Search security leadership insights...

Brief

The Mandos Brief gives you a quick, 3-minute rundown of the week's top cybersecurity updates. It's your go-to source for staying informed and cyber-aware, fast.

149 Articles

Latest Insights in Brief

Brief #148: Telnyx PyPI Supply Chain Attack, F5 BIG-IP RCE Exploited, Databricks Launches Lakewatch SIEM

Brief #148: Telnyx PyPI Supply Chain Attack, F5 BIG-IP RCE Exploited, Databricks Launches Lakewatch SIEM

TeamPCP compromised the Telnyx Python SDK on PyPI using audio steganography, partnered with LAPSUS$ and a ransomware group, and turned developer tools into entry points for extortion campaigns.

Mar 29 6 min read
Brief #147: Trivy CanisterWorm, Stryker Wiper Attack, XBOW Hits $1B

Brief #147: Trivy CanisterWorm, Stryker Wiper Attack, XBOW Hits $1B

Happy Sunday! In this week's brief: * Trivy CanisterWorm Supply Chain Attack: A self-spreading worm infected 47 npm packages using blockchain-based C2, harvesting developer tokens to automatically compromise entire package ecosystems. Time to audit those postinstall hooks. * Stryker Wiper Attack: Iran-linked Handala group destroyed thousands of devices across 79

Mar 22 10 min read
Mandos Brief Cybersecurity Newsletter

Brief #146: InstallFix Targets Claude Code Users, CrackArmor Hits 12.6M Linux Servers, Armadin Launches With $190M

Happy Thursday! In this week's brief: * CrackArmor Linux Apocalypse: Nine vulnerabilities in AppArmor, hiding since 2017, let any unprivileged user escalate to root on 12.6 million enterprise Linux servers. Patch now. * AI Malware Is Real: IBM X-Force caught ransomware group Hive0163 deploying AI-generated malware in a live

Mar 15 10 min read
Brief #145: CISO Liability Hits 78%, Trump Bans Anthropic, Check Point's $150M AI Push

Brief #145: CISO Liability Hits 78%, Trump Bans Anthropic, Check Point's $150M AI Push

Insider risk costs surge to $19.5M per org as shadow AI creates invisible data loss. CISA leadership in chaos during government shutdown.

Mar 1 10 min read
Brief #144: FortiGate AI Attack Hits 55 Countries, Password Manager Vaults Exposed, Zscaler Acquires SquareX

Brief #144: FortiGate AI Attack Hits 55 Countries, Password Manager Vaults Exposed, Zscaler Acquires SquareX

WEF reports 87% of leaders flag AI as fastest-growing risk. Claroty raises $150M at $3B valuation with 2027 IPO planned.

Feb 22 7 min read
Brief #143: Check Point Spends $340M on Four Acquisitions in 60 Days

Brief #143: Check Point Spends $340M on Four Acquisitions in 60 Days

Check Point just dropped $150 million on three Israeli startups in a single earnings call. That's on top of the $190 million Lakera AI deal two months ago.

Feb 15 8 min read
Brief #142: VMware ESXi Ransomware Exploit, GPT-4o Prompt Injection, Mesh Security's $12M Raise

Brief #142: VMware ESXi Ransomware Exploit, GPT-4o Prompt Injection, Mesh Security's $12M Raise

77% of advanced email threats bypass Microsoft E3/E5 defenses. LLMjacking marketplace sells stolen AI access at 60% discount.

Feb 8 8 min read
mandos brief cybersecurity newsletter

Brief #141: 65% Abandon Prevention Strategy, Gemini Calendar Injection, Nike Breach

VS Code malware installs ScreenConnect RAT with Rust fallback mechanisms. AI cybercrime subscriptions start at $30/month enabling novice attackers. Automotive security market hits $28B by 2036.

Feb 1 7 min read
Brief #140: 6K Palo Alto Firewalls Exposed, $217K Email Breach Costs, Rapid7-ARMO Deal

Brief #140: 6K Palo Alto Firewalls Exposed, $217K Email Breach Costs, Rapid7-ARMO Deal

First AI-generated malware framework VoidLink built in under a week with rootkit capabilities. 50% of SMBs already breached while only 34% have incident response plans. FortiGate SSO exploits create persistence accounts.

Jan 25 7 min read

Level Up Your Security Leadership

Join security leaders who receive knowledge and resources on becoming a more effective security leader. One actionable newsletter every week.

Trusted by CISOs, Founders, and Cybersecurity Builders