Hello, Wednesday! Gather your cyber squad and save 50% on tickets to IT Brew's cybersecurity event in New York on Oct. 31! Use code: “GROUP” to unlock serious savings on tickets for teams of three or more.
In today’s edition:
I’m only non-human
CAPTCHA if you can
Attack!
—Brianna Monsanto, Billy Hurley, Eoin Higgins, Patrick Lucas Austin
|
|
Amelia Kinsinger
Businesses nationwide are undergoing an identity crisis, and it’s not the existential, edgy kind.
Non-human identities (NHIs), digital credentials that enable machines and applications to interact with one another without human intervention, are outnumbering their human counterparts in organizations. According to a recent AppViewX report—which queried 367 IT, cybersecurity, DevOps, platform, and cybersecurity engineering professionals across North America—the average company manages about 20 times more NHIs than human ones.
However, security around NHIs has remained a large problem for businesses. The report, conducted in partnership with TechTarget’s Enterprise Strategy Group, claims that nearly 46% of professionals surveyed admitted that their organization experienced an NHI-related breach in the last 12 months.
A brewing problem. AppViewX VP of Product Marketing Christian Simko told IT Brew that security concerns around NHIs have been “percolating” for a long time and that the issue has garnered a lot more “mindshare” from security teams within the last year. Simko blamed the problem largely on a lack of visibility around the full scope of NHIs used across an organization.
Read the rest here.—BM
|
|
presented by Amazon Web Services
|
From new product announcements to growing your technical skills, AWS re:Invent 2024 is back, better than ever, and ready for takeoff. The question is, are you grabbing a window seat?
Happening Dec. 2–6 in Las Vegas, AWS re:Invent is a gathering of industry leaders who wanna learn the latest on generative AI, expand their skill sets, and network with peers and trailblazers.
If this sounds up your alley, you also won’t wanna miss the selection of over 2.5k sessions and workshops, AWS Training and Certification activities, and the annual re:Play party.
Snag your ticket here, and if you can’t make it, no worries. Just sign up for the free livestream.
|
|
Cosminxp Cosmin/Getty Images
As if CAPTCHAs weren’t already perplexing enough (what if every square contains a bus?!)—now some of the human-verifying site tools come with malware.
Security researchers see at least a little cleverness in the threat actors’ recent corruption of a common, trusted site feature, and common keyboard commands.
“It’s weaponizing copy-and-paste, but it works,” John Hammond, principal security researcher at cybersecurity company Huntress, told IT Brew.
How it works. In September, Hammond shared his security operations team’s discovery of coded commands seeming “to come from absolutely nowhere,” according to a team notification shared in Hammond’s YouTube presentation.
An investigation of a targeted user’s browser history found an initial online redirect (an ad or popup, Hammond guessed), leading to a static page hosting a fake CAPTCHA, team notes read. “Verify that you are human,” the false CAPTCHA asks.
A user clicking “I am not a robot” then gets two instructions:
- Press the Windows button + R
- Press Control + V
Following these “verification steps” may show you’re human indeed—in a “to err” kinda way.
Read more here.—BH
|
|
Peerapong Boriboon/Getty Images
Up, down, all around—2024 has been a chaotic year for ransomware attacks. While overall attacks have been higher than in 2023, a month by month view shows a more complicated picture.
After dropping below 2023 year over year (YoY) in June and July, ransomware attacks were up 14% in August and increased YoY from 335 attacks to 450, NCC Group reported in its latest Monthly Threat Pulse. Matt Hull, NCC Group’s global head for strategic threat intelligence, told IT Brew that he expects to see a rise in attacks as we come to the end of the year.
“We do seem to see a ramping up of activity in the run up to the Christmas holiday period, and whether we continue to see this increase right the way through to December is yet to be seen,” Hull said. “But September so far is looking like it could be heading that way as well.”
New kid. The report detailed how threat actor RansomHub continues to be a major vector of ransomware attacks, responsible for 16% of attacks for August. Industrials were the highest targeted sector.
Keep reading here.—EH
|
|
Power up. The rise of AI = higher demand for computing power. To handle the workload, tech companies are redesigning + optimizing their stacks. Arm (NASDAQ: $ARM) helps the world’s tech leaders unlock AI’s potential. From foundational computing platforms to software ecosystem leadership, Arm Neoverse helps companies stay on the cutting edge. Learn more. |
|
Francis Scialabba
Today’s top IT reads.
Stat: 118. That’s the number of flaws patched by Microsoft in its monthly security update, including five zero-day vulnerabilities. (Bleeping Computer)
Quote: “We’re improving the overall performance and reliability, making it easier and faster to navigate, switch to and create custom views, and filter large data sets.”—Jason Moore, vice president of product for OneDrive, on the service’s new updated feature list (The Verge)
Read: Running a Linux machine? You might be infected with malware too sneaky to be seen. (Wired)
Blast off in 3, 2, 1: Get your ticket to AWS re:Invent 2024 to access interactive workshops, product launches, and the annual re:Play party. Can’t make it live? Sign up for the free livestream.* *A message from our sponsor.
|
|
Share IT Brew with your coworkers, acquire free Brew swag, and then make new friends as a result of your fresh Brew swag.
We’re saying we’ll give you free stuff and more friends if you share a link. One link.
Your referral count: 2
Click to Share
Or copy & paste your referral link to others: itbrew.com/r/?kid=9ec4d467
|
|
ADVERTISE
//
CAREERS
//
SHOP
//
FAQ
Update your email preferences or unsubscribe
.
View our privacy policy
.
Copyright ©
2024
Morning Brew. All rights reserved.
22 W 19th St, 4th Floor, New York, NY 10011
|
|