Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
Beyond phishing, the rise of LLMs will make the endpoint a prime target for cybercriminals in 2024
By Dr. Ian Pratt, Global Head of Security for Personal Systems at HP Inc.
One of the big trends we expect to see in 2024 is a surge in use of generative AI to make phishing lures much harder to detect, leading to more endpoint compromise. Attackers will be able to automate the drafting of emails in minority languages, scrape information from public sites – such as LinkedIn – to pull information on targets, and create highly-personalized social engineering attacks en masse. Once threat actors have access to an email account, they will be able to automatically scan threads for important contacts and conversations, and even attachments, sending back updated versions of documents with malware implanted, making it almost impossible for users to identify malicious actors. Personalizing attacks used to require humans, so having the capability to automate such tactics is a real challenge for security teams. Beyond this, continued use of ML-driven fuzzing, where threat actors can probe systems to discover new vulnerabilities. We may also see ML-driven exploit creation emerge, which could reduce the cost of creating zero day exploits, leading their greater use in the wild.
Simultaneously, we will see a rise in ‘AI PC’s’, which will revolutionize how people interact with their endpoint devices. With advanced compute power, AI PCs will enable the use of “local Large Language Models (LLMs)” – smaller LLMs running on-device, enabling users to leverage AI capabilities independently from the Internet. These local LLMs are designed to better understand the individual user’s world, acting as personalized assistants. But as devices gather vast amounts of sensitive user data, endpoints will be a higher risk target for threat actors.
As many organizations rush to use LLMs for their chatbots to boost convenience, they open themselves up to users abusing chatbots to access data they previously wouldn’t have been able to. Threat actors will be able to socially engineer corporate LLMs with targeted prompts to trick them into overriding its controls and giving up sensitive information – leading to data breaches.
And, at a time when risks are increasing, the industry is also facing a skills crisis – with the latest figures showing 4 million open vacancies in cybersecurity; the highest level in five years. Security teams will have to find ways to do more with less, while protecting against both known and unknown threats. Key to this will be protecting the endpoint and reducing the attack surface. Having strong endpoint protection that aligns to Zero Trust principles straight out-of-the-box will be essential. By focusing on protecting against all threats – known and unknown – organizations will be much better placed in the new age of AI.
##
ABOUT THE AUTHOR
Dr. Ian Pratt, Global Head of Security for Personal Systems at HP Inc.
Ian has spent his career spanning industry and academia, inventing new technology and bringing it to market. He was a tenured faculty member at the University of Cambridge, where he led the prestigious Systems Research Group for over 9 years. He has founded 3 successful technology companies, in areas of networking hardware, virtualization/cloud and cyber security. Nemesys Research build hardware to send broadcast quality audio video over data networks and was acquired by FORE Systems in 1997.
In 1999, Ian initiated and led the XenoServers research program, leading to the creation of the Xen hypervisor, and the first infrastructure as a service Cloud platform. Ian co-founded XenSource in 2003, to build enterprise- class virtualization products based on the Xen, and worked to build the open source community around Xen and oversee its adoption by Amazon, HP, Intel, IBM, Google, Sun and other vendors. XenSource was acquired by Citrix in 2007 for $500M, where he served as Vice President for Advanced Products and CTO.
Ian co-founded cyber security company, Bromium, in 2011. Bromium pioneered a novel approach to endpoint security built on virtualization that results in radically better efficacy than traditional approaches, resulting in over 65 patents. HP Inc acquired Bromium in 2019, where he leads the personal systems security business unit. Ian holds a PhD in Computer Science, is a Fellow of the Institute of Engineering and Technology, and a Fellow of the Royal Academy of Engineering from which he was awarded the Academy’s Silver Medal in 2009.






