Apple’s Security Engineering and Architecture (SEAR) team announced Private Cloud Compute (PCC), a new cloud intelligence system for private AI processing. PCC extends the security and privacy of Apple devices into the cloud, ensuring personal user data sent to PCC isn’t accessible to anyone other than the user, not even Apple. PCC is built with custom Apple silicon and a hardened operating system designed for privacy.
OpenAI operates some of the largest AI training supercomputers, enabling industry-leading model capabilities and safety. To achieve their mission safely, they prioritize securing these systems, including measures to protect sensitive model weights within a secure environment. The research infrastructure, built on Azure and utilizing Kubernetes, must support protecting model weights, algorithmic secrets and other assets while giving researchers sufficient access.
SkyQuest projects the global AI in cybersecurity market will reach $114.30 billion by 2031, growing at a CAGR of 22.53% from 2024-2031. The increasing use of real-time threat detectionsystems is driving demand for AI in cybersecurity. Organizations are realizing the need for proactive threat detection and response due to the growing complexity and frequency of cyberattacks. Service offerings like automated threat detection, real-time response, and predictive analytics are dominating the market due to their effectiveness in mitigating sophisticated cyber threats.
Leadership Insights
Amy Herzog, one of several CISOs at Amazon, is responsible for securing hardware devices and advertising products and services. Herzog describes how Amazon takes a “working backwards” approach, starting with customer needs and involving security specialists early in the product development process to collaborate with design and product teams. This avoids last-minute security reviews and fosters a positive feedback loop, producing better results faster.
Robert Grazioli, CIO at Ivanti, says effective cybersecurity is non-negotiable in today’s complex threat landscape. Despite increased spending on risk management and cybersecurity, companies face challenges managing their attack surface due to staffing shortages and uncertain economic conditions. Grazioli argues it’s time to break down silos between IT and security by fostering alignment between the CIO and CISO roles, which have historically had distinct and sometimes contradictory objectives.
Richard Starnes discusses how the rise in cyberattacks has created a communication gap between CISOs and executives. Traditional security metrics often fail to provide a clear picture of the effectiveness of cybersecurity investments. Outcome-driven metrics (ODMs) offer a solution by shifting focus from activity-based metrics to measuring actual protection levels achieved. ODMs help align security with business objectives and risk appetite, fostering better communication and resource allocation.
Stay Ahead in Cybersecurity!
Get the week's top cybersecurity news and insights in 8 minutes or less
I will never spam or sell your information.
Career Development
A Reddit user shares their experience progressing in the cybersecurity industry over 5 years without any certifications. They started in an entry-level SOC analyst role monitoring alerts, then moved into a tuning-focused role dealing with false positives and SIEM projects. Now they are getting offers for full SOC L2 positions. The user questions whether their hands-on experience has weighed more heavily than certifications, or if they have just been lucky in their career journey so far.
A Reddit thread explores the career progression options for cybersecurity professionals who prefer to remain as individual contributorsrather than transitioning into management roles. Responses suggest that while there are senior, staff, and principal engineer positions available for software engineers, the equivalent path for cybersecurity is less clearly defined. Some suggest that security architect roles may be the closest parallel, while others point out that the ceiling and opportunities vary greatly depending on the organization and industry. The discussion highlights the need for clearer career progression frameworks and recognition for high-level technical expertise within the cybersecurity field.
A recent discussion thread explores what security leaders should prioritize when starting in a new role. Commenters suggest beginning with a thorough risk assessment and business impact analysis to understand the organization’s current security posture. Choosing a security framework and evaluating the company’s level of compliance is also recommended. Building trust and relationships with key stakeholders from the outset is seen as critical for the success of any new security initiatives. The overall advice is to first assess where things stand before developing a roadmap to address gaps and strengthen the security program.
Supply Chain
Cole Gromus shares insights on the strategic brilliance of the CrowdStrike-AWS partnership. CrowdStrike, a long-time AWS customer potentially spending over $10M annually, leveraged this relationship to establish a strong partnership. By selling products on the AWS Marketplace since 2017, CrowdStrike became the first cybersecurity partner to hit $1 billion in sales. Remarkably, Amazon is now an eight-figure customer of CrowdStrike, fueling their growth towards $10 billion ARR. This symbiotic partnership allows CrowdStrike to scale while providing AWS with a robust security narrative.
Fortinet announced plans to acquire cloud security startup Lacework for an undisclosed amount. Lacework, founded in 2015 and valued at over $1 billion, raised $1.9 billion from investors like Google Ventures. The acquisition will modernize Fortinet’s cloud security offerings by integrating Lacework’s CNAPP product into Fortinet’s Unified SASE solution, allowing customers to identify and remediate risks in cloud-native infrastructures. Fortinet will ensure a smooth transition for Lacework’s 1,000 customers and partners.
Seven AI, co-founded by Yonatan Striem Amit and Lior Div, raised $36 million led by Greylock to develop AI-based software that autonomously hunts for cyber threats. The company, valued at over $100 million, is testing its system with early corporate users to perform actions like verifying user identities and removing threats. The NSA recently highlighted the security challenges of AI systems and the need to harden defenses as AI is increasingly integrated into business operations.
Obsidian Security detects phishing kits or Phishing-as-a-Service (PhaaS) websites for customers by analyzing fuzzy hashes of visited website content. EvilProxy/Tycoon is an Adversary-in-the-Middle (AitM) phishing kitthat steals credentials and session cookies in real-time, often protected by Cloudflare’s bot/scraping protection. Computing a fuzzy hash for the DOM after Javascript obfuscation is unwound proves useful for detecting similar EvilProxy/Tycoon sites. The same fuzzy hashing technique can catch users visiting phishing sites created by a popular APT group targeting different companies.
Justin Bui introduces Hermes, a tool developed in Swift for testing and exploiting the security of macOS systems. The talk covers the development process, functionality, and practical applications of Hermes in red teamingscenarios. Bui provides insights into how this tool can be used to improve security assessments and enhance defense strategies for macOS platforms.
Scammers are increasingly using OTP bots to bypass two-factor authentication (2FA) by manipulating victims into sharing one-time passwords (OTPs) via social engineering. The bots automate the process of calling victims, following pre-configured scripts to impersonate legitimate organizations like banks, payment systems, or cloud services. Attackers manage the bots through browser-based panels or Telegram, customizing the calls with victim details and using features like voice selection and phone number spoofing to increase credibility. Once the victim shares the OTP, the attacker gains access to their account.
A command line utility for managing volume shadow copies with capabilities for evasion, persistence, and file.
Serverless, real-time data analysis framework for incident detection and response.
Open source application to instantly remediate common security issues through the use of AWS Config.
If you found this newsletter useful, I'd really appreciate if you could forward it to your friends and share your feedback below!
Have questions, comments, or more detailed feedback? Let me know on LinkedIn, X, or fill-out the form.
Best,
Nikoloz