Opens in a new tab
vmblog logo 2024 wht (updated)

Bugcrowd 2024 Predictions: 2024 Security Trends and Predictions

Share: 

David Marshall | Published: December 12, 2023
VMblog Predictions 2024

 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

2024 Security Trends and Predictions

By Casey Ellis, Founder and Chief Strategy Officer, Bugcrowd

Expanding Threats from Global War and Terror Campaigns

The growing conflicts between Israel and Hamas and Russia and Ukraine will continue in 2024, leading to new risks from global threat actors. This will require preparedness on both sides for new asymmetric threats. Defenders don’t know how to model these threats because they are used to dealing with ransom attacks, so they are not sure what these guys are here for.

We should expect to see different groups popping up in Israel-Hamas like in Ukraine, with these ad hoc asymmetric fighting forces popping up on both sides of Israel and Hamas. Once we get to the Molotov cocktail environment, that is where the chaos part comes in, and now those conflicts are turning into fodder for information warfare ahead of the U.S. election.

There is no shortage of things to be upset about on all sides. This is a volatile, noisy, and fluid environment that is getting a lot of people around the world concerned and upset. And if those threat groups do act, their direct actions will be difficult to predict. We need to listen to outside views with a diverse range of opinions, and that is the place where the crowd can help. We should insert the crowdsourced hacker mindset into this discussion to show how to prepare for that sort of chaos when the hackers do try to monkey with IT systems. 

The Rise of AI Lowers the Bar for Attackers

The availability of ChatGPT and generative AI tools have lowered the bar for creating sophisticated attacks. In the past, knowledge was a barrier to entry for the attackers to get big outcomes. Now gen AI has given them access to a lot of new tools and it has broadened the potential threat group.

In using AI for defense, the challenge comes because prioritization is usually defined by the business leaders, not by the security practitioners. What we security folks feel is most urgent sometimes does not align with the company priorities, which creates a risk to the organization. Seen through that lens, our work around AI is to surface insights from the overall data set as it relates to risk. A vulnerability on its own is not good, but a vulnerability plus a real threat now makes it urgent – it’s like a bomb that hasn’t gone off.

Prediction #1

The “chaotic threat actor” returns

The last time defenders had their attention squarely focused on “asymmetric” or “chaotic” threat actors was Lulzsec and Anonymous in 2013. In 2023, Lapsu$ demonstrated that defenders have been focused on financially and state motivated attackers, leaving open doors for those whose goal might seem “irrational.” The increasing array of reasons for hacktivists to use hacking as a protest tool puts this at the top of my list for 2024.

Prediction #2

Election Security… 2024 edition

Has it been four years already? Despite progress in election system security, a deepening distrust in election integrity in North America will once again bring the subject of vulnerabilities, hacking in good faith, and the place of security research in public discourse.

Prediction #3

AI speeds up *everything*

Since the release of ChatGPT, the potential of AI has captured imaginations everywhere, including those of the adversary. The cat-and-mouse game between attack and defense is as old as time, but the general availability of power AI tooling is set to speed things up.

Prediction #4

“Risk becomes sexy”

The first three predictions beget this one-with higher volume, greater volatility, and a wider range of “baddies” to think about, the importance of prioritization will never be more obvious, and the core role that risk plays in assessing priority will breathe a fresh interest into risk management and calculation.

##

ABOUT THE AUTHOR

Casey Ellis 

Casey pioneered Crowdsourced Security as-a-Service, launching Bugcrowd and its first bug bounty programs in 2012, and co-founded the disclose.io vulnerability disclosure standardization and adoption project in 2014. 

Since then, he has personally advised the US Department of Defense and Department of Homeland Security/CISA, the US Department of Justice around CFAA reform, the Australian and UK intelligence and policy communities, and various US Whitehouse, executive, and judicial branch legislative cybersecurity initiatives, including the Computer Misuse Act, US National Cyber Strategy and preemptive cyberspace protection ahead of the 2020 and 2024 Presidential Elections.