This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Internet Threat Radar – The Current Cyber Threat Landscape

Download resources

About this session

John Engates, Field CTO at Cloudflare and former 18-year CTO of Rackspace, surveys the threat landscape Cloudflare observes across its global network, which handles roughly a fifth of the web's traffic. He covers phishing, still the primary compromise vector, driven by deceptive links and newly registered domains used within minutes of registration, machine learning's growing role in classifying zero-days before signatures exist, and the explosion of unsecured API traffic, now 58 percent of Cloudflare's network volume. He details a sophisticated credential-phishing attack against Cloudflare itself, defeated only because employees used hardware-key MFA, and argues boards are now demanding cybersecurity updates as SEC disclosure rules tighten. He runs through current attack tactics including pro-Russian hacktivist DDoS campaigns, DNS laundering, Mitel-based amplification attacks, and increasingly powerful botnets built from hijacked cloud VPS capacity rather than home IoT devices. He closes on generative AI cutting both ways, sharpening phishing and deepfakes for attackers while helping defenders, plus predictions for 2024: more destructive and state-sponsored attacks, quantum-safe encryption, and passwordless authentication.

Key takeaways

  • Assume attackers can register and weaponize a phishing domain within about 40 minutes; block on newly-registered-domain heuristics, not just known-bad lists.
  • Deploy phishing-resistant MFA (hardware security keys) on critical applications; Cloudflare's own credential-phishing incident caused zero compromises only because of this.
  • Take an inventory of your exposed APIs and validate their schemas before applying protections; API traffic now often exceeds half of total network volume and is frequently unmonitored.
  • Build a blame-free reporting culture for phishing clicks; punishing users for clicking suppresses the reports you need to respond fast.
  • Watch for DDoS amplification and dependency shifts: attacks increasingly launch from hijacked cloud VPS capacity rather than home IoT devices, and can reach thousands of times normal volume.

Speakers

John Engates
John Engates
Field CTO · Cloudflare
John Engates joined Cloudflare in September of 2021 as Field Chief Technology Officer and is responsible for leading the Field CTO organization globally. Prior to Cloudflare, John was Client CTO at NTT Global Networks and Global CTO at Rackspace… Read moreRead less

John Engates joined Cloudflare in September of 2021 as Field Chief Technology Officer and is responsible for leading the Field CTO organization globally. Prior to Cloudflare, John was Client CTO at NTT Global Networks and Global CTO at Rackspace Technology, Inc. Earlier in his career, John helped launch one of the first Internet service providers in his hometown of San Antonio, Texas. John is a graduate of the University of Texas at San Antonio and lives in Texas with his wife and two daughters. He is passionate about technology and enjoys mountain biking, snowboarding, and spending time traveling with his family.

Resources

Tags

More from GoSec 2023

Also from John Engates

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.