This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Focusing On The Sophistication Of Recent Attacks Only Gives Us Half The Picture

Download resources

About this session

Marc Rogers, VP of cybersecurity at Okta, head of security at DEF CON and co-founder of the CTI League, argues that calling every breach 'sophisticated' hides the real story. He compares the 1988 Morris worm, which chained two zero-days and self-propagated, with the 2021 Kaseya VSA ransomware campaign, which relied on a single authentication routine that had failed open for fifteen years and on customers whitelisting the update folder from endpoint protection. He then walks through the Citrix ADC, Pulse Secure, FortiGate and F5 BIG-IP flaws that topped CISA's list of most exploited vulnerabilities in 2020: all simple directory traversals or one-line remote code execution, all weaponised within hours of disclosure and still exploited years later. Ransomware crews prefer phishing, stolen or stale credentials (the Colonial Pipeline VPN account) and exposed RDP because they are predictable, scalable and cheap from access brokers; the sophistication sits in the execution and monetisation, not the entry. His prescription is basic hygiene: no admin interfaces on the internet, remove old accounts, MFA everywhere and patch critical flaws within days.

The last 24 months have seen a significant escalation in the complexity and frequency of attacks launched by cybercriminals. However that's not the elephant in the room. In this talk I am going to cover the obvious, the unremarkable and the ugly: The things we aren’t talking about - but which we need to - in order to actually start getting ahead of the cybercriminals. 

Key takeaways

  • Stop calling attacks sophisticated when the entry vector was phishing, a stale credential or a directory traversal; reserve the word for the operation as a whole.
  • Patch critical vulnerabilities in internet-facing appliances (VPN, ADC, load balancers) within days; proof-of-concept code appears within hours of a patch.
  • Never exclude a directory that receives external code from endpoint protection; Kaseya customers who did were the ones encrypted.
  • Remove admin interfaces from the internet, deprovision departed users' accounts and enforce MFA on every remote access path.
  • Treat vendor mitigations with caution: several 2020 advisories were incomplete and gave a false sense of security while attackers had already siphoned credentials.

Speakers

Marc Rogers
Marc Rogers
Vice President of Cybersecurity · Okta
Marc Rogers is VP of Cybersecurity at Okta. With a career that spans more than twenty years, he has been hacking since the ’80s and is now a white-hat hacker renowned for hacking things like Apple's TouchID and the Tesla Model S. Prior to Okta, Mr… Read moreRead less

Marc Rogers is VP of Cybersecurity at Okta. With a career that spans more than twenty years, he has been hacking since the ’80s and is now a white-hat hacker renowned for hacking things like Apple's TouchID and the Tesla Model S. Prior to Okta, Mr. Rogers served as the Head of Security for Cloudflare and spent a decade managing security for the UK operator, Vodafone. He's been a CISO in South Korea and has also co-founded a disruptive Bay Area startup. In his role as technical advisor on “Mr. Robot,” he helped create hacks for the show. He's also an organizer and the Head of Security for the world’s largest hacking conference: DEF CON. Most recently Mr. Rogers helped found the CTI League, a multinational cybersecurity initiative combining industry professionals, government agencies, and law enforcement from 80 different countries.

Resources

Tags

More from GoSec 2021

Also from Marc Rogers

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.