Breach Proof researchers discovered several vulnerabilities in Microsoft’s Azure Health Bot, a software used by healthcare providers as a patient-facing chatbot. The flaws could have allowed attackers to access confidential medical information and backend infrastructure across multiple tenants. Microsoft quickly fixed the issues after receiving the report, and found no evidence of exploitation. The most severe vulnerability enabled taking control of a shared backend server with access to databases containing multi-tenant data.
A new GitHub project aims to organize and track the techniques used by threatActors leveraging artificialIntelligence in their attacks. The project focuses on cyber threat attacks facilitated by AI, excluding political influence or mis/dis/mal information campaigns, with some coverage of AI-enhanced fraud activities. Confirmation of AI use by threat actors is limited to reporting from organizations using their own AI tools or actors using AI on already-compromised endpoints. The project also attempts to map these techniques to MITRE ATT&CK and ATLAS, and builds off Microsoft and OpenAI’s classification of LLM TTPs to better describe this activity.
A new study by IBM and AWS reveals that while generativeAI is a top priority for many organizations, there is no simple solution to ensure its security. The survey found 82% of C-suite leaders believe secure and trustworthy AI is crucial for business success. However, organizations are currently securing only 24% of their generative AI projects, highlighting a discrepancy between priorities and actions. IBM is working with AWS on approaches to improve the situation and is launching the IBM X-Force Red Testing Service for AI to advance generative AI security.
Leadership Insights
A growing number of CISOs are dissatisfiedwith their roles, with 75% open to changing jobs according to recent studies. CISOs cite a lack of executive support, misalignment on acceptable risk, and increased personal liability from new regulations as key reasons for their frustration. To address this, experts say organizations should give CISOs a direct line to the board, include them in D&O insurance, and provide standalone security budgets to better align authority and accountability.
LogRhythm reports that 95% of companies worldwide adjusted their cybersecurity strategy in the past year due to the rapidly changing threat environment. 78% state that the cybersecurity leader or CEO are now responsible for protecting against and responding to cyber incidents, reflecting a shift to viewing cybersecurity as a central pillar of business strategy. The top factors driving strategy changes include the shifting regulatory landscape (98%), customer expectations for data protection (89%), and the rise of AI-driven threats (65%). However, communication gaps remain, with 44% of non-security executives not understanding regulatory requirements.
New research from IANS Research and Artico Search reveals that nearly a third of CISOs in the tech sector are dissatisfied with their compensation. The study found that CISO pay varies significantly based on organization type and size, with those at publicly listed firms earning the most (median $1 million) and those at founder-majority-owned companies earning the least. The researchers note that the complexity of the CISO role increases with company scale, leading to higher compensation packages, but emphasize that “not all CISO roles are equal in tech.” The dissatisfaction among CISOs, coupled with the high-pressure nature of the role and potential business impact of cyberattacks, raises concerns for cybersecurity industry leaders.
Stay Ahead in Cybersecurity!
Get the week's top cybersecurity news and insights in 8 minutes or less
I will never spam or sell your information.
Career Development
Dray Agha, a UK member of the Huntress Threat Operations team, describes a day in the life working with US and Australian colleagues to provide 24/7 threat defense. The global team has developed a smooth process to handoverincomplete cases between regions. Internal team sync-ups happen over Zoom calls and asynchronous communication to brainstorm improvements. When investigating suspicious activity, the team uses every available tool and telemetry source to gain context and provide detailed analysis to partners. Tuning detectionsand alerts is a constant process to reduce false positives. Downtime is used to proactively hunt for novel attackTechniques that don’t yet have detections.
George Platsis describes the life of a cybersecurity incident responder, which can go from calm to chaotic in an instant when an incident occurs. Responders are driven by a sense of duty, enjoy challenges, and thrive in the constant change. Pre-incident tasks include vulnerability scanning, threat research, and tool configuration. When an incident hits, responders jump into action following the NIST incident response lifecycle of preparation, detection and analysis, containment, eradication, and recovery, and post-incident activities. Thorough preparation is key to reducing harm and stress during the response. Incident response is intense and demanding, requiring both technical and soft skills, and organizations should support responders’ well-being.
Tom Van de Wiele, principal security consultant at F-Secure, leads red team operations that are hired by well-protected companies to thoroughly test their security by taking on the role of attackers. The red teams use a diverse range of skills and real-world hacking methods to find weak points in the companies’ security, often involving on-location physical access in addition to digital attacks. The goal is to help companies protect against real-world threats from criminals and opportunistic attackers.
Vendor Spotlight
Akamai Technologies announces a definitive agreement to acquire API security company Noname Security. The acquisition will enable Akamai to extend protection across all APItraffic locations and meet growing customer demand as API usage expands. Akamai has seen 109% year-over-year growth in API attacks and believes the addition of Noname will provide the breadth of integrations and deployment choices needed to deliver comprehensive API protection for customers across all environments.
Wiz, a CNAPP provider, has raised $1 billion at a $12 billion valuation, led by Andreessen Horowitz, Lightspeed Venture Partners, and Thrive Capital. The company attributes its success to the dedication of its employees, investors, and customers who trust Wiz to support their cloud security journey. Wiz plans to use the new capital for talent acquisition, product expansion, and strategic acquisitions to propel innovation and cover more ground in the rapidly evolving cybersecurity landscape.
Anomali unveiled its new AI-powered Security Operations Platform, centered around an intelligent Anomali Copilot that automates key tasks. The platform leverages a proprietary cloud-native security data lake for improved speed, scale, performance and reduced costs. Former DoD CIO Dana Deasy praised the Copilot’s automated productivity benefits for security talent.
Community Highlights
Embracing Large Language Models (LLMs) requires understanding the associated risks and actively mitigating potential security implications. The article explores risks, vulnerabilities, and ethical considerations based on the author’s experiences with LLMs. It aims to provide insights for security enthusiasts new to LLM security, including an overview of the OWASP Top 10 for LLM applications, vulnerability categorization, and open-source offensive and defensive tools for bug bounty hunters and pentesters to try.
Maciej Pocwierz created an empty private S3bucket for testing and was shocked to find a $1,300 AWS bill the next day due to nearly 100,000,000 PUT requests. Enabling CloudTraillogs revealed thousands of unauthorized write requests from third parties due to a popular open source tool having a default configuration using the same bucket name. AWS charges for unauthorized requests to S3 buckets, so the author was billed despite the requests being rejected. The author also found they could collect over 10GB of sensitive data in 30 seconds by opening the bucket to public writes, highlighting the potential for serious data leaks.
Amjad Ali discovered a bug allowing unauthorized account creation in a web app using Auth0 for authentication. The app had registration disabled, but by modifying the login request to the /dbconnections/signup endpoint with required parameters like client_id, connection, email, and password, he successfully created an account and logged in. This authentication bypass is due to improper configuration of Auth0’s “Disable Sign Ups” feature. To mitigate, ensure this setting is enabled in the Auth0 application database settings.
Tools
In-depth tool for attack surface mapping and asset discovery in network security.
Advanced red team and adversary simulation software in the current C2 market.
A framework for executing arbitrary VBA source code directly in memory.
Thank you
If you found this issue useful, I'd really appreciate if you could forward it to your friends and colleagues!
Have questions, comments, or feedback? Let me know on LinkedIn, Twitter, or share your feedback.
Best,
Nikoloz