
A pattern is surfacing in recent security incidents. Attackers are gaining access to systems by using something a user already trusts, such as a help desk process, a software update, a job posting, or a piece of remote access software. Nothing about the technology itself has to fail. The person or the process behind it is the target.
Here are five recent examples.
1. A breach that got in through people. Apollo Global Management was recently hit by attackers who used social engineering, exposing sensitive personal data. The social engineering attacks bypassed 2FA and other security measures by reaching out to the users directly.
2. A cyberattack that disrupted 911 service. A California city had to shut down its own network after an attack disrupted emergency dispatch and other municipal systems. It is a reminder that a cyberattack can quickly become a safety and business continuity issue.
3. Malicious code hidden in trusted software. Attackers compromised a software project’s release process and published tainted packages that looked legitimate. Even businesses that only use trusted third party software are exposed if the pipeline behind it gets compromised.
4. A fake job offer that led to a major exploit. Attackers used fake job postings to trick targets into opening the door to a serious Windows vulnerability. It shows how a single convincing message can lead to a much bigger compromise.
5. A ransomware group that has hit over 500 victims. Federal agencies updated their warning about a ransomware group using stolen credentials and legitimate remote access tools. It is a reminder that ransomware can come from several smaller gaps that, in combination, provided enough information to gain access.
The common thread in all five is trust. Attackers are finding ways into systems by using relationships and processes that businesses already rely on.
If you would like help reviewing where these vulnerable points exist in your environment, reach out to us.

