Attackers Follow the Path of Least Resistance
When most of us think about protecting something valuable, we naturally focus on the thing itself. If you want to protect your house, you lock the doors. If you want to protect your phone, you use a passcode. If you’re protecting company data, you secure the systems where that data lives.
Attackers don’t always think that way. Sometimes the easiest way through the front door is to never use the front door at all.
That stood out to me while reading this week’s cybersecurity news. Valve notified customers about a breach that didn’t happen at Valve, but at its logistics provider. Levi Strauss reported an incident that started with social engineering against employees. Hedge funds were targeted through help desk processes. Attackers compromised TrueConf servers and turned trusted software updates into a delivery mechanism for malware.
The targets and techniques were different, but the idea behind them was remarkably similar: find an easier path.
We spend a lot of time in Security identifying the things that matter most. Critical applications, sensitive data, privileged accounts, cloud environments, endpoints, and network infrastructure all deserve that attention. But protecting an asset also means understanding all the paths that can eventually lead to it.
That can include a vendor with access to your data, an employee who can approve a request, a help desk capable of resetting credentials, an application that automatically trusts software updates, or a seemingly ordinary business process connected to something much more important.
This is where looking at your environment from an attacker’s perspective becomes useful.
Instead of only asking, “Is this system secure?” try asking, “How else could someone get here?”
Maybe they don’t need to defeat your MFA if they can convince someone to reset it. Maybe they don’t need to compromise your environment if a trusted vendor already has the information they want. Maybe they don’t need to attack an endpoint directly if they can compromise software the endpoint already trusts.
None of this means we should stop trusting people, vendors, or technology. Organizations couldn’t operate that way. Trust relationships are what allow businesses to function.
The lesson is simply that those relationships are part of the Security picture too.
One of the best exercises a Security team can perform is to choose something important and work backward. Who can access it? What systems connect to it? Which vendors support it? What processes can change that access? What happens when someone forgets a password? What software does it inherently trust?
You’ll probably discover that the path to the asset is more complicated than the asset itself, and attackers are very good at finding those paths. We should be just as good at understanding them.
🔒 Security Tip of the Week:
Choose one critical system or dataset and map the people, vendors, applications, and processes that can eventually lead to it. Don’t stop at direct technical access. Look for the trust relationships surrounding it too.
📌 This Week’s Outlook in a Shareable Statement:
Your attack surface isn’t defined only by the systems you own. It includes the people, processes, vendors, and technologies your organization trusts.
The goal isn’t to eliminate every path. It’s to understand them well enough that the easiest route for an attacker isn’t one you’ve forgotten exists.
Stay safe!
— Tiffany Carberry
Pinpoint Security
Pinpoint Security
📰 Weekly News Roundup:
🎮 Valve Notifies Steam Hardware Customers of Data Breach via CEVA Logistics
Valve notified European Steam hardware customers that attackers compromised systems at shipping partner CEVA Logistics. The breach exposed customer names, shipping addresses, phone numbers, email addresses, and order prices, while payment information and Steam credentials were not affected.
Valve notified European Steam hardware customers that attackers compromised systems at shipping partner CEVA Logistics. The breach exposed customer names, shipping addresses, phone numbers, email addresses, and order prices, while payment information and Steam credentials were not affected.
👖 Levi Strauss Discloses Corporate Data Theft Following Social Engineering Attack
Levi Strauss disclosed that attackers used social engineering against three employees to gain access to company-issued computers and steal internal corporate files. Initial findings indicate customer information and operational systems were not affected.
Levi Strauss disclosed that attackers used social engineering against three employees to gain access to company-issued computers and steal internal corporate files. Initial findings indicate customer information and operational systems were not affected.
🚢 Cyberattack Disrupts Operational IT Systems at North Carolina Ports
A cyberattack disrupted IT systems supporting the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Operations temporarily shifted to manual gate processing, creating shipping and trucking delays while systems were recovered.
A cyberattack disrupted IT systems supporting the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Operations temporarily shifted to manual gate processing, creating shipping and trucking delays while systems were recovered.
🏦 UNC6671 Threat Group Targets Major Hedge Funds in Vishing Campaigns
Researchers linked targeted attacks against hedge funds and private equity firms to UNC6671. The group used sophisticated help desk voice-phishing attacks to obtain single sign-on credentials and bypass multi-factor authentication.
Researchers linked targeted attacks against hedge funds and private equity firms to UNC6671. The group used sophisticated help desk voice-phishing attacks to obtain single sign-on credentials and bypass multi-factor authentication.
📹 Hackers Breach TrueConf Servers to Deliver Trojanized Client Updates
Attackers exploited unpatched TrueConf video conferencing servers, installed web shells, and replaced legitimate software updates with trojanized installers containing persistent backdoors.
Attackers exploited unpatched TrueConf video conferencing servers, installed web shells, and replaced legitimate software updates with trojanized installers containing persistent backdoors.
|
|