Skip to content

company

Mandiant

Mandiant is a cybersecurity firm within Google Cloud specializing in incident response and threat intelligence, publisher of the annual M-Trends report.

Known aliases

  • Google Cloud Mandiant
  • Google Cloud / Mandiant
  • Google Mandiant
  • Google's Mandiant
  • Mandiant Consulting
  • Mandiant Inc.
  • Mandiant Managed Threat Defense
  • Mandiant, part of Google Cloud
  • mandiant.security
  • M-Trends
  • Мандіант

Relationships

No evidence-backed relationships are recorded.

Current stories

invest3 publishers

Issuers and protocols have frozen about 0.2% of the $387 million taken from Bitget

Chainalysis tied the $387 million Bitget hack to North Korea-linked hackers, saying it pushed their 2026 crypto theft past $1 billion. Its AI cut more than 20 hours of tracing to minutes, while the bill falls on a Bitget user fund the exchange puts above $464 million.

Perspective Coverage

3 publishers
Builder
Builder 32%
Operator
Operator 41%
Investor
Investor 27%

Reality

Evidence70
Adoption25
Hype gap+35
Incentives60
Confidence65
security3 publishers

Unauthenticated Dell CSM flaw leaks admin credentials for every registered storage array

Dell patched six critical flaws in its Kubernetes storage modules, one letting unauthenticated attackers pull admin credentials for every registered array. The Authorization module holds those keys for each array it fronts, so one reachable deployment exposes all the storage registered behind it.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 65%
Investor
Investor 8%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence72
security6 publishers

Mandia's Armadin raises $255.5 million to point AI attack agents at customers' networks

Kevin Mandia's Armadin raised $255.5 million at a valuation above $2.5 billion, bringing its total to $445 million seven months after launch. Its case against periodic pen tests rests on performance data from an exercise Armadin ran with a partner.

Perspective Coverage

6 publishers
Builder
Builder 24%
Operator
Operator 38%
Investor
Investor 38%

Reality

Evidence55
Adoption30
Hype gap+40
Incentives75
Confidence60
invest4 publishers

Bitget's CEO doubts the $387.5 million lost through a vendor-linked backend will come back

Bitget CEO Gracy Chen doubts much of the $387.5 million stolen via a backend tied to a third-party security vendor will come back. So far about 0.2% of the loss has been frozen, so the exchange itself is paying for an outsourced security flaw.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 41%
Investor
Investor 34%

Reality

Evidence68
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence70
build3 publishers

Kevin Mandia's Armadin raises $255.5 million to run red-team work as continuous AI software

Kevin Mandia's AI cybersecurity startup Armadin raised a $255.5 million Series B at a valuation above $2.5 billion. Security teams comparing its AI agents with periodic human pentests have only Armadin's own platform figures to go on.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 37%
Investor
Investor 40%

Reality

Evidence55
Adoption25
Hype gap+35
Incentives65
Confidence60
invest6 publishers

Investors price Kevin Mandia's seven-month-old Armadin above $2.5 billion

Armadin, the AI attack-testing startup run by Mandiant founder Kevin Mandia, raised $255.5 million at a valuation above $2.5 billion. Investors are betting that always-on AI agents will take over the budget companies now spend on periodic penetration tests.

Perspective Coverage

6 publishers
Builder
Builder 31%
Operator
Operator 32%
Investor
Investor 37%

Reality

Evidence55
Adoption20
Hype gap+40
Incentives80
Confidence60
security9 publishers

FBI presses ShinyHunters members to surrender after Dutch police hold an alleged leader

FBI's Brett Leatherman urged ShinyHunters members to surrender after the Dutch arrest of an alleged leader of a group tied to $70 million in extortion. Dutch police have not ruled out more arrests, though the public record so far shows one suspect in custody.

Perspective Coverage

9 publishers
Builder
Builder 17%
Operator
Operator 68%
Investor
Investor 15%

Reality

Evidence68
Adoption
Insufficient
Hype gap+30
Incentives60
Confidence64
security4 publishers

Google traces most of 2026's exploitation growth to fast n-day weaponization

Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.

Perspective Coverage

4 publishers
Builder
Builder 33%
Operator
Operator 61%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+30
Incentives35
Confidence65
security3 publishers

Microsoft says China-linked operators hand-install NeedyMantis to keep hold of breached networks

Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption
Insufficient
Hype gap+18
Incentives40
Confidence60
security5 publishers

Kiteworks clears customers to restart file-transfer servers after a weekend shutdown on a federal tip

Kiteworks lifted its worldwide shutdown advice after patching a critical flaw in a feature used by under 1% of customers. Self-hosted operators stopped and restarted on the vendor's word alone, with no CVE yet to check the fix against.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 60%
Investor
Investor 17%

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives70
Confidence60
security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
invest2 publishers

Bitget customers withdrew $463 million in 24 hours, more than the $388 million hack took

Bitget customers pulled about $463 million in the first 24 hours after withdrawals reopened, more than the $388 million hackers stole on September 24. The protection fund covers the theft with about $76 million to spare, so the withdrawals now test whether the $5.7 billion left in reserves matches what Bitget owes customers.

Reality

Evidence60
Adoption
Insufficient
Hype gap+12
Incentives58
Confidence58
build1 publisher

Kelp DAO sues LayerZero in British Columbia over the $292M rsETH bridge exploit

Kelp DAO has sued LayerZero Labs and co-founder Bryan Pellegrino for negligence and misrepresentation over April's $292 million rsETH bridge exploit. The forged message cleared a bridge that trusted one LayerZero-run verifier, so the case tests who answers for that setup.

Publishers:dev.to

Reality

Evidence35
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence35
security8 publishers

ShinyHunters slips past PeopleSoft firewall rules by encoding one character

ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.

Perspective Coverage

8 publishers
Builder
Builder 25%
Operator
Operator 58%
Investor
Investor 17%

Reality

Evidence78
Adoption
Insufficient
Hype gap+8
Incentives58
Confidence74

Earlier coverage

  1. One URL-encoded letter gets ShinyHunters past PeopleSoft WAF rules on unpatched servers

    Security · September 28, 2026 · 1 publisher

  2. Bitget traces its $388 million wallet theft to a flaw in a third-party security product

    Security · September 28, 2026 · 1 publisher

  3. Bitget traces $387.5 million breach to stolen internal credentials via third-party product flaw

    Invest · September 28, 2026 · 2 publishers

  4. Suspected North Korean attackers used Bitget's own signing process to move $351.6M

    Security · September 25, 2026 · 10 publishers

  5. Kiteworks' shutdown all-clear sends self-hosted Advanced Forms customers to support

    Security · September 28, 2026 · 1 publisher

  6. Bitget presses THORChain to cut off the wallets holding its stolen $387.5 million

    Invest · September 26, 2026 · 3 publishers

  7. Most of Bitget's $387.5 million hack loss sits untouched in attacker wallets

    Invest · September 27, 2026 · 15 publishers

  8. Bitget's own approval process moved out $388 million on spoofed transaction data

    Product · September 25, 2026 · 3 publishers

  9. ShinyHunters says its FBI haul of up to three terabytes includes staff psychiatric records

    Invest · September 26, 2026 · 1 publisher

  10. ShinyHunters percent-encode one letter to slip PeopleSoft's 9.8 RCE past the WAF

    Build · September 26, 2026 · 1 publisher

  11. BlackFile wears four extortion brands, so your threat feed is counting one actor as several

    Security · August 17, 2026 · 1 publisher

  12. ShinyHunters routes around PeopleSoft firewall rules to hit systems still missing Oracle's patch

    Invest · September 26, 2026 · 1 publisher

  13. ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered

    Security · August 25, 2026 · 5 publishers

  14. Fire Ant taught a Cisco IOS XR router to forward only log lines containing the word Health

    Security · August 31, 2026 · 6 publishers

  15. Breeze Comet talks its way into Brazilian payment systems with a help-desk call and AnyDesk

    Security · September 1, 2026 · 2 publishers

  16. Attackers rode the Trivy compromise into Checkmarx's GitHub and out through its VS Code extensions

    Build · September 3, 2026 · 1 publisher

  17. PREY-0058 phones executives to harvest Microsoft 365 session tokens

    Security · September 7, 2026 · 3 publishers

  18. Bitget's own authorization process approved $351.6M in transfers built on spoofed data

    Build · September 25, 2026 · 1 publisher

  19. Google's undercover analyst watched TeamPCP poison packages from inside its core chat

    Product · September 18, 2026 · 1 publisher

  20. ShinyHunters pins its claimed FBI breach on an unpatched PeopleSoft RCE

    Security · September 23, 2026 · 14 publishers

  21. An agent now picks the packages the person prompting it will never see

    Build · September 23, 2026 · 1 publisher

  22. A $10 limit stored as text on a Kinde token cut the agent off after four calls

    Build · September 22, 2026 · 1 publisher

  23. A record 1,449-patch Oracle update turns AI-assisted finding into a change-window problem

    Build · September 19, 2026 · 1 publisher

  24. Unauthenticated SAP attackers hit memory corruption before any login check

    Security · September 18, 2026 · 1 publisher

  25. Verizon's 43-day median patch time, against a five-day weaponization clock

    Security · September 17, 2026 · 1 publisher

  26. Attackers went from stolen cloud credentials to mass credential harvest in under six hours

    Leadership · September 16, 2026 · 2 publishers

  27. Mandiant's testers talked an internal AI assistant into pushing private repos to their own GitHub

    Security · September 16, 2026 · 1 publisher

  28. Clearing Mythos Preview's 6,105 open findings at 97 fixes per two months takes a decade

    Build · September 12, 2026 · 1 publisher

  29. An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud

    Build · September 12, 2026 · 1 publisher

  30. Amazon puts Mandiant's founder on both its Audit and Security committees

    Product · September 11, 2026 · 1 publisher

  31. Anthropic's most capable model built working exploits from 16 of 39 published patches

    Leadership · September 11, 2026 · 1 publisher

  32. Amazon hands a board seat to the incident responder who built the firm Google now owns

    Security · September 10, 2026 · 2 publishers

  33. Stealer logs now carry AI session tokens that replay straight past MFA

    Security · September 9, 2026 · 1 publisher

  34. Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours

    Security · September 8, 2026 · 3 publishers

  35. Slim Spider lifted crypto custody keys out of a Brazilian bank's cloud secret manager

    Security · September 8, 2026 · 1 publisher

  36. Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks

    Product · September 8, 2026 · 1 publisher

  37. IMDSv1 turns an SSRF finding into unauthenticated credential theft in one hop

    Build · September 6, 2026 · 1 publisher

  38. Counting from the vendor advisory stretches the exploitation window to 116 days

    Build · September 5, 2026 · 1 publisher

  39. Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD

    Security · September 3, 2026 · 1 publisher

  40. Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020

    Security · August 28, 2026 · 1 publisher