Security Stop-Press: Asus Routers Hit by Stealth Backdoor Attack

Thousands of Asus routers have been compromised in a silent, persistent attack that gives hackers remote access, even after firmware updates.

Cybersecurity firm GreyNoise uncovered the campaign, which targets internet-facing Asus models like the RT-AC3100 and RT-AX55. Attackers use brute-force logins or old vulnerabilities to gain admin access, then exploit a flaw (CVE-2023-39780) to enable hidden logging features and install a stealthy backdoor.

SSH access is then enabled through official settings, with an attacker-controlled key added. GreyNoise warns this “persists across firmware upgrades” and may be part of a long-term botnet operation, with over 4,800 affected devices already detected.

Businesses using Asus routers should check for SSH on port 53282, inspect authorised\_keys, and block known malicious IPs. If compromise is suspected, only a full factory reset can remove the backdoor.

Tech Insight : Google’s $32 Billion Bet on Wiz

Google Cloud has just signed one of the biggest cybersecurity deals in history with a bold $32 billion all-cash agreement to acquire Wiz, a fast-growing cloud security firm.

Awaiting Approval

The deal, still subject to regulatory approval, signals Google’s most aggressive move yet to close the gap with rivals Amazon Web Services (AWS) and Microsoft Azure, while doubling down on multicloud and AI-driven cybersecurity.

Who Is Wiz and Why Does It Matter?

Wiz, founded in 2020 by former Microsoft cloud executives, has quickly become one of the most talked-about players in cloud security. The company offers an agentless, user-friendly platform that helps organisations identify and remediate security risks across all major cloud providers, including AWS, Azure, Oracle Cloud, and yes, Google Cloud too.

Rather than waiting for breaches to occur, Wiz scans cloud environments continuously, maps out all assets and their connections, and flags high-risk vulnerabilities in real-time. Its promise is straightforward: understand your entire cloud environment, see where the threats are, and fix them before attackers can exploit them.

For example, if a developer accidentally leaves a storage bucket open to the internet or misconfigures a sensitive workload, Wiz alerts security teams, and even helps them prioritise the most critical risks. This “code-to-cloud” view has made it hugely popular with everyone from nimble start-ups to sprawling enterprise IT teams and public sector bodies.

Results

The results speak for themselves. For example, in just under five years, Wiz has reached an estimated $700 million annual revenue run rate, with projections it would have crossed $1 billion within a year. That makes it one of the fastest-growing software companies in history (and a highly attractive acquisition target).

Why Is Google Buying Wiz Now?

Google Cloud may be strong on paper, with top-tier infrastructure, AI expertise, and a solid security record. However, it remains a distant third in the cloud infrastructure race, trailing AWS (30 per cent global market share) and Microsoft Azure (21 per cent) by a wide margin. Google Cloud sits at around 12 per cent (Statista).

This acquisition by Google Cloud is designed to change that. By bringing Wiz into the fold, Google is looking to supercharge its credibility with enterprise customers and respond to two urgent trends in tech:

1. The surge in multicloud use. Most large organisations now use a mix of cloud providers for different workloads. That makes managing security even harder — and makes a vendor-agnostic platform like Wiz essential.

2. The rising cybersecurity threat landscape. As more businesses go digital and deploy AI-driven systems, the complexity of defending modern IT environments is exploding. Wiz offers a way to simplify that defence — and make it more proactive.

In a recent blog post, Thomas Kurian, CEO of Google Cloud, summed it up clearly: “Multicloud is something our customers want… Our commitment to multicloud means that new IT projects an organisation does with Google Cloud can work with their existing IT investments.”

Kurian also noted that AI is accelerating this trend: “AI architectures typically see large enterprises pool data from multiple places… This means multicloud protection is more critical than security for a centralised cache of data.”

Multicloud or Bust

Interestingly, Google is not planning to make Wiz a Google Cloud-only tool, and that’s no accident.

Wiz’s success has been built on its neutrality. Many of its customers don’t even use Google Cloud. If Google were to make Wiz exclusive, it could easily drive those users into the arms of competitors. That’s the most likely reason why the company has gone to great lengths to reassure customers that Wiz will continue to work seamlessly across all major cloud platforms.

In fact, as part of the deal, Google and Wiz have even earmarked an additional $1 billion retention package to keep key staff and leadership in place (including CEO Assaf Rappaport) and ensure continuity for clients.

As Wiz’s Rappaport puts it: “Wiz and Google Cloud are fully committed to continue supporting and protecting customers across all major clouds, helping keep them safe and secure wherever they operate.”

For Google, this “multicloud-first” positioning also helps defuse potential antitrust concerns. The deal comes at a time when Big Tech M&A activity is being watched closely by regulators in both the US and Europe. Emphasising openness, competition, and customer choice could make the acquisition easier to push through.

What’s in It for Google Cloud Customers?

From a business standpoint, the deal could be seen as a major play to strengthen Google Cloud’s value proposition to enterprise and government buyers. By integrating Wiz into its broader portfolio, alongside Mandiant, Google Security Operations, and its AI threat intelligence tools, Google hopes to create a unified, AI-optimised security platform that:

– Helps customers detect, prevent and respond to cloud threats faster.

– Lowers the cost and complexity of managing security across hybrid and multicloud environments.

– Boosts productivity of cybersecurity teams with automated tools and AI-powered agents.

– Provides “measurable defence” by helping teams test and validate their own security controls.

Example

As an example of how this could work, a large bank (e.g. using AWS for customer-facing apps, Azure for internal services, and Google Cloud for AI modelling) can now use Wiz to monitor all those environments from a single dashboard. That unified approach, backed by Google’s infrastructure and AI muscle, is what the tech giant hopes will make its cloud platform more attractive.

Wiz’s tools will also remain available via the Google Cloud Marketplace and other partner channels, giving system integrators and resellers access to a much broader toolkit for customers.

A $32 Billion Price Tag (And Plenty of Pressure)

At $32 billion, the acquisition is the largest in Google’s history, and one of the biggest cybersecurity deals ever made. To put that into perspective, it’s more than 3x the price Google paid for Motorola Mobility in 2012, and well above the $5.4 billion Amazon spent acquiring MGM Studios in 2022.

It’s also far above Wiz’s most recent private valuation, which was reportedly around $10 billion. So why the premium?

Partly, it reflects the sheer scale of the opportunity. Cloud security is one of the fastest-growing segments in enterprise IT. According to Gartner, global spending on cloud security is expected to top $18 billion in 2025, up from $13.5 billion in 2023.

Google sees Wiz not just as a product, but as a platform, and one that could become the default choice for securing modern cloud-native and AI-driven systems. The acquisition could give Google a critical edge as AI becomes more embedded in everything from healthcare to finance to national infrastructure.

However, it also raises expectations. With such a steep price tag, the pressure will now be really on Google to show real returns not just in terms of revenue, but in market share gains and customer trust.

What This Means for the Rest of the Cloud Market

For competitors like AWS and Microsoft, the acquisition of Wiz is a clear signal that Google is not backing down in the cloud wars. It’s a bet on openness, AI integration, and simplified security, and it’s likely to accelerate innovation across the industry.

However, some analysts have warned that integrating Wiz successfully won’t be easy. Cultural clashes, product overlaps, and customer scepticism could all pose challenges. There are also questions around whether Wiz’s lean, start-up-style pace can be maintained under the umbrella of a tech giant like Google.

Still, if Google can pull it off, the payoff could be significant. As cyber threats grow more sophisticated and cloud environments become ever more complex, customers will be looking for solutions that just work, regardless of where their data lives. That’s essentially the promise Google is betting $32 billion on.

What Does This Mean For Your Business?

By snapping up one of the most agile and highly regarded multicloud security firms on the market, Google has positioned itself to offer something that many enterprise customers have long been asking for, i.e. a single, unified security platform that doesn’t demand vendor lock-in and can evolve with their increasingly complex IT environments.

For Google, this is about more than plugging a gap in its offering. It’s a strategic move to become a serious contender for the next wave of cloud growth, where AI, hybrid systems, and multicloud deployments are the norm. If it can successfully integrate Wiz and maintain the platform’s independence and speed of innovation, it may finally start to close the distance between itself and the cloud giants that have dominated the space for years.

For UK businesses, from financial institutions and healthcare providers to the growing ecosystem of digital-native start-ups, the benefits could be substantial. Many are already juggling data across multiple platforms, wrestling with compliance demands like GDPR, and navigating increasingly sophisticated cyber threats. A more integrated, intelligent and cloud-agnostic security solution could offer much-needed simplification, cost efficiency, and peace of mind. At the same time, UK-based security consultancies, MSPs and technology partners may find new opportunities through the Google Cloud Marketplace and expanded integrations with Wiz’s tools.

However, the deal is not without its challenges. Regulatory scrutiny remains a looming question, and customers will be watching closely to see whether Google can truly preserve Wiz’s independence in practice. There’s also the risk that the sheer scale of the acquisition could dilute what made Wiz successful in the first place: its speed, focus, and user-friendly approach.

All that said, in a market crying out for more flexible, AI-ready security solutions, this acquisition may be exactly the kind of move Google needed. Whether it pays off, and whether customers, partners and regulators will buy into Google’s multicloud pitch, remains to be seen. One thing, however, is clear – the race to secure the cloud just entered a new phase, and Google has firmly placed its bet.

Security Stop-Press: Record-breaking DDoS Attack Highlights Growing Cybersecurity Threats

Cloudflare’s latest DDoS Threat Report for Q4 2024 highlights a dramatic surge in Distributed Denial of Service (DDoS) attacks, including a record-breaking 5.6 Tbps assault.

The web security and infrastructure company’s report reveals a 53 per cent year-over-year rise in DDoS activity, with Cloudflare blocking 21.3 million attacks in 2024, 6.9 million of which occurred in Q4, a staggering 83 per cent increase from the same period in 2023!

The largest attack, a 5.6 Tbps assault by a Mirai-variant botnet of over 13,000 IoT devices, targeted an ISP in Eastern Asia. Cloudflare says it mitigated it autonomously within seconds, preventing any disruption. Hyper-volumetric attacks exceeding 1 Tbps grew by 1,885 per cent quarter-over-quarter, reflecting the increasing scale and intensity of these threats. Nearly half of all attacks targeted OSI Layers 3 and 4, with the remainder focused on HTTP-based attacks, predominantly launched by botnets exploiting IoT devices.

Cloudflare’s report also highlighted how emerging attack methods like Memcached and BitTorrent DDoS vectors have seen dramatic growth, and ransom-motivated attacks surged by 78 per cent compared to Q3. The report also identifies telecommunications and marketing as the most attacked industries, with China, the Philippines, and Taiwan being key hotspots. Cloudflare says those responsible for the attacks include competitors, state-sponsored groups, and disgruntled users, highlighting diverse motives behind these incidents.

To counter these growing threats, businesses should deploy always-on, automated DDoS protection, secure all connected devices, and adopt proactive defence strategies. With attacks becoming faster and more sophisticated, real-time mitigation and robust security are critical to minimising risk.

Tech News : GoDaddy Complaint Over Years of Poor Cybersecurity

The US International Trade Commission (ITC) has issued a scathing complaint against web-hosting giant GoDaddy, accusing the company of failing to implement basic cybersecurity tools and practices since 2018.

What Is the ITC, and What Is the Complaint?

The ITC is a US federal agency responsible for enforcing trade laws, addressing unfair trade practices, and protecting industries from harm. Although its remit typically covers trade-related matters, it has increasingly expanded its oversight to include consumer protection, particularly in cases where corporate failings have broader implications for commerce and public interest.

In a recent formal complaint, the ITC alleged that GoDaddy violated Section 5 of the Federal Trade Commission Act, which prohibits unfair or deceptive business practices. Despite marketing itself as a secure and reliable hosting provider, GoDaddy (according to the ITC) failed to live up to its claims, thereby leaving millions of customer websites vulnerable, resulting in multiple security breaches and significant data compromises.

The Allegations in More Detail

The ITC’s complaint paints a troubling picture of GoDaddy’s cybersecurity practices (or lack of them). It accuses the company of failing to implement even the most rudimentary safeguards to protect its hosting environment. Among the lapses cited by the ITC are the absence of essential measures such as multi-factor authentication (MFA), proper asset inventory, and robust threat monitoring.

Specifically, the ITC’s complaint (published online) identified the following failings:

– No centralised asset management. As of 2020, GoDaddy had visibility over only 15,000 devices out of the approximately 450,000 in its environment.

– Irregular patch management. Despite a policy requiring critical updates to be applied within 30 days, GoDaddy relied on scattered teams to handle patches with no central oversight, leading to unpatched vulnerabilities across thousands of servers.

– Inadequate logging and monitoring. Security-related events were inconsistently logged, making it difficult to investigate breaches or suspicious activity.

– Weak authentication practices. The company relied on username/password combinations without requiring MFA for privileged accounts until 2020, thereby exposing sensitive systems to unauthorised access.

– Network mismanagement. A lack of segmentation between shared hosting and other services enabled threat actors to move laterally within GoDaddy’s infrastructure.

– API insecurity. GoDaddy’s APIs, critical for managing customer data, used outdated protocols, such as plaintext credentials, leaving them highly susceptible to interception and exploitation.

A History of Breaches and Consequences

The ITC report also details several high-profile security incidents that occurred under GoDaddy’s watch, starting back in 2019. The ITC alleges that these breaches highlight the tangible risks posed by the company’s inadequate security measures.

The 2019-2020 Breaches

A breach in October 2019 saw attackers exploit vulnerabilities in GoDaddy’s infrastructure to move laterally into its shared hosting environment. Threat actors replaced critical server files with malicious versions, ultimately compromising customer and employee login credentials. Shockingly, these intrusions went undetected for six months until another unrelated event in March 2020 prompted an external security audit.

During this time, attackers reportedly stole credentials for over 28,000 customer accounts and 199 employees, gaining administrative access to key systems. The breach also involved the theft of approximately 1,000 payment card details.

2021 WordPress API Breach

In November 2021, GoDaddy discovered another breach targeting its Managed WordPress hosting service. This time, attackers exploited an exposed API, obtaining data for 1.2 million customers, including email addresses, private encryption keys, and login credentials for WordPress and database management tools. Evidence suggests the attackers used this access to plant malware and commit search engine optimisation (SEO) fraud, misleading visitors and search engines alike.

2022 Malware Resurgence

The most recent breach, in December 2022, saw the same threat actors return to exploit remnants of the 2019-2020 compromise. This time, attackers deployed malware that redirected visitors to customers’ websites to malicious destinations, such as phishing pages or explicit content. Despite the repeated nature of these attacks, the ITC alleges that GoDaddy failed to proactively detect the intrusion, learning of it only through customer complaints.

Impact on Customers and the Broader Ecosystem

The consequences of GoDaddy’s (alleged) failings have been far-reaching. Small businesses that rely on its hosting services have endured significant disruptions, including compromised websites, stolen customer data, and tarnished reputations. Some customers have faced financial fraud or identity theft, while others have spent substantial time and resources remediating the damage caused by breaches.

The ITC’s complaint makes the point that these harms were entirely avoidable had GoDaddy employed widely available, low-cost security measures. Also, it accuses the company of misleading customers by marketing its services as secure while failing to back these claims with appropriate protections.

GoDaddy’s Response and the Way Forward

In response to the ITC’s allegations, GoDaddy has neither admitted nor denied the charges but has agreed to implement a comprehensive security overhaul. This includes creating a centralised inventory of its hardware and software, adopting SIEM (Security Information and Event Management) tools for real-time threat detection, and enforcing MFA across all privileged accounts.

A spokesperson for the company stated: “We are committed to safeguarding our customers’ data and continually improving our security posture. Many of the measures outlined in the settlement are already underway.”

The Settlement

Despite the gravity of the accusations and the scale of harm outlined in the ITC’s complaint, the settlement agreement struck with GoDaddy has left some questioning its adequacy. Under the terms of the proposed deal, GoDaddy must implement sweeping improvements to its cybersecurity practices. This includes undergoing regular, independent third-party assessments of its security programme and adhering to a ban on making deceptive claims about its data protection efforts in the future.

Notably, the ITC has not imposed any fines but has warned that future violations could result in penalties of up to $51,744 per breach.

What’s Next?

The ITC has opened the settlement for public comment, and its finalisation will mark a critical juncture for GoDaddy. The case serves as a cautionary tale for other companies, demonstrating the risks of neglecting cybersecurity in an increasingly hostile digital landscape.

What If You’re A Business Customer of GoDaddy’s?

For businesses that rely on GoDaddy’s hosting services, the revelations in the ITC’s complaint may understandably be a little unsettling. Many may now be questioning whether their websites or customer data were compromised in the breaches. Those who suspect they have been affected can review communications from GoDaddy, as the company has stated that it notified impacted customers following major incidents. Also, another option for businesses may be to engage independent security experts to audit their sites and data for any lingering vulnerabilities. Moving forward, customers will need to think carefully about whether GoDaddy’s promised security enhancements can restore their confidence or if alternative hosting providers may better meet their needs.

What Does This Mean For Your Business?

As one of the largest web-hosting providers, GoDaddy holds a significant position of responsibility, safeguarding not only its customers but also the broader ecosystem of internet users who interact with its hosted websites. The ITC’s findings, therefore, paint a very concerning picture of (allegedly) some very basic and systemic failures in cybersecurity practices over several years, leading to serious breaches that have impacted countless businesses and their customers.

For GoDaddy, the settlement offers a chance to repair its reputation and demonstrate a renewed commitment to cybersecurity. Although the lack of financial penalties has been surprising to some, it appears to be more of a case of getting some swift remedial action rather than prolonged litigation. However, it is understandable that some stakeholders may view the resolution as lenient, given the scale of the alleged failings and the potential harm caused. The onus is clearly now on GoDaddy to follow through on its promises and implement the sweeping changes outlined in the settlement.

For businesses affected by the breaches, the road to recovery may be a long and complex one. While GoDaddy’s notification efforts and security improvements may offer some reassurance, the damage to customer trust and the potential for lingering vulnerabilities remain pressing concerns. Businesses should, perhaps, weigh the risks and benefits of continuing their reliance on GoDaddy and consider proactive steps to safeguard their operations, regardless of the hosting provider they choose.

This case serves as a wake-up call for the entire tech industry, underscoring the need for vigilance in an era of evolving cyber threats. Basic security hygiene, while often viewed as a standard requirement, is essential to maintaining trust and preventing harm on a global scale. For organisations of GoDaddy’s stature, the stakes are even higher, as lapses in security can reverberate far beyond their own systems.

The ITC’s intervention, therefore, not only holds GoDaddy to account in some way but also sends a clear message to the industry, i.e. that data protection and cybersecurity are not optional. As businesses and consumers alike navigate the fallout, the hope is that this episode will lead to meaningful changes, not just for GoDaddy but for the industry as a whole, ensuring a more secure digital landscape for everyone.

Sustainability-in-Tech : Underwater Data-Centres Vulnerable to Soundwaves

A study by cybersecurity and robotics researchers at the University of Florida and the University of Electro-Communications has revealed how powerful sound waves could disrupt the operation of underwater data-centres.

Why Underwater Data-Centres? 

With demand for data-centres growing due to increasing demand for cloud computing and AI, plus with data-centres producing large amounts of heat, one idea from data-centre operators in recent years has been to submerge servers in metal boxes beneath the sea. Doing so can harness the natural cooling properties of ocean water and can help dramatically cut cooling costs and carbon emissions. For example, back in 2018, Microsoft submerged 2 racks with 864 servers beneath the waves in Scotland as part of the experimental project ‘Natick’.

Soundwave Threat 

However, the news from a group of cybersecurity and robotics researchers at the University of Florida and the University of Electro-Communications in Japan has revealed that the successful operation of underwater data-centres has a critical vulnerability – the potential to be seriously affected by underwater sounds. Also, there is the added complication that if servers are submerged in metal boxes below the sea and components broken/damaged (e.g. by sound or other means), it will be a complicated (and costly) operation to fix them.

As highlighted by Md Jahidul Islam, Ph.D., a professor of electrical and computer engineering at UF and author of the study: “The main advantages of having a data center underwater are the free cooling and the isolation from variable environments on land,” but “these two advantages can also become liabilities, because the dense water carries acoustic signals faster than in air, and the isolated data center is difficult to monitor or to service if components break.” 

Why Is Sound A Threat?

The study involved submerging test data centre-style servers in a laboratory water tank and in a lake on the UF campus with a speaker playing music in the water, tuned to five kilohertz. This is a frequency designed to make hard drives vibrate uncontrollably and one octave above what can be played on a piano.

The results were that networks were able to be crashed and their reliability disrupted by sound waves generated from 20 feet away. In wild conditions for example, similarly loud and potentially damaging sound waves could be generated by marine life, submarine sonar systems, industrial activity (drilling), earthquakes and seismic activity and more.

The study appears to have shown, therefore, that even something as simple as an underwater speaker playing a D note could have the potential to seriously disrupt or damage server operations in submerged data centres.

Deliberate State-Sponsored Attacks 

One key worry highlighted by the study is how deliberate sound injection attacks / acoustic attacks (e.g. by other states as an act of sabotage) could be a real threat to underwater data-centres. For example, as highlighted by UF Professor of Computer and Information Science and Engineering Sara Rampazzi, Ph.D, acoustic attacks on a submerged data-centre could be subtle: “The difference here is an attacker can manipulate the data centre in a controlled way. And it’s not easy to detect”. 

Other Defences Tested 

As part of the study, the researchers tested different defences for the submerged servers. For example, sound-proof panels were tried but raised the servers’ temperature too much, thereby countering the advantages of cooling with water. Also, active noise cancellation was found to be too cumbersome and expensive to add to every data-centre.

Algorithm 

To counter the threat of soundwaves to underwater data-centres, the research team developed a software-based solution in the form of an algorithm. The algorithm they developed (using machine learning) can identify the pattern of disruption caused by acoustic attacks and it’s anticipated that improvements to this algorithm could minimise the damage to networks by reallocating computational resources before an attack can crash the system.

What Does This Mean For Your Business? 

With Microsoft’s submerged server tests showing very positive results in terms of low failure rates and dramatically reduced cooling costs, underwater data-centres appear to be something that will be put into practice in the near future. However, until now, the potential threat to their operation caused by sound is not something that has been fully realised or explored until this research.

The study has therefore been valuable in raising awareness of the threat. For example, in addition to demonstrating how server disruption by sound can happen inadvertently (e.g. from a loud submarine sonar blast), it has also raised awareness of how data-centres could be vulnerable to deliberate acoustic attacks as acts of sabotage. Not only does the research have value in highlighting the threats, but it has also enabled the development of what appears to be an effective solution,i.e., an algorithm.

Finding a way to protect underwater data-centres from acoustic attacks helps future-proof the idea, thus enabling its rollout which will benefit data-centre operators (e.g. with lower costs, better heat management, and expansion of much-needed capacity). It also provides protection for all the businesses, organisations, governments, and economies for whom the smooth operation and expansion of the cloud and now AI is vital to their operations, prosperity, and plans. This study, therefore, helps contribute towards both healthier economies and a healthier planet through reducing data-centre carbon emissions.

Tech Insight : ‘Networkless’ Attacks?

In this article, we look at why and how networkless attacks (which target cloud apps and identities) have created new opportunities for attackers and new risks for businesses, plus what your business can do to mitigate these risks.

The Move To SaaS and Cloud 

In the rapidly evolving digital landscape, one of the key drivers enabling attackers to compromise an organistaion without needing to touch the endpoint or conventional networked systems and services is the increased reliance on cloud-based services and software-as-a-service (SaaS) applications (to drive efficiency and innovation). This shift, while beneficial, has also created new cybersecurity challenges for businesses, primarily due to the decentralisation of ‘digital identities’ and the interconnected nature of cloud services.

The SaaS Revolution and Its Impact on Security 

The proliferation of SaaS applications is a direct result of the digital transformation that has reshaped the business world. For example, companies can now be using hundreds (if not thousands) of cloud applications to perform daily operations, from customer relationship management to financial operations. This shift is driven by the convenience and scalability of SaaS solutions, however it comes with inherent security risks.

The new risk that businesses are facing is that each application potentially serves as an entry point for malicious actors, and the interconnectivity between these apps can allow a breach in one service to cascade through to others.

Why Digital Identities Are The New Security Battleground 

As the traditional network perimeter dissolves, digital identities become the new security frontier. Put simply, a digital identity can be a user account created for services that someone in the business has signed up for using a username/email and password. More broadly, it can also mean other personal data used to identify and authenticate users online.

These digital identities, which provide access to a myriad of cloud applications, are now central targets for attackers. Securing them has become increasingly complex due to the sheer number of them that businesses may be using and their dispersion across various cloud platforms, each with its own security environment. This decentralisation not only makes consistent security policies harder to enforce but also increases the complexity of monitoring these identities for potential breaches.

How Attackers Are Exploiting Vulnerabilities in Cloud Identities 

Attackers have adapted to this new environment by developing sophisticated techniques to exploit vulnerabilities in cloud identities without ever touching the physical endpoints or traditional networked systems.

Examples of techniques include AiTM (Adversary in The Middle) phishing, SAMLjacking, and Oktajacking, all of which exploit weaknesses in the authentication processes and session management of cloud services.

AiTM phishing involves intercepting and manipulating real-time data during a session to steal credentials or manipulate transactions. SAMLjacking and Oktajacking focus on manipulating Single Sign-On (SSO) processes to gain unauthorised access.

Security stats now increasingly reveal that attackers are deliberately targeting cloud services as a way into organisations. For example, CrowdStrike figures show that 3 out of 4 attacks last year were malware-free (malware used to be one of the main threats) and that the targeting of cloud services has increased 110 per cent. This helps to illustrate why cloud identities are the new digital perimeter and that Cloud apps and identities (because of the shift to cloud services) now give attackers the same result as old-style attacks without them having to try and breach a network perimeter via the endpoint.

The Security Gap in Identity Management 

Despite advances in cybersecurity, it’s clear to see why many businesses are now vulnerable to identity-based attacks. Traditional security measures like endpoint detection and response (EDR) systems and firewalls, for example, are less effective in a cloud-centric world where applications are accessed primarily through web browsers. This gap is exacerbated by the reactive nature of many security strategies, which focus on mitigating threats after they have been detected rather than preventing them proactively.

What Does This Mean for Your Business? 

For UK businesses, their move to the cloud and the usage of a wide range and complicated combination of SaaS apps, digital identities, and the interconnection and decentralisation of these have meant that they are now vulnerable to networkless attack techniques, perhaps without realising it until now. The shift to cloud computing has not only expanded the attack surface but also highlighted the inadequacies of traditional security models in protecting digital identities. This means that UK businesses must now take a much closer look at the security of these identities as part of their overall cybersecurity strategy.

To mitigate the risks associated with networkless attacks, businesses should perhaps consider adopting a zero-trust security model, which assumes that threats could be internal or external and verifies each identity and device continuously, regardless of their location. Additionally, enhancing visibility across all cloud services and implementing advanced security measures like multi-factor authentication (MFA), behavioral analytics, and more sophisticated identity and access management (IAM) solutions could help.

In short, as these networkless attacks continue to evolve, UK businesses must be proactive with security, stay vigilant and adapt their security strategies. By understanding the vulnerabilities associated with digital identities and cloud services, and implementing security measures accordingly, businesses can safeguard their assets in the cloud era.

Security Stop Press : ConnectWise LockBit Alert

Just days after it was announced that the UK’s National Crime Agency (NCA), the FBI, and Europol had taken down the Russian LockBit ransomware gang’s website, it’s been reported that LockBit ransomware is still being deployed via flaws in a popular remote access tool.

Researchers at cybersecurity companies Huntress and Sophos have highlighted how two bugs in the ConnectWise ScreenConnect remote access IT support tool, usually used by IT technicians, are being exploited to launch LockBit attacks.

ConnectWise has issued an alert urging IT administrators to take quick action to patch the two critical vulnerabilities. Details are available here.

Security Stop Press : Google Launches AI Cyber Defence Initiative

In a bid to “tilt the cybersecurity balance from attackers to cyber defenders,” Google has announced the launch of its AI Cyber Defence Initiative. The initiative involves the introduction of:

– Secure AI Framework (SAIF) – a conceptual framework for secure AI systems, to help collaboratively secure AI technology.

– $2 million in research grants and strategic partnerships to help strengthen cybersecurity research initiatives using AI.

– An open sourced, in-house machine-learning-powered file identifier called Magika, which can help network identifiers to quickly identify (and at scale) the true content of files.

Google says it’s “excited about AI’s potential to solve generational security challenges while bringing us close to the safe, secure and trusted digital world we deserve.”

Tech News : Cyber Attacks Burn Out Security Experts

A new survey from CyberArk has revealed that increased workloads caused by a surge in cyber threats and attacks has led to 59 per cent of UK senior cyber security professionals facing burnout.

Cyber Crime Levels High 

The results of the survey highlight the growing workload pressure on cyber security professionals because in just the past 12 months alone, a staggering 80 per cent of UK organisations have experienced a ransomware attack, a 10 per cent increase on last year. Also, almost half of those affected (47 per cent) have opted to pay the ransom (at least twice) to enable recovery.

Workload And Other Challenges 

In order to protect businesses from growing threat levels, cyber security teams have, therefore, been required to work long hours whilst facing the challenges caused by the limited budgets and resources that are the result of economic pressures, as well as the challenges of a skills gap and global shortage of cybersecurity professionals. For example, a recent ISC2 report shows that there was a 3.4 million global shortage of cyber security professionals last year, compared with a total cyber workforce of 4.7 million.

Other Supporting Research 

Other research that supports the plight of under-pressure cyber security workers includes a Chartered Institute of Information Security (CIISec) survey that found almost a quarter of security practitioners work more than 48 hours per week, and Gartner research (2023) highlighting how high levels of stress could see nearly half of security leaders switching careers by 2025.

Taking A Break Or Leaving The Profession 

Consequently, even though cyber security professionals need to be performing at their absolute best, instead they are experiencing burnout (according to the CyberArk survey), and are choosing to either take a break from work to concentrate on their wellbeing or leaving the professions, thereby adding to the lack of security professionals in businesses, increasing the vulnerability of those businesses to cyber-attacks.

More Than Two-Thirds Of Senior Decision Makers Affected

CyberArk’s survey shows, for example, that 66 per cent of C-level executives (senior cyber defence decision makers in businesses) feel that they are experiencing burnout, which raises concerns about their ability to deal with the increasing and evolving threats effectively.

For example, as David Higgins, senior director, of the field technology office at CyberArk puts it: “Burnout is alarming in that context, because it impairs the ability to defend their organisation. One wrong decision or missed signal can open the door to reputational and monetary damage for an organisation.” 

What Does This Mean For Your Business? 

The findings from CyberArk paint a stark picture for UK businesses, showing the front-line against cybercrime is wearing thin. The apparent burnout epidemic among cybersecurity professionals is not only a health crisis but a strategic business vulnerability. When these specialists are overworked and stressed, their capacity to guard against cyber threats is compromised, and as a result, the risk to business operations, sensitive data, and company finances escalates.

UK companies should, therefore, take immediate steps to prioritise the well-being of their security teams. This means cultivating an environment where work-life balance is possible and supported by management. It also includes re-evaluating workloads to ensure they are sustainable and providing access to mental health resources. These measures may help in maintaining a vigilant and capable cybersecurity workforce.

Equally critical is addressing the shortage of cybersecurity professionals through targeted talent development and diversified recruitment strategies. Training programs and professional development opportunities can be powerful incentives for both recruitment and retention, and recruits that can grow with the company.

C-level executives (cyber security decision-makers) experiencing burnout themselves need to set the right tone for the organisation’s work culture, for example by openly acknowledging the issue and advocating for sufficient resources. This could (in some measure) help bring the change that reinforces the company’s defence against cyber threats.

Preventing cybersecurity burnout, therefore, is more than a human resources issue and is an essential investment in a business’s operational security. As cyber threats increase, it is clear that protecting the protectors through a compassionate and comprehensive approach to workforce management is not just beneficial but necessary for sustaining business integrity in the digital age.

Security Stop Press : Booking.com Customers Targeted By Phishing Emails

It’s been reported that following a hack of online travel agency Booking.com’s email system, customers have been receiving phishing emails asking for their bank card details to avoid cancellation of their hotel booking.

The emails, which have been reported to come from a standard booking.com email address, appear to be targeting customers who have checked-in or are due to check in, and although they vary slightly in content, give customers a limited time (4 to 12 hours) to provide their card details following the fraudulent payment request.

It’s been reported that booking.com denies having its email hacked and blames the breach on partner hotels’ email systems being hacked following phishing attacks. The advice for those who have received the emails and are suspicious is to contact Booking.com’s customer service team, contact the hotel directly, or if payment has been made, to contact their bank.