pwshub.com

Cybersecurity teams respond to new wave of AI-based ransomware

Artificial intelligence has opened up new vulnerabilities in cybersecurity, requiring a different kind of security posture from companies looking to defend against increasingly advanced threat actors.

At Trellix, which specializes in detection and response, experts are preparing customers for targeted attacks in their sectors.

John Fokker, head of threat intelligence at Trellix, examines how AI is transforming the requirements for a customer's security posture at mWISE 2024.

John Fokker of Trellix discusses how AI is changing cybersecurity.

What we’re trying to do is elevate that intelligence … to a more proactive stance,” said John Fokker (pictured), head of threat intelligence at Trellix. “So, if there’s a weakness or there’s anything else, or let’s say you’re a company in a certain sector or geo, we will provide you with, OK, these are the threats relevant to your sector or geo … these are all the elements in their attack. And, by the way, you can increase your security posture by applying rule XYZ out of the box.”

Fokker spoke with theCUBE Research’s John Furrier and Savannah Peterson at mWISE 2024, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how AI has impacted ransomware and how organizations can strengthen their defenses. (* Disclosure below.)

An iron-clad security posture for a gen AI age

The last year has seen the rise of ransomware as a service, changing how threat actors collaborate together. Trellix, which provides extended detection and response, has found unsettling trends for AI in the ransomware space.

“We saw threat actors just like us trying to find solutions for things that were annoying,” Fokker said. “They used Gemini to get more information on vulnerabilities, web scanners. They’re researching some deep fake[s]. There was one instance that was really interesting and very timely that [the threat actor] was asking for … voice cloning type of software, specifically to extort politicians and crypto influencers.”

In response to these evolving attacks, cybersecurity is increasingly a team effort, according to Fokker. Trellix has a partnership with Google, allowing experts from both companies to pool their findings

“Our relationship is very, and stronger than ever,” he said. “We really have researchers helping each other out. We’re looking at similar threats, some of the most imminent threats to the U.S. administration. One of the things that we’re doing … is a project called RPP, or Research Partner Program, where we help out certain nations in the world that are on a heavy attack but might not have the funds to protect themselves.”

The companies deliver Trellix appliances with joint investigations to these government organizations, allowing them to defend against international attacks. Fokker’s advice for companies guarding against attackers such as email phishers or information stealers is to know their businesses inside and out.

“Asset management, actually knowing what you have within your network, knowing your attack service … but also internally knowing, OK, what’s my security posture?” he said. “These are some very basic things, together with patch management, understanding the threat landscape, all that stuff. Those are really basic things that we still see are not always done either correctly or up to a certain standard.”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE Research’s coverage of mWISE 2024:

(* Disclosure: Trellix sponsored this segment of theCUBE. Neither Trellix nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

Source: siliconangle.com

Related stories
1 month ago - Data management provider Cohesity Inc. today announced enhancements to its artificial intelligence-powered data security management platform aimed at improving generative AI detection and recovery capabilities. The new additions to the...
3 weeks ago - As AI cybersecurity becomes more critical, hackers are becoming increasingly sophisticated, uncovering new and unexpected attack surfaces in today’s interconnected systems. But here’s the good news: The average time attackers remain...
3 weeks ago - Industrial cybersecurity firm Nozomi Networks Inc. today announced the general availability of the Nozomi TI Expansion Pack, a new federated solution powered by Mandiant Threat Intelligence that helps strengthen the way industrial and...
1 month ago - It was another busy day today at the annual Black Hat USA 2024 conference in Las Vegas, as cybersecurity companies 1Password LLC, ArmorCode Inc., Legit Security Ltd. and NetRise Inc. al made product announcements aimed at enhancing the...
2 days ago - Managed cybersecurity company LevelBlue Inc. today announced the availability of LevelBlue Managed Threat Detection and Response for Government, a new service designed to protect highly sensitive data and data that is subject to...
Other stories
11 minutes ago - The European Commission is expected to bring formal charges against Google LLC over its business practices in the search market. Bloomberg revealed the upcoming regulatory action today, citing people familiar with the matter. Google...
56 minutes ago - Nvidia has built a solid position for itself in this fast-growing data center niche that could help generate sizable revenue for the company in the long run.
2 hours ago - Qualcomm Inc. has approached Intel Corp. about a potential acquisition, the Wall Street Journal reported today. It’s believed that the mobile chip designer floated the idea in recent days. The Journal’s sources cautioned that a deal is...
2 hours ago - As cyberattacks become more sophisticated, advanced threat detection continues to play a critical role in safeguarding enterprise environments, particularly against long-standing threats with extended dwell times. Despite technological...
2 hours ago - As technology advances, so too do cybersecurity threats, and a new point of vulnerability for companies could be remote access tools. Nader Zaveri (pictured), senior manager of Mandiant incident response and remediation at Google Cloud,...