Stay Ahead in Cybersecurity!
Get the week's top cybersecurity news and insights in 8 minutes or less
I will never spam or sell your information.
AI & Security
Cisco's 2024 Data Privacy Benchmark Study reveals that data privacy is a top concern for enterprises adopting generative AI (GenAI) technologies. The rise of "Shadow AI" poses significant risks, including data leakage and compliance violations, with record-breaking fines imposed on companies for breaching customer trust. Traditional methods like data sanitization and anonymization are insufficient against modern AI capabilities, necessitating more robust privacy-preserving techniques like confidential computing, which uses hardware-based trusted execution environments (TEEs) to secure data during processing.
Google announced updates to its Chronicle cybersecurity platform at the Google Cloud Next '24 conference, leveraging the Gemini LLM to summarize threat intelligence and guide investigations. Google is also adding security capabilities to GCP, including a natural language interface for Cloud Assist to identify potential attack paths, an Autokey tool for encryption key management, and recommendations for invoking confidential computing services. The company previewed a Privileged Access Manager (PAM) tool, Principal Access Boundary for identity-based policies, and released a next-generation firewall (NGFW), DDoS protection, and data protection services.
Maria Rigaki, Sebastian Garcia and colleagues from MUNI in Brno presented research on using large language models (LLMs) as pentesting agents in real network environments. They developed NetSecEnv, a simulated and real environment allowing multiagent, multigoal scenarios to study attack/defense dynamics. Human experts achieved a 100% win rate in a small 5-host environment without defenders. LLMs were then tested, showing they can work as effective planning agents that generalize to any environment without further training. The most successful used a two-stage "ReAct" design to reason then select the best action. Models like GPT-4 performed as well as humans, while fine-tuned local models outperformed GPT-3.5. However, challenges remain around LLM stability, hallucinations, repetition and cost. The research is part of a 4-year "AI Dojo" project to train human and AI agents.
Leadership Insights
Kane Narraway, Security at Canva, shares insights from over ten IT and security leaders on securing mass layoffs. He notes that systems aren't designed to handle exiting thousands of people at once, leading to issues like email delays and access not being removed promptly. Narraway emphasizes the importance of considering the experience of those impacted and designing the process with empathy. He presented on this topic at ComfyCon, sharing lessons learned from the group's collective mistakes.
Christina S., a CIO at KIK Consumer Product, shares a comprehensive 100 day plan framework for onboarding new CISOs. The plan focuses on defining the CISO's role, building rapport, assessing the current security program, developing a strategic plan, and gaining stakeholder support. Key activities include meeting with leadership, the security team, and critical partners, performing a gap analysis, identifying top risks, and presenting the security plan. The post generated extensive discussion, with cybersecurity leaders offering additional insights on understanding the business impact, evaluating the security culture, and maintaining flexibility in executing the plan.
Mike Holcomb wrote a guide to help IT cybersecurity professionals get started in industrial control systems (ICS) and operational technology (OT) security. The 10 steps include learning to think like an engineer, understanding ICS basics, exploring training options, learning standards and regulations, gaining hands-on experience, networking with the community, staying current, finding a mentor, building soft skills, and getting certified. Lee notes another version exists for engineering and automation professionals.
Career Development
A software engineer who recently transitioned to an information security engineer role, shares tips for others looking to make a similar career change. They recommend targeting a specific area of cybersecurity that aligns with your interests and background. Earning relevant certifications like Security+ and CEH can help, but are not guaranteed job offers. Getting feedback on your resume is crucial - if you're applying to many jobs without landing interviews, your resume likely needs improvement. Networking on LinkedIn and connecting with recruiters can open doors. In interviews, aim to be clear, concise and confident. Persistence is key - don't give up in a challenging job market.
Interesting discussion about the highest paying skills in cybersecurity industry. Some users says that combining deep technical skills with people leadership abilities in security is highly valuable and well-compensated. Others highlight application security (AppSec) engineering as a high-impact, well-paid skill, especially designing minimally invasive security controls in development pipelines.
Kevin Fielder, CISO at NatWest Boxed & Mettle, says many companies have slick hiring processes for external candidates but challenging internal promotion processes. To retain the best talent that already has organizational knowledge and demonstrated great work, companies should nurture existing employees and make it easy for them to progress. Otherwise, top performers will eventually take an easier path to career growth by moving on to another company.
Vendor Spotlight
Cloud security startup Wiz is reportedly in advanced negotiations to acquire rival Lacework for $150-200 million, a 98% markdown from Lacework's $8.3 billion valuation in 2021. Lacework has faced challenges including layoffs, C-suite turnover, and lagging adoption of its agent-based workload protections. The acquisition could expand Wiz's SMB customer base and complement its agentless approach to cloud workload security.
Singapore-based startup Staple has raised US$4 million in a pre-Series A funding round led by Wavemaker Partners. Staple uses AI to bridge the gap between physical documents and digital workflows, addressing document management challenges for businesses across 56 countries. The company plans to use the funds to enter new markets, improve its AI technology, and expand its document processing solutions. CEO Ben Stein emphasized Staple's focus on breaking down language barriers and simplifying complex document processing tasks, particularly in linguistically diverse regions like South-east Asia.
Upstream Security, a provider of XDR for connected vehicles and IoT, received an investment from Cisco Investments. The spread of complex IoT devices in mobility, automotive, and transportation introduces operational efficiencies and data-driven services, but also opens the door to large-scale cyber risks. Upstream's cloud-based platform analyzes the state of IoT assets in real-time to identify and mitigate risks, requiring no software or hardware installation. With 95% of new vehicles expected to have embedded connectivity by 2030, investing in automotive cybersecurity solutions is critical for wide adoption of the technology.
Tools
Open-source network monitoring tool, focusing on security-driven analysis.
A SIEM tool designed for Red Teams, aiding in tracking and alerting on Blue Team activities, with enhanced usability for extended operations.
Tool for reporting phishing websites to help combat cybercrime.
Community Highlights
Samip Aryal discovered a rate-limiting issue in Facebook's password reset flow that allowed bruteforcing a 6-digit nonce to takeover any account. The vulnerable endpoint lacked proper invalidation of the nonce after multiple incorrect attempts and had a long expiration time of ~2 hours. By bruteforcing the entire search space of 000000 to 999999, an attacker could obtain a valid nonce and reset the account password, resulting in a 0-click or 1-click account takeover depending on how the nonce was rendered to the user.
Researchers released an exploit code for the actively exploited vulnerability CVE-2024-3400 in Palo Alto Networks’ PAN-OS. Justin Elze, CTO at TrustedSec, also published the exploit used in attacks against the CVE-2024-3400 vulnerability on twitter. This week, US CISA added CVE-2024-3400 to its Known Exploited Vulnerabilities (KEV) catalog, giving U.S. federal agencies until April 19th to remediate the flaw. The public availability of the exploit code may lead to a surge in exploitation attempts.
@bxmbn discovered an IDOR vulnerability in a major U.S. bank's special offer application process. By decoding a ridNumber parameter, they could access other users' offers, exposing PII like full names, addresses, emails, phone numbers, and birthdates. The bank, despite having an active bug bounty program, had overlooked this issue which could have allowed attackers to harvest customer data.
Thank you
If you found this issue useful, I'd really appreciate if you could forward it to your friends and colleagues!
Have questions, comments, or feedback? Let me know on LinkedIn, Twitter, or share your feedback.
Best,
Nikoloz