pwshub.com

Identity-based attacks drive need for faster cybersecurity defenses - SiliconANGLE

Whether it’s the Volt Typhoon hack or one of several other attacks targeting the healthcare sector, something has become clear: speed is the name of the game. In addition, there’s been a rise in identity-based attacks aimed at crippling or, at the very least, disrupting public and private-sector operations.

Adam Meyers, senior vice president of intelligence at CrowdStrike talks to theCUBE about identity-based attacks at Fal.Con 2024.

CrowdStrike’s Adam Meyers talks about identity-based attacks with theCUBE.

“We had a customer that on a Monday, hired one of these North Korean remote IT workers,” said Adam Meyers (pictured), senior vice president of Counter Adversary Operations at CrowdStrike Inc. “By Saturday, the laptop that they were being issued was shipped to a laptop farm where it was going to be plugged in. It was plugged in on Saturday. Within an hour, the Overwatch team notified the customer and they were able to terminate the employee. We have gotten pretty fast at stopping the threats.”

Meyers spoke with theCUBE Research’s Dave Vellante and Rebecca Knight at Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed the importance of speed in detecting threats, the shift in adversary tactics and the growing role of artificial intelligence in both cyberattacks and defense. (* Disclosure below.)

Identity-based attacks on the rise

A key finding from CrowdStrike’s “2024 Threat Hunting Report” is the growing shift in how adversaries are targeting organizations. Attackers have moved away from traditional methods such as phishing emails containing malware-laden documents. Instead, they are increasingly focusing on identity-based attacks, which involve compromising legitimate credentials to infiltrate systems undetected, according to Meyers.

“They know if they come in with a compromised but legitimate credential, they’ve moved off the X,” he said. “Now, they can continue to operate without being detected. They’re able to operate as a legitimate user who’s just logged in, maybe, from a different location. Identity attacks have been probably the biggest issue I think we’ve covered in that last threat-hunting report.”

Cross-domain threat hunting has emerged as effective against identity-based attacks. By hunting across different domains — whether it’s the endpoint, cloud or hypervisor — organizations can detect malicious activity that might otherwise go unnoticed, Meyers added.

“As you start to bring in the identity protection data and you start to bring in your crowd data from your control plane and you start to bring in VPN concentrator logs, that’s where Next-Gen SIEM infused with intelligence and powered by threat hunting becomes a really critical capability,” he said.

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE Research’s coverage of Fal.Con

(* Disclosure: CrowdStrike Inc. sponsored this segment of theCUBE.)

Photo: SiliconANGLE

Source: siliconangle.com

Related stories
2 weeks ago - These stocks are trading at attractive valuations relative to their history, especially in light of their opportunities in the artificial intelligence space.
3 weeks ago - Cloud networking and security company Infoblox Inc. today launched a new suite called the Universal DDI Product Suite with an aim to improve collaboration and efficiency among NetOps, SecOps and CloudOps teams. The new Infoblox suite...
1 month ago - Broadcom Inc. today unveiled the latest version of VMware Cloud Foundation, calling it “the future” of the company’s private cloud platform. Broadcom said the new release simplifies private cloud deployment, consumption and operations...
1 week ago - Concerns are mounting over when and how all this investment in artificial intelligence will pay off — even at AI leader OpenAI, which reportedly predicts it will lose $14 billion in 2026 on $100 billion in revenue and won’t make a profit...
1 month ago - Artificial intelligence infrastructure is taking really big bucks now to build out, as BlackRock and Microsoft joined this week to invest up to $100 billion in AI data centers and power projects. And that’s not all: Microsoft also teamed...
Other stories
40 minutes ago - GQG had decided to sell up by July, having told BBVA's management team that it believed the Sabadell bid would be too time consuming and distracting, while also diluting its exposure to emerging markets, the FT report said. Neither GQG,...
40 minutes ago - (Bloomberg) -- Asia’s stock markets are gearing up for their busiest week of listings in more than two years, offering a crucial test of demand as companies rush to raise money before the US election.Most Read from BloombergA Broken Oil...
1 hour ago - SoFi Technologies (NASDAQ: SOFI) is on a roll. The stock recently soared to $10 per share, its highest price since early 2022. It's progress, but...
2 hours ago - A turnaround plan is in place and now it has more money to make the plan a reality.
3 hours ago - Warren Buffett hasn't seen a lot to like in the stock market lately.The Oracle of Omaha has sold more stocks than he bought in each of the last...