Lumen DDoS and Application Threat Research Finds Threat Actors Advancing their Attack Game

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• In new research from telco operator Lumen, the provider posits that cybercriminals are taking advantage of the increase in connected home devices to use them to build out bot networks for DDoS and other application attacks.

• For the first time, banking was the most targeted sector for DDoS attacks, largely because a single day in September 2023 when Lumen helped one institution stave off 230 separate attacks.

In research Lumen released this week based on DDoS and application threat data captured on its mitigation platform, the operator observed interesting trends in the way hackers are applying more sophisticated, and in some cases, relentless tactics to flood targeted enterprise servers with malicious traffic and steal data. Threat actors are tapping connected consumer devices to launch denial of services incidents.

Continue reading “Lumen DDoS and Application Threat Research Finds Threat Actors Advancing their Attack Game”

Malicious Synthetic AI Poses an Ominous Security Threat to Business and Governments

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• The recent rash of synthetic AI-driven deepfakes have business and government entities alarmed about potential security implications.

• The US National Security Agency (NSA) has issued guidance on how to detect images designed for malevolent purposes and what steps they can take to minimize damage from deepfakes.

Advances in generative artificial intelligence (AI) are offering promising use cases. But the technology can also be applied for more nefarious purposes. Cyber criminals can harness synthetic AI to spread misinformation, cause harm to organizations, and potentially to profit from their attacks. In one of the most recent high-profile cases, the actor Tom Hanks criticized a dental plan advertisement that used an AI-generated image of him without his consent. In a separate case, the “CBS Mornings” host Gayle King said a deepfake video using her likeness and voice to hawk a weight loss product was created and distributed without her permission. The synthetic AI video was built using a sanctioned post publicizing King’s radio show.

Continue reading “Malicious Synthetic AI Poses an Ominous Security Threat to Business and Governments”

FTC Takes a Big Swing at Amazon with Monopoly Lawsuit, but Will it Land?

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• The US Federal Trade Commission (FTC), along with 17 state attorneys, is suing Amazon for what it terms monopolistic practices for what it terms have “inflated prices, degrade quality, and stifle innovation for consumers and businesses.”

• Though the lawsuit does not cite Amazon’s size, but rather its market dominance and practices, it doesn’t require too much imagination to read between the lines and think the FTC wants Amazon split up, with the obvious potential spin-out business being Amazon Web Services (AWS).

After a lengthy investigation, the FTC and 17 state attorneys filed a lawsuit against Amazon claiming it’s the retail giant’s “illegal, exclusionary conduct makes it impossible for competitors to gain a foothold.” In a press release announcing the suit, the FTC goes on to call out specific practice as monopolistic and harmful to both businesses and consumers. The FTC specifically calls out Amazon’s search feature, which the agency says is “degrading the customer experience” by switching out “relevant, organic search results with paid advertisements.” The agency claims this hurts both customers frustrated with “junk ads” and sellers who are trying to promote their own products by limiting the return on their advertising investment.

Continue reading “FTC Takes a Big Swing at Amazon with Monopoly Lawsuit, but Will it Land?”

New Research Delivers Insights into the Mobile Lives of Children and Teenagers

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• A new study from the non-profit research organization Common Sense Media reveals how youths between the ages of 11 and 17 use their mobile devices.

• The research finds social media and other apps flooding the teens phones with notifications in an effort to keep them engaged.

It is unsurprising that devices are omnipresent for youths who have never experienced a time before the advent of cellular technology. But new research from Common Sense Media, involving both an online survey and mobile device tracking, offers some surprising insights into how, and how much, pre-teens and teenagers are using their phones.

Continue reading “New Research Delivers Insights into the Mobile Lives of Children and Teenagers”

As Ransomware Attacks Accelerate in Frequency and Severity, How to Respond is Just One of the Questions

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Reports surfaced that both MGM Resorts international and Caesars Entertainment had been hit with ransomware demands earlier this month.

• This comes in a year when both the frequency and cost associated with ransomware demands have skyrocketed.

Earlier this month both MGM Resorts International and Caesars Entertainment were targets of ransom demands. Caesars disclosed that it quietly paid off $15 million to hackers who had breached its customer loyalty database, negotiated down from the initial $30 million demand. MGM went the opposite route, refusing to pay hackers who took over its Okta authentication servers. The result was a multi-system outage that affected everything from reservation systems and digital room key processes to casino floor operations for at least ten days.

Continue reading “As Ransomware Attacks Accelerate in Frequency and Severity, How to Respond is Just One of the Questions”

MGM Under Fire After a “Cybersecurity Issue”

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• On September 10th, casino giant MGM Resorts International was hit with a cybersecurity “issue” that impacted its hotel booking and restaurant reservation systems, as well as digital keys and corporate applications including its web site.

• The company acknowledged the incident in a Securities and Exchange (SEC) filing on September 12th which affected properties in several states including Maryland, Massachusetts, Michigan, Mississippi, New Jersey, New York, and Ohio.

On September 10th, an incident came to light that affected multiple MGM casino and hotel properties in a number of US states. The company issued a press release on September 12th and also filed an 8-K report with the SEC. An 8-K filing is a notification of an event that might have a material financial impact on a publicly-traded company.

Continue reading “MGM Under Fire After a “Cybersecurity Issue””

New SEC Cybersecurity Disclosure Rules Raise Questions and Criticism

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• The SEC released new rules on the expediency and response detail required of public companies in reporting cybersecurity incidents after a comment period.

• The rules were met with a mix of concern and criticism, including from two SEC commissioners who expressed dissenting opinions, raising red flags around the reporting requirements potentially revealing key elements of the breached organization’s defenses that could put them at risk of another attack and going beyond the agency’s authority.

In an intensifying threat environment, the US SEC posted new rules requiring how and when public companies will report security incidents that have a material impact on their operations. The new SEC rules oblige organizations to disclose a cybersecurity incident within four days of determining that the event had a material impact on the business. The guidelines state breached organizations are also compelled to outline their practices for detecting, assessing, and managing material risks from cybersecurity threats. The breached organization will need to also reveal prior incidents. The SEC is holding foreign companies conducting business in the US to the same standard. The rules do allow disclosure to be postponed if the US attorney general decides that immediate posting of the incident would put national security or public safety at risk.

Continue reading “New SEC Cybersecurity Disclosure Rules Raise Questions and Criticism”

Generative AI Watch: Hyperscalers Tap Generative AI to Improve Healthcare Efficiencies and Patient Outcomes

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• The top hyperscalers are diving headfirst into generative AI as a solution for healthcare sector challenges around administrative efficiency and improving patient outcomes.

• While the technology is promising in a medical context, there are concerns about patient privacy and potential inaccuracies.

Generative AI has dominated headlines – and the conversation among tech leaders in 2023. Now the top leading hyperscalers based in the US are looking to leverage generative AI to help address some of the biggest issues around process inefficiencies and patient diagnostics in healthcare. The technology models, which tap into neural networks to spot patterns and structures in data to create new insights, look promising on paper as mechanism to address both healthcare administrative and diagnostic challenges, though there are some very vocal critics.

Continue reading “Generative AI Watch: Hyperscalers Tap Generative AI to Improve Healthcare Efficiencies and Patient Outcomes”

US School Districts Take on Social Media – in Court

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• In January 2023, Seattle Public Schools filed a lawsuit against social media platform providers alleging they had violated a Washington State public nuisance law, resulting in a youth mental health crisis.

• 100 other districts are also suing the providers, and in May 2023, US Surgeon General Dr. Vivek Murthy issued an advisory warning of the possible dangers of social media to youth mental health.

The need for human connection in the disconnected digital age in which we live makes social media a dominant force. This is particularly true among younger generations who seem to live for ‘likes’ and ‘snaps’ and ‘Tik Toks.’ But in a medium where the users (and their data) are the product and not the client, there is a definite dark side.

Continue reading “US School Districts Take on Social Media – in Court”

Verizon’s 16th Annual DBIR Finds Social Engineering is a Weapon of Choice in Cyberattacks

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• The Verizon Data Breach Investigations report (DBIR) revealed a sizeable jump in pretexting while ransomware continues unabated.

• While actors external to the breached organizations are responsible for most incidents, 19% of the either intentional or accidental security events are perpetrated by internal staff.

With contributions from dozens of organizations including law enforcement agencies like the US Federal Bureau of Investigation (FBI), Verizon’s 2023 DBIR offers insight into the nature of current threat landscape through the analysis of more than 16,000 security incidents, 5,199 of which were confirmed data breaches. What the report reveals is an environment dominated by profit-motivated bad actors who continue to advance techniques in areas like social engineering that exploit human susceptibilities.

Continue reading “Verizon’s 16th Annual DBIR Finds Social Engineering is a Weapon of Choice in Cyberattacks”