A Zero Trust Leadership Podcast

Title: Hackers Don't Break In. They Log In. | Keren Elazari
Cybersecurity researcher and TED speaker Keren Elazari joins to explore why identity, visibility, and containment matter more than ever in an AI-driven threat landscape.
Transcript
Raghu Nandakumara 0:10
Welcome, everyone, and thanks for joining us. I'm Raghu Nandakumara, VP of Industry Strategy at Illumio, and I'm excited to be joined today by cybersecurity researcher, TED speaker, and friendly hacker Keren Elizari. Keren, welcome.
Keren Elazari 0:26
Hi, Raghu. Thanks for having me on your show. It's very exciting to be here. Can't wait to jump in. Yeah,
Raghu Nandakumara 0:34
It's awesome to have you here. I mean, I've just literally just finished watching your TED talk, which I highly recommend. They're going to be in the notes, so go and check that out. Well, it seems like every cybersecurity conversation today starts with AI.
Keren Elazari 0:45
Yeah.
Raghu Nandakumara 0:45
But while the technology is evolving rapidly, today's most successful attacks still rely on familiar weaknesses. As Keren often says, hackers don't always break in; they log in.
Keren Elazari 0:55
Yeah, we log in. It's true.
Raghu Nandakumara 0:57
I love the way you say that. So you're going to have to say that line at some point today. So today we're going to cut through the hype and talk about what attackers actually exploit, why strong security foundations matter more than ever, and where AI can and can't make a difference. So Keren, how are you doing today?
Keren Elazari 1:17
I'm doing great. Excited to jump right into these topics, and you know, I was looking through my closet for a T-shirt because I literally have a T-shirt that says, "Hackers, we don't we don't break in, we log in. This is really a thing. It's a T-shirt that I have. But in all honesty, when I say this and when we talk about that, it's not just you know hyperbola. The Verizon average incident report. I don't know if you're familiar. Many people might be familiar with that. It's a great database for actual incidents that happened that Verizon came in and helped research, and they do this report every year. And every year, including the last couple of years with the advent of AI, we still see that credential misuse, credential theft, pass passwords that have been recycled, passwords that have been stolen are still such a major initial attack vector. And when we look specifically at web apps, and that means attacks on anything that's web facing, it's over 80% that is the type of attack that is being used. So it's not fancy new exploits taking advantage of zero-day vulnerabilities that some yet unnamed AI model have just found. It's really the classics, and this is what's happening industry wide globally. And yet all the conversations are about the new capabilities of the. Have we reached Odyssey class yet? I don't know. I guess that's coming soon, right? With the movie, everybody's talking about the Odyssey. So from Fable to Mythos to Odyssey, we might be getting there too. And I think that's really a major distraction, honestly,
Raghu Nandakumara 3:03
in the cybersecurity conversation. Yes, AI has accelerated timelines for so many of what are the fundamental things we're working with, but that's exactly it. It accelerated. It shared the spotlight on all of these fundamentals that have been broken. Some of them have been broken, or let's say misaligned for quite a few years. So that's a major hard truth, I think, for everybody to deal with. I completely agree because I think when the news, whether it was Anthropic's mythos announcement or the news that has come after it, right? Because like pretty much we're accepting that every frontier AI model has these capabilities or exceeds them, and the Odyssey thing is that that that was a funny comment because we were just talking about when to go and see Odyssey over the next two weeks. But and I think that I think you're absolutely right. I think a lot of the over focus and hype has been around. Oh my God, it's going to find all these new vulnerabilities, right? Or even okay, hey, well, we know we've had a ton of vulnerabilities out there that have kind of been lying dormant. It's going to generate patches, and I've been going, yeah, I mean that's true, right? But if you put yourself in the shoes of the attacker, those things, whether it's discovering new vulnerabilities or creating an exploit, you're going to burn through tokens doing that, and the attack is like, I don't want to do that. There's already a ton of existing vulnerabilities with known exploits, and guess what? Now I can just say go, right? And that's the power that AI gives.
Keren Elazari 4:35
Exactly, and you know one of the key data sources that again I don't think people are looking at enough. Is something called the Kev, the Kev. That's the known exploited vulnerabilities, and it's a database maintained by CISA, by United States Security Agency, and it's basically a database of the known attacks, known exploits against vulnerabilities, and at this time. As I know, we have under 30% of those vulnerabilities patched. So there's no need for fancy new zero days, new exploits. And yes, it's true. Frontier AI models are finding vulnerabilities, and they're doing it faster. Are they mitigating against these vulnerabilities at that same speed, not yet, because it turns out models are really good at finding vulnerabilities and even crafting exploits, but they're not necessarily as good at patching those vulnerabilities. And specifically, there is not yet a solution to bringing those patches to production environments in all of the myriad different nuanced environments with all of their variants and their curious, you know, little things that are different. And let's just go even one level deeper. Let's talk about something that I focus a lot in my work, which is identity and authentication. So I don't know if there is currently an AI solution to the fact that for so many organizations, basic multi-factor authentication isn't fully rolled out yet. Last I checked, and I tried to look at some statistics, for a lot of companies they're still really not at full multi-factor authentication, or they're still relying on very, in my humble opinion, okay, let's be honest, seldom humble opinion. In my opinion, outdated modes of authentication. Passwords belong in our past. They are no longer a sufficient means of identity verification, and you know the Shiny Hunters campaigns from the last year. For those unfamiliar, Shiny Hunters is the latest super group of young Gen Z hackers, cyber criminals came out of the previous organizations or affiliated very loosely with some of those groups like Lapsis and the one that people have been calling scattered spider. So now it's shiny hunters, but it's kind of all part of something that the FBI calls the com, which is short for the community. And in their playbook is calling up the help desk of an organization, impersonating as an employee, typically an employee that would have access to a super administrator account and getting the help desk to reset that access. Now in the last year, shiny hunters basically evolved that tactic, and what they're doing is now they're impersonating the help desk and they're calling people, initiating SSO sign-ins and password resets, and they're grabbing the credentials, and they were pretty sophisticated, but not because of AI. They were pretty sophisticated in the social engineering, in the pretexting, even in the taking over of phone numbers, something called SIM swapping. So that's a practice that those groups have gotten really good at. Last year, Shiny Hunters also brought in the AI, but not so much for the big new exploit development. More around the lines of using deep fake voice generators. So that's kind of like Mission Impossible level or Oceans 13, if you will. But these cyber criminals and many of the other more garden-variety cyber criminals, they are extremely innovative and creative in how they can use what they already have. They love using things they already have, and they're sitting on databases of usernames and passwords. They're sitting on internal access. It's not about AI, really. I think the AI conversation misses the point completely if we just focus on that. And I'll be the first to admit we all should be using AI in some way to enhance our productivity. Yes, to improve our security posture. Absolutely, it's part of our ecosystem. It's part of our world. I'm not. I'm not a luddite. I'm not going back, you know, to raising a flock of sheep in the woods. Although that seems like a very fun afternoon for some people, but yes, we are supposed to use AI, and I encourage for that.
Keren Elazari 9:13
I advocate for people to learn how to work hand in hand with AI tools, but we can't just sit back and say, "Yeah, yeah, it's going to it's going to fix everything, and we'll just sprinkle some LLM powder, and that's going to find all of our vulnerabilities and patch them for us, and prioritize which vulnerabilities we're going to patch first, because those problems are there. It's the it's the security depth or the technical depth of the last 20 years of using passwords, of unpatched vulnerabilities, of identity sprawl, of unsegmented networks, and in so many cases we see once attackers are in, lateral movement is easy, it's undetected.
Raghu Nandakumara 9:58
Yep.
Keren Elazari 9:58
So these are the. Hard truths, and I think to be honest, I could do with a little bit security ABCs before we talk about security AI.
Raghu Nandakumara 10:08
I love that. So, so we're going to like you've covered. I think you've sort of touched on a lot of the things that we're going to just dig deeper into in the rest of the conversation. Yeah. So I'm glad you set it up like that. So let's go back to something that you said about AI, right? And as we've kind of already touched on, there's been all this news around vulnerability discovery, exploit creation, etc. etc. But I think a really important point you made was that there is all of this kind of urgency around, right? On the defender side, we must adopt AI. But as you said, and actually one of the recommendations that we're seeing from pretty much every organization, government body, regulatory organization, etc. is oh right, one of the things that organizations should be doing is patching faster, right? Using AI to automate patching, etc. But as you said, right, AI at the moment is not great at generating the patches. So, what we're seeing here is this incredible asymmetry developing between attacker capabilities and defensive response. So, how do we collapse that gap? Because otherwise, that gap is just going to get wider and wider, and we're going to be in a really difficult place.
Keren Elazari 11:24
Yeah. So one way I like to look at it, and this is maybe one positive way to look at AI in this case, AI is like a time machine. It's a time machine for attackers because it allows them to do things that used to take them weeks or months. Now they can do that in days or hours. It should also serve as something like that for us for our timelines when we look at mitigation, when we look at vulnerability patching, and there is a reason. There is a really you know deep mathematical, theoretical, hard coded reason for why LLMs right now are better at finding vulnerabilities and creating exploits than they are at patching it because they it's very very difficult to train them on that how to patch the code how to make the code more secure but it's actually easier for them to find vulnerabilities because the model can very easily also check if the vulnerability is exploitable, so there's a really clear way for the model to understand, and there it reinforces itself. Now this is kind of maybe deeper machine learning stuff, but we have to get better at how we use AI and the capabilities that we already have to, like you said, collapse that gap, shorten those timelines to mitigation to breach containment, and there are different ways to do that. So I think again, identity sprawl is such a. I'm not going to call it an easy fix. There is a reason that there are so many credential reuse, password reuse, identity sprawl. Picking identity and authentication is boring. It's not sexy. It doesn't get you like a keynote slot at RSA conference. It's not exciting. It's not the new frontier model thing. But it actually stops the largest single initial attack vector from the breaches that have been reported and investigated, so that's one thing that could already reduce the attacker's success ratio significantly. So those are the areas where I think we really need to focus. And well, I've got more ideas, but I'll hand it back to you.
Raghu Nandakumara 13:38
I want to hear more about your ideas, right? So before we kind of move on to identity and other fundamentals, right? Let's leave the AI topic at least for a short while. But what I want you to do is essentially I want to address this first hard truth, right? What is the hard truth about AI in cybersecurity?
Keren Elazari 14:00
I think you just described it yourself, and we've been talking about this for the past 10 minutes. Is that AI is really handing attackers some advantages, but it's not necessarily giving defenders the advantages in a symmetrical way. In fact, the asymmetry is only widening. So this is a hard truth, and we can't just say AI is going to fix it. We can't just sprinkle AI magical LLM powder on everything, and that's going to fix all of our fundamental security problems. So, from my point of view, is that AI? Yes, it accelerates attackers. It exposes the fundamental security depth, fundamental security problems that we have not addressed in years, and it's not yet really giving defenders the advantage or the means to close that gap, and the gap is widening. So that's a lot of hard truths. It's kind of, you know, it's not easy. And again, I do have some ideas, and I do have some causes for optimism. I think there are great conversations to be had about how we can use AI to help defenders. How we can also really enrich our humans. So let's let the humans in our teams use their time more wisely. Let's invest not just money in the next shiny new AI product, but also time and attention in how are we as humans co-working with AI in a security. What's our new security paradigm for this AI age, and it's you know it's this is one of the things that we're coming up on DEF CON season, the Hacker Summer Camp, Black Hat, DEF CON B Sides, and I'm talking to people, and some people are saying we don't have the budget to send people out to a conference, and when I compare that with the budgets that are being spent on AI solutions, I think there's some short-sightedness there. I think we do need to invest in our humans, invest the time. You know, if you're a manager, give them five days out of the calendar and go immerse them in hacker culture in the red team village in the AI adversary village, let them see how people are using AI tools as attackers, so that they can bring that mindset in. That's an investment. It's not like a holiday, right? That's my point of view. And
Raghu Nandakumara 16:34
more than anything, right? Come and hang out with you and me, right? At Black Hat and DEF CON that week, okay.
Keren Elazari 16:41
With 30,000 of our hacker friends. Yeah. Exactly.
Raghu Nandakumara 16:46
Exactly. So before we get into how we address this and how we fix this, right? Let's go to essentially your job, right? You're a hacker. You're a friend. You're a friendly hacker. A friendly hacker. Talk us through because you touched on it when you when you kind of quoted the Verizon DBIR and sort of the initial how attackers gain initial access. So just walk us through very briefly end to end, right? Just the typical play a hacker executes.
Keren Elazari 17:16
So if I'm on a red team engagement where I'm allowed and given liberty to hack my way into an organization, I'm not necessarily going to try to develop a custom exploit and attack the organization with a new attack that the AI tool just created for me.
Raghu Nandakumara 17:35
Can I pause you? I just want to pause you there. Yeah. Why? Why?
Keren Elazari 17:40
Because it's a waste of resources, it's a waste of money, tokens, and time. And typically, what we spend a lot of our time on, and this has been the case for years, is the reconnaissance, reconnaissance. And in the reconnaissance phase, AI is helpful, but then I still have to execute the approach. And what I'm looking for is access. The easiest access in ideally someone's credentials, a legitimate employee's access because that's the best type of access I can use. It gets under the radar. The sim doesn't blink. You know, sometimes for me in my engagements, it might also mean physically sneaking in or tailgating or just smiling and waving my way into an organization, and that has worked more times than I can count, much more than a fancy new attack. So a lot of times, what attackers will spend their time on is the reconnaissance phase, and then figuring out, okay, what is my most efficient, least effort way to get in, and only after I have exhausted maybe three of the low effort ways to get in, which would typically mean using credentials, using access through social engineering, phishing, attacking the human element. Only then I might go into the more let's exploit some public-facing system. Let's try and really get our way in from there because that's also the more highly detectable attack. So it's not a preferred method of operation, at least not from my perspective in the red team engagement.
Raghu Nandakumara 19:19
I'd like to just pull. Sorry, sorry to interrupt because I just want to interrupt wherever I think that there's something more that I want to understand. So let's just so let's just take that point where you say you've got maybe three or four approaches which are kind of under the radar, right? And if those don't work, you've then got a choice about do I have to attempt, let's say, leveraging finding a vulnerability and exploiting it is that at that point when you're making that decision, is it a decision between proceed or walk away, or is it yeah I'm still going to proceed? I just need to decide which of these more expensive ways I'm going to do. Like you decide I could walk away.
Keren Elazari 19:56
So when it's a red team engagement, I will proceed because. That's what I'm hired to do, right? But and typically, what we're seeing now with a lot of real world cybercrime, in the past it used to be that if it's a little bit extra more challenge, maybe they move on to the next victim. When it's a garden variety type attack, when it's kind of like a spray and pray type of attack, where they're just trying to get as many info stealers into organizations as they can, but now the last couple of years have shown us that there are actually highly motivated attackers, not just advanced persistent threats, not just nation state attackers, but also very highly motivated cybercriminal groups, and they are motivated, and they will make the extra effort, and they are incredibly creative and innovative in how they use all of the tools in their arsenal. And another thing that we know, and we've seen this again from the postmortems, from the incident reports, the attackers seem to know their way inside an organization sometimes better than their victims. So if they know your network, if they can enumerate all of your assets, if they can easily access different systems that maybe you know central HQ forgot about or left behind or left unpatched for a couple of years because it wasn't a priority project, but the attackers, they'll find it. So you'll think you can think about them kind of like really savvy smugglers, and they know which post on the border control is maybe a little not very highly staffed on a Friday afternoon, and they'll know where the fence says it's electric, but it actually really doesn't work. They have all of these different know-how and skills, and you know, by the way, that's something that would be very difficult to train an AI on. Where the AI comes in, and this is where we see the elite attack groups, like the state-sponsored attacks, like GTG 1002, what a catchy name, right? So that's the attack.
Raghu Nandakumara 22:06
Rolls off the tongue. Rolls off the tongue.
Keren Elazari 22:09
It really does. So that's the attack. For those unfamiliar, that Anthropic wrote a report about late 2025. I think it was November 2025. That they discovered a nation-state attacker basically role played and convinced mod code to be its accomplice in an orchestrated cyberattack against different organizations. So that's where we see the sophistication come in. It's not necessarily in the write me a custom exploit. It's more the very deliberate use of AI agents for the orchestration, and for you know, I don't know all the full details because not a lot has been published about the victim organizations that were targeted in that particular incident. But in many of those cases, I'm willing to bet that it was access, it was credentials, it was some way in that would have been covered by basic security fundamentals. So the agent, the AI orchestrator, basically helped the attackers compress their timeline and achieve their target, achieve or probably get into the systems faster than they would have if they took their sweet time doing it over some weeks or months. So that's the time machine element, and we sure do need to learn how to use that in the defensive side. And we're just not there yet. We're not seeing, you know, the rate of discovery of new vulnerabilities. Yes, that's great, but it's not matching the rate of patching and mitigation, and that's the problem that I think is a very hard truth that we need to deal with.
Raghu Nandakumara 23:50
So, as a like in red team exercises, as a hacker, what's typically the more difficult phase of the attack? Is it the initial intrusion and establishing that entry point into the target environment, or is it what happens after initial intrusion? Right. Which of these is typically the more resource intensive, the more challenging, and maybe sophisticated?
Keren Elazari 24:16
Yeah. So there's a theory for this. Some of you might know it. Lockheed Martin came up with it maybe 20 years ago, called the cyberattack kill chain. And in the kill chain, typically, classically, a big chunk of time would have been spent on reconnaissance, and then maybe on tool development. So that would be the custom exploits, the tooling, finding the right mechanisms for the job, and then there would be some lateral movement enumerating inside the target systems, trying to figure out where the assets that I'm most interested are, and then there's exfiltration. And typically, and if it's a recurring kind of scenario where you want to get back, then you also have. To set up some remote access, some CNC infrastructure, so that you might, as an attacker, come back to that same system over time and utilize it again and again. That theory still holds in the sense that all of those phases are still required, but they don't take nearly as much time as to you as they used to. So reconnaissance used to be very resource heavy. Now it's a lot shorter. Tool development a little bit resource heavy. Now that's shortened. I think lateral movement is still a part where the human hacker needs to kind of invest some of their attention in the prioritization. Which target am I going to go after is this asset truly valuable or not? A machine, an LLM might not know the difference between you know a lot of big Excel files with a lot of data in them and something that a hacker would know to be valuable. If it's whether it's financial information or different types of data that can be traded, that's something where a human still needs to put their attention. So that's still the case, I think. Exfiltration also not an easy phase where you want to get the data out. And typically, I think at least in the last couple of years, typically that's where we see also some of the detection happening, which is kind of after the fact, and to be honest, I think attackers are now also spending quite some time on monetization. So we do have this kind of phenomena in the cybercrime world where they are cultivating access. They're getting into an organization, and once they're in, they're thinking, "Okay, how can I make money out of this? Am I going to sell this as an initial access broker to another attack group? Am I going to partner with maybe a ransomware as a service brand because they are brands, ransomware as a service campaigns, right? It's absolutely a branded world. So we saw this in the last couple of years, like with Alpha V and LockBit and all of these big names, Killian, there's quite a few. So they have to decide how they're going to monetize the access, and that's again, I think, still a human activity, not really an AI activity. So it's a it's a wild world out there.
Raghu Nandakumara 27:19
So just to wrap this section before we go on to how we how we address this. So, what's like the second hard truth, right? What's the hard truth about how hackers actually get in?
Keren Elazari 27:32
That it's not that hard. That it's easier. That it's access. It's logging in. It's not breaking in. It's not cracking. It's most in so many cases it's logging in with stolen credentials, with stolen tokens, with cookies or other forms of identity. Sometimes it's like more complicated. It's not a password, but in so many cases it's logging in, and in so many cases, the attackers will know the organization, the network, the environment better than the defenders, or better than some of the defenders, because especially when it's a company that is a multinational company that has different deployments, different locations, different data centers, different digital assets, just visibility and understanding what is happening there is sometimes difficult when it's when people are trying to do that from the defender side. But you can't defend what you can't see, right? Yeah. And if attackers are able to enumerate your digital assets and to get a really clear picture, and they often do, and they get that faster than you do. Then the defenders are going to start from a disadvantage initially, you know, because of how that works. Because the bad guys seem to know their way better than the defenders.
Raghu Nandakumara 28:57
So I think that's a great part to sort of move on to the next part of our conversation, and you've mentioned this a couple of times about how attackers enumerate their target environment and often have a much better understanding of what exists in the target environment, and also how those things are interconnected and interlinked, right? And they leverage that, of course, to sort of map out their next steps. Now, what you just described sounds like something so fundamental, and if it's easy enough for an attacker to build that with a lack of a priori knowledge about the target environment, why is it that a large number of organizations still fail to have a good understanding of what they have in their environment and how those things interact?
Keren Elazari 29:51
Wow, it's very big philosophical fundamental questions. Let's have a go.
Raghu Nandakumara 29:56
Let's have a go.
Keren Elazari 29:56
Yeah, let's have a go at it. So first of all, even the most. Well-intentioned, mature, sophisticated security leaders still have to deal with the reality of doing business. Right, the business that they're securing is not a cybersecurity operation. It's a bank, or it's a retailer, it's a pharmaceutical, or it's a fashion brand, whatever it is. And the work needs to be done. The security can't just be saying no and shutting everything down. There's business that needs to be enabled, so that reality creates gaps and it creates shadow IT usage, shadow AI usage, where people across the organization are just using whatever systems and technologies are helpful for them to conduct their business because they're a company, they're a business. They're not in the business of return on security investment. They're in the business of return on investment. Right? There's no way to show return on security investment. It's very difficult to show return on security investment because you have to show what you've prevented. You have to show the catastrophic losses that you've prevented, and so this is the reality that defenders don't defend hygienic environment in the you know some philosophical realm. They defend the business, and the business has to do payroll and procurement, and there's external vendors, and there's different tools for productivity that people have to use, and that creates a lot of the gaps and a lot of the gaps in the visibility. How many cases we've seen and we've heard where the initial attack began because of a third-party software provider or a connectivity solution or an API that was misconfigured? So it's not necessarily very super sophisticated attacks that will take advantage of these gaps. It's more the understanding, and I'll even say the confidence that attackers have that they know that there will be a gap, that they will find it. Because if the organization is out there in the world doing business, it's not in some philosophical make-believe world where everything is disconnected and everything is knocked down. They will find a way.
Raghu Nandakumara 32:08
So you've said this, right? Is this the little jingle that you had? Is that attackers don't break in, they log in. That the fact is that they will find a way, and as you said just now, right? They know that certain things will not have been addressed, right? There is a confidence that once they get in, they will find something that they can leverage, right? Exactly. If
Keren Elazari 32:28
You remember the you remember the exploit Eternal Blue, there is a reason for the name. The people who named it Eternal Blue knew that it's going to still be unpatched, and for so many years, it allowed attackers to get in. It was, I believe, in the S and P Microsoft product. But I'll give you another example for outside visibility into an organization. Tools like Shodan and Censis have existed for years, and yet I still meet and I still see companies and organizations that have never used something like that to look at their own environment from the outside perspective. So there is a lot of maybe groupthink or an internal belief that attackers are not looking at us, where in fact attackers can very easily look at you, especially if they have automated tools, I'm not talking about AI. I'm talking about basic automated tools for scanning and enumeration that have served hackers like me for years. And yet, I see that people don't employ the same techniques. So that's one of the things I'm advocating for. We can't afford not to bring that attacker mindset, not to try and sometimes you know spend some time learning on how these tools work and look at how our organization might look like if an attacker is scanning us. Now the AI actually plays into this with the shadow AI deployments. So shadow AI is when people are bringing in or using AI services inside the organizational network, but it's unbeknown to the defenders. It's not approved. It's not part of the security policy. It's not monitored. And we saw this really six months ago with OpenClaw, also known as Cloud Bots, if you remember, which really exploded in usage. And really, within a month, there were hundreds and 1000s of local installations, local machines running OpenClaw, and OpenClaw's basic out-of-the-box configuration is to only listen on 1.7001, which is a local machine. But a lot of people who installed it didn't know that 127 001 is local machine, so they changed it to listen on 0000, which means all ports listening to all ports externally, and a lot of people really innocently they wanted to be innovative. They wanted to bring an AI tool. He said, "I'm going to only install it locally. There's no issues. It's safer than you know messing around with something in the cloud. Where in fact they basically created an entry point. A very in fact, I just did a scan on this a couple of weeks ago. Still, there are 1000s of 1000s of open claw cloud bot installations that are still listening on all boards, and this is just because of an innocent misunderstanding. Maybe a wish to be innovative with this new AI tool, and you know it was very trendy when it first came out. If you remember, there was this whole conversation about Mortbook and how the different robots are talking to each other. It was very trendy, and this is part of the thing. It's another hard truth with AI. It is super easy to go after the next new shiny thing, the new model, the new thing. Wow! Let's put it on. It's sparkling. It's new. It's shiny. Security fundamentals. Don't configure it to listen on all ports. And that's something that you know because AI is so trendy, it's a basic thing that people will miss.
Raghu Nandakumara 36:08
Absolutely, and you made this point about you. I think you referred to it as groupthink, and I think another sort of relevance of sort of groupthink is where we see is that organizations have investments in? I think what is it? I think on average most enterprises have somewhere between 50 and 60 cybersecurity tools in their suite in their stack. And then there is the assumption that well, if I have tools, I have all the necessary coverage, right? But what they're not doing is going back to what you said is taking a very essentially an attacker mindset to how like how would an attacker go through their environment right what would an actual attack look like and then map out the tools to the actual sort of whether detection or prevention that they are actually able to achieve, because I think that would then show that actually they may have 5060, tools, but if you lay it out against whether it's the Lockheed Martin kill chain or the MITRE attack framework, actually what they have doesn't cover an end to end, right? And there's and the attacker still has a path. Is that what you see?
Keren Elazari 37:20
It's what I see, and it's also what I hear. You know, there are so many organizations where I speak to. I might speak to leadership, and they'll you know they will seem and they will look like they're super mature and sophisticated in their security posture. And in fact, they are. You know, if you look at the benchmarks, if you look at all the tools that they're using, all of the activities that they're engaged in, but I bet, and I've seen this happen so many times, I can find somebody who works in that company who, over a cup of coffee, will tell me, "Yeah, all of those tools are really nice and fancy, but they completely don't cover this system over there that's been run by Mikey because that's like his system. It's a different department, or they don't cover this thing that we spun up in the cloud somewhere, or there's all this new AI that's a different department that's uncovered. I've seen this happen in so many cases. So having a ton of tools, and we have unfortunately seen this again, also from the Verizon DBIR report, but also from so many other postmortems. Having a ton of security tools does not necessarily mean you're going to be immune to attacks. In fact, I think a hard truth is that for a lot of organizations, assuming that an attack is taking place, have taken place, and then learning to look for that, to threat hunt for that, and to stop it, that is the sophisticated move. Yeah, and that is something I'm seeing, but not in all of the organizations. You know, that's something that more people should be doing. I think.
Raghu Nandakumara 39:01
Yeah, absolutely. So, so let's go to our third hard truth because I think we've kind of touched on bits and pieces. So, what's the hard truth about the ABCs of security?
Keren Elazari 39:10
Okay, so first of all, AI is not in the ABCs of security, in my point of view, and I I really have been thinking a lot about this, and I want to offer my ABCs, but before I before I offer what they are, I think the hard truth is, is that the fundamentals of cybersecurity are not sparkling, sexy, trendy, new thing, latest thing, get you on all the podcasts thing. The fundamentals of cybersecurity. When I when I learned this profession many years ago, many moons passed in a you know in a galaxy far far away. We used to talk about the CIA triad. I don't know if you remember that confidentiality, integrity, and availability. And that's you know. As soon as I said that, it's okay. It's boring. Oh, it's basic integrity, availability. You know, it's not super sophisticated prevention of APTs and the new anthropic model or the new ChatGPT model. So I want to offer these new ABCs. Let me know if you like them or not. It's not ABC actually; it's IVC because I couldn't figure out the acronym. So, identity, visibility, and containment. We talked about all of these things today. Identity, such a big part of fundamental security posture that needs to be solved, that isn't solved, that is still stuck in 20th century thinking with passwords, identity. It's a big, big fix. Can remove at least 20% of initial attack vectors from the data we've seen. Visibility. We talked about this as well. If attackers can know your network, enumerate your network, scan your network, know about the different assets that you don't even know that you have. You have a problem, so you need visibility. You need to invest in the capabilities, whether they are AI driven or human driven, that give you better visibility over your digital footprint. And the last one is containment, and we didn't talk a lot about that because for me as a hacker, I don't want to be contained, right? It's something I want to avoid containment. But that's where that's where an attack stops short. If if lateral movement isn't easy, if networks are segmented, if you get in and then you can only get into that one system and you can't easily hop your way to different systems, that's when attack gets stopped. That's containment, and when we say that people need to be assuming that a breach has happened or looking for what that might look like, threat hunting, it also means how can we contain it. So I often talk about proactive paranoia. In our industry, we talk about fear, right? The biggest thing, the biggest gift I got from the hacker community is learning how to be paranoid without being afraid, and it's an art. But here's the difference for Google. Okay, bear with me. When you're afraid, fear paralyzes you. Fear is something that you know you can do fight or flight or freeze. You don't necessarily respond well. Being proactively paranoid means preparing for these things to happen. So it's like doing fire drills. I I recently went on a camping trip, right, and I heard the saying, "You don't need to wait for the rain to build the tent, and that makes perfect sense to me, right? Now, granted, we're all going to be camping in Las Vegas, where you don't need so many tents, hopefully. But in our cybersecurity world, that's containment. You don't wait for the rain. You set up systems that are going to stop the attack when it transpires, when it happens, and that can take shape in different ways. It could be microsegmentation, it could be hyperverterization, it could be hardening different systems, it can be rethinking your network architecture. There are many ways to play that, but if you haven't spent enough time thinking about that, that's security ABCs, in my seldom humble opinion.
Raghu Nandakumara 43:24
All opinions don't need to be humble, particularly when they're right. So, okay, I I love the way that you framed that, right? As the ABCs, or I should say, IBCs.
Keren Elazari 43:32
Yeah, identity visibility containment, yeah.
Raghu Nandakumara 43:35
Identity visibility, containment. So now we all wish they were as easy as 123, right? However, we hear right often that oh, I can't invest in visibility because I like getting that coverage. It's too challenging, right? I can't invest in containment because that's as but that's burdensome. It's potentially intrusive. It's going to take a long time, right? I can't go and address identity sprawl because just too many systems and too many different sources of identity. So we hear a lot of pushback for reasons why organizations haven't done more of this.
Keren Elazari 44:13
Yeah.
Raghu Nandakumara 44:14
Now you tell me whether that pushback is reasonable or is this just organizations failing to prioritize the things that are most important?
Keren Elazari 44:27
So yes, both of the things you said are true. First of all, it's human nature doing these things is boring. It's time-consuming. It's not glamorous. It's not let's deal with this sexy new technology. Let's roll out some new deployment. It's let's go back and see all of our basically see in the mirror meet all of the technical depth and the security issues that we let we left unattended for many years. So it's like it's like sorting out your attic, you know. It's something people are postponing. They're procrastinating. It's human nature. They don't want to do it. But also, yes, I think the second thing you said could be true here as well. There is some lack of foresight from the strategic view, from the top view, lack of prioritizing of these fundamentals. Because, and I think this is absolutely something that's happening, because people at the top want to talk about the trendy things. They want to talk about AI. They want to be leading the new next gen something project, and it's difficult to position visibility, identity, containment as next gen, new, trendy, sparkling, shiny-it's boring, and or I mean, people think it's boring, but hey, turns out for attackers, it's the goldmine, right? That's how that's how we make a living. That's how we get in. So that that is, I think, again another hard truth. There's a mismatch in the in the strategic thinking about these issues, and I hope some people listening today might kind of wake up tomorrow and drink a coffee and say, "Hey, how about we go have a look at all of those identities and credentials that we're using and see if we can tidy them up a little bit.
Raghu Nandakumara 46:19
Absolutely, it's kind of like just working out just for the summer versus right versus kind of like for to build sort of lot strength a long-term health and strength and resilience. Mass and
Keren Elazari 46:31
mask, yes.
Raghu Nandakumara 46:32
Yeah, yeah, yeah. Exactly. Okay, I want to ask you about a couple of things that you may have seen in the news over the last few weeks, right? That sort of just captured my attention recently. Firstly, there was this there was Jade Puffer, which was essentially this first. Well, maybe the first example of a outside research labs of a truly agentic ransomware. Right, it's got its own LLM. It's able to execute end to end with essentially no human in the loop. Right, and execute the entire attack chain. Like, what when you saw that? When you heard about it, what did you think?
Keren Elazari 47:04
Okay, so first of all, ransomware has been a pet project of mine in the last couple of years. So when I say that, is not to glamorize ransomware. The opposite. It's one perhaps one of the most successful forms of cybercrime in the last couple of years, in the sense of how much money it's made, and in the sense of how many criminals got into cybercrime because of the big headlines and the glamorous appeal of ransomware campaigns. For me, as a researcher, ransomware was a really good petri dish to look at innovation and creativity, and what I saw with ransomware operators is that there is a lot of creativity, a lot of innovation, not just in the technical side, but also in the business model side and the monetization side. So yes, people can come up with, you know, you can get an LLM to write ransomware for you, and there's, or you can do it all automatically with AI, but it's still going to meet this the crime side of cybercrime, where they still need to choose targets. There's monetization, there's money laundering, which is where a lot of the criminals actually were tracked down through blockchain transactions and things like that. So it doesn't automate the entire crime of ransomware, and I'm I wasn't really very surprised by it as well because I knew that ransomware is a highly competitive form of cybercrime, and it's also mind you, and we know this from leaks of inner communications of ransomware groups, where they invest back some of the proceeds into R and D. So when I say highly innovative, I don't not just mean a bunch of kids in hoodies coming up with clever ploys. Yes, ransomware campaigns, ransomware groups, ransomware operators took some of the proceeds, some of the money, and they put it back into R and D, in in some cases 30% back into R and D, which is an unprecedented number. You know, there are very very few companies, maybe pharmaceutical companies, I don't know, that spend that much of the revenue back into R and D.
Raghu Nandakumara 49:15
I was going to say that like an early stage startup probably has heavily weighted towards R and D, but as it matures, most of the most of the revenue goes into sales and marketing.
Keren Elazari 49:24
Yeah. So you say it's amazing. I agree with you. It's really fascinating as a researcher, which is why I spent a lot of time. I could I could probably write some you know five books on the innovation in the ransomware ecosystem, which is why I wasn't surprised with a phenomenon or an artifact like Jade Puffer, because ransomware does kind of cultivate a lot of criminal, a lot of cyber criminals are in that ecosystem, and they're coming up with different tools, different mechanisms, very creative at how they can be more efficient. They're still going to be the. Human side to the crime, and the human side is the targeting. The human side is the monetization. It's the money laundering. It's the crime, right? It's not just the technology, and that's I think not going to go away.
Raghu Nandakumara 50:14
Okay, so that that that was an example of essentially attackers leveraging AI as part of their toolset, so let's look at another example that that's been in the news. This came to my attention yesterday. Hugging Face. I don't know if you came across this, right? Of course. This I thought this I thought was really funny, right? Because yeah, they've got the attackers using like an autonomous AI agent. But what I thought was really funny here was that on the defender side, they're leveraging AI as part of their detection response, and the AI is flagging their own forensic capabilities as malicious and blocking it. Right? So you've got you've got your own AI thwarting your attempts to investigate, and I and I think that's kind of like a it feels like a case in point about how we can't just say, "Oh, AI and cyber is the answer.
Keren Elazari 51:04
Yeah, it's turtles all the way down, right? That's how I like to. At some point, so when we do use AI tools, automatic tools, and there's this concept in the security industry now, people are talking about LLM as judge, where you let one LLM come up with a set of results, and another LLM comes in as the judge to try and verify, critique, assess those results. But specifically with Hugging Face, what I want to say, and this is really crucial, we're what we're seeing play out with in platforms like Hugging Face or like the skill hubs for Open Claw or many of the other basically supply chain platforms where people are uploading libraries, modules, LLM components that anybody can download and use, and everybody is downloading and using. Naturally, we're seeing something play out, which happened with GitHub, and it happened with other repositories or platforms before. Attackers will go to the watering hole, right? They'll go to the place where all the developers and all the people are grabbing their skills. They're downloading their models there. And yes, the platforms have gotten better and better trying to detect this. And GitHub has said that in there's something called the GitHub advisory, where the last couple of months they said we've seen like a 5000 fold increase in the amount of potentially malicious stuff that people are uploading, and with Hugging Face they have their own system. And actually, for those interested, there was a really cool attack demonstrated actually by security researchers, not bad guys, called Nullify AI, where they use that same practice of nullifying the pickle checker. Fun fact: a pickle file is a type of Python markup file that's used as part of the validation of models and uploads in Hugging Face, and basically they create an attack that can nullify the detector's capability to identify malicious content. So this again is not a new practice; it's not a new phenomena. But with every new thing, like the advent of all of these open source tools, platforms, the information sharing economy around AI. Of course, attackers are there, and of course, they're taking advantage of a trusted watering hole, a trusted platform. That's one of their favorite. You know, it's one of my favorite techniques: is to basically upload a library or a piece of code that's got Trojan horse built in, that's got the remote access built in, or the backdoor built in, or some other malicious content. We're just seeing that play out in the supply chains of AI tools.
Raghu Nandakumara 53:55
It's like, hey, here's the code to turn off the EDR or bypass EDR detection, as an example, right?
Keren Elazari 53:59
Yeah, but of course, the sophistication is there, so it's not just it's not as simple as that. But ultimately, as security practitioners, it does kind of leave us with a lot of turtles. It's turtles all the way down, right? Yeah, we can't just keep AI lalamas judge, lalamas judge AI verifying everything. At some point, you have to reach ground truth.
Raghu Nandakumara 54:24
Yeah, absolutely. Okay, look, I think we're almost at time, right? So before we wrap, Keren, to you, right? What's one hard truth the cybersecurity industry still refuses to admit, and how do we go about addressing it?
Keren Elazari 54:40
Ooh, it's a big one. I'm going to give you a personal one, okay? I think it's still ultimately about humans, and it's about human defenders, and it's also about the humans in the loop and the human users. So many times we've heard in the security industry. That users, humans are the weakest chain in the security. You know, the weakest link in the security chain. I should say, how many times we've heard that saying, right? That there's no there's no patch for human stupidity, and if people keep falling for phishing links, it's their fault, and it's a lot of victim blaming. So I think this is a really big hard truth for the security industry. We are here to serve. Security is a feature of an organization. It is not the end goal for most organizations. An organization is a business. It's a bank. It's a healthcare provider. It's a fashion retailer. It's a publishing house. They have their business and security practitioners. We are here to serve. We should be serving the humans at the other side. We should be thinking as leaders if the tools we're bringing in, the technologies we're bringing in, are they serving our humans or not? And don't forget that criminals are humans too, and they are clever, and they will come up with creative, maybe innovative ways to be efficient, to use AI, to use automation, to use the knowledge that they can easily gather about your organization against you. So I would say this is a hard truth for me. It's don't forget the humans in all of this AI discussion, the humans are at the heart of
Raghu Nandakumara 56:24
it. I think that's beautiful, right? The humans are at heart of it, and we are ultimately in service, right? And that that's what we should that's what we should keep in mind. So yeah, Keren, thank you so much for your time. This has been incredibly insightful and entertaining.
Keren Elazari 56:40
My pleasure.
Raghu Nandakumara 56:41
It's been it's been it's been awesome, and I don't know if you realized, but we unintentionally referenced three different Michael Jackson songs. So for the listeners, they need to go back and figure out what three they were. Oh, cool! Yeah, I'll send you the answer once we once we get offline. Right.
Keren Elazari 56:58
Very cool.
Raghu Nandakumara 56:59
So with that, thank you all for joining us, being live with this. If you found this interesting, entertaining, which I'm sure you did, we have a ton of other hard truths content on the Illumio website, on our LinkedIn pages. So go and check those out, and of course, right, come over and visit us and visit Keren at Black Hat and DEF CON in early August. So, with that, thank you all for your time. Thanks for joining us.
Keren Elazari 57:24
Bye, everyone.
Raghu Nandakumara 57:25
See ya. Thanks for tuning in to this week's episode of the segment. For even more information and Zero Trust resources, check out our website at alumio.com. You can also connect with us on LinkedIn and Twitter at Illumio. And if you like today's conversation, you can find our other episodes wherever you get your podcasts. I'm your host Raghu Nandakumara and we'll be back soon.

