This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

CrowdStrike 2025 Global Threat Report – Ce que vous devriez savoir pour préparer vos équipes!

Download resources

About this session

Stephane Asselin, Director of Sales Engineering Canada at CrowdStrike, presents highlights from CrowdStrike's 2025 Global Threat Report. He explains the nation-state, e-crime and hacktivist adversary taxonomy, notes CrowdStrike now tracks over 265 named adversary groups with 14 new ones added in the first half of the year, and shows that 73 percent of hands-on-keyboard intrusions are financially motivated, concentrated in tech and professional services. He details how AI speeds up attackers through saved 'prompt books' rather than replacing tradecraft, and walks through concrete cases: North Korea's Famous Chollima creating fake remote-IT identities with deepfake interviews (including an Arkansas laptop farm with 92 devices), Scattered Spider bypassing MFA via a help-desk password reset and exfiltrating SharePoint data in five minutes, and China-nexus groups (Genesis Panda, Glacier Panda) patiently compromising cloud control planes and telco endpoints. He closes on identity behaviour monitoring, daily cloud posture checks, closing cross-domain access gaps, and prioritizing patches by real exploitability and chainability rather than raw CVSS severity.

Dans cette session, nous examinerons les derniers thèmes, tendances et événements liés aux adversaires, suivis par l'équipe des Opérations Contre-Adversaires de CrowdStrike – les experts leaders de l'industrie en matière de renseignement sur les menaces et de chasse aux menaces. Nous aborderons des découvertes frappantes comme celles-ci, et ce que vous pouvez faire pour garder une longueur d'avance sur les adversaires: Augmentation de 150% des activités liées à la Chine dans tous les secteurs Croissance de 442% des opérations de vishing entre le premier et le second semestre 2024 51 secondes était le temps de propagation le plus rapide enregistré pour la cybercriminalité 79% des détections pour gagner l'accès étaient sans logiciel malveillant

Key takeaways

  • Drop SMS-based MFA and require a stronger challenge (FIDO token, callback with information only the real employee knows) before help-desk password resets and new-device registration.
  • Review remote-hire interview and onboarding procedures for video-verification gaps that let fabricated identities like Famous Chollima get hired as remote IT staff.
  • Check cloud posture continuously, not periodically; put automated baselines in place so new containers, control-plane changes and misconfigurations are flagged the day they appear.
  • Map and monitor cross-domain access boundaries (network, identity, application) so a compromise in a low-security zone cannot silently reach sensitive HR or payroll systems.
  • Prioritize patches by real-world exploitability and chainability across multiple moderate CVEs, not just CVSS severity, since low-severity bugs are often chained into full compromises.

Speakers

Stephane Asselin
Stephane Asselin
Director, Sales Engineering Canada · Crowdstrike
Stephane Asselin, with his 29 years of experience in IT, is the Country Manager for the CrowdStrike Canada Engineering Technical Team. He has national responsibility for Canada for a team that works with customer at planning, designing, and… Read moreRead less

Stephane Asselin, with his 29 years of experience in IT, is the Country Manager for the CrowdStrike Canada Engineering Technical Team. He has national responsibility for Canada for a team that works with customer at planning, designing, and implementing Security solutions and all processes involved. At CrowdStrike, Mr. Asselin works with top Canadian strategic customers and partners, enabling them on all Modules of the CrowdStrike platform, developing technical expertise and helping them secure their local and remote workforce. He had an Offensive Security company for a few years and has delivered multiple talks on Ethical Hacking and Threat Hunting.

Resources

Tags

More from GoSec 2025

Also from Stephane Asselin

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.