news.mlab.sh
Back to the feed
threat-intel

Should you care about an “AI slowdown?”

High
Summary

Cisco Talos is advising that focusing solely on AI improvements won't solve cybersecurity problems, and that a more holistic approach – strengthening foundational security practices – is needed. The firm highlights a growing ransomware landscape, driven by actors like "The Gentlemen" and "Qilin," who are leveraging AI to enhance their attacks. These groups are using large language models to generate destructive scripts and employing stealthy techniques like exploiting Google's Work Profile feature to evade banking security controls. Cisco Talos recommends focusing on core security practices, such as managing internet-accessible devices, strengthening credentials, and implementing network segmentation, to mitigate these evolving threats.

This week’s Threat Source newsletter from Cisco Talos emphasizes a critical shift in cybersecurity strategy: don’t chase the shiny object of AI to fix everything. While AI has potential, focusing solely on improving AI models won’t address the underlying security weaknesses that attackers exploit. Talos argues that a more robust approach – strengthening traditional security practices – is essential.

Currently, there’s a growing ransomware landscape, particularly in Japan, where actors like "The Gentlemen" and "Qilin" are aggressively targeting small and medium-sized enterprises with double-extortion tactics. "The Gentlemen" relies on established red-teaming frameworks like AdaptixC2 to blend in and evade detection, while "Qilin" is utilizing large language models to generate destructive scripts, significantly accelerating their attack speed and lowering the barrier to entry. Notably, Qilin is leveraging Google's Work Profile feature to help fraudsters evade banking security controls.

Talos stresses that these groups are becoming increasingly sophisticated, using AI to enhance their operational efficiency and stealth. They recommend a layered defense strategy, including strict management of internet-accessible devices, robust credential security, and network segmentation. They also advise implementing NGFW/IPS combinations and regularly updating defenses to detect and block malicious activity.

Top security headlines include Indonesia being targeted by Android banking malware using Google's Work Profile, a 200-vulnerability patch for iOS and macOS, and a new ClickFix attack leveraging a compromised HBO Max account to trick users into hacking themselves. VectraRAT, a previously undocumented Windows implant, is also being offered for $250 per month. Talos has also shared details on several recently identified malware files, including W32.9F1F11A708-100.SBX.TG, W32.C4DD71E347-95.SBX.TG, W32.38D053135D-95.SBX.TG and AAct.exe.

Talos will be at several upcoming events, including LABSCon, VB, CAMLIS, SecurityOnion Conference, BsidesAugusta and SAINTCON.

Read the full article at Cisco Talos