Wiz researchers discovered a vulnerability in AI provider Replicate that could have allowed threatActors to access customers' proprietary AI models and sensitive information. The issue stems from Replicate using the open-source Cog tool to package models, which can allow arbitrary code execution and enable cross-tenant attacks via malicious models. The researchers achieved remote code execution with elevated privileges on Replicate's infrastructure and manipulated the centralized Redis server to tamper with customer requests and AI outputs, threatening model integrity and accuracy.
New research finds 60% of employees use generative AI tools at work, but only 15% of organizations have formal AI governance policies. The gap is attributed to leaders' discomfort with rapidly evolving AI technologies and employees prioritizing AI benefits over adhering to policies. Experts suggest building AI policies from the ground-up with employee input and leveraging industry frameworks like NIST's AI Risk Management Framework. In cybersecurity, AI risks include data poisoning, evolving threats, and model bias due to opacity.
Google researcher Alissa Irei described at RSAC 2024 how the company has seen modest but significant success using generativeAI to patch software vulnerabilities. On average, a data breach from a known vulnerability costs $4.17 million, and nearly half remain unpatched two months after fixes are available. Google's experiment used an AI model similar to Gemini Pro to generate and test patches for 1,000 simple bugs, with engineers approving 15% to add to Google's codebase, potentially saving months of effort.
Leadership Insights
Dr. Ryan Louie, a psychiatrist, highlights the importance of psychological safety in medical teams, which is often lacking in cybersecurity due to the need for secrecy and discretion. Malcolm Harkins, chief security and trust officer at Hidden Layer, emphasizes that burnout in cybersecurity is a systemic problem, with origins in the relentless pace of demands like Patch Tuesday. Surveys confirm the toll of never-ending work cycles on cybersecurity professionals' mental health. CISOs face additional isolation due to the secrecy and confidentiality expected in their roles, compounded by the increasing complexity of securing remote and hybrid workforces.
According to a KPMG survey of 200 security leaders, CISOs, and AI security officers at firms with over $1 billion in revenue, 40% reported their SOC was hit by a recent cyberattack leading to a security breach. However, 85% remained confident in their SOC's ability to prevent sophisticated attacks. Nearly 90% anticipated their company's SOC budgets and headcount will increase by under 20% over the next two years, with the average annual SOC budget currently at $14.6 million. The anticipated budget increases come amid a growing number of cyber threats against large organizations.
Richard Starnes, a strategic CISO, warns that technical debt is a often-overlooked threat in cybersecurity. Technical debt refers to the accumulation of shortcuts, workarounds, and outdated systems that prioritize speed over long-term security. Legacy systems with technical debt often contain unpatched vulnerabilities that can be exploited in attacks like ransomware and supply chain compromises. Technical debt also hinders the ability to implement new security solutions and establish effective governance.
Stay Ahead in Cybersecurity!
Get the week's top cybersecurity news and insights in 8 minutes or less
I will never spam or sell your information.
Career Development
Prof Bill Buchanan OBE FRSE, Professor of Applied Cryptography at Edinburgh Napier University, provides tips on how to get started learning cryptography. He recommends focusing on one topic at a time, including hashing, symmetric key, key exchange, public key, KDFs, MACs, tunneling, and digital signatures. OpenSSL is highlighted as a valuable tool for exploring cryptographic methods. Prof Buchanan emphasizes the importance of understanding both theory and practice, and suggests diving deep into specific topics of interest. He also provides links to several cryptography libraries to facilitate hands-on learning.
Reddit users share advice for managing ADHD while working in cybersecurity. Key tips include taking breaks to avoid hyperfocus burnout, prioritizing tasks, setting boundaries, and taking care of your mental health. Some find ADHD traits like hyperfocus can be an advantage in the field. Medication may help with inconsistent work ethic. Put on a professional mask when needed but be yourself otherwise. Make notes to stay on track when context switching.
I argue that the cybersecurity skills gap is largely due to the industry's unrealistic job requirements and elitist gatekeeping. Entry-level positions often demand years of experience, advanced certifications, and proficiency in multiple programming languages. This creates an intimidating barrier to entry that discourages talented individuals, including experienced software engineers, from transitioning into cybersecurity roles. I suggest hiring for potential and attitude, investing in training and mentoring, fostering inclusive environments, and celebrating diverse backgrounds to help close the skills gap.
Supply Chain
CyberArk announced a deal to acquire Venafi for $1.54 billion to integrate Venafi's machine identity and access management expertise with CyberArk's human IAM offerings. The acquisition is expected to enable CyberArk to secure every identity with the right privilege controls in a cloud-first, GenAI, post-quantum world. The deal includes $1 billion in cash and $540 million in shares, and is expected to close in the second half of 2024.
SonicWall announced its new SonicPlatform cybersecurity management platform at RSA Conference 2024, designed to unify SonicWall products into a single interface. The platform aims to simplify management of both cloud and on-premises infrastructures, and deliver deep product integration for sharing contextual information across enforcement points. SonicPlatform is especially beneficial for MSPs and MSSPs, enabling efficient management of multiple client environments, automation of key tasks, and valuable insights through a user-friendly interface.
SAGE Cyber, formerly part of HolistiCyber, has launched as an independent company offering a cybersecurity defense planning and optimization (CDPO) platform. The SAGE Platform helps CISOs assess overlapping tools, eliminate redundant platforms, and perform strategic self-assessments. By automating various processes, the platform enables data-driven decisions to optimize security posture, budgets, and gain visibility into the effectiveness of security programs, while improving operational efficiency and reducing risk.
Malware researcher shares their first public malware analysis of Formbook, a threatActor malware that has been active in the wild for over 5 years, spread mainly through phishing campaigns. Static analysis using Detect It Easy and Exeinfo PE reveals the malware executable contains an embedded AutoIt3 script, a BASIC-like scripting language for automating Windows tasks. The researcher hypothesizes the executable is a loader that prepares memory and loads the AutoIt script for execution.
Ilias Mavropoulos provides a comprehensive guide to the Flipper Zero multi-tool device. The guide covers the unique features, basic functionality, and step-by-step instructions for common hacking use cases seen in the wild, such as capturing and replaying Sub-GHz signals, using it as a BadUSB to emulate a keyboard, RFID fuzzing, exploiting insecure NFC cards, and interacting with screens or HVAC systems during red team engagements. It also provides resources for customizing the firmware and extending functionality with external plugins.
Jose Selvi reviews the strengths and weaknesses of HTTP Strict Transport Security (HSTS), a protection against SSLStrip attacks. An attacker could exploit an inter-operation vulnerability to bypass HSTS protection and use techniques like SSLStrip. The Network Time Protocol (NTP) is used by operating systems for time synchronization and uses UDP port 123. Selvi introduces Delorean, a tool that can be used in MitM attacks to manipulate NTP responses and jump the victim's clock to a future date, potentially bypassing HSTS.
Powerful open-source log management platform for data analysis.
Versatile security appliance solution, offering firewall and VPN functionalities.
A C++ shellcode launcher designed to be fully undetected.
If you found this newsletter useful, I'd really appreciate if you could forward it to your friends and share your feedback below!
Have questions, comments, or more detailed feedback? Let me know on LinkedIn, Twitter, or share your feedback.
Best,
Nikoloz