News flash: your top security priorities in a world where attackers move faster thanks to AI tooling are...
...the exact same as they are today. CIS Top 20 is still the CIS Top 20. Execute those well, you'll be better prepared than your peers. And remember: attackers are lazy.
People shouldn’t be scared by this CrowdStrike report. I don’t even know why they added the “AI-enabled ransomware” part -probably a PR idea that nobody stopped
The real issue is wrong risk perception. CISOs worry about what sounds new instead of what actually causes incidents. AI-enabled ransomware” isn’t really a thing. Maybe an AI written phishing email here and there, but the rest is still human work.
Meanwhile, most orgs lack asset visibility, detection on legacy or OT systems, have exposed RDP without 2FA and poor monitoring. Yet somehow this gets less attention than a buzzword in a report.
It’s like when everyone panicked about tracking pixels in emails around 2018–2021 simply because PR people pushed it as a serious issue.
It generates distorted perception of risks. Our job as a community is to make people aware of this distortion.
https://t.co/Mcj0S23KTO
Hey @LinkedIn - your newly aggressive notification preferences are so loud and your UX for disabling the types so tedious I am on the precipice of turning off all notifications from everywhere.
That’ll make my experience worse, but right now lesser of two evils. Please fix.
@jeremiahg@SevcoSec I was wrong. At least in this [one, small] sample it is ~25% differing results:
One org, ~10k devices, ~21k total CVEs, two sources of CVEs. ~75% of those CVEs reported by both.
More to come soon!
@jeremiahg@SevcoSec I was wrong. At least in this [one, small] sample it is ~25% differing results:
One org, ~10k devices, ~21k total CVEs, two sources of CVEs. ~75% of those CVEs reported by both.
More to come soon!
@jeremiahg@SevcoSec Overlapping. We’ll see what the actual numbers end up like, but in general I expect wider variance than most end users expect. Smaller variance on a single machine, increasing as count of assets compared increases.
📣 @jjguy will be talking Vulnerability Management & Asset Inventory at #ThursdayDefensive tomorrow. We hope to see you there! https://t.co/cgKxtfliwr #cybersecurity
@secprentice @TheSharp0ne Here's a screencap from the console showing the overlap between Crowdstrike, Active Directory and SentinelOne. (lifted from a client during their migration from S1 to CWRD)
https://t.co/o36FmA4dpS or DM me to get rolling
@iggyf @TheSharp0ne @ryujin 👍👍❤️ I will never forget the plate of humility you served us!
We were a bunch of former VR guys whose sense of identity was strongly wrapped around finding non-pubs.
To have someone else find them in our own software hurt!
In six months of working for an MDR that services all manner of industries, I feel like any time I see an incident occurring it started on an asset that didn't have EDR installed.
🧙♀️ CISO Story Time
This is not exaggeration.
I have a good friend. He's a CISO of a multinational organization in the technology sector. We talk often.
Market trends, sales, and business regulations had the business decide to open an facility in China.
a 🧵 👇