AI & Security
Google announced new AI-powered theft protection features for Android devices running versions 10 and later. The features aim to secure users’ devices and data before, during, and after a theft attempt. A new “private space” feature allows users to host sensitive apps in a hidden, PIN-protected area. Theft Detection Lock uses Google AI to sense if someone snatches the phone and tries to flee, automatically locking the screen. Offline Device Lock provides added protection when a thief tries to disconnect the phone for prolonged periods.
Palo Alto Networks researchers Bar Matalon and Rem Dudas discuss their groundbreaking research into AI-generated malware on the Threat Vector podcast. The researchers successfully generated sophisticated malware samples based on MITRE ATT&CK techniques for Windows, macOS and Linux, testing them against their Cortex product. Alarmingly, AI models can impersonate specific threat actors and malware families with high accuracy using open-source materials. Dudas predicts impersonation and psychological warfare will be significant in coming years, potentially enabling nation-state actors to conduct false flag attacks that complicate attribution and detection.
Wallarm’s Q1 API ThreatStats report highlights the business impact of API vulnerabilities in AI projects. Mercedes-Benz suffered a major API leak exposing source code and internal data. NVIDIA’s Triton Inference Server, used for AI model deployment, had a vulnerability (CVE-2023-31036) enabling unauthorized path traversal. The report emphasizes the prevalence of API attacks targeting popular enterprise applications and DevOps tools, resulting from a lack of sufficient security controls in the rush to leverage APIs.
Leadership Insights
Rex Booth, CISO at SailPoint, argues that cybersecurity hiring managers are looking for candidates in the wrong places by overemphasizing certifications and degrees. Entry-level positions often have burdensome requirements like specific degrees, certifications like Security+ or CISSP, and expensive training courses, artificially raising barriers to entry. Recruiters also fall into the trap of using these credentials as de facto indicators of value. Booth suggests broadening the candidate pool and reevaluating which qualifications truly matter to find candidates ready to deliver value in roles like SOC positions.
Trend Micro surveyed 2600 IT leaders and found that 79% of CISOs feel pressure from their board to downplay the severity of cyber-risks. CISOs are often seen as repetitive, overly negative, or dismissed by the board. This leads to cybersecurity being treated as part of IT rather than a strategic business impact, resulting in a lack of proactive investment until a costly breach occurs. However, when CISOs can measure and communicate the business value of cybersecurity, they gain more credibility with the board.
According to Deryck Mitchelson, Field CISO EMEA at Check Point, cyber resilience is crucial as threats increase, with a 90% rise in publicly extorted ransomware victims in 2023. Resilience goes beyond just having a secure perimeter; it’s about maintaining core functions during and after attacks, and being prepared for inevitable breaches. Leadership must actively engage in cyber resilience, treating it as a critical business function, not just an IT issue. The technological and human elements must work together, with advanced solutions like AI for threat detection and human insight for contextualization and fostering a security-aware culture.
Stay Ahead in Cybersecurity!
Get the week's top cybersecurity news and insights in 8 minutes or less
I will never spam or sell your information.
Career Development
A recent Reddit thread asked cybersecurity professionals to share how they broke into the industry. The responses highlight diverse paths, from transitioning within IT support roles to leveraging military experience. One common theme was the importance of earning the CompTIA Security+ certification to demonstrate foundational cybersecurity knowledge to potential employers. Several commenters also credited a combination of luck and good timing in landing their first security role, emphasizing the importance of being prepared to seize opportunities. The stories underscore that while there is no singular path into cybersecurity, a combination of relevant experience, practical skills, and professional networking can help aspiring practitioners break into this high-demand field.
Ron Reiter, CTO and co-founder of cybersecurity firm Sentra, started hacking as a teenager in Israel for fun, not harm. His skills led to his recruitment into the IDF’s elite Unit 8200, where he received professional training in SIGINT and cyberwarfare. Reiter’s journey from curious kid to professional hacker was shaped by his military service defending Israel’s national security.
Industry critics argue many top cybersecurity certifications are too theoretical, impractical, and superficial to keep up with rapidly evolving threats. Valuable certifications should emphasize practical application, in-depth knowledge of specific areas, and resourcefulness. For enterprises, certifications ensure employees have necessary skills for security operations and compliance. Employers should carefully evaluate certifications based on showcased knowledge and practical skills, not just popularity. Certifications are one important piece of the holistic cybersecurity puzzle, alongside experience and continuous learning.
Supply Chain
LogRhythm CEO Chris O’Malley says the merger between LogRhythm and Exabeam will create a “strong, customer-obsessed, singularly focused global leader in AI-driven security operations.” The deal is expected to close in Q3 with details on leadership and terms not disclosed. The combined company would be the fourth-largest SIEM vendor by revenue based on 2022 IDC data. Forrester analyst Allie Mellen suggests Cisco’s recent $28 billion acquisition of Splunk has created an opening in the SIEM market that may be pressuring other vendors to consolidate.
Palo Alto Networks and IBM announced a broad partnership to deliver AI-powered security outcomes for customers. Palo Alto Networks will acquire IBM’s QRadar SaaS assets, including QRadar intellectual property rights. QRadar SaaS clients will be migrated to Palo Alto Networks’ Cortex XSIAM platform, while on-prem QRadar clients can choose to remain or migrate with no-cost migration services offered.
Cybersecurity insurance companies like Coalition and Beazley are now offering their own MDR services to end customers and MSPs. Coalition’s John Roberts says their services help MSPs become MSSPs. Coalition introduced MDR in Q2 2023 as an outgrowth of their incident response services, after customers asked them to “stick around” following successful engagements. The company aims to provide comprehensive protection by combining insurance with security tools and services.
Investigations by ZachXBT reveal that the threatActors Lazarus Group (aka Bluenoroff or APT38), tied to the North Korean government, laundered $200M from over 25 hacks targeting cryptocurrency companies and individuals between August 2020 and October 2023. Funds from hacks like CoinBerry, Unibright, and CoinMetro were transferred through intermediary wallets, consolidated, and deposited to Tornado Cash for mixing. The laundered funds were then slowly transferred in batches to P2P marketplaces Paxful and Noones to exchange for fiat until November 2023.
Jason Jacobi, an 18-year-old researcher, discovered a VirtualBox guest-to-host escape vulnerability in 2019 which was assigned CVE-2019-2703. Jacobi was inspired by the VirtualBox research of Niklas Baumstark and focused on finding subsystems reachable with guest-controlled inputs. By analyzing the VirtualBox source code and the RT_UNTRUSTED_VOLATILE_GUEST macro, Jacobi identified the VBVA subsystem as a promising attack surface for further investigation.
A Reddit user sparked a discussion among cybersecurity practitioners about their successes in automating security tasks and the challenges they face. The thread reveals a strong desire to streamline processes, but hurdles remain for many. Respondents shared a range of automated tasks, from vulnerability scanning to incident response, while also highlighting areas where automation proves difficult or elusive.
Tool aimed at helping malware researchers identify and classify malware samples.
Project to enumerate proxy configurations and generate shellcode from CobaltStrike.
Comprehensive vulnerability scanner dedicated to identifying and managing security threats.
Thank you
If you found this issue useful, I'd really appreciate if you could forward it to your friends and colleagues!
Have questions, comments, or feedback? Let me know on LinkedIn, Twitter, or share your feedback.
Best,
Nikoloz