through this anonymous feedback.
- 👍 Prefer condensed version.
- 💬 I have a suggestion (provide more detailed feedback)
- 👎 Prefer extended version.
Thank you for helping me deliver even more value to you.

Linux Malware Hides Credit Card Skimmer Using Unconventional Persistence Technique
Aon's Stroz Friedberg researchers uncovered a stealthy Linux malware named "sedexp" that uses udev rules to achieve persistence and conceal credit card skimmer code on infected systems, demonstrating the evolving sophistication of financially motivated threat actors beyond ransomware.
Researchers Discover Vulnerability in Airport Security System Allowing Unauthorized Cockpit Access
Security researchers Ian Carroll and Sam Curry found a SQL injection vulnerability in FlyCASS, a third-party service used by some airlines to manage the Known Crewmember (KCM) program and the Cockpit Access Security System (CASS), potentially allowing unauthorized individuals to bypass airport security screenings and gain access to aircraft cockpits.
Iranian APT 33 Hackers Develop New "Tickler" Backdoor Malware
Microsoft reports that the Iranian government-backed hacking group APT 33, also known as Peach Sandstorm, has developed a new multistage backdoor called "Tickler" to establish remote access into victim networks, targeting sectors such as satellite, communications equipment, oil and gas, and government entities in the US and UAE.
BlackByte Ransomware Evolves Tactics with New Vulnerabilities and Techniques
Cisco Talos identified that BlackByte ransomware group continues to leverage established tactics while also exploiting newly disclosed vulnerabilities like CVE-2024-37085 in VMware ESXi and using victims' remote access tools to support ongoing attacks.




