At RSA Conference, tales of real-world cyberattacks and warnings of … – SiliconANGLE News
The challenges of securing organizations havent changed much in the past year, and that means theres still a lot more that needs to be done especially as generative artificial intelligence and chatbots will require new tactics to fight attackers.
Thats according to two panels that presentedat last weeks RSA Conference in San Francisco. Among their other findings: Responding to incidents still could be better with more threat sharing and better public/private partnerships, analysts still have some tough sledding ahead as these new attacks appear almost like clockwork, and theres still a burning need for more training of new professionals in the field.
There are some bright spots, such as the way analysts quickly figured out the 3CX supply chain attack and shared its particulars. But ransomware and data extortion are still popular attack methods, and the bad guys are getting better at finding and fooling their target victims.
The first panel wasa perennial favorite at the conference, organized by the SANS Institute, a leading security training and education nonprofit. Moderated by Ed Skoudis, who is president of the SANS College, it featured SANS top cybersecurity instructors with many decades of collective cybersecurity experience: Heather Mahalik, a senior director at Cellebrite DI Ltd.; Katie Nickels, director of threat intelligence for Red Canary and one of the contributors to the Mitre ATT&CK framework; and Stephen Sims and Johannes Ullrich, both of SANS.
They came together to discuss their top most dangerous new attack techniquesthey have seen in the past year. Each panelist focused on their own favorite attacks, includingsearch engine optimization and paid advertising, adversarial AI, ChatGPT-powered social engineering and software supply chain attacks.
Nickels showed Gootloader, a new piece of this type of malware(below), which exploit SEO keywords and paid ads by placing their search results and ads at the top of the page. This tricks victims to click on their spoofed, and similarly appearing, websites and then download malware to their computers that open up access for the attackers.
The best ways to fight these attacks is to continually improve user awareness training methods that illustrate the attacks and train users to download software from trusted sources. If you see Gootloader in your environment, make sure you cut it off early because it could lead toward ransomware, Nickels said. This can lower the barriers for attackers and make them more effective.
Adversarial AI attacks are certainly top-of-mind these days as the explosive use of machine learning and large language models has focused interest in this topic. AI has made it easier to hone phishing attacks, improving their focus and their grammar to make them more realistic to temp their targets. Sims showed how he used the AI to seek out and find these types of exploits. Sims and Nickels both suggest that better defense-in-depth is needed that automates detection, response and mitigation actions.
ChatGPT-powered social engineering is your malicious access point, says Mahalik, who took the AI-as-bad-actor theme a step further. She had it write various impersonating phishing lures for her nine-year old son, with his prior consent. They were quite believable. For businesses, she recommends that you learn how to use it and understand how it works.
Next up are attacks specifically targeting third-party developers as part of leveraging the software supply chain. These attacks included malware that was installed on developers during the SolarWinds and LastPass breaches, along with the more recent 3CX attack. Ullrich showed how hard it is to figure out when a malicious piece of code is substituted for a legit one during the development cycle. He mentioned that often developers ignore security warnings, thinking they are false positives. A better strategy is to educate developers, review plug-ins, audit and limit credentials, and scan for dependent code throughout software supply chains.
The 3CX exploits were also the topic of another panel that described real-world incidents and threat response stories. The panel featured Lily Hay Newman, a Wired magazine senior writer and the moderator, Lesley Carhart of Dragos Inc., Nickels from Red Canary in her second appearance at the conference, and Wendi Whitmore, senior vice president of Unit42 at Palo Alto Networks Inc., who also appeared on theCUBE, SiliconANGLEs livestreaming video studio.
While the first panel spoke about the actual incidents, this panel was focused on more of the how, such asdealing with breach fatigue, disclosure announcement timing, transparency and mentoring new professionals.
Nickels pointed out that the quick action of CrowdStrike Holdings Inc. analysts on a Reddit discussion forum elevated the method of the 3CX attack, the specifics which Wikibon Chief Analyst Dave Vellante and Idiscussed recently, to a wider community of threat responders who were able to diagnose, mitigate and document what happened.
It is an example of the power of collaboration and public sharing, she said. Something that is targeting you is probably hitting other organizations, and it helps to share tactics and techniques. Carhart and Whitmore both recommend getting more involved in professional groups that are designed for sharing breach details, such as the various Information Sharing and Analysis Centersand NSAs Cybersecurity Collaboration Center that have been constructed for this purpose.
The first24 hours after a breach are critical, especially for an analyst to get beyond being scared and to try to be somewhat skeptical. Think skepticism, curiosity and stay calm, Whitmore advised. Nickels said analyst must be careful of what they know and what they dont know, especially initially. She mentioned cases of data extortion, and recommended that an analyst should take the time to figure out if the stolen data is actually a new case or something that transpired in the past.
The panel discussed how to deal with breach fatigue and analyst burnout as well. There is a lot of high stress and can go on for weeks, so it is important to plan for handoffs among analysts, Carhart said. And as Nickels pointed out, Panic should not a necessary part of incident response, there is a difference between panicking and having a sense of urgency. She also recommended having a shorter on-call rotation among a group of analysts, such as a couple of days, and conducting after-action discussion after an incident has ended and follow up on any needed changes so analysts dont make the same mistakes.
Newman asked her panel to talk about difficult issues for incident responders, and the panel touched on the fact that many incidents happen because of simple security hygiene mistakes, and that many victims dont want to disclose to the public what happens. Know what your perimeter is, that your network is properly segmented, and you know what your overall assets are, said Carhart. They can be challenging especially if you have a large network.
The panel also covered how to train and mentor the next crop of analysts. We didnt have a great support structure when we all got into this field, noted Carhart. She runs several online resources, including career counseling office hours, to help build our pipelines. We need people from all over the world to help with this effort, she said.
TheCUBEis an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate thecontent you create as well Andy Jassy
THANK YOU
Original post:
At RSA Conference, tales of real-world cyberattacks and warnings of ... - SiliconANGLE News
- 70+ PPC and Google Adwords Interview Questions and Answers for 2025 - Simplilearn - November 16th, 2024 [November 16th, 2024]
- Reframing SEO: Why training search engines is the new game in the age of AI - Search Engine Land - August 29th, 2024 [August 29th, 2024]
- Redefining SEO: How training search engines is shaping the future of digital content - Tech Edition - August 29th, 2024 [August 29th, 2024]
- SEO University Partners with Salterra to Launch Advanced Schema - WICZ - August 25th, 2024 [August 25th, 2024]
- SEO University Partners with Salterra to Launch Advanced Schema Course, Empowering SEO Professionals with Expert Training - Barchart - August 20th, 2024 [August 20th, 2024]
- SEO University Partners with Salterra to Launch Advanced Schema - openPR - August 20th, 2024 [August 20th, 2024]
- Top Websites to Learn SEO in 2024 - Analytics Insight - July 26th, 2024 [July 26th, 2024]
- What is the process to Learn SEO Step by Step? - INSCMagazine - January 30th, 2024 [January 30th, 2024]
- Park Seo-joon Mentions V's Photo At Army Training Center, He Wore The Same Raincoat As I Did 15 Years Go - KBIZoom - December 17th, 2023 [December 17th, 2023]
- The Bicycle Coalition Attends the Vision Zero Cities 2023 Conference - Bicycle Coalition of Greater Philadelphia - October 27th, 2023 [October 27th, 2023]
- The 40 best crime movies of all time - Entertainment Weekly News - October 27th, 2023 [October 27th, 2023]
- 50 Remote Jobs That Pay Over $50000 a Year: Part Two Jobs ... - Medium - October 23rd, 2023 [October 23rd, 2023]
- How Search Generative Experience works and why retrieval ... - Search Engine Land - October 23rd, 2023 [October 23rd, 2023]
- ONE: Radzuan responds to Stamp rematch talk, impressed by title win - South China Morning Post - October 23rd, 2023 [October 23rd, 2023]
- California Law Limits Bitcoin ATM Transactions to $1,000 to Thwart ... - Slashdot - October 23rd, 2023 [October 23rd, 2023]
- Tech CEO Sentenced To 5 Years in IP Address Scheme - Slashdot - October 23rd, 2023 [October 23rd, 2023]
- Is Digital Marketing Training Worth it - Kings of War - October 3rd, 2023 [October 3rd, 2023]
- The 2023 Nonprofit Power 100 - City & State - October 3rd, 2023 [October 3rd, 2023]
- 'Embarrassing' Court Document Google Wanted to Hide Finally ... - Slashdot - October 3rd, 2023 [October 3rd, 2023]
- H&R Block, Meta, and Google Slapped With RICO Suit, Allegedly ... - Slashdot - October 3rd, 2023 [October 3rd, 2023]
- FBI Indicts Goldman Sachs Analyst Who Tried Using Xbox Chat for ... - Slashdot - October 3rd, 2023 [October 3rd, 2023]
- 8 top marketing certifications and courses for 2023 - TechTarget - July 17th, 2023 [July 17th, 2023]
- How to win SEO allies and influence the brand guardians - Search Engine Land - July 17th, 2023 [July 17th, 2023]
- How relying on LLMs can lead to SEO disaster - Search Engine Land - July 17th, 2023 [July 17th, 2023]
- Become the next generation of multimedia content creators and ... - Education Times - July 17th, 2023 [July 17th, 2023]
- A Week in My Life: Fiona Brindle, Head of SEO, TrunkBBI - Prolific North - July 17th, 2023 [July 17th, 2023]
- Preparing the underserved: Five Auburn University alumni ... - Office of Communications and Marketing - July 17th, 2023 [July 17th, 2023]
- Should You Have a Go at Search Engine Optimization (SEO)? - Printing Impressions - June 9th, 2023 [June 9th, 2023]
- Chris Raulf of Boulder SEO Marketing to Give Masterclass on Micro ... - Digital Journal - June 9th, 2023 [June 9th, 2023]
- Augmented Reality Training Simulator Market 2031 Key Insights and ... - KaleidoScot - June 9th, 2023 [June 9th, 2023]
- Training Software Market 2023 Trends with Analysis on Key Players ... - KaleidoScot - June 9th, 2023 [June 9th, 2023]
- Training Outsourcing Market 2023 Trends with Analysis on Key ... - KaleidoScot - June 9th, 2023 [June 9th, 2023]
- COVID-19 Impact Analysis of Education Market 2031 | Key Players ... - KaleidoScot - June 9th, 2023 [June 9th, 2023]
- MarTechBot: Insights from real-world usage (so far) - MarTech - June 9th, 2023 [June 9th, 2023]
- Cognitive Assessment and Training Healthcare Market 2031 Growth ... - KaleidoScot - June 9th, 2023 [June 9th, 2023]
- Prestige whisky brand appoints Wild PR to support business growth - Bdaily News - June 9th, 2023 [June 9th, 2023]
- Erling Haaland Names Toughest Opponent He's Faced This Year ... - Sports Lens - June 9th, 2023 [June 9th, 2023]
- Local Brand Advisor Proves Its Worth As Leading and Results ... - Digital Journal - May 29th, 2023 [May 29th, 2023]
- Family: The Unbreakable Bond - K-drama Episode 10 Recap ... - TheReviewGeek - May 29th, 2023 [May 29th, 2023]
- Salesbop: The AI-Powered Sales Coach and Trainer ... - Digital Journal - May 29th, 2023 [May 29th, 2023]
- Career Technical Educational Opportunities for Students Attending ... - Demopolis Times - May 29th, 2023 [May 29th, 2023]
- Doctor Cha Episode 13 Twitter Reactions: Cliffhanger Over ... - Leisure Byte - May 29th, 2023 [May 29th, 2023]
- The National Eating Disorder Helpline Replaced Its Staff With a ... - The Mary Sue - May 29th, 2023 [May 29th, 2023]
- Brendan Johnston: A 15 year pro-racing quest with a gravel resolution - Cyclingnews - May 29th, 2023 [May 29th, 2023]
- Business Briefing: Apple Blossom Holistic, business news and ... - Laois Today - May 29th, 2023 [May 29th, 2023]
- How the media is covering ChatGPT - Columbia Journalism Review - May 29th, 2023 [May 29th, 2023]
- BSM to Host a Complimentary Webinar Entitled "AI and SEO. The ... - Digital Journal - May 18th, 2023 [May 18th, 2023]
- Developing Skills to Stay Competitive - ATD - May 18th, 2023 [May 18th, 2023]
- The biggest challenges facing small businesses and how to ... - Arizona Big Media - May 18th, 2023 [May 18th, 2023]
- Priyanka Chopra Jonas On Husband Nick Jonas' 'Mean' Martini, Her ... - ELLE UK - May 18th, 2023 [May 18th, 2023]
- The Idaho Towns Bankrolling Donald Trump's Campaign - News Radio 1310 KLIX - May 18th, 2023 [May 18th, 2023]
- Online Stable Startup: Tips and Tricks for Launching a Horse Business - Everything Horse UK - May 18th, 2023 [May 18th, 2023]
- ReKommendations: My Perfect Stranger, Duty After School, and more; K-dramas to catch up with this weekend - PINKVILLA - May 18th, 2023 [May 18th, 2023]
- The Full Cast of Netflix's 'Black Knight' - We Got This Covered - May 18th, 2023 [May 18th, 2023]
- Thanet business news: CAMRA awards, Thanet Earth, Dirtee Feast ... - The Isle of Thanet News - May 18th, 2023 [May 18th, 2023]
- Top 100: New to the List Fast Action Pest Control - PCT Magazine - May 18th, 2023 [May 18th, 2023]
- We are in content marketing era, the opportunities are diverse - Capital FM Kenya - May 14th, 2023 [May 14th, 2023]
- 25+ Best Remote Jobs Without Degree or Experience in 2023 - Southwest Journal - May 14th, 2023 [May 14th, 2023]
- SEO Fight Club Episode 198 Explores AI Training Corpus And AI ... - Digital Journal - May 12th, 2023 [May 12th, 2023]
- Various Advantages of HubSpot - CIOReview - May 12th, 2023 [May 12th, 2023]
- How to Start and Grow a Successful Real Estate Business: Business ... - RealtyBizNews - May 12th, 2023 [May 12th, 2023]
- Small Business, Big Results: Rely on Top SEO Company in Ahmedabad - The Week - May 12th, 2023 [May 12th, 2023]
- How to Get Google's Attention with AI-Generated Content - PR News - For Smart Communicators - May 12th, 2023 [May 12th, 2023]
- Meet the next Leadership Academy for Women in Media cohort in ... - Poynter - May 12th, 2023 [May 12th, 2023]
- Republic of Korea and U.S. Navy Conduct Combined Maritime ... - Pacific Command - May 10th, 2023 [May 10th, 2023]
- Boostly introduces ChatGPT integration for direct booking websites - Short Term Rentalz - May 10th, 2023 [May 10th, 2023]
- YACSS Announces Panel of Speakers for the First Annual YACSS SEO Conference - Yahoo Finance - May 10th, 2023 [May 10th, 2023]
- Google On Protecting Anchor Text Signal From Spam Site Influence - Search Engine Journal - May 10th, 2023 [May 10th, 2023]
- How To Start A Business In 11 Steps (2023 Guide) - Forbes - May 10th, 2023 [May 10th, 2023]
- Ocean Tomo, a part of J.S. Held Welcomes Delegation from Korea ... - PR Web - May 10th, 2023 [May 10th, 2023]
- Lionel Messi Returns To PSG Training After Suspension Lifted - Sports Lens - May 10th, 2023 [May 10th, 2023]
- Engaging Consumers in a Generative AI World - BCG - May 10th, 2023 [May 10th, 2023]
- Alyse Anderson has been training with Rose Namajunas - Asian MMA - May 8th, 2023 [May 8th, 2023]
- 12 questions to ask SEO platform vendors during the demo - MarTech - May 8th, 2023 [May 8th, 2023]
- How To Write ChatGPT Prompts To Get The Best Results - Search Engine Journal - May 8th, 2023 [May 8th, 2023]
- Roses and thorns: 5-6-23 - The Commercial Dispatch - May 8th, 2023 [May 8th, 2023]
- Achieving success in your own terms through the eyes of six Filipino ... - Manila Bulletin - May 8th, 2023 [May 8th, 2023]
- Rethinking SEO Strategy: Mindset Coach Helps Businesses Achieve ... - BusinessMole - May 2nd, 2023 [May 2nd, 2023]
- Achieving SEO Success: Mindset Coach Offers Innovative Problem ... - Business Manchester - May 2nd, 2023 [May 2nd, 2023]
- Megan Bridgeman named SEO editor based on the West Coast - The Washington Post - May 2nd, 2023 [May 2nd, 2023]