Opens in a new tab
vmblog logo 2024 wht (updated)

DirectDefense 2024 Predictions: The Top Cyber Security Threats for 2024 – Expect More Sophisticated Attacks, More Cunning Bad Actors

Share: 

VMblog Predictions 2024

 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

The Top Cyber Security Threats for 2024: Expect More Sophisticated Attacks, More Cunning Bad Actors

By Jim Broome, President and CTO, DirectDefense

As we step into 2024, it is imperative for organizations to reevaluate their cyber security threat management protocols. The evolving landscape, characterized by cyberattacks that circumvent traditional endpoints to target on-premise cloud environments, coupled with increased investments from attackers, means that organizations must update their approach to internal and external security protections.

What will next year bring? Read on to learn what to expect, and tips to thwart these attacks.

Going around endpoints to attack on-premise cloud environments

Attacking an organization’s network infrastructure isn’t new, but this is one of those trends that’s morphing into something less familiar. Companies that have invested in the latest and greatest next-generation antivirus software will be less than thrilled to know that attackers have found a way around it. They’re now simply avoiding endpoints altogether and going right into the organization’s network to attack on-premise cloud environments. Attackers don’t face much of a barrier since there is little oversight for cloud product development (on-premise or otherwise) and if an organization has poor network segmentation, attackers have an even easier time moving through a cloud-networked environment once they’ve gained access.

All cloud environments (on-premise or otherwise) should have configuration hardening and network segmentation or access controls in place to minimize access to administrative services. Companies using VMware should be aware that there is no EDR solution to protect the VMware host solutions, making them easier for attackers to compromise. Limiting access and enabling logging are best practices for spotting suspicious activity, and network segmentation should be utilized to prevent easy access to management interfaces.

Increased investment in attack campaigns

Attackers are now allocating substantial resources to execute their campaigns, aiming for a more substantial payoff. This financial infusion enables them to scale and intensify attacks, underscoring a monetization of cybercrime. This trend underscores the importance of bolstering defenses, as even trusted security measures can be circumvented.

Organizations must take proactive steps to prevent breaches in the first place, as the aftermath of an attack can result in significant damage and financial losses.

Ransomware attacks shift to a “calling card” after the network has been breached

While ransomware has and still can be a perennial threat, its utilization has evolved in 2023 and leading into 2024. Due to the increased requirements from insurance providers that organizations properly invest in backup and restoration solutions, ransomware threat actors now deploy it as a ‘calling card’ after infiltrating victim networks and are largely attacking on-premises clouds (like VMware). When successful, these compromised on-premise cloud environments now take more time to perform system restoration as each bare-metal system must be re-installed before restoration of the guest virtual machines can start. This shift ensures attackers have the opportunity to demand a significant ransom in exchange for restoring a victim’s network. However, it also provides the threat actor ample time to locate and extract valuable data pilfered during the exfiltration phase of their attack. Presently, this stolen data represents the primary source of revenue for the attackers from the victim organization. In other words, extortion pays more than the restoration costs for the threat actions.

In this landscape, prevention is paramount. Make sure attackers aren’t getting into your network in the first place – and make sure your backups are not easily accessible to the threat actor through the use of network segmentation and access controls.

Taking advantage of weak application security

App development has been a notoriously slow industry to adopt security visibility as part of its overall quality assurance process.  Moving into 2024, it won’t be sufficient to rely only on web application firewalls (which monitor entry points) and database access monitoring (which alerts you to unauthorized access) because there is no “middleware” monitoring what’s actually happening if an attacker gets into the application itself.

App developers and security analysts need to be concerned about abuse of functionality. In many cases, a company realizes something is amiss because there’s a ton of traffic hitting the website all at once, or there are suddenly millions of transactions in the queue – but there’s no way to know what’s happening inside the application to cause those activities because the applications lack security visibility. The best way to stay on top of this information is through application security visibility coupled with monitoring your application.

SSO gets scrutinized

Gone are the days of “one password to rule them all!” While single sign-on (SSO) is a great way to streamline logins for employees, it’s also a great way to hand over widespread access to an attacker. When SSO is abused, attackers will log into multiple accounts and environments at the same time, so a company will struggle to fix or revoke access to everything all at once.

A company’s best defense is to apply conditional access policies for SSO-enabled applications to limit logins for privileged accounts to only selected devices or from specific locations as well as other conditions, such as being enrolled into Microsoft Intune as an example.

##

ABOUT THE AUTHOR

jim broome

 

Mr. Jim Broome is a seasoned IT/IS veteran with more than 20 years of information security experience in both consultative and operational roles. Jim leads DirectDefense, where he is responsible for the day-to-day management of the company, as well as providing guidance and direction for our service offerings.

Previously, Jim was a Director with AccuvantLABS where he managed, developed, and performed information security assessments for organizations across multiple industries, while also developing and growing a team of consultants in his charge.

Prior to AccuvantLABS, Jim was a Principal Security Consultant with Internet Security Systems (ISS) and their X-Force penetration testing team.

Jim has also developed and provided training courses on several security products, including being a primary author of the CheckPoint Software Software CCSA/CCSE/CCSI training program, as well as creating and delivering numerous client-focused training programs and events.