Compromised Platforms – Ofer Maor, Mitiga
Mitiga CTO Ofer Maor explains how platforms such as Slack and Microsoft Office 365 are being compromised by cybercriminals.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with over me or his CTO for America and we're gonna be talking about Security in the land of Office 365 and slack offer. Welcome the show. Thank you.
Thanks for having me. we've seen large numbers of organizations Embrace slack and Office 365 messaging I guess because there's email in there to a certain degree, but I'm It's working to varying degrees from a workplace perspective, but irregardless of what you think of those platforms. They still need to be secured but it seems to me a lot of organizations are overlooking that so why is that happening over?
So I wouldn't say overlooking is necessarily the world but I think you know as we look through different technologies that we've embraced over the years starting with emails and so on attackers would always find way to take advantage even of existing functionality and existing usage and we've built a lot of compensating controls and a lot of user education as well. Right if you get a weird email, you suspect it's officiating or whatever these Chat platforms are still young and attacks on them are still young as well. We haven't got a lot of mileage there.
And so we haven't build a lot of the security both in the technology side the you know, compensating controls and security products on top of them nor the user awareness and attention around that. Are these attacks fundamentally different or is it basically the same thing where somebody steals somebody's credentials and pretends to be somebody else and then starts passing around Files full of malware or is there something unique and different about the way that these platforms are compromised? So I think there's there's a little of both right?
So of course a very popular attack Vector is I get credentials and use them for various things. I think there's something about the You know the instant culture of chat that allows for certain types of fraudulent activity to be easier if we look at the EA attack from a year ago where somebody got their hands on a slack count and then they use that to reach out to tech support through slack and have the main user reset password and and the multi-factor authentication right? This is something that wouldn't be you wouldn't be able to do by email in an old fashion way.
But because everybody in slack, you know, just write something somebody reports. It's like a conversation only the authenticities is determined by the little line that says if you are it makes it easier so I would say that on one side we're going to see a lot of all types of attack that manifest through the new way of communication not necessarily now we're but in personation miss, you know using misconfigure permissions and so on. They're also other things that are a little more unique to these platforms.
So again, some of this culture some of its technology if we take slack for instance everybody in slack can create any group and add people to start talking about things in there. Right and the default if you create a new group in slack is that it's public group. That's part of the slack culture, right?
Everybody can search everybody can join people know is think about it people are not security people. So you go into organization and you look at their groups. A lot of their public groups have very sensitive data that maybe only the five or six people on that group should see but in theory anybody who searches it can join it and see anything in it be thousands of people in the organization.
So one compromise account will be able to access a lot of data. another thing that that we see is that a lot of this is also used not just for you know chatter conversation, but it's sort of Knowledge Management System people started using slack as a place to start documents history and a lot of other things. Haven't done the technology side when we also see and that's true for all SAS platforms to a degree, but very strong was slack is that it's an ecosystem.
So there's a lot of third party integration and a lot of trust. It goes on between those integration. So I may be able to take over a slack account and use it to do things in Office 365 or in Salesforce or in another system that has a Plugin or integration into Slack.
Mmm, do you think that some of these folks are lurking on these platforms for months trying to get a Vibe for how the organization operates and that's part of their strategy is they want to impersonate somebody but they got to go and actually sit there and kind of observe how they work for a while before they can successfully do that. Of course and that's we see that with attackers especially around ransomware attacks in pretty much every way we look right when you look at the big ransomware attacks. The one you hear on the news with millions and tens of millions of Ransom.
These numbers are not random attackers learn their organization. They take advantage of the access. They have to figure out what would be the right Target and the right number of to go with that Target and we expect the same to happen with slack and an Office 365 and we've recently investigated a few Office 365 incidents where they initial attack Vector was months before the actual exploitation or taking advantage of the system to place and we can see that this was used to together intelligence.
Are there best practices for thwarting these types of attacks? I mean am I supposed to be training my end users or their Technologies and policies I've put in place. How do I kind of approach this?
So like anything in security It's a combination right? It's it's process technology and people so the first thing is awareness teaching your employees that this can happen goes a long way telling them, you know to to not respond immediately on anything in slack, but if it looks weird to stop for our second and think wait, maybe the person talking with me on the other side is is not that real person. It's also about building the right security controls in place permission.
So in my org whenever I see a new public group being formed I look at it and I check whether it should be public and if it's not I change it to private and I also tell the person who created it to notice that in the future they need to do it private safe works. It works because people learn when when you teach them and so getting people to understand that making sure there's less permissions, but also, Employing the right security features a lot of these platforms have security features. Unfortunately, some of these security features are only available in the higher tiers.
So for instance, if you look at slack only the Enterprise here gives you the full single sign on and logs and all of those things. But if you are an organization that wants and cares deeply about security and uses slack as a core platform, then you should go up there and use those features. We hear a lot about AI these days.
Do you think AI will play a role at some point helping us mitigate these types of breaches and attacks or is it more hype than substance? I just had it. I had I had this exact conversation an hour ago with with an investor and he said the very good statement.
He said the day that all that the only way attackers will attack us will be using AI that attacks then AI that defense could be sufficient. But as long as humans are smart enough to create new ways to attack. We will need also humans to help defend.
AI can help of course, but I think AI is is sometimes over hyped in thinking how much it can do because attackers hackers is all about being smart and finding ways to circumvent technology necessarily for bad. Right when we say the word hacker something necessarily a bad thing, but hackers in nature people who look for ways around technology limitations. So when we build good AI It will just mean that the hackers will need to come up with new ways to break.
They are new attacks on AI now. A lot of these attacks are essentially social engineering and in the early days, you can always kind of somewhat spot them but it looks to me now that the people who are perpetrating. These attacks are getting a lot more sophisticated in their ability to mimic organizations and kind of mimic individuals in your boss and everybody else.
So is that because they're language skills are getting better or they just hire people who are native speakers and going for it. I think it's because they're investing more resources, right? So so everything you said is right that they hire the right people they perfect the skill and it's it's become mainstream.
If you look I've been an industry for a long time now 20 years ago most attacks were either individuals small groups people doing it for for fun. Today it's a business organized crime has moved online and and it's a business and because of that they get the people with the right skills and I think as us as as Defenders as the organizations that are being attacked we need to understand that this is not going to stop there will always be social engineering and it will always be successful. To stand degree and so it's about building compensating controls.
It's about building additional layers of verification for critical things and it's also about preparing and being ready for breaches to happen because they will happen they're unavoidable, but we can reduce their impact if we're ready to them and we know how to respond to them quicker. Hmm. So what is your best advice to folks?
What should they be thinking about or doing or what? Do you wish that? A lot of them would do is a fundamental before they even got a hold of you.
so there, you know two areas to focus on right. The first one is is protection do better job at securing your environment permissions. Of course, you know, I'm gonna start with a trivial but I still see organizations that don't use two-factor authentication that such a basic thing that helps doesn't solve but helps a lot.
So putting the right Security in place putting permissions making sure you have a strong strong minimal permission policy for everything you do in in your environments, but then the other thing is get ready for a breach and what does it mean it means that? You have plans in place. You understand how it breach is going to look like you collect the right data so that when a breach happens, you can go back and investigate and discover what happens so that you can respond to it and know what happens in the most efficient way and those are things that all can be done today before there's any incident before anything happens just improving your your posture both around protection and around response.
All right. Well, let's just assume that something bad's gonna happen and be prepared to respond accordingly over. Thanks for being on the show.
Thank you very much. All right back to you guys in the studio.