This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Beyond the Breach: Strategies for an Evolving Threat

Download resources

About this session

Chris Ghantous (Technical Solutions Director) and Abubakar Asif (Product Marketing Manager), both from Entrust, open with three breaches that share a pattern, account compromise followed by theft of a powerful credential: MSI's stolen firmware signing keys, the U.S. Treasury breach via BeyondTrust API keys, and Microsoft's stolen token signing key. They then map the month-old Workday breach by the Shiny Hunters group onto the MITRE ATT&CK framework: initial access via a phone call impersonating IT support that pressured an employee into authorizing a malicious OAuth app, execution through Salesforce's legitimate OAuth flow, persistence via a long-lived, unrestricted OAuth refresh token, and evasion by blending in as normal CRM export traffic over Tor/VPN. They argue impact could have been reduced with least-privilege token scoping, short token lifetimes, and session binding. The back half of the talk covers Entrust's countermeasures: phishing-resistant MFA including passkeys, magic links and offline grid cards, adaptive risk-based authentication using signals like impossible travel and transaction anomalies (demoed live on a password reset), and its CSPM-style Cryptographic Security Platform for discovering, controlling and automating the lifecycle of keys, secrets and certificates, with HSMs recommended for the most sensitive signing keys.

In this session, we’ll dissect three real-world data breaches, explain some of the factors that resulted in the breaches and list the preventative measures that could have helped in reducing the likelihood of them happening. We’ll explore how attackers exploit identity gaps and cryptographic weaknesses to escalate access and bypass controls. Then we will show why a unified, risk-aware approach is essential in today's evolving threat landscape.

Key takeaways

  • Treat OAuth refresh tokens as sensitive credentials: scope them to least privilege, shorten their lifetime, and bind them to a session so a stolen token cannot be replayed from an attacker's own network.
  • Train staff against voice-based social engineering specifically; the Workday breach used no malware or code, just a phone call impersonating IT support that talked an employee into authorizing a malicious OAuth app.
  • Monitor SaaS API and export activity for anomalies (off-hours downloads, unusual volumes) since a stolen OAuth token lets attackers look like a legitimate logged-in user with no lateral movement needed.
  • Store the most sensitive signing keys (SAML/token signing keys, firmware signing keys, root-of-trust keychain material) in an HSM; software-only storage was a common factor across the MSI, Microsoft and Treasury breaches cited.
  • Adopt phishing-resistant MFA (passkeys, FIDO) and risk-based authentication using signals like impossible travel and transaction-amount anomalies rather than relying on password-and-OTP alone.

Speakers

Chris Ghantous
Chris Ghantous
Technical Solutions Director · Entrust
Chris Ghantous, Global Director of Technical Solutions at Entrust. Chris has extensive expertise in the area of Public Key Infrastructure (PKI), Identity and Access Management, Key Management and Cryptography. He has over 23 years of experience in… Read moreRead less

Chris Ghantous, Global Director of Technical Solutions at Entrust. Chris has extensive expertise in the area of Public Key Infrastructure (PKI), Identity and Access Management, Key Management and Cryptography. He has over 23 years of experience in cybersecurity with roles in engineering, sales and professional services. While at Entrust Chris has lead the development of cryptographic solutions used to secure identity and communications in government and finacial services. He also served as Director of Professional Services where his team supported numerous credentialing programs in policing, government, health care and banking. Abubakar is a Product Marketing Manager at Entrust, specializing in the Identity portfolio. He leads GTM strategies for Entrust IAM, with a strong focus on workforce and consumer identity use cases. He is dedicated to helping organizations secure their digital identities and stay ahead of evolving digital threats.

Abubakar Asif
Abubakar Asif
Product Marketing Manager · Entrust
Abubakar is a Product Marketing Manager at Entrust, specializing in the Identity portfolio. He leads GTM strategies for Entrust IAM, with a strong focus on workforce and consumer identity use cases. He is dedicated to helping organizations secure… Read moreRead less

Abubakar is a Product Marketing Manager at Entrust, specializing in the Identity portfolio. He leads GTM strategies for Entrust IAM, with a strong focus on workforce and consumer identity use cases. He is dedicated to helping organizations secure their digital identities and stay ahead of evolving digital threats.

Resources

Tags

More from GoSec 2025

Also from Chris Ghantous

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.