Google Cloud and CSA Research Finds Enterprises See AI’s Potential to Elevate Threat Intelligence

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• In a survey of 2,486 IT professionals conducted by the Cloud Security Alliance (CSA) and Google Cloud, 63% say AI will help them elevate threat detection and response.

• Most view AI as beneficial to their roles, rather than a replacement of personnel.

Artificial intelligence (AI) is central to many tech conversations. Cybersecurity is no different. Enterprises have been using machine learning (ML) to set a baseline of a normal operating environment and then to discern malicious activity from harmless anomalies. With the rise of generative AI (GenAI), there are more discussions on how to use the technology to improve threat intelligence, workflow, and incident response. At the same time, there is some nervousness about the integrity of AI output. There are also questions around the subject of bad actors using AI as an offensive weapon.

Continue reading “Google Cloud and CSA Research Finds Enterprises See AI’s Potential to Elevate Threat Intelligence”

Verizon Data Breach Investigations Report (DBIR) Sees Vulnerability Exploitations Soar

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Verizon’s Data Breach Investigations Report (DBIR) uncovered exploitation of vulnerabilities nearly tripled last year, up 180% from 2022.

• The DBIR underscores the need for end-user education, with non-malicious human interactions associated with 68% of breaches.

Verizon’s 2024 DBIR paints a complex and challenging picture of the global threat landscape. Studying 30,458 security incidents and 10,626 confirmed breaches, the report saw a huge jump in vulnerability exploitations versus the prior year. Fourteen percent of all breaches involved the exploitation of vulnerabilities with Verizon assigning responsibility for this to the targeting of unpatched systems and zero day vulnerabilities. Verizon noted threat actors used MOVEit and other zero day exploits to launch their ransom demands.

Continue reading “Verizon Data Breach Investigations Report (DBIR) Sees Vulnerability Exploitations Soar”

IBM Extends its Automation and Multi-Cloud Management Game with $6.4 Billion Bid to Buy HashiCorp

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• IBM’s pending deal to acquire HashiCorp, with its Terraform infrastructure-as-code software platform, gives the company a popular cloud configuration toolset.

• The buy isn’t a slam dunk; HashiCorp has struggled to make money from its formerly open-source software.

One of the issues organizations struggle with is efficiently setting up and managing their multi-cloud environments. Last week, IBM announced plans to acquire Hashicorp, a vendor with a Terraform platform the company says can help IBM clients do that. HashiCorp’s catalog includes infrastructure lifecycle management and security lifecycle management solutions enterprises can use to automate hybrid and multi-cloud environments. This will extend IBM’s automation and multi-cloud management product set, which it delivers through the Red Hat subsidiary.

Continue reading “IBM Extends its Automation and Multi-Cloud Management Game with $6.4 Billion Bid to Buy HashiCorp”

The White House Warns US Governors of Serious Threats to Critical Water Infrastructure

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• US government officials are advising state governors that drinking water and wastewater systems are under threat.

• Recent attacks carried out by bad actors working on behalf of the Iranian and Chinese governments used different techniques to breach critical infrastructure; the government expects more to come. A letter from the White House included a link to guidance on what security controls water systems should have in place.

Concerns about attacks on critical infrastructure are nothing new, but recent events have shown that bad actors are becoming more brazen. A survey conducted by Mitre and the Harris Corporation in February 2024 found that 81% of 2,046 Americans reported concern about critical infrastructure safety and security. Drinking water and wastewater systems are particularly attractive targets to attackers because they are essential to the population and typically under-secured.

Continue reading “The White House Warns US Governors of Serious Threats to Critical Water Infrastructure”

IBM X-Force Research Finds Identity Has Become the Entry Point into the Enterprise for Cybercriminals

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:
• For enterprising hackers, using legitimate credentials is the fastest path into the enterprise. IBM X-Force’s 2024 Threat Intelligence Index reported that bad actors commandeered valid credentials in 30% of all incidents the research arm responded to last year, the most common access method of any used in 2023.
• IBM saw an 11.5% decrease in ransomware demands, which the company attributed to increasing resistance from targeted companies to pay.

Today’s cyber threat environment remains toxic, virulent, and challenging for enterprises on the defensive. The 2024 IBM X-Force Threat Intelligence Index, sourced from the research team’s insights gained from tracking over 150 billion security threats each day, uncovered some changes in the processes and methodologies threat actors are using to mine enterprise resources for profit. Noting that hackers prefer an access path into the enterprise of one of least resistance, IBM reported a 71% jump in 2023 from the prior year in threat actors using legitimate credentials to breach a targeted enterprise. During incident response engagements, X-Force found a 100% rise in “Kerberroasting,” a tactic that uses Kerberos authorization tickets to steal Microsoft Active Directory credentials.

Continue reading “IBM X-Force Research Finds Identity Has Become the Entry Point into the Enterprise for Cybercriminals”

Hackers Take Aim at Microsoft 365 Users with Targeted Phishing Campaign

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Cybersecurity vendor Proofpoint flagged a hacking operation in November in which cybercriminals are employing phishing bait inside shared Office 365 documents to steal credentials.

• Hackers have targeted end users in a spectrum of corporate roles in multiple organizations with titles ranging from account managers and sales directors to CFOs and CEOs.

The Cloud Security Response team at security vendor Proofpoint issued an alert this week about an ongoing phishing campaign involving Office 365 apps that the organization first uncovered in November. Hackers have been threading together credential phishing and account takeover tactics to gain access to enterprise resources. So far, dozens of organizations and hundreds of users have been hit. One method these bad actors are using is to insert links that direct targeted users to click on to view a document. The links then route the users a harmful phishing web page. Continue reading “Hackers Take Aim at Microsoft 365 Users with Targeted Phishing Campaign”

Verizon Discloses a Breach Impacting More than 63,000 Employees

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• In late January 2024, Verizon began alerting more than 63,000 employees impacted by the breach of a file in September 2023 containing personal information that could encompass social security numbers, addresses, union affiliation, and compensation.

• Verizon took nearly three months to detect the incident, which the carrier blamed on “insider wrong doing.” Verizon doesn’t believe the data was shared with external entities.

Verizon joined the long list of companies facing the aftermath of a 2023 security incident. Nearly three months after an employee gained unauthorized access to a document containing sensitive data on more than 63,000 staff members, Verizon finally became aware of the breach. In January, Verizon sent letters to the employees impacted by the breach. In the letter, the carrier says the file could include name, address, social security number or other national identifier, gender, union affiliation, date of birth, and compensation data. Verizon says there is no indication the information has been misused or shared outside of Verizon. The carrier is providing affected staff with identity protection and credit monitoring services for two years.

Continue reading “Verizon Discloses a Breach Impacting More than 63,000 Employees”

Cybersecurity in 2024: AI as a Defensive Tool – and a Cyber Weapon

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Cybercriminals will elevate their tactics in 2024, leveraging next-generation technology like generative AI to capture credentials through social engineering.

• Threat actors will increasingly apply AI as a mechanism to exploit vulnerabilities, but the technology will also become a potentially important element in protecting enterprises resources from attacks.

2023 was a complicated year for cybersecurity professionals. Progress in areas like machine learning, analytics, and automation yielded more accurate and faster threat intelligence, more efficient administration, and streamlined workflows. But at the same time, bad actors continued to innovate in their tactics. As a result, the number and cost of security breaches skyrocketed. Resource-constrained cybersecurity scrambled to safeguard enterprise resources without interfering with corporate productivity.

Continue reading “Cybersecurity in 2024: AI as a Defensive Tool – and a Cyber Weapon”

AT&T Reveals Plan to Spin Off its Cybersecurity Unit

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Last week, AT&T answered the looming question concerning the fate of its cybersecurity organization when it announced plans for a spin out in early 2024

• At least in the near term, AT&T will hold majority ownership in the fledging company with Chicago-based investment house WillJam Ventures also taking a share.

After months of rumors swirling that AT&T was shopping its cybersecurity unit, the telco giant broke its silence last week by announcing it is spinning out the unit in early 2024. The company will keep a majority ownership stake in the standalone company with a new investment from WillJam Ventures, the Chicago-based investment firm involved in the deal. WillJam has a history in cybersecurity. The company currently has a stake in the PCI compliance vendor Viking Cloud as well as XDR provider GoSecure. WillJam facilitated the deal to sell TrustWave to SingTel for $850 million in 2015.
Continue reading “AT&T Reveals Plan to Spin Off its Cybersecurity Unit”

Okta’s Market Valuation Takes a Hit After the Identity Management Company Discloses Breach

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Okta admitted on October 20, 2023 that the company detected “adversarial activity that leveraged access to a stolen credential” to breach the company’s support management system.

• The cybercriminal tapped into customer files as part of recent support incidents; Okta was careful to note that the support case management system is distinct from the production Okta service.

Cyberattacks are expensive, and not just for enterprises and consumers. After Okta disclosed that threat actors had breached its customer support systems, the identity and access management supplier saw its market cap collapse. Over the course of a week, the company’s share price plummeted by 9%, and the company lost nearly $2 billion in its valuation.

Continue reading “Okta’s Market Valuation Takes a Hit After the Identity Management Company Discloses Breach”