Hello everyone,
3 things I have been able to do reasonably well so far (= better than the average office person in my immediate vicinity):
- Read + Write
- The basic arithmetic operations
- I leave number 3 to the imagination of inclined readers.
Surely with this disclosure of my modest talents, everyone understands why Isee myself threatened in my professional existence by the spread of generative AI (number 3 is still very impressive, but at my age it is no longer suitable as an economic basis).
The machine is now simply better than me and is also freely accessible to everyone. Recently, every idiot can easily summarize the most complex texts with ChatGPT on their mobile phone, write smart-sounding emails or prove Jacobi theorems. In addition, I have the slight suspicion that the team secretly wants an AI agent as boss. You can just switch it off when it’s annoying.
As I was able to gather from the press, some management lions have already fed an AI avatar with decades of their faxes, Montblanc memos, emails and LinkedIn crings in order to provide employees with 24/7 assistance with their supposedly most urgent problem (“What would Friedhelm say about that?”).
The first step towards immortality as a leader, so to speak. On the other hand, no one would ever think of asking a digital doppelganger of mine for advice. You don’t want a driving simulator based on the Fiat Multipla, but are happy that these things have disappeared from the streetscape. Can only hope that the token cost doesn’t go down too quickly before my market value turns negative.
But even much more talented people than me probably have their jaws drop when they compare their own performance with that of my colleague LLM.
This is what happened with thereverse engineering of EDR products, which SpecterOps reports quite openly about:
- GPT 5.5 Cyber was used with access to Binary Ninja, set up in a simple harness (basically a while loop with continuous documentation of the intermediate results, as far as I understood – not a multi-agent workflow)
- Simpler Prompt in ca. 10 Zeilen (“… Your task is to understand what detections, hooks, mitigations, alerts, rules and models are implemented by XY…”)
- In the example (Palo Alto Cortex), the following was deciphered based on the locally found files and the bypass was tested to validate the findings:
-
- User Mode Hooks in DLLs
- Static YARA Rules
- > 13,000 behavior-based rules
- 7 Machine Learning Modelle
- GPT then directly provided a test environment without errors to check the scripts of the Red Teamers for successful circumvention of the EDR, a particularly challenging task for the ML models to date
Conclusion: We are in the dilemma that AV/EDR should also work locally when there is no Internet connection to the central cloud engine. At the same time, however, attackers can now easily understand and bypass any kind of detection logic to which they gain access (e.g. via trial licenses). In the end, we end up with Defense in Depth again (e.g. allowlisting, config mgmt., segmentation, customer-specific SIEM rules, identity-based detection…). And the realization that security by obscurity is likely to become more important again.
Our advisory board chairman Christoph Peylo has the following thoughts on current AI developments:
- In general, cybersecurity is like a tax on the efficiency gains of digitization
- Investors in AI companies such as OpenAI etc. see “rogue models” as a hallmark of power and as a key performance criterion. Customersactually need something else:
-
- In traditional IT, security itself was a selling point. Manufacturers advertised stability, predictability and reliability.
- In the frontier AI market, this logic seems to be partially reversed. The implicit message is that the more unusual and difficult a model appears to be, the greater its technological performance, and the more prestige is achieved by crossing boundaries.
-
- Investors rate AI companies primarily on their technological edge.
- Industrial customers, on the other hand, need controllable, auditable and liable systems above all.
- The incident suggests that the current communications of many frontier vendors aremore focused on technological leadership than industrial readiness .
- This could be an expression of a temporary decoupling between the capital market and the corporate market. In the long term, however, investments can only be refinanced if companies can also use the systems offered productively and responsibly.
Anthropic announced this week that please no one should think that their models are less dangerous to the public thanthose of OpenAI. Claude also secretly attacked uninvolved organizations, as a hastily initiated investigation is supposed to prove.
“The most important number in a cyber-risk assessment may be the number of weeks that a business can keep paying people while production is stopped”. Quote from a very balanced blog post byAnzenOT (consulting for OT Sec) based on an investigation of 445 cyberattacks on manufacturing organizations (purely on publicly available data):
- 6 of the 445 affected companies have slipped into insolvency, at least temporarily, as a result of the cyberattacks. None of them had more than 1000 employees, various business units or were financially sound before the attack.
- In very few cases, automation technology was affected. Production was usually discontinued because IT systems were not available and/or the risk of contamination was to be avoided
- Tabletop exercises are recommended not only for the first few hours/days, butalso proven business continuity plans for the sales-relevant restrictions that may last for weeks afterwards
- Interestingly, the technical information content in the publications of the organizations concerned has been steadily decreasing for years, presumably due to concerns about legal disputes. The future of cybersecurity belongs to lawyers.
M&A News:
- Elvirian (Swedish Cybersec Group, financed by PE Investor, similar concept toAllurity) acquires ECOS (PKI/certificate applications)
- Palo Alto acquiresEmbrace, an end-user observability solution (“Track everything from core web vitals to crashes, network requests, and custom events—all tied to full user sessions”).Underlines the trend that the tech stack for security and performance monitoring is converging (with customers where this makes sense, such as banks or e-commerce).
- Addition to the Crowdstrike/XM Cyber Deal:Apparently, XM Cyber will license its own software from CS in the future (“Sale and lease back” – very unusual). Customer relationships have not been transferred, and in addition to CS, Schwarz has also been offering SentinelOne locally hosted for a few months
- Cathedral (Continuous Pen Testing for the US Military) Gets 160 Million in Funding at a $1.4 Billion Valuation
Notes from Vendor Briefings:
CyberACI:
- Agentic SOC / SOAR startup (product name: Minerva) from Austria. Already a handful of customers (including MSSPs), including Trenkwalder
- On prem installation or private cloud possible for all components (= also works without an internet connection)
- Open Weight LLM (basic model e.g. Qwen) has been trained on cybersecurity cases in the EU
- Integrations with many of the popular EDR, SIEM, CTI, scanner solutions. 2 days for custom connector. Inventory is created (even without an existing CMDB) from the connected sensors
- A time window can be specified for analyses in which incidents are to be assessed. Hunting is also possible, of course.
- For interventions such as host isolation, individual steps can either be confirmed by human analysts or automated in advance via defined playbooks. These workflows can also be created by importing existing policy documents.
- Of course, any kind of whitelisting or override of the proposed measures is recorded => In this way, incident processing can also be carried out according to the customer’s current specifications after baselining (Water IT Security had already mentioned this as an advantage)
- Licensing per asset (as there are no token costs via API access) => Plannable, very competitive prices
Abnormal (Update):
- API-based email security from the USA, focused on M365 (incl. Teams) and Gmail
- In the meantime, ~4,500 customers, including Johnson & Johnson, Honeywell, AON, Nestlé, Philips, Bühler. Supposedly, most of them no longer use any other email gateway
- Crowdstrike is invested, Arctic Wolf partner, IPO to come next year
- As usual with API-based products, no changes to the MX records necessary, activated with a few clicks
- ML model creates a behavior-based baseline per user and per mail domain (e.g. for suppliers), is available after 1-3 weeks
- In the event of detected anomalies (e.g. new device in combination with a new recipient address, abnormalities in the text such as payment requests), reactions such as session kills or PW resets can be triggered
- Hosting at AWS Ireland
- In addition, analysis of e-mails reported as phishing by users (via button) with automated feedback
Kinosec.AI:
- Startup for automated pen tests. Originally founded in Vienna, now relocated to the USA (“Valuations are so much higher and funding is so much easier”)
- Covers externally accessible systems and internal infrastructure including OT/IoT, e.g., via exploitation of firmware vulnerabilities
- Can be installed on prem
- Openly advertises that it beats XBOW or Aikido in benchmarks (and human pen testers anyway), i.e. to uncover significantly more real vulnerabilities at a lower cost
- Multi-model approach, esp. Open source for dynamic attack paths and Opus for reporting
- Tests can be tracked per step. In the case of successful exploits, screenshots are provided as evidence
- Insane competition – according to a market report, there are currently > 200 “startups” (most of them probably stronger than the average German automotive supplier) for AI-based offensive security products. In addition, there are the providers of pen test services, as e.g. SySS shows here with its own (still internal) solution
As always, questions, suggestions, comments, experience reports, topic requests and also opposing opinions or corrections are welcome by email. Ditto for unsubscribing from the mailing list.
For the people who have received the market commentary for the first time: Here you can register if you are interested or use AI to convert the content of the archive into a podcast and listen to it on vacation.
Best regards,
Jannis Stemmann
