.@RSAConference USA is officially bigger than ever: #RSAC2025 final attendance is just under 44k (43,500+), up from 41k attendees in 2024 & topping the previous all-time high of 42,500 in 2019. Also #RSAC2026 will be in calendar Q1, slated for March 23-26 in SF. #RSAC
As #RSAC2025 begins, here's a great snapshot of what adversaries are now focused on, and in turn what CISOs should be pivoting to detect & prevent.
We’re seeing a clear trend: attackers are bypassing the endpoint entirely. Not just avoiding traditional EDR-monitored systems by pivoting to embedded and edge devices, but now also operating purely in the cloud. No shell, no malware, no persistence on the endpoint. Just an OAuth token and full access to whatever’s in the victim’s Microsoft 365, Google Workspace, or AWS console.
It’s a complete inversion of how things used to be. The endpoint, once the weakest link, is now usually the most monitored, most policy-enforced part of the infrastructure. You’ve got EDRs, SIEM integration, automation, threat hunting - the full stack. But attackers don’t need to touch it anymore.
Instead, they go after the new soft spots:
- Cloud platforms, where logging is limited, expensive, or off by default
- Network devices and appliances, which are practically blind spots - obscure OSes, no EDRs, hard to monitor, hard to forensicate.
- Embedded systems and IoT junk that no one really knows how to secure, but that sit in critical network paths.
Cloud especially is a mess:
- Logging tiers cost extra and the good stuff is behind paywalls.
- Detection content is lacking, both from vendors and the community.
- You don’t get memory dumps or full control like you do on endpoints.
- You’re at the mercy of the provider when it comes to visibility and response.
And that’s the shift: attackers aren’t hacking computers anymore. They’re hacking trust relationships, identities, and APIs. The whole idea of detection and response needs to evolve with that. Otherwise, we’re securing the hell out of endpoints while attackers happily fish through mailboxes and cloud shares from halfway across the planet.
Best wishes to everyone attending #RSAC 2025 next week. I will be focusing on my new role, but will miss many friends, colleagues, and the buzz of the event. I will *not* miss making lap after lap in and around Moscone on foot!
One of the scariest phishing attempts I’ve seen in a long time. Good that Google has agreed to fix the root vulnerability, but in the meantime, be careful.
Recently I was targeted by an extremely sophisticated phishing attack, and I want to highlight it here. It exploits a vulnerability in Google's infrastructure, and given their refusal to fix it, we're likely to see it a lot more. Here's the email I got:
Super cute marketing/training effort coming up next week from @immersivelabs "Christmas Tree-Son" Virtual Crisis Simulation: "Immerse yourself in a unique and engaging crisis scenario set against the backdrop of the North Pole." https://t.co/9tlPBJJTsS
Important new primary research: The app for your internet-connected litter box should NOT require your wifi network password for connectivity. (Manufacturers should ensure the device can connect directly and securely w/o an app. Software is always the weakest link!) #IoTsecurity
Great quote from special guest Venus Williams, borrowed from Billie Jean King: “Pressure is a privilege… it means that you’re doing things and going places.” #opentextworld
Barrenechea commits @OpenText to masking all of its data and eliminating passwords in favor of biometric authentication over the next two years. #OpenTextWorld
Barrenechea on integration: "With enterprise security you need to compose a solution. No company can do it all. All the (technology) partners in your ecosystem throw off security events, so you have to do it in a composable way, connecting disconnected islands." #OpenTextWorld
Barrenechea on integration: "With enterprise security you need to compose a solution. No company can do it all. All the (technology) partners in your ecosystem throw off security events, so you have to do it in a composable way, connecting disconnected islands." #OpenTextWorld
Barrenechea on @OpenText security strategy: "We’re here to make security as important as anything we do...
We think it’s no longer human vs machine, it’s machine vs machine." #OpenTextWorld
Barrenechea on @OpenText security strategy: "We’re here to make security as important as anything we do...
We think it’s no longer human vs machine, it’s machine vs machine." #OpenTextWorld
Barrenechea on AI: “Agents are going to make decisions on your behalf. This is going to make us uneasy... would you let a piece of software do that? I think you will, and we’ll give you the tools to do it.” #OpenTextWorld
Barrenechea on AI: “Agents are going to make decisions on your behalf. This is going to make us uneasy... would you let a piece of software do that? I think you will, and we’ll give you the tools to do it.” #OpenTextWorld
Barrenechea: "We’re going to continue to extoll that security is job one… built all the way into the software, and it needs to work across multicloud." #OpenTextWorld
Barrenechea: "We’re going to continue to extoll that security is job one… built all the way into the software, and it needs to work across multicloud." #OpenTextWorld
I really like how @OpenText CEO/CTO Mark Barrenechea highlights the value of #AI in the enterprise in his opening keynote: "Every organization has two proprietary gifts: talent and data... AI transforms the value of both of those gifts." #OpenTextWorld
I really like how @OpenText CEO/CTO Mark Barrenechea highlights the value of #AI in the enterprise in his opening keynote: "Every organization has two proprietary gifts: talent and data... AI transforms the value of both of those gifts." #OpenTextWorld
Pleased to spend time with @OpenText & @OpenTextSec this week at #opentextworld
Key Qs: Is this *really* a security company vs an information management co w/ security?
Has the Micro Focus deal/integration been a force multiplier? @OmdiaCyber
Pleased to spend time with @OpenText & @OpenTextSec this week at #opentextworld
Key Qs: Is this *really* a security company vs an information management co w/ security?
Has the Micro Focus deal/integration been a force multiplier? @OmdiaCyber