Skip to content

The Impact of GenAI Risks on Security Postures

Unpacking the Pandora’s Box: Understanding GenAI Risks

Generative artificial intelligence, or GenAI, represents a double-edged sword in the realm of cybersecurity. Its ability to mimic human cognitive functions opens a Pandora’s box of cyber threats that are both sophisticated and difficult to predict. One of the most significant risks is the potential for GenAI to elevate phishing attacks to an unprecedented level of realism and personalization. These advanced phishing attempts can effortlessly bypass traditional detection methods, appealing directly to human vulnerabilities.

Further complicating the landscape is the advent of deepfake technology, a nefarious offspring of GenAI, which can fabricate audio and video content with alarming authenticity. This capability not only fuels the spread of misinformation but also introduces severe risks for identity theft and fraud, making it imperative for organizations to reassess and strengthen their security measures.

Moreover, the scalable nature of GenAI introduces a velocity of threats that was previously unattainable. Automated attacks can now be launched at a scale and speed, posing significant challenges for cybersecurity defenses. This rapid proliferation of threats necessitates a reimagined approach to cybersecurity, where traditional defenses are no longer sufficient to guard against the agility and adaptiveness of GenAI-powered attacks.

Lastly, the ethical quandaries and privacy implications of deploying GenAI in surveillance and data analysis cannot be overlooked. These concerns highlight the need for a comprehensive reevaluation of security frameworks, ensuring they are not only effective against the current landscape of threats but are also adaptable to the evolving capabilities of GenAI technologies.

Reinforcing the Barricades: Mitigating GenAI Risks

In navigating the complex terrain of GenAI risks, organizations must adopt a holistic and proactive strategy that underscores vigilance, innovation, and collective action. The implementation of state-of-the-art threat detection technologies stands as a critical first step. These advanced systems, empowered by GenAI themselves, offer the agility to keep pace with evolving threats, providing nuanced, real-time insights that enable swift and decisive responses to potential security incidents.

Equally vital is the commitment to fostering a culture of cybersecurity awareness among all employees. As the landscape of threats becomes increasingly sophisticated, the human element remains both a potential vulnerability and a formidable line of defense. Tailored training programs, regular updates on the latest GenAI threats, and simulations of phishing attacks are essential tools in empowering employees to act as vigilant custodians of the organization’s digital integrity.

Moreover, the ethos of collaboration must permeate the organization’s approach to GenAI risk mitigation. By engaging in industry-wide exchanges of intelligence on new vulnerabilities and attack vectors, companies can significantly bolster their defenses. This collective wisdom, coupled with partnerships with GenAI innovators, ensures that security measures evolve in tandem with GenAI capabilities, embedding resilience at the core of technological advancements.

Embracing these strategies requires not just foresight but a commitment to embedding security into the very fabric of organizational operations. By doing so, leaders can navigate the GenAI landscape with confidence, safeguarding their organization’s future in an era of unprecedented digital challenges.

The Future is Now: Embracing Next-Gen Cybersecurity Solutions

In the vanguard of cybersecurity, the integration of cutting-edge technologies heralds a transformative era where defense mechanisms are not merely reactive but predictive and resilient. Quantum computing emerges as a beacon of hope, with its potential to revolutionize data encryption, rendering it virtually impenetrable to GenAI-induced threats. This leap in securing communications and digital assets signifies a pivotal shift towards safeguarding privacy and integrity in the digital domain.

Simultaneously, the advent of blockchain technology promises an unprecedented level of security in transactions and data storage. By decentralizing data management, blockchain mitigates the risks of tampering and fraud, establishing a transparent and secure ledger system that stands resilient in the face of sophisticated cyber threats.

The deployment of AI and machine learning in cybersecurity ushers in an era of self-healing networks. These networks, characterized by their adaptability, are designed to autonomously identify and rectify vulnerabilities, thereby preempting potential breaches. Their capacity to learn from each interaction and predict future threats embodies the proactive and dynamic approach necessary for navigating the complexities of the digital age.

As we embrace these next-gen cybersecurity solutions, we are not just responding to the challenges posed by GenAI; we are anticipating and neutralizing these threats before they can manifest. This forward-leaning stance in cybersecurity is not just about technological advancement but a commitment to creating a digital environment where innovation, security, and trust coalesce, propelling us towards a future where organizations can thrive without the looming specter of cyber threats.

Navigating the Regulatory Maze: Compliance in the Age of GenAI

The regulatory framework governing the utilization and impact of GenAI in cybersecurity is swiftly transforming, introducing a complex maze that organizations must adeptly navigate. This dynamic environment demands more than mere adherence to current laws; it calls for a proactive, insightful engagement with the principles of creating a secure and ethical digital world. Forward-thinking organizations recognize that compliance is a multifaceted endeavor, encompassing not only the strict observance of legal requirements but also the active promotion of digital trust and safety.

Engagement with regulatory bodies is critical. By maintaining a pulse on the evolving regulatory landscape and participating in dialogues surrounding new legislation, organizations can anticipate changes and adapt more efficiently. This proactive engagement is essential, enabling entities to not only meet compliance demands but also influence the development of regulatory frameworks. Offering insights grounded in real-world experience helps shape regulations that are both effective in enhancing cybersecurity and pragmatic in their implementation.

Moreover, this proactive approach to compliance serves as a benchmark for ethical leadership in the use of GenAI technologies. It underscores an organization’s commitment to not only protecting its digital assets and customer data but also to advancing the broader goals of digital integrity and trust. In this age of GenAI, navigating the regulatory maze with agility, foresight, and a commitment to ethical practices is not just a legal obligation; it is a strategic imperative that positions organizations as trailblazers in the cultivation of a secure, innovative digital future.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

Future trends for MSPs: evolving network security with SSE

In the evolving MSP market, network security is undergoing a revolution thanks to Security Service Edge (SSE). This new approach, vital in a cloud-centric world, replaces outdated perimeter-based models with a more integrated, flexible strategy.

SSE combines multiple security services for comprehensive protection across all locations. This shift towards agility, scalability, and user focus is crucial for MSPs to meet their clients’ changing needs.

Let’s see what trends emerge in the future of the MSPs market and what experts have to say about it.

Is the MSP market growing?

Managed services involve outsourcing various IT and computing processes like cloud computing, IT infrastructure, and managed IT security.

In 2022, the value of the global managed services market approached $279 billion, with North America leading (a share of 36.6% in 2022 and a projected CAGR of 10.6%) and Asia Pacific emerging (a projected CAGR of 11.2%) as the fastest-growing region. By 2026, this market is projected to surpass $400 billion.

The managed services market is projected to expand to $680.08 billion by 2030, advancing at a Compound Annual Growth Rate (CAGR) of 11.9% from 2023 to 2033.

In 2022, the Banking, Financial Services, and Insurance (BFSI) sector dominated the managed services market with the largest revenue share of 18%, and it is anticipated to grow at a CAGR of 11.6% during its forecast period of 2023-2033.

What products will MSPs focus on selling?

In terms of popular products, security, and business applications lead in Europe and North America as of 2023.

These services offer the advantages of extensive IT infrastructure without requiring substantial in-house hardware. Additionally, managed services in the cloud are poised for growth due to their increasing adoption in organizations’ digital transformation strategies worldwide.

IT security services encompass various sectors, including:

  • cloud security

  • data protection

  • identity access management.

These tailored managed security services are essential for businesses globally to defend against cyber threats, comply with regulations, and secure their digital assets.

In 2023, Statista survey participants from North America and Europe indicated that they plan to allocate, on average, 12 percent of their 2024 IT managed services budget to both security and hosting services. Conversely, data analytics is expected to receive a smaller portion, with an average allocation of just 6 percent of their companies’ managed services budgets.

The future of MSPs, driven by technological advancements and evolving business needs, indicates a strategic shift toward more sophisticated, integrated, and efficient approaches, such as adopting the SSE framework.

From the surge in automation and cloud-based security services to the harmonization of diverse tools and infrastructures, these developments signal a new era of agility and resilience for MSPs.

Automation

Embracing technologies like AI for improved efficiency and task management. This trend indicates a shift towards automated processes for routine tasks, enhancing operational productivity.

Moreover, tools that provide automation solutions besides AI also help minimize repetitive tasks and increase attention to detail. It allows security administrators to avoid overlooking or missing important indications that may lead to a data breach.

MSPs as service providers will benefit from platforms that allow bulk onboarding of an organization’s users, whether tens or hundreds of them.

From the security perspective, for instance, setting up internal rules, if a non-compliant device tries to access the company network with a feature like Always On VPN, it will be automatically rejected, and the user account will be blocked until further admin action is taken. Such functionalities help reduce manual monitoring and resources, preventing human errors that could lead to incidents.

Reliance on security as a service

With cybersecurity threats evolving, MSPs will likely increase reliance on cloud-based security services. This shift highlights the importance of robust, scalable cybersecurity measures in a digitally interconnected landscape.

Cloud-based solutions like a cloud firewall help transition existing infrastructure to a more modern and up-to-date setup, adapted to contemporary technological and security challenges. These solutions are easy to deploy as they don’t require hardware or manual labor, and they can be launched and operational without needing on-site presence.

More importantly, security as a service is instant. When the right solution to the existing problem is selected, MSPs can onboard entire organizations within hours, if not minutes, rapidly shrinking the attack surface and enforcing security policies to protect a business. Meanwhile, MSP customers are safe without having specific knowledge of network security.

Cross-platform tools and infrastructure deployment

The anticipated growth in integrating diverse tools and infrastructure systems indicates a move towards more cohesive and flexible IT solutions. In this case, smooth integrations of different vendors’ tools and solutions are critical for seamless implementation, ensuring successful business continuity.

Compatibility with existing tools is beneficial, for example, to simplify the process of user management. SCIM user management with market leaders Okta and Azure AD (now Entra ID) allows smoother user provisioning by reducing manual handling time case by case and improving security levels by sorting access right effectively.

Besides user onboarding and offboarding processes, integrations with JumpCloud, OneLogin, Google, or the same Okta and Entra ID enable more secure access to the systems as Multi-factor authentication (MFA) and Single sign-on (SSO) are implemented for strong user authentication.

Adoption of managed cloud security services

There’s an expected rise in the adoption of cloud-based security services, reflecting the growing need for specialized security solutions in cloud environments. This trend underscores the recognition that cloud security needs specialized solutions beyond standard IT security measures.

Multi-cloud strategies, hybrid models, and an array of diverse services and apps require stepping up the game in cloud security to meet the specific needs of these environments.

There’s an increasing need for continuous monitoring, real-time threat detection, and rapid response mechanisms. Managed cloud security services are equipped to handle these demands, offering round-the-clock surveillance and immediate action against potential breaches to protect sensitive data and ensure uninterrupted business operations in the cloud.

Tendencies clearly direct us to cloud-based services and infrastructures. SSE framework fully addresses projected needs, so more and more managed service providers will incorporate it into their client offerings.

SSE dominance naturally raises questions about its potential to replace a VPN and what its strongest attributes are that MSPs can benefit from.

We asked our internal experts on the matter to understand the benefits and potential of the SSE framework for MSP partners. One thing is clear: the framework in question holds the future of cybersecurity. It supports various business models and needs, providing an integral approach to security challenges.

Zero Trust, and more specifically, Zero Trust Network Access (ZTNA), is one of the core SSE framework components. Alongside Secure Web Gateway (SWG), Firewall as a Service (FWaaS), and Cloud Access Security Broker (CASB), ZTNA is the most advanced and prominent part of the framework.

The following question is whether the SSE framework is capable of replacing Virtual Private Network (VPN) tools. While both solutions ultimately serve the same purpose of securing the network, they have quite different roles in cybersecurity.

A VPN tool connects devices, while SSE ensures overall security layers essential for devices’ and, ultimately, networks’ security. They complement rather than replace each other. Thus, VPN tools that go beyond primary connection and encryption but evolve into solutions with functionalities of SSE ensure more robust protection against digital threats.

Industry experts’ perspectives

We asked major MSPs in the industry to share their view regarding SSE adoption in a modern business environment.

With the subject focusing on SSE popularity and adoption, experts reveal what tendencies show clients’ demand for cloud security services and what implications create the need for such technology integration in the infrastructure.

Has adopting remote work and cloud services impacted MSP clients’ demand for SSE solutions?

Impact of remote work and cloud services on Managed Security Service Provider clients' demand for SSE solutions

Are there any specific industries, sectors, or types of businesses where SSE adoption will be particularly critical in the near future?

What are the predictions for cloud and network security in the next 5 years? How can MSPs prepare for this change?

Experts predictions and MSP industry trends for the next 5 yearsWhy should MSPs offer solutions to their clients based on an SSE framework?

Explanations why MSPs should offer solutions to their clients based on an SSE framework

The experts’ insights highlight the growing demand for SSE solutions among MSP clients, driven by the widespread adoption of remote work and cloud services.

Both TEKRiSQ and Sequentur emphasized that while remote access increases vulnerability to security breaches, implementing SSE frameworks can mitigate these risks through layered security controls, such as phishing-resistant MFA and stringent device usage policies.

Key expert insights

1. Increased demand for security: the shift to remote work has made SSE solutions more critical for ensuring secure access to networks and protecting against breaches.

2. Industry-specific needs: sectors with sensitive data, like healthcare, finance, and accounting, face higher regulatory pressures, making SSE adoption crucial for compliance and protection against financial penalties.

3. Future security trends: the next five years will see a focus on enforcing basic security measures, such as phishing-resistant MFA and tighter controls on how employees use their devices. Regular cyber risk assessments will become essential for identifying and addressing security gaps.

4. MSP engagement and compliance: MSPs must regularly reassess their clients’ security needs in light of technological changes and regulatory requirements. Ensuring the implementation of recommended security measures is crucial, rather than merely suggesting them.

5. Layered security approach: with hackers employing increasingly sophisticated tactics, MSPs need to offer solutions that provide multiple layers of security, addressing both digital and physical vulnerabilities.

6. Staying relevant: offering SSE solutions is not just about enhancing security. It’s also critical for MSPs to remain competitive and relevant in the industry.

The insights underscore the importance of proactive security management, the need for continuous reassessment of security protocols, and the critical role of MSPs in guiding their clients through these challenges to ensure robust protection against evolving threats.

The primary goal of Managed Security Services Providers (MSSPs) is to proactively protect organizations from cyber threats and ensure regulatory compliance through a blend of technology and expert analysis.

Implementing SSE framework-based tools into the clients ‘ infrastructure is an effective and trusty way to achieve these goals. Luckily, NordLayer’s secure remote network access solution is built using technology-forward SSE design. It makes the tool comprehensive and robust for securing and enabling businesses of all sizes and industries.

A cloud-based network security tool for data protection and access control

Since MSPs will mainly focus on cloud security, data protection, and identity access management in 2024, NordLayer offers a solution that is exactly for it.

  • Being a cloud-native solution, NordLayer is hardware-free, thus deployable remotely from any location to any setup.

  • Built on the SSE framework, NordLayer’s design combines security services based on SSE’s components like ZTNA, SWG, and FWaaS.

  • The features and capabilities can scale and add up to create a layered network security shell against digital internal and external threats.

  • Seamless integration with identity management tools enables smooth user identification and robust access controls.

  • The ability to set up and implement a set of security rules and policies allows automated monitoring and actionable network protection.

  • Functionalities that are based on automation ensure every connection is encrypted and secure from malicious actors whether the team is working remotely or in a hybrid setup.

  • Online browsing on untrusted networks is secure whether employees work from a coffee shop, home, or hotel while on a business trip.

  • 24/7 active tech-savvy customer support and an extensive materials base don’t leave partners and users alone in the unknown.

  • Easily deployable and manageable, NordLayer doesn’t require manual work and maintenance, letting it optimize resources and not rely on the user’s extensive expertise.

  • NordLayer helps companies adhere to ISO 27001, GDPR, HIPAA, SOC 2 Type 2, and PCI-DSS regulatory requirements and stay compliant in the market.

The key takeaway is that NordLayer is extremely easy to use, manage, and deploy while ensuring stress-free and robust security implementation to any infrastructure, industry sector, or organization size.

Try it yourself—book a demo call with our tech-savvy experts and get all the answers you need to become a member of the NordLayer Partner Program.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

24.2.0 ‘Mimas’ released

Mimas is the latest entry in our quarterly rollup series. It branches off from our main rolling Voyager development into a fixed target for our partners to qualify and build upon.

Mimas is named after a moon of Saturn, which in turn takes its name from an ancient Greek mythological giant. Mimas is relatively small compared to Earth’s moon, with a diameter of about 396 kilometers (246 miles). Its composition is primarily made up of water ice with a small amount of rocky material. Its most distinguishing feature is a giant impact crater which stretches a third of the way across the face of the moon, making it look like the Death Star from “Star Wars”.

As for the software, Comet 24.2.0 Mimas brings 3 new features and 14 enhancements, including Dark Mode for the Comet Server Web Interface.

As always for a new quarterly release, there are two changelogs for 24.2.0 Mimas depending on whether you are coming from the previous quarterly release or the previous Voyager release:

Changes compared to 23.11.4

New Features

  • Added a new Java SDK which allows customers to access the Comet Server API via JDK version 11+
  • Added a Debian package for linux clients which installs the Comet Backup desktop app as a systemd service
  • Added support for Dark Mode to the Comet Server web interface

Enhancements

  • Changed the order in which Before commands are executed when running a job. Storage Vault Before commands now run first and then the Storage Vault connection is checked. This resolves issues where Before commands were unable to be used to authenticate the connection to the Storage Vault as connections to the vault were made before running these commands. Before commands configured on a Protected Item or Schedule only run if the job is not skipped
  • Added a Storage Vault connection check at the start of each job to check if it’s possible to continue with the job
  • Added additional warnings about being unable to remove buckets containing Object Locked files when setting Object Lock retention on a Storage Vault
  • Updated the appearance of badges for cross-organization users when logged in as the top level admin. Instead of displaying “Other Tenant” the badge now displays the tenant name on the Users, User detail, Client news and Storage buckets page
  • Changed “Job History” on the Comet Server web interface and Comet Backup desktop app to “Job Logs”. The Job Logs page contains logs for both running and finished jobs
  • Added a new log message when temporary files are in use during either Backup or Restore jobs
  • Added the ability for top-level admins to create a new user in any tenant in the Comet Server web interface
  • Added support for custom HTTP headers in the “Custom Remote Bucket” Storage Template option
  • Improved the performance of S3-compatible Storage Vaults when Object Lock is enabled
  • Improved the performance of simulated restores for most Protected Item types
  • Added a Job History tab to the User details page which shows jobs for the selected user in the Comet Server web interface
  • Added server log messages to Comet Server startup to indicate when certain subprocesses have finished initializing
  • Added a S3-compatible (Object Lock) storage vault template type
  • Improved Microsoft 365 incremental backups of SharePoint Sites and OneDrive to be more efficient and quicker

Changes compared to 23.12.9

Bug Fixes

  • Fixed an issue during restore jobs where the error message “incomplete data” was displayed instead of the real underlying error message

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

Finding ScreenConnect installations with runZero

ConnectWise disclosed two serious vulnerabilities in their ScreenConnect (formerly Control) remote-access product.

The first vulnerability is an authentication bypass vulnerability. Successful exploitation of this vulnerability would allow attackers to execute arbitrary commands with full privileges on the target system. This vulnerability has been assigned a CVSS score of 10, indicating a highly critical vulnerability.

The second issue is a path-traversal vulnerability. Successful exploitation of this vulnerability would allow attackers to access restricted resources on vulnerable systems. The vendor has not disclosed what resources may be accessed when exploiting this vulnerability. This vulnerability has been assigned a CVSS score of 8.4, indicating a high severity.

Note that CVEs are not yet assigned for these vulnerabilities.

Note that there is evidence that these vulnerabilities are being actively exploited in the wild.

What is the impact?

Successful exploitation of these vulnerabilities would allow attackers to execute arbitrary commands with full privileges on the target system, potentially leading to complete system compromise.

Are updates or workarounds available?

ConnectWise has released an update, version 23.9.8, that fixes these issues. ConnectWise recommends that all users upgrade to this version immediately.

How do I find ScreenConnect installations with runZero?

From the Services Inventory, use the following query to locate potentially vulnerable ConnectWise ScreenConnect systems:

vendor:ConnectWise AND (product:Control OR product:ScreenConnect)

Note the check for the former product name (“Control”).

Additional fingerprinting research is ongoing, and additional queries will be published as soon as possible.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

The Mother of All Data Breaches: Why It’s Worse Than All the Others

The Mother of All Data Breaches: Why It’s Worse Than All the Others

It seems like every other day, there’s news of a new data breach hitting the news. It’s so common that we’ve become largely desensitized to it; after all, this has been going on for years, and despite a lot of handwringing, nothing bad really seems to happen to most people. However, this breach, which has already been called “the mother of all data breaches,” promises to bring a lot of heartache and trouble to impacted people, and there are a LOT of them.

Old News

To understand why, we need to look at exactly what this is, and it might be shocking to find out that nothing in this breach is, in fact, new. Some enterprising data scientist-turned-hacker collected as much information as they could from all the previous public data breaches and combined it into one mega-breach database, consisting of over 26 BILLION records. Breaches from companies like LinkedIn, Twitter, Weibo, Tencent, MySpace, Zynga, and X (you can tell from some of those names that they went back quite a long way! I bet you haven’t checked on your farm in FarmVille for a long time…) Now, the most shocking news coming from that statement might be that some of these websites still exist, but the second most shocking thing is the sheer scope of the breach. The dirty reality of cybercrime is that for all the fancy hacks you read about, like acoustic attacks where listening to the keys you type might reveal a password or the rise of AI in cyber-attacks, the number one way a hacker gets into anything is via compromised credentials. And the way credentials get compromised is because we simply don’t take cyber security seriously enough. In one survey by LastPass, 91% of people surveyed acknowledged that re-using passwords is bad; 66% of them do it anyway. The most common password in 2024 is 123456. It’s not a huge shock that passwords remain the weakest link in the chain.

The Problem in the Patterns

Here’s what makes the mother of all breaches so bad: the ability to correlate login data. A hacker who has bought access to this massive database can pick an e-mail, any e-mail, and query every record containing that e-mail and see the associated password for each service. So, let’s say you’ve had your e-mail, llamas@gmail.com, since the days when MySpace was cool and your beloved cat, Dr. Whiskers, was just a kitten. A hacker would see something like this:

ApplicationE-mailPassword
X (formerly Twitter)llamas@gmail.comDr.Whiskers1!
MySpacellamas@gmail.comDr.Whiskers1!
Zyngallamas@gmail.comDr.Whiskers1234!
LinkedInllamas@gmail.comDr.59Whiskers1234!

You see the issue there – even though the passwords themselves aren’t inherently insecure (they’re long, alpha-numeric, and have special characters), they’re re-used in a similar enough way to give the hackers a massive clue as to how to get into your account. Now, they have options.

Credential Stuffing

23andMe drew some fire when they blamed their recent hack on users re-using passwords, but they weren’t wrong – it was a simple credential stuffing hack – when hackers try previously leaked username/password combinations in an attempt to find one that works. Users who had opted to share their information via the DNA Relatives feature opened up the door for other accounts’ information to be breached as well.

Attacker in the Middle

 The second option employed by the hackers is far more concerning because of how difficult it is to detect. Commonly known as Attacker in the Middle, or AiTM, this involves setting up a fake site to resemble a legit bank. The attacker then sends out a targeted phishing e-mail campaign with the goal of getting you to enter your credentials and intercepting the one-time passcode you get from your bank:  Attacker in the middle or AiTMLast year, researchers at Microsoft uncovered a massive AiTM attack targeted at financial institutions; and of course, it all started with a phishing campaign designed to get credentials.

So, What Can We Do?

First and foremost, stop re-using your passwords. With the proliferation of password managers, having strong, unique passwords for everything is much easier. From a personal standpoint, you must make sure all your passwords are unique – especially your e-mail passwords.  If someone hacks into your e-mail, they can use that to do a lot more damage (like changing the passwords on all your other accounts!) More and more companies are allowing some form of multi-factor authentication for personal services – turn that on whenever possible. And don’t ever mix work and personal functions on your devices – both Cisco and Okta were hacked via an employee’s personal Gmail account. Even though it wasn’t anything the employee did deliberately, they probably didn’t have a good day when that was discovered. From a business standpoint, get rid of the passwords altogether and implement certificate-based authentication.  It’s several orders of magnitude more secure than any other MFA/password combo, and actually provides a better user experience since the user doesn’t have to enter anything – authentication is handled when the device presents a certificate.    And one more time, louder for those in the back…STOP. REUSING. YOUR. PASSWORDS!!!!

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。