It used to be ”oh, random USB stick in the mail (or on the ground) - I wonder what happens if I just briefly plug it in?”
Seems we’ve progressed to ”oh, random smart watch - I wonder what it can do if I just connect it to my phone & wifi?”
Pro-tip: don’t. Nothing good happens.
There have been incidents of military personnel receiving D18 smart-watches in the mail.
The watch can be used as a tool to gain personal information & cause significant security threats to the @USArmy and its members.
An update on the number of AI related mentions on earnings calls and other transcripts of publicly traded companies: {Data from TA<Go>}
*No shock here, it's gone vertical
Unpopular opinion: LLM-based query interfaces won’t take over the world.
Why: they’re undoubtedly great for getting started, but the more advanced a user you become - the more you start to know exactly what & how you want to do - an LLM turns from convenience to hindrance
The hard stuff nobody talks of when building products with LLMs:
-Context windows
-LLMs are slow & chaining is a nonstarter
-Prompt engineering is weird
-Correctness vs. usefulness
-Prompt injection
-LLMs aren’t products by themselves
-Legal & compliance
https://t.co/UfTWHWFzeF
It won't matter how great your product, portfolio, story or marketing is. If your biz fundamentals & unit economics aren't healthy & if you aren't top2 in your market, it'll be tough.
Pick your ideal customer profile carefully and stick to it. Be a winner in a smaller segment.
There are about as many cybersec unicorns as listed firms (50-60 depending on source). Not all can win their overall market. Cybereason is a Gartner MQ leader but just saw their valuation drop from 2.7B$ in '21 to 250M$ now (-90%). Being a runner-up is a harsh reality.
Manage R&D programs to launch products, coordinate complex tech stack changes, or improve business unit economics? Develop WoW of a big R&D unit building cyber security software for all major OSs?
I’m hiring a Program Manager for @WithSecure’s Agents R&D https://t.co/ax8YHCg2ZM
While performing a threat hunt exercise using telemetry data from @WithSecure Endpoint Detection and Response (EDR), our researchers noticed some Veeam servers that generated suspicious alerts https://t.co/v9FlZoieko
The power of real-world investigations. We investigated attacks against servers running Veeam Backup & Replication software. We have high confidence it's FIN7. Initial access was likely via a recently patched Veeam Backup & Replication vuln CVE-2023-27532 https://t.co/awuVAOw1i5
Our incident responders recently battled TheDukes/CozyBear/APT29 out of a customer environment. We also developed tooling to help investigate the timeline of the breach. We added 3 techniques for the analysis & timestamp enrichment of Shimcache entries https://t.co/uQGERBDLHY
Do you make machinery, motor vehicles, or medical devices? Or provide services to the postal delivery chain? EU NIS2 expands the scope & requirements of the original. If you're not sure of the expanded scope & requirements, here's a good simple checklist. https://t.co/m9F43pREGe
It started with selling hacking tools but evolved to selling access
Webinar June 1st: The growing professionalization of cyber crime & what you can do, with Jack Fowler (Head of Information & Cyber Security, Harris Federation) https://t.co/Gq2rS9V7rf
Do you plan your cybersecurity initiatives to achieve improved customer experience & revenue growth for your org? Unless cybersec initiatives are aligned with the business outcomes that business people expect, they'll struggle to get priority and funding. https://t.co/bCM2332EkN
The problem: "when the risks being mitigated aren't what's important for the outcomes the business wants to achieve, it can lead to cyber security investments being completely disconnected from the business or not getting the appropriate funding" https://t.co/MNFdK2Q27h
@martijn_grooten Yup. Back ~10y ago GOZ, Ursnif, and some others started on this route by reselling/reusing their access. E.g. GOZ deploying Cryptowall for victims deemed to have too low bank balances to be of interest for banking malware.
I’ve now been tracking cyber crime & threat landscape for ~9y, and IMHO the emergence of “access-as-a-service” is by far the single thing that has had the most far-reaching impact. It’s enabled threat actors to specialize and to scale.
#Ransomware and access-as-a-service remained our top threat to most organisations in 2022, with groups displaying an increasingly fractured and fluid nature while continuing to chase the 💰.
Good walkthrough of a real cloud incident. Exposed credentials -> S3 access -> disable versioning -> delete files -> leave a ransom note.
https://t.co/fRd0gMFRUq
Top advice:
- Often I felt I didn’t deserve the spot or I wasn’t as good as others. It was more common amongst my colleagues than I knew. One way I overcame this was surrounding myself with mentors and like-minded colleagues
- Lean into your strengths https://t.co/B7HF7xjoXo