Google security researchers Lambert Rosique, Jan Keller, Diana Kramer, Alexandra Bowen and Andrew Cho share how they are using generative AI to significantly speed up writing incident summaries as part of their security and privacy incident response process. By structuring incident data with tags and refining AI prompts, they found AI-generated summaries covered all key points, were rated 10% higher in quality than human-written ones, and cut drafting time in half. Risks of AI errors are mitigated through human review, disabling data storage, and monitoring quality over time.
The Department of Homeland Security (DHS) has released new guidelines to help critical infrastructure owners and operators defend against threats related to artificialIntelligence (AI) systems. The guidance addresses risks such as adversarial manipulation of AI systems, unintended consequences due to AI shortcomings, and the use of AI to augment and scale attacks. It emphasizes the need for transparency, secure by design practices, and a culture of AI risk management throughout the AI lifecycle.
Google has published a new Secure AI Framework white paper detailing their approach to securing the AI software supply chain. As AI becomes more integrated into everyday products, the same software supply chain security problems are emerging as with traditional software, but at an accelerated pace. Google argues that existing security measures like provenance metadata, SLSA, and artifact signing can be adapted to AI ecosystems. The framework emphasizes capturing and organizing metadata, increasing integrity, and sharing provenance info with others to enable AI practitioners to verify the source and integrity of models and datasets. Google believes building security into AI infrastructure from the start is key to preventing future supply chain attacks.
Leadership Insights
Jonathan Trull, Chief Security Officer at Qualys, shares his perspective on the overuse of the word "critical" in cybersecurity. He advocates for greater focus on cyber risk quantification and using business language to effectively communicate with executives, boards, and risk committees.
The SOC-CMM team has released a new version of their assessment tool with minor bug fixes, improvements, and added guidance based on community feedback. A major change is the addition of mapping to NIST CSF 2.0, while retaining NIST CSF 1.1 mapping for now. Future versions will drop the 1.1 mapping. The tool also now includes an embedded results sharing form to share anonymized assessment results back to SOC-CMM for trend analysis.
Zscaler shares insights on the career path of a CISO and the option to become a virtual CISO (vCISO). A vCISO is an independent or contracted employee who carries out the role of a CISO for companies that may not have the case or budget for a full-time equivalent. vCISOs can advise multiple organizations simultaneously or focus on one at a time, typically working from home. The article highlights five signs that a seasoned CISO may be ready to transition into a vCISO role.
Stay Ahead in Cybersecurity!
Get the week's top cybersecurity news and insights in 8 minutes or less
I will never spam or sell your information.
Career Development
Adam Goss, a senior CTI analyst, shares his typical workday which involves threatIntelligence, vulnerabilityIntelligence, and threatHunting tasks. In the morning, his team analyzes threat intelligence from open sources and their TIP to identify new threats relevant to their organization. They also analyze vulnerability intelligence to check for new vulnerabilities that may impact their systems and report them to the vulnerability management team for patching. For threat hunting, they use IOC-based hunting with indicators from their CTI database, behavior-based hunting with SIEM/EDR detection rules, and TTP-based hunting with Sigma rules.
Euan Doyle, a businessInformationSecurityAnalyst, describes his journey from musician to cybersecurity professional. He manages security training programs, phishing simulations, and external support teams. Doyle also handles security exceptions, vetting and approving requests from the business. Indicator of Compromise (IOC) checks are an ongoing task, involving sharing information with industry peers and ensuring email and firewall security are properly managed.
Chevron Cyber Threat Intelligence Analyst Protects Global Assets
Jessica Lee, a cyber threat intelligence analyst at Chevron, works to protect the company's information and technology assets across all countries where Chevron operates. With a background in linguistics, Lee transitioned from a coordinator role to an analyst position, leveraging her skills in researching and writing about the cyber threats Chevron faces. In collaboration with other teams, Lee helps make recommendations to keep the company protected against adversaries attempting to steal data, corrupt systems, or force shutdowns. Staying ahead of highly motivated threat actors is one of the biggest challenges in cybersecurity.
Vendor Spotlight
Israeli startup Apex, focused on protecting rapid enterprise adoption of AI tools, raised $7M in a seed round led by Sequoia Capital and Index Ventures, with participation from OpenAI CEO Sam Altman. Apex has been running trials with Fortune 500 companies and investment firms, nearing paid contracts. The funds will accelerate product development, hiring, and marketing. With growing demand for AI tools like ChatGPT, users seek ways to protect their data and prevent threats and inappropriate data from entering their systems. Apex is building extra security layers needed for enterprises to safely adopt AI.
British cybersecurity firm Darktrace announced it has agreed to be acquired by U.S. private equity firm Thoma Bravo for $5.315 billion in an all-cash deal. The board believes Darktrace's achievements are not reflected in its current valuation on the London Stock Exchange, trading at a discount compared to its global peers. The deal represents a 44.3% premium to Darktrace's average share price over the past three months. Darktrace, founded in 2013 and based in Cambridge, UK, specializes in AI-based protection against cloud attacks for large companies and events.
Ashish Kurmi and Varun Sharma, former Microsoft engineers and cybersecurity veterans, founded StepSecurity in 2022 to help developers secure their CI/CD pipelines. The startup raised a $3M seed round led by Runtime Ventures to expand its product that currently supports GitHub Actions, with plans to add other CI/CD tools. StepSecurity has paying customers across crypto, healthcare, and cybersecurity industries, aiming to prevent CI/CD attacks like the SolarWinds and Codecov hacks.
Community Highlights
A phishing campaign in August 2023 distributed IcedID malware using the Prometheus Traffic Direction System (TDS), leading victims to download a malicious JavaScript file from a fake Azure portal. The executed file downloaded and ran an IcedID DLL, establishing persistence and C2 communication. After 30 hours, IcedID downloaded a Cobalt Strike beacon, which the threat actor used for discovery, credential access via LSASS, and privilege escalation with GetSystem. Within 5 minutes, lateral movement began, targeting a domain controller and file shares using tools like AdFind and a custom PowerShell script called AWSCollector. Data exfiltration to AWS S3 buckets started 1.5 hours later, and additional Cobalt Strike beacons were deployed to more hosts over the following days as discovery efforts continued, focusing on the virtualization infrastructure and sensitive documents. On day 8, AnyDesk was installed on a domain controller, a new user was created, and another Cobalt Strike beacon was deployed.
Sergio Marotco shares a project publishing best practices for segmenting corporate networks suitable for any company. Diagrams are available showing basic segmentation at Level 1 to protect against targeted attacks, though the corporate network should still be considered potentially compromised. Level 2 adopts more security practices like duplicating production infrastructure and implementing DevSecOps, making it harder to compromise production but increasing cost and complexity. Level 3 requires strong executive support for cybersecurity and a sizable dedicated security team.
Security researcher Crypto discovered a stored XSS vulnerability in the Apple Discussions forum that allowed arbitrary JavaScript execution via user profiles. By injecting a malicious payload in the "Location" field of a profile, the XSS could be triggered when other users viewed it, potentially allowing cookie theft and other attacks. Apple awarded a $5000 bounty for the finding after a 3-month remediation process and acknowledged the researcher on their security Hall of Fame page.
Tools
Platform for search, logging, security, and analytics, using the Elastic Stack.
Advanced tool focusing on endpoint monitoring, digital forensics, and incident response.
A tool that automates the reconnaissance process for identifying attack surfaces.
Thank you
If you found this issue useful, I'd really appreciate if you could forward it to your friends and colleagues!
Have questions, comments, or feedback? Let me know on LinkedIn, Twitter, or share your feedback.
Best,
Nikoloz