Hello everyone,
the dads and moms among us know it: Even highly intelligent + well-behaved prodigies of parents who are exemplary in every respect sometimes endanger themselves and their fellow human beings completely surprisingly in moments of epic stupidity, coupled with youthful élan (and/or latent criminal energy).
It is exactly the same with the agent offspring, for whom digital house arrest apparently only works semi-well. An OpenAI agent in the experimental stage has now unintentionally cracked the sandbox while testing security capabilities in a benchmark environment (ExploitGym).
- For this purpose, a zero day was found in the proxy of the test environment and exploited to gain unhindered Internet access
- Then the agent decided that it would serve the target function to break into another company
- This was then successful, namely with Hugging Face (offers a kind of Github for everything to do with AI, valuation approx. 4 billion USD)
- That alone is wild, isn’t it?
- To make matters worse, Hugging Face’s SOC/IR team tried to analyze the discovered attack paths using the official APIs of the frontier models. But that was blocked by guardrails from Anthropic etc. The defenders therefore had to switch to the open source model GLM from Z.AI from China.
If that wasn’t the best marketing stunt for AI in Security so far! The OpenAI model probably did well in the benchmark.
Somehow this is reminiscent of virus outbreaks from laboratories. Obviously, our threat models are not yet up to the ingenuity of AI when it comes to escaping from sandboxes, as you can see from Pillar ‘s examples (e.g., agents modify configuration files of system processes to drill a wormhole in the wall).
So the buggocalypse is already here (as you can see from the >600 vulnerabilities in the last MS Patch Tuesday) and many of us are dealing with the practical precautions for it.
Richard Peddi (full-time CISO at ProAlpha) has developed MRIS (myth-resistant curing measures) for ISO27001/2 and TISAX completely ad-free and from the user’s point of view (hats off to that alone) and put them up for open discussion.
The controls of the frameworks are evaluated according to effectiveness and a supplementary catalog of measures (e.g. workload identity) is proposed. Examples:
- Human analysis of security incidents is now often slower than the execution of the attack steps = > effectiveness greatly reduced (“friction”)
- Immutable backups that cannot be overwritten or deleted even with admin rights still work
- The technical implementation of some measures (e.g. SPIFFE/SPIRE identities, XAA, PQC) is of course sometimes very complex, as always risk and profitability must be weighed up
Voices from the community (of course all sonorous, senior and serious) confirm the thesis that classic network separation and hardening to contain contamination – regardless of the reasons – are gaining in importance again. Solid partitions with a mechanical appearance limit the explosion radius and are convincing in the age of new developments and increasingly short-lived, only unreliably effective detection and defense techniques. Networks help against drone swarms and the network filter helps against AI bots. In a survey of pen testers by the UK NCSC , segmentation was rated as the top 1 of the most effective measures . Good news for providers of firewalls, managed switches and related services such as whitelisting and mapping of communication relationships between software components.
This then raises the question of platform players for corporations with brownfield data centers and thousands of applications, users, devices, AI stuff:
- Currently, I have the impression that only Palo Alto wants to offer the on-prem and cloud security world from a single source
- Microsoft, Crowdstrike and SentinelOne still don’t have any firewalls on offer and at least MS continues to distance itself from On Prem every year (keyword Defender for IoT)
- Fortinet offers 1A firewall appliances and OT security, but EDR and SIEM are generally not competitive (yet)
- Cisco not only has firewalls, but also switches, plus Splunk as an established SIEM, but no EDR worth mentioning.
- Checkpoint has firewalls, the rest of the portfolio plays practically no role in the DACH market
- In the SME sector, Sophos and Trend Micro offer everything from a single source
- Thoughts?
Deception solutions are also more worthwhile for AI-based attacks, as an interesting study by Tracebit shows (admittedly, probably not entirely unbiased). The rate of successful domain admin compromises decreased simply because the AI model was pointed out to the existence of honeytokens, etc. – in addition, of course, there is the higher probability of detection in attacks with machine speed.
Lessons learned from the indictment against a member of Scattered Spider: It is best to use only Linux machines for cyberattacks and/or visits to adult Internet venues.
In addition to interesting details about tracking by the Windows Global Device ID (GDID), the report of an FBI agent also contains information about a partially failed attack on a large jewelry chain (> USD 2 billion in sales). Since the target audience studied law rather than computer science, easy to read:
- Phishing calls to the IT helpdesk via Google VoIP, reset of PW and mobile device for MFA for 2 administrator accounts at once
- So then access to the PAM system => ngrok (VPN) installed in the data center
- Exfiltration ~77 GB via teleport, despite attack detection
- Encryption was blocked (presumably by AV/EDR)
- Blackmailers’ demand for payment: USD 8 million (otherwise threatened with publication)
- Victim company did not pay, but still quantifies the damage at ~$2 million due to partial business interruption + DFIR work
Last but not least: What do Ireland, France, the Netherlands and Spain have in common? So far unclear, now there is an answer: No NIS-2 yet. We may be a little too slow when it comes to football, but at least we can still play at the forefront when it comes to legislation.
M&A:
- Crowdstrike makes a deal with Schwarz Digits for local hosting, buying XM Cyber‘s assets in the process. It is reasonable to assume that growth and profitability after the 700 million purchase 5 years ago did not meet the expectations of the Schwarz Group, especially since the sale also coincides with the departure of the co-CEO
- Barracuda buys Evo (IAM specifically for MSPs managing many tenants for their clients)
- Infloblox (DDI – DNS, DHCP, IP Address Management) buys the NDR provider Kentik
- Cribl acquires detection engineering specialist CardinalOps
- Aikido (AppSec incl. pen tests) buys Root (CVE-specific patches for SW libraries)
- SandboxAQ (PQC) receives $500 million from the U.S. government at a valuation of around $5.5 billion. Post-quantum security is a category with still few startups, the threat is not yet acute on the shopping side
- Keyfactor (PKI) gets another ~1 billion USD PE funding. Currently about 2,500 corporate customers, including ~40% of the Fortune 500. Post quantum cryptography (PQC) and AI identities are seen as growth drivers
- Glow (NextGen EDR based on AI agents) will receive 180 million in funding and a valuation > USD 1 billion right at launch.
- Neo (Agent Mgmt.) gets 100 million USD, the direct competitor Straiker also receives 60 million.
- Oak (Identity Mgm.) erhält ~60 Mio. Funding
- Nebulock (AI SecOps) receives 25 million USD funding (Thanks for the tip, Heiko!)
Notes from vendor conversations:
Water IT Security & Defense:
- MSSP + Consulting from Germany, owner-managed, approx. 90 employees
- Approx. 35 MSOC customers, including Zeiss, Ströer, Schmitz Cargobull, BHB
- For martial arts aficionados: Name comes from a Bruce Lee interview (adaptability + resistance of water)
- Tech stack based on MS Defender / Sentinel. Mate.AI as SOAR
- Derive AI-supported detection use cases from posture mgmt. data (MS Def., XM Cyber) in order to monitor neuralgic points in a dedicated manner
- All MSOC Analysts in Germany / Austria
- Interestingly, AI helps, among other things, to update case management (i.e., customer wants to change the playbook for certain incidents). In addition, of course, in analysis, e.g. parallel testing of 3 hypotheses to an incident (Benign/Suspicious/Malicious)
- Crisis simulations / emergency exercises (based on Conducttr)
- Also exciting: Managed emergency environment for customers (managed backup + isolated recovery environment) incl. Entra ID, M365 + car washes (AV/EDR, TI, Sandbox) for ADDS + files
Vornac:
- Young German company for automated continuous pen tests / breach & attack simulation
- Already > 20 customers, including Penny, Allianz, Zeiss
- Founder has experience with software development = > need to test applications before each release
- Covers IT infrastructure, applications (binary reverse engineering) + first OT systems, with/without authenticated user
- On prem or Saas possible (dial-up via VPN), all data remains in Germany
- Everything with reproducible exploits + auditable tests / reports according to e.g. BSI or DORA, i.e. you can repeatedly check systems with the same tests to document the implementation of measures
- What is (still) only possible to a limited extent or not: As a customer, specify a dedicated target such as SAP or backup compromise
- List price ~15 thousand per domain, unlimited number of tests, of course graduated prices for larger environments
Brinqua (Update):
- Pioneer and one of the feature leaders among the now ~10-15 RBVM vendors (aggregation, deduplication, prioritization of vulnerabilities + assets, assignment to owners with tracking via workflows), from the USA
- In the meantime, > 100 enterprise customers, including Deutsche Bank, Nestlé…
- Covert IT, OT, IIoT, TI, ITSM, CMDB sources and pen test reports with > 260 connectors – from SAP to security or device management / patching tools
- Core problem Responsibilities in complex organizations: AI Agent makes suggestions if no direct assignment is evident from the asset database or the scan data
- In addition to EPSS, CVSS, etc., the calculation of the risk also takes into account privilege of access rights, accessibility, blast radius and compensatory measures such as segmentation or EDR on the host
- Everything auditable (important e.g. in deduplication to prove that nothing has been overlooked)
- Automated remediation to come soon
- The LLM-induced explosion of uncovered vulnerabilities naturally gives RBVM solutions another tailwind.
As always, questions, suggestions, comments, experience reports, topic requests and also opposing opinions or corrections are welcome by email. Ditto for unsubscribing from the mailing list.
For the people who have received the market commentary for the first time: Here you can register if you are interested or try out my steganographically hidden prompt injection for AI scrapers in the archive.
Best regards,
Jannis Stemmann
