Hackers leak configs and VPN credentials for 15,000 FortiGate devices
The cybersecurity landscape continues to evolve, and for Managed Service Providers (MSPs), the latest battleground is clear: edge devices. In a recent Cyber Call featuring experts from Blackpoint Cyber, the conversation focused on a surge in attacks against firewalls, VPNs, and internet-facing devices—components that form the first line of defense for most clients.
The issue isn’t new, but it’s escalating. Threat actors are repeatedly exploiting known and zero-day vulnerabilities in devices like FortiGate, SonicWall, and others. These attacks are increasingly successful due to outdated software, poor configurations, and a general lack of consistent patching. The shift to remote work, coupled with increased reliance on VPNs, has only widened the attack surface.
Worse still, the release of data dumps containing firewall configs, VPN credentials, and management certificates gives attackers a fast-track to breach networks. As the panel noted, this provides attackers with a “pre-escalation” advantage, giving them immediate insight into internal networks and credentials—no need for initial brute-force tactics.
So what can MSPs do to respond? First, assume breach. This mindset shift encourages active monitoring, anomaly detection, and stricter controls. Audit and review client edge configurations regularly, looking for weak settings, insecure access methods, and default credentials. Harden remote access—consider VPN jump boxes, enforce MFA, and limit administrative access.
Always push for prompt patching and verify that firmware is current across all client devices. Implement network segmentation to limit lateral movement in the event of a breach, and revisit your vendor stack. If a vendor repeatedly fails to respond to vulnerabilities, it may be time to look elsewhere. Additionally, educate your clients—make sure they understand the risks and their role in protecting the business.
Looking ahead, artificial intelligence will only accelerate the threat landscape. While defenders are leveraging AI for better detection and response, attackers are doing the same to automate reconnaissance, payload delivery, and lateral movement. This arms race requires MSPs to stay informed and invest in modern, adaptive security strategies.
The bottom line? The edge is no longer just a point of connection—it’s now a primary attack vector. MSPs that act now to strengthen edge security, train their clients, and select the right tools will be far better prepared to defend their networks in 2024 and beyond.
Guests
Video Transcript
Here, and lemme turn off my happy Monday, everybody. Um, we'll give this a minute or two for you all to come in. I just wanna make sure that you can all hear and see us. Okay. If you could let me know, that would be great. Um, and also, let me turn off my dinging and doning. That's always fun. Um, uh, bear with me. All right. All right. Awesome. We're live.
The, uh, the reason I, I hesitate everybody out there, um, who's listening and, Hey, Kevin, good to see you, is there's always this little bit of a delay with Restream. Um, so it starts, and you guys don't see it on YouTube for a little while. So thanks for hanging in there with us. Yeah. Happy, happy MLK to you all.
And, uh, MLK day, obviously in the States here, not only is it on K Day, it's inauguration day, lots going on, um, in, in the, uh, us and, um, but, uh, um, lots going on as always, um, in the world of cyber. And, uh, that's what we are going to talk about today. Um, you know, Mac reached out to me and, you know, I'd been tracking this, you know, what's, what started Mac Right. As a, you know, another zero day, um, earlier, a few days before, what we're gonna be talking about.
And we will, we'll probably be talking back and forth between both, but, um, yeah, boy, this, you know, seems to be the gift that just keeps giving Mac. I mean, uh, whether it's, uh, and, and that, that this isn't about picking on vendors, but whether it's Fortinet or Sonic mm-hmm. Wall or Avanti, right? This, this seems to be, uh, the threat actor de jour. What, you know, they're focusing on these days is, am I right from your perspective, Mac? Absolutely.
And I mean, I feel like this has been a theme since 2003, just on the basic best practices we keep talking about. But I think we have a whole hour to get into that. But yeah, I'd say this is like a continuation of the Deens desensitization or really focusing on what I would consider, like threat actors cutting their time in half, being able to target these edge appliances and place a pretty good bet that there's some misconfigurations going on. Mm-hmm. Yeah. Yeah, yeah.
Well, we're gonna definitely talk about that, and I'll get to the intros in a second. But yeah, in setting the stage, I mean, this, this seems to be like the, uh, monthly affair, whether it, like I said, those three. Um, and, and, and, but by and large, I mean, if you look back, um, you know, uh, Bob, it, it kind of right around the pandemic time, you know, that's when threat actors really started to say, you know what? There's, there's something here with VPNs.
And we started to see it, um, quite a bit, um, right as the pandemic unfolded and people went remote, and VPNs really started to get used considerably more, obviously, as a result of not being in the office. Um, do you think that was part of like the s the smoke became fire Bob? Like, you know, when you See, I, I think it was a perfect storm, honestly. I, I think it was, you know, being the pandemic forcing everybody to go remote, right?
So that turned, that turned the sample size up of, of, of places where you could go test these practices. It it turned it up in order of Mag Seed or two, right? So, you know, it, it, they were already working that angle, but there were limited people who were really using it to the vol. Nothing like the volume we saw during the pandemic, right? Where Yeah, just about everybody's virtual.
So just from a target standpoint, it went from being a, you know, a little bitty puddle to being an ocean to go play with. And then it's just a matter of time, right? Because they're gonna try these statistically, they're gonna keep trying. We also know, I mean, we already know credential theft is the number one methodology for doing these things, right? Networks on VPNs as well.
So, um, I think these were all just related in that they had a lot more practice space to work with, still using, I know McKenzie's, I like watching McKenzie's veins pop out on her neck when she starts talking about people that haven't been doing the standard s**t we've been trying to tell 'em to do for last 10 years. Right? I mean, it's hard to sugarcoat that she'll do it. I I'm not any good at it, so I won't talk about that. She's better at sugarcoating it, but that's part of it.
So I agree with you. I think, I think it was a perfect storm that allowed all this to get to be a lot more prevalent. Yeah. But Bob, everybody uses two A on VPN, so I'm surprised this is happening, aren't You? Yeah. Yeah. Are you, I just hope you're grounded so lightning doesn't hit you squaring head, because we all know that ain't true, right?
So, yeah, I mean, I, I'm not trying to be a, a pessimist on just the v PN conversation 'cause it's rising, but I don't think we've even seen the full picture yet as far as even even the SSL vulnerabilities out there, I don't think, I think there's, you know, not to be a bear of bad news or doom doom, future escaping, but, um, I'm, I'm a little concerned we don't even know the full extent because of, like you said, of the end usage.
And that's the number one thing too, that becomes a continuation of an issue in socks and monitoring makes it real difficult. Yeah, I'd second that. I think we'll probably get into that, but definitely agree With that. Yeah. Aaron, I see you shaking your head, right? So you, you know, obviously you have background as we'll talk about in a minute from obviously NSA days, but do you, do you think there's more supply chain stuff here that we haven't even started to uncover? Oh, for Sure. Yeah.
It's, it is a complex situation, right? And just one of the things is, you know, one vulnerable library, right? That can cascade through multiple, um, you know, one vulnerable SSL library, whatever, can cascade through multiple different appliances, software packages, et cetera. Um, yeah. So there's probably gonna be a lot more to unpack as, as the year goes on, sadly. Yeah. Okay. Well, let's get on into it.
So let's start with some intros and, um, Mac, uh, as, as you intro, I mean, a lot of people know out dear, uh, there know you, but, um, is there just one last question to you as you intro, like, I mean, money aside, I mean, why aren't people just sunset VPNs and going to like A-Z-T-N-A solution right now? Like, I mean, I, I, I just, again, I get it, it's like we can't get people to still do MFA sometimes, but like Right.
If money weren't an object, would everybody be on A-Z-T-N-A and VPN sunset, in your opinion? Yes. I believe if money wasn't an object, um, I think if the conversation between a business decision operationally creating productivity and just general cybersecurity, um, if that wasn't something that had to be continuously battled apart in the boardrooms, I think a lot more organizations would be adopting this.
And now, I mean, you flip it on the side of the MSP, they're now managing, having to manage all these organizations and say, do we default deny them? Basically saying, Hey, we won't support you unless you do x, y, z of these basics. And a lot of that isn't going on, nor is it, again, productive for business to be able to do so.
Yeah, I, i, zero trust is something I'm sure we'll bring up many times, but they, I, it's, the architecture of it seem is seemingly complicated and expensive, but I think that's, that's where we need to start moving as far as how we're supporting them. Cool. So how about an intro? Mac, and thanks for joining as always. Yeah. Um, Mackenzie or Mac Brown, many of you know me. Um, I'm at Black Point Cyber.
I'm the VP of the Adversary Pursuit group, or a PG, which is our very coup fancy name, um, for our threat intelligence and threat research team. So we really work close in hand in step with our SOC to be able to take what's going out there, be able to provide accuracy, and then also really being able to say, how does this impact all of our partners and perform as much, um, predictive analysis as possible that is contextualized intelligence.
And I will toss it over to my, uh, cohort Aaron here, uh, who also works with me on this team. You're welcome, Aaron. Good to have you, man. Yeah, thanks Andrew. It's, uh, another good, uh, well, probably not of the best circumstances, but good to talk to you again in a couple weeks. Yeah. Um, so Aaron Shaha, um, yeah, I, I work with Mackenzie on the A PG. I'm the chief of threat research and intelligence.
Um, the, I think McKenzie hit on a couple key points there, um, that are really interesting, right? So, so everybody gets confused on the purpose of intelligence, and really what we're here to do is reduce uncertainty, right? We're, we can't predict the future.
We can't mind read, we can't, you know, tell you what's gonna happen specifically, but we can, you know, talk in probabilities and try and help you understand, you know, kind the lay of the land as, as imperfect information that we get in does.
So that, that's kind of my job day to day, um, with Mackenzie inside, you know, informing the soc, informing our client partners, um, looking around, you know, kind of down range and trying to be forward looking as to what's coming while understanding what's out there and what's hitting us now, like we're doing right now. Yeah. Good. Good. And Bob, thanks for joining as a co-host For those that may not know you, quick intro for yourself.
Yeah, Bob Miller, I am Chief Operating Officer, global Data Systems, and the founder of IR Game, which is an instant response game online game. Um, and man, I've been working all day on my inauguration. I, I'll tell you this, Andrew, that we're expecting about eight inches of snow in Lafayette, Louisiana. Wow. We're expecting six to eight inches of snow in the next couple days. So I've been working on my inauguration day, hell frozen over jokes all day.
So I was looking forward, I was really looking forward to getting into this, but I I, I, I've been watching some of the comments too, Andrew. A lot of people are pointing out, even if you gave them zero trust, if it was a business process change and it was inconvenient, yeah, it'd sit right there regardless of whether it was free or not. So yes, I, I'm in agreement with these people. I, yeah, I, and I get, I get, I, I'm hearing the, and I see the, and thank you for the comments.
Please keep them coming. I, I get it as well. You know, there, there are, you know, there are some really good solutions. This isn't about tech right now, but No, but, but, but it, it was more just kind of a hypothetical, like, do we need to get off of these solutions? And yes, there's change is always painful and people don't like change this, that, and the other. But, but then again, people don't like their entire business down and their data exfiltrated either.
So, you know, again, we have to, we have to, you know, pick our poisons here. Um, okay. So, Bob, with that, let me throw it over to you to kick things off Sure. Here with the team and, uh, kick, kick, get, get it going. Yeah, absolutely.
So this, um, McKinsey, this is for you because I, I'm curious, I'm so dying to hear what you, your and Aaron's perspective on this, but what in the hell is going on with FortiGate for, it's hard for me to tell which, which notice that I'm looking at nowadays, right? Because they're starting to look a lot like, and they're starting to come so frequently that I can't tell the damn things apart. So what in the hell is, what is going on with that, right?
And, and then it seems to be a consistent theme. Right Now we go from zero day to full breach, and I'm concerned that they're not telling us everything like source codes being jacked from there, right? Because that's another thing they could do when they get in and, and, and breach four gates. It's not the day Bridge four gate. So go ahead, take it from There. That was Ally back in the day. Yeah.
Um, so I think we're talking about today, I mean, or what prompted it is, um, there's this new group, Belsen group. They're basically doing New year, new us, nice to meet you, put up a site. Here's a data dump of 15,000 targets. The one side of that, we all know from a target perspective, even though this is allegedly connected back to 2022 to 2023, there was a lot of Chinese hacking operations going at that time. Fortinet was getting hit left and right.
Um, they also were silently fixing things and then waiting a few weeks to release the update information to people. And so we were used to being left in the dark. And so now they're saying that this Belsen group is promoting themselves with this lovely marketing strategy of, uh, you know, spinning up a tour site. Here's the data dump, know our name, we're here to help.
Um, so the, the concerning thing here, and this is probably a theme of like, like what you said, we're seeing a lot of things we're trying to recently, and by recently, I mean, just in three weeks, SonicWall of vti, um, the Microsoft purview stuff, Clio, we're still dealing with those things. So we're trying to, you, you can imagine our teams chats are starting to get less clarified, and we have to almost just have so many war rooms just to organize all of them.
Um, but in this data dump, you have, um, basically every IP is connected to, um, full firewall configuration, which we've seen a lot of this. Um, it's, uh, connected to VPN passwords, plain text, um, in many cases, the, uh, device management certificates, and in not all cases, but apparently they're saying more is firewall rules. So you're not just getting access to a privilege system, so you're gaining pre escalation, initial access very easily, and you're moving on to the next thing.
But you're almost getting a little bit of reconnaissance information about the organization you're targeting in the first place, how well they do management as far as firewall rules too. Not saying there are any, any, but there may actually be some very easy targets. And everyone's saying, okay, so, so what? There's a patch for this. This is old versions 2022, that's two years ago.
But the concerning thing that we all know is people still don't, there are still actually, um, easy targeted paths here of unpatched un outdated organizations from two years ago. That's super common. I mean, we saw the solar wind stuff. We saw some of these sonic walls hitting these vulnerabilities that were causing these investigations. They're still hitting a year, two years later. So, I mean, we're long in the short. Basically, we see these zero days specifically.
This one is, we can imagine any zero data now, especially when you see them packaged on one specific vendor, that it could be connected to threat exposure notices from years prior. Um, we know people have a difficulty patching updating their environments. All in all, this just cuts the time for threat actors resource constraints to be able to perform a lot of what they need in their attack chain when they've already accomplished by targeting the edge.
So we're gonna see an increase of this is, again, targeting the edge. Can I bump in there, Bob for a second? Sure. I mean, aside from what you just outlaid, which was awesome, Mac, Aaron, I mean, we're, isn't this open up a pathway also for awesome phishing? I mean, you know, if you know specifically 15,000 organizations, I mean, what a, what a brilliant phishing campaign you can put together. No. Oh, yeah. So was that the to Mac, Andrew? Sorry. Yeah.
So, so one of the problems we have, and it's a little bit of a rent of mine, um, I have many, but is we tend to look at these events as discreet elements in time, right? Hey, Bob's PC just got hacked. Okay, we wiped it, we passed it, whatever. Right? We brought it back and recovered it, put it back online, and now we're good to go. Right? The reality is there's a reason that there's a P in a PT, right? The persistence, right?
Not every attack against you is an A PT, but probably more of 'em than you think you are have some sort of larger group behind them, right? And, and we do a disservice by kind of splintering up these groups, right? We have like 52 different pandas, right? Mm-hmm. There's probably not 52 different pandas in the world, right? There's probably six or seven, right? And we, we look at these attacks as, as very isolated events, and, and they're not, they're all related, right?
And, and exactly like you said Andrew, right? The, you know, maybe the adversary gets this information pivots to, um, phishing. Maybe they're, they're just trying to understand something larger about the organization, or, you know, kind of going with the, the theme that we've started off with about supply chain, right? Maybe they're looking for kind of connections. Maybe you're a supplier to a larger organization that they want to get into, right?
And now there's VPN tunnels there that they can exploit to get into, right? So there's, there's a lot of different things that can happen here. And, and this is a really complex domain, but especially like just looking at these boundary devices, right? It's not just the attack on the boundary device, right? There's lots of different ways that adversary can come at you from this. Yeah. Yeah.
Bob, since you're so, um, interested in the inauguration, um, and politics, how do you think the secure by design is gonna look like at this again, like, you know, is that gonna be something real? Do you think that's gonna gain teeth? You know, this, shouldn't this be Now, you know, again, if, if you look at that mantra, this is a Fortinet issue, this isn't, I, I'm air quoting, right?
Th this is something the manufacturers should be responsible for, and not the end user's always taking the brunt of. What, what are your thoughts there? Yeah. Well, you wanna talk about a rant, Aaron? This is one of mine, right? Because look, I, I'm a software developer by training. So, you know, I, I, yes, what's going to have to happen? We don't have a damn choice.
The vendors, the vendors that create software and create operating systems for these devices, they're gonna have to change the way they develop code for the future. That's, it's not gonna work the same way. It's worked forever, right? You can't have unsigned DLLs in your shareware libraries that your damn firewall depends solely on, right? I mean, unsigned, DLLs in a production piece of code, a small thing, a very small error, I'll tell you small thing, huge ramifications, right?
So we're really gonna have to get a lot more deterministic about how we do these things. We're gonna have to have, people are gonna have to get some damn discipline at the code level. And I am tired of us MSPs taking the fall for what I consider just sloppy, lazy or, or greedy companies not spending the time and effort to harden their systems when their systems are part of a cybersecurity ecosystem. Yeah. There's really no excuse, right?
It's like, tell 'em airplane manufacturer, don't worry, don't worry about the, the doors, you know, I mean, the doors are the least thing we worry about, right? It's just the seats we care about. Uh, it's the same thing in this case. So, yeah, I, you know, you have to design this stuff. Like, and, and Aaron and, and McKenzie will tell you, you can look at a config file from someone's firewall and tell a whole bottom a ton about an, uh, whole organization.
I literally, it tells you more than what the lines are and what, what it does. It tells you how their minds are organized. It tells you what their logic is. It tells you how they go about doing what they do. It's like reading your poem for somebody who's an actual palm reader. So it's very difficult. And, and McKinsey, this segues right into the next question I had for you is, look, I mean, from a technical perspective, is this just, are we seeing a flaw, a base?
And I, I have in my own opinion, but I want to hear yours is are we seeing a flaw in the way the design and architecture, that software on the, for the device itself, the for device and how it's built? Are we seeing that it's being exploited so much because of a flaw there? Or are we, or is it more on the side of configuration errors? You know, what's your opinion on that? I think, I mean, I think it's both.
Um, I think on one side we have had significant, like you said, supply chain issues and scenarios over the past five years, especially. Um, we've seen packaged it, we're almost desensitized to whoever vendor it is because it could be, um, everything from SonicWall releases a bunch in three weeks to what Aaron and I are dealing with Fortinet and trying to connect the dots, because there is also a lot of Fortinet FortiGate, everything's getting released right now.
So yes, on one side, I absolutely think that it is a software issue. Um, and again, not to be doomsday, but I, I'm concerned that there are more out there that haven't been revealed. This is a lot what Aaron and I'S team works on from a research perspective, is we see things in the wild. This is the benefit of having a sock.
And when you pull apart what it look, what is going on or what the threat actor did, we can examine the actual version and what's going on with some of these devices and say, wait, these are clean devices, these are patched. This is, we can't figure out how they were able to execute some of these tactics on this system. And that's when a lot of these zero days come up, like, oh, wait, there might actually, oh crap. There's actually zero day on this, we think, but we have to wait to confirm it.
And this happened a lot with the Clio stuff. I was gonna say, that's what Happened with cle. Yeah. Literally Every single mdr RI can tell you, we're all seeing the same thing in real time. It's almost like we were holding hands together because we were like, this is, this is a zero day. Like this is getting hot. Um, so yes, I, I think we're gonna, I think the, the software aspect, I, I think we don't see the full picture yet.
We're only picking up almost pieces of the breadcrumb, and it's a matter of time before we see a full on. This is also the concern we have with these vendors is, like you said, this is an opportunity for POCs to be developed on how to be able to dump things like config files, use firewall PA rules, use the passwords and creds, and then the syndication. Aaron's talking about the opportunity for ransomware operators to say, oh, hi, shake your hand. Let me take this data.
'cause I could use this also. And then the conversation around persistence. My biggest concern has always been in past experiences, a backdoor or something more silent, getting hit on or hidden and embedded, like you said, in some of these vulnerable locations of these software. And there is something more deeply rooted, connected in all these systems, whether they're patched or not, which is a zero day, but it's more a persistence mechanism that concerns me. And then, yep.
The other side of the coin is misconfiguration. I mean, it's no surprise, um, Aaron can attest to this too, and all it's, it's either, I think there was actually, I'm, I'm, I'd have to look up the stat, but Microsoft pulled out the, the recent stat for the MDDR this year is everyone's concerned about, you know, social engineering and phishing, but it's misconfigurations and weaknesses. That's one of our biggest issues that we have collectively.
And so it's one thing to be able to say, okay, well, can you use A VPN and put MFA on it? It's like, no, but can you use a VPN only trusted devices or trusted ips? You're connecting to a jump box internally that's even saying you, like are creating multiple, the zero trust concept, multiple layers of that buffer zone, um, to be able to access it, making the threat actor say, okay, this is too much work. Let me just socially engineer someone and get in.
Instead, You just made Phyllis Lee really happy at CIS with, uh, secure configuration. Mackenzie. Too bad. She's not. Oh, Good. Yeah. So I think it's both. I mean, yeah, a lot of my answers will be, it depends. D all the above or both, but yeah, Bob, I think, I think misconfigurations are something we all are having big issues with. And then my doomsday brain is like, there's just something more to this that would be way more impactful than a bunch of RCE vulnerabilities, right?
A bunch of authentication bypass capabilities. Like, we're gonna continue to see those, but I'm more worried about the vendor getting hit at a deeper level in the supply chain. Yeah. The, the thing that I find ironic is how easy it is to get either a tool or even in, in readily available help in looking at configs to tell if they're configured to best practice. It is not the hardest thing in the universe at all, right?
To get some help on a device that you've got, just to make sure you got best practices, um, re related to the configuration, right? Yeah. Geofencing and all the other things. These are small requirements for a device that is so critical to your, to the ecosystem, right? So it, it floors me how easy that is and how many people don't take advantage of it.
So that as it relates to this particular actor, I mean, something was interesting, and again, I always have an opinion about these things because I'm like, you, I think this is, this is a long-term play, and I think some nation states are involved, and I think they're involved in getting access, and I think they're involved in putting that out for all of the little, the two dudes and a dog that want to go create chaos and try to make some money.
And I think they're just seeding that ground, right for that. Because when they really want to disrupt us, what's gonna be the best possible cover if it's coming from a hundred different directions, a thousand different directions, and it's little things that keep us occupied while the big things are actually going on, right? I can see this, this, mm-hmm.
I'm like you, I'm concerned about our inability to connect the dots with these things and understand that, hey, these are, in my mind, these are precursors to someone setting themselves up to be able to disrupt us in a big way at a much bigger level than just an enterprise. I think these enterprise ones are people getting the benefit of that data being released. And that, that was a question I had for you. What's the deal with them releasing?
What do you think the deal is with them kind of releasing this data and not just holding onto it? Because again, I, I think I got my opinion, but I wanna hear your errands shot on that. I mean, that's a, that's a really good one. It's been two years. They, I mean, they weren't obviously the original threat actor group, right? Um, I, they're a fair, it's a fairly new group that's coming out.
I think what we see a lot of, um, and Aaron and I can, you know, drink whiskey all day long talking about this pretty much is the affiliation changes of these nation state a PT groups. We are just barely, like you said, too many pandas. There's just so many groups out there now. I mean, we're looking at our top ransomware ones that we commonly see. We're seeing what Clop is doing. We're seeing how Ransom Hub has become extremely popular as well, but it's based on the amount of attacks.
But then you look at Alf v Black Cat, and then you look at new up and coming ones, how do we know that's just not a spinoff of the other group? Exactly. So I Think that's, that's the biggest issue I see too, is we're trying to narrow it down to these threat actors, which those are valuable to have some profiles around them, but it doesn't necessarily tell us the big picture of this. Why would they leak it now? Right?
How do we know this Belsen group isn't just an affiliate of another larger nation state A PT? Yep. Yeah. You know, they're basically saying, Hey, here's a be my friend, we cleaned up this data for you in a very nice sub folder so you can access all the things that you wanna get. And, uh, there's a high likelihood that a lot of these are gonna be helpful.
I mean, what we did too is, um, a, a big part of us is like, okay, how do we take some of these real time events, what our SOC is seeing and start to do hands on partner outreach. That's the big goal for us, is how does it impact our partners? How can we help 'em now and get ahead of the game? And some of the stands we've doing with the Fortinet stuff, there was a handful of them coming back as WatchGuard. This is just mm-hmm. Cross correlation.
But as a really good thing, we reached out and said, Hey. They're like, oh, well we don't use Fortinet. Like, okay, well, we're seeing this. They're like, it's watch card, but we didn't know it was exposed. So actually, thank you. This is concerning. Everything is an opportunity at that point. We're like, okay, yeah, here's, let's look at that, then how can we help you remediate it and harden it?
And that's, you know, we're almost, we're we're, I don't wanna say we're losing the game, but we're too far behind the bad guys at this point. We're far behind. So we're just trying to make predictions and keep up with them. Bob, can I answer your question indirectly? Yeah, please. So, so I really like the question actually. Um, so, so a my gut kind of tells me like, this is just chaff or, or noise, right? It's out there to distract.
I could be wrong, happy to be wrong, but it just, it feels weird, right? The timing and it's an all that right. New group. I don't know. There's a lot of weirdness there. The, the thing we need to keep in mind, tying into what McKenzie was saying, it's really important to understand, especially for MSPs who don't deal with this stuff every day.
There's multiple groups out there and, and those affiliations do shift and, um, not necessarily exclusively, some of them are sponsored by nation states who then give the money to organize crime, write the research, to organize crime, who then go out and further those nation state objectives and oh, by the way, make money for themselves, right? So it's really complicated that way. Really muddy. The, the thing that's not appreciated out there is there's multiple layers of groups, right?
So you have the initial break in group, right? You've got the guys out there who scan, right? Then you have a smaller percentage of that, let's say 10% that actually go kick in the door and break in, right? Those guys generally not always will go sell that access to somebody like a data broker who then har goes internal to the network, harvests the data, steals the data for that double extortion that we're now well familiar with, right?
Pilfer that off and then sells that access yet again to a, a ransomware group who's gonna exploit the network. The dirty secret is the ransomware guys might actually implant another backdoor if you don't have a good IR process there, they might actually resell that access yet again. Yeah. Right. Now that doesn't mean that all of those pieces aren't part of one master group, right? I don't wanna push any country out of the bus. So let's say the Ians right.
Have, have an intelligence organization. Yeah. Right. They could be doing all of that, but it could also be a loose affiliation of groups, some of which are sponsored by states, some of which are sponsored by organized crime, some of which are sponsored by all of the above, that have various interest in each of those pieces. Yeah. I find it fascinating. I think you and Aaron, we could sit in a room and draw this on a, on a big ass whiteboard, right?
And it would be really interesting to say here how that all that ecosystem kind of ties together based on what we can see externally. So yeah, It's gonna like the always sunny in Philadelphia guy, right? With where Yeah. Yeah. Right. Whiskey, Yeah. The prediction today is, yeah, more ransomware coming from the east. Yeah, I'm with you. Right. Alright, Andrew, over to you for now. You got the, yeah.
Um, so, so Aaron, you know, one Thing I am curious about is, is the timing of this whole thing, right? Right. So we, let's just go back 5, 6, 7 days. This, I forget exactly the day, but we had this 40 for gate, uh, vulnerability, another zero day, um, that came out. Then, you know, the, this comes out. So do we have a sense, is there correlation? Do we have a sense of, you know, how do they get all these configs? Is Fortinet saying anything?
Because, you know, they would've had to get to Fortinet themselves into some master database, and I haven't read anything about that. Does that make sense? That it does? Um, yeah. Yeah. So, so not to sound too paranoid, and maybe I am, man, that's fine. Um, I don't believe in coincidences, right? I just, I bet between my military time, my intelligence time, right? And my time is like, there's not that many coincidences, right? So yeah. Are these two things related?
I would, I would bet a steak dinner on. Yes. How? I'm not sure yet, right now, maybe some of this was this, this exploits has been out there much longer than we know about, right? Just because it's a zero day doesn't mean the adversary hasn't been using it well ahead of time, right? Or was there, uh, I think Mackenzie said, you know, was there another one that they were harvesting? Right? Um, it it, it's really hard to tell, right?
And, and you know, the actors aren't really gonna go out there and, and say much, but, you know, maybe they got burned. Maybe they realized that this one was getting burned and they got sloppy and, you know, um, or maybe Fortine got lucky and caught it, which is what it appears for the, the latest one, the 9.8, right? That's a really severe remote access vulnerability. Right? And that's why I'm suspicious about this lead credential thing coming out.
'cause it, it seems to be taking our eye off the ball, right? The, the, the current one that's very nasty. We're looking at, you know, hey, this thing that happened maybe two years ago by this weird unknown group, and there's all this credential spillage, right? Like, it, it feels like we're taking, they're, they're, they're shaping us to take our eye off the ball. Again, I could be totally wrong on that, but that's, that's kinda what my gut tells me. Yeah. Mac, did you have any comment?
I saw you shaking your head a little bit. Did you have anything you wanted to add there? No, I, I mean, I agree a a lot with what Aaron's saying is it, it wouldn't shock me. It wouldn't surprise me if this is, like you said, low hanging fruit in a way. Mm-hmm. Mm-hmm. Um, not necessarily a distraction, but absolutely low hanging fruit vulnerability that we're all aware of. Even the data dump, like we're all not surprised by it.
We're more intrigued by, I would say, I gotta be careful how I p**s off people. Um, No, you don't. Black And low, let's go. I'm like Wrong with it. Let's go. Um, I think we're gonna need to have, we're having one conversation on the misconfigurations and, and actual adoption of things that we want people to run through, right? Like, if you, like, why are we still exposing our management interfaces? Why are we still doing that?
And if you have to, like maybe if, if you can't stomach limiting ips, go through again, the VPN jump box. Let's try and like work together to create a solution. But almost some of these solutions feel like band-aid solutions, because on the other side, I'm more concerned about vendor transparency. I mean, as I've always been.
But we're seeing, when you start seeing 20, uh, vulnerabilities or zero days getting hit in a year, you're really curious of what have you guys done from an after action to clean that up? Like, what does secure design look for you? Like, why aren't you talking about your equities process? Like, who discovered this? Or how were you notified this existed in the first place? Right?
Because researchers are doing, I'd like to say research searcher communities getting a little bit better where we, they don't automatically post a POC online. In many cases. They do reach out to the vendor. But then how does everyone else see the other side of that? Like, who notified you? How did they find it? Was it found in an active incident or was it someone just stress testing the system? Like, so those are all the unknown questions of transparency that I'm, I don't have a lot of faith.
We're gonna get those, um, from any vendor, you know, but I, I do, that's where my curiosity always lies too, is like, how did they find it? Because now we're, we're kind of all like not working together in that realm of getting ahead of it. Yeah. Fair.
So, so Aaron, I got a question for you the same, and I'm gonna pose it to Bob in a slightly different way, but for you, if you're an, you know, a customer using Fortinet right now, and hey, it's patched, or you just, you patched this and you know, what, what's the recommendation? You know, are you really patched if we look at the Clio thing? Like what, what if you were, you know, just a consultant today talking to an organization running the Fortinet?
Like what are, what's the con, what's that conversation look like with their it, you know, leaders? Yeah. So, so cut me off if I go too deep here because it's pretty complex. Um, there's no easy answer, right? So, so MSPs in particular have a challenge where they're trying to remotely administer a lot of these boxes in a lot of different places that are probably geographically disparate, right? That's, that's not easy, right?
But the big thing is, we gotta get these remote management ports off the internet, right? They need to be secured, um, wrap 'em in SSL or you know, some sort of VPN, right? We talked about earlier that that might not be the right answer either, given everything we've seen. Um, zero trust, sure. But it's really hard to get zero trust, right? For the most part, from what I've seen. And you, if your user base isn't ready for it, I, I think was Bob said earlier, right?
They're just gonna work around it and it's gonna undermine you. Um, so, so get 'em off the internet, right? That, that opens up its own set of challenges. One of the things we've gotten away from in this industry is foundational blocking and tackling somebody in the chat posted it. Um, and, and getting back to basics, right? Like we don't do network segmentation anymore. We don't do auditing of the firewalls like Bob talked about anymore, right?
We just put it in the cloud and we assume everything's good. Well, kind of, except there's a, a new, um, ransomware, uh, tactic out there that adversaries are using where they're just, there's cred credential stuffing into your Amazon account and then encrypting your Amazons, that that's gonna be much worse than i, I think, or much a much worse impact, right? For you than if your, your local onsite Veeam got nailed, right? Because AWS there's a lot of data out there, right? Yeah.
So we need to go back to kind of the blocking and tackling network fundamentals, really look at how do we do secure access that's MFA, all the stuff we talked about, right? Probably IP whitelist, as bad as that sounds right? But there's, I mean, we're kind running outta answers. Yeah, yeah. I know, right? It does work mean It actually does work. Yeah.
It, I a lot of these things don't have price tags too, but I just love that you said network segmentation, not a, a lot of people have been Saying that later. Yeah, that was awesome. Network segment, cramp stamp tattoo of zero trust, but everyone forgets that it's, that's Big Mac.
I can't remember if I, I told you this story or not, but one of the last IRSs I worked was a, a small, we'll call 'em, we'll say they're in the manufacturing vertical, and they had offices all over the US and one overseas, and the adversary popped the overseas network and the MSP saw something happen there. They weren't sure what it was, but they dropped all the VPN tunnels at that point, and that's safe. They're bacon, right? Because the adversary completely smoked that other network.
Um, just giving yourself time and space to, to have that time to think, right? Okay. Yeah. You know what, maybe our network admin will screw up every now and then and kind of take the service down for an hour or two. But you know what, I'd rather err on that side than losing everything to a ransomware attack. It's just gonna blow through a flat network, right? So I, I really do think that's important to get back to those fundamentals. That's fair, Bob.
Um, quite, you know, people don't like me talking hypothetical in the, I'm joking around in the chat, they're like, no, no more hypothetical. But, um, but Bob, you were, you know, let's just say you were running Fortinet that was in your stack. You know, you've, you've been dealing with this, you know, zero day and vulnerability after vulnerability and the web interface and the FortiGate os, et cetera, et cetera. Now this, what, what are you doing as an MSP?
If, if there, you know, are you, are you still trying to work things out with, with Fortinet, you know, as a partner? Like what do you, what do you, what, you know, 'cause third party risk management Eric sent brings that up as a lot, which is fair, right? You know, you, you're representing this cust this company mm-hmm. Right? Through your stack, through your customer, but you're, this is causing a lot of constant work for you because you can't sit there and bill your customer.
You gotta go fix it and patch it and whatever, right? So what are you doing at this point? Well, look, I'm gonna, I, so Fortinet can take a deep breath because I, I'll tell 'em this, it doesn't matter who the damn vendor is. If they have a pattern, like the pattern we're seeing in this case, then yeah, we're not on, we're not on that platform. We're not gonna, I mean, we don't wait until the 18th time, you know, something happens before we pull the trigger on this, right?
I mean, we're, we've got a really low tolerance for, for anything that comes from this. I can tell you SolarWinds was a perfect example. SolarWinds, we watched them very carefully for the next year, right? Because if there would've been a pattern established in that situation, we would've got our ass off of it. And I, and it would've been a forklift upgrade and it would've been difficult to do. It would've been all that opex cost to go pull it off.
We wouldn't have had any choice, though, at some point, if you're an MSP and the, and these patterns are forming and you continue to stay on that same horse, then whose fault is it at, at some point, right? I mean, at some, I mean, if you're really responsible for your customer's networks and this pattern, there are other pieces of hardware that do the same job that do not have this pattern.
So how are you gonna explain that to a customer that, you know what, I'm sticking with these guys 'cause I've known 'em for years and I get the best discount rate that is not gonna cut it, right? That s**t is not gonna cut it as a conversation with a customer. Especially when you're dealing with larger enterprises and you're doing co-managed work with them and they're taking your recommendations and putting in these much larger networks. You just don't have the luxury o of of doing that, right?
Yeah. So from an MSP perspective, regardless of who the vendor is, if a pattern starts establishing itself, we don't have a choice. I now, it's like you can't unsee it. I always say, you can't UNL a cat once it's happened, it's bloody well happened. You can't unsee that. You have to go and make something out. And to your point, the other, the other indirect point of this is, is if they're having these problems, the MSP's bearing the burden of the labor to go clean that mess up.
It's not like they're gonna give you an extra 20 points on the next device you buy Yeah. To cover your labor for cleaning that crap up. That's not how it works. Right? It's Also distracting the crap outta your, your sock and your team. And Yeah, it's a cultural problem at that point, right?
You're wearing your people out and they don't know where to, I mean, you know how it is, it, it, you, you shoot a shotgun off behind somebody's head long enough, they flinch when somebody rings a doorbell, right? I mean, so that's just stress on your team, so you just have to mitigate that. So you really don't have a choice, in my opinion, when patterns like to start showing themselves. I don't have to say anything. You're a logical person.
You need to make a damn logical decision in this situation. Got it. Which we would do, you know, categorically we would do. Cool. Good. Good. Well, good to, I, I love it, Bob. Um, Aaron, I was gonna ask, you know, we've talked about the next question a little bit, which was, you know, sun setting older architectures, let me, and, and in favor of like A-Z-T-N-A. We beat that one up and, and the, and the chat beat that one up. So, but, so let me ask you a little differently.
Um, and again, this is opinion, um, cyber insurance. What, what do you think is gonna happen there? Meaning, okay, you know, like, you know, are they gonna sit there and go, Hey, look, to Bob's point, you know, you're sticking with the solution, it's known to have, you know, defect after defect after defect. Um, no, we're not gonna pay, it's your fault for staying with a fault. Like, could we see the, because insurance companies can pretty much do what, what they like to do. Mm-hmm. Right?
It's almost like, you know, we, and, and here in Florida with the hurricanes, you know, there's Yeah. You know, there's certain, there's always these causes to allow them, uh, well, that it's your choice to live by the water. It's your choice to do these things, so therefore we won't pay.
Um, what are your thoughts that might start to come out of these recurring companies that are having these zero days vulnerabilities and, and then going to your cyber carrier and going, okay, we need, need you to cover this. Yeah, there's a lot there. I I do agree. I think there probably will be some pushback from the insurance industry, right? At some level trying to assign blame maybe to the MSP, maybe to the owner. Maybe there's some litigation coming.
I mean, you, ulo ELO reform really needs to happen, right? The fact that you can just have a mandatory click through piece of, of code, uh, or text on your, on your device, on your software or whatever, that just completely removes all liability from you, just doesn't seem like a, a, a viable solution, right? Especially with the threats we're facing. So I I think it's probably gonna be some interesting litigation that comes out over the next year or two.
Um, I mean, I think we're seeing a little bit of that from the CrowdStrike debacle, right? That's happening at least some of what's been reported in the press. So, so that might port force some things. I think we are going to see, um, insurance companies definitely look at and be more strict on like, what are you putting into your network, right? Who's responsible for that? Who's patching it? Right? And, and you're right. I mean, they're not in the business of, of cutting checks, right?
And, and they probably shouldn't be, um, for, for that, um, to, to stay in business bottom line. Got it. Um, so, um, sorry, I'm just getting rid of somebody. Yeah. Can we boot that guy? Yeah, I am, I'm doing, yeah, yeah, I saw that. Yeah. Really horrible. Um, Gimme the idea of that person, please. That's, that's the kind of thing you should do, right? Start taking shot at cybersecurity people. Yeah. All right. So we got rid of that person. Yeah. Okay. Um, yes. Okay.
So Aaron, About to go turn into a fight club In here for a second. Alright, so, um, Aaron, last one for you, right? And then I'll turn it, Bob. But, um, what are you guys seeing, you know, like, are, are you seeing, I guess, patronistic, you know, Ms P like MSPs having multiple of their customers dealing with this, and if so, how are you kind of coaching them through this? Are you seeing exfiltration, are you seeing, you know, um, kind of a concentration at, at a, at a single MSP level?
And if so, um, how is, how are you guys working through that To, to go back to Max, uh, earlier answer and it depends. Um, yes. There, there, there are some people, right? I think Bob, Bob made a really good point about, you know, hey, this, this is kind of the horse you brought, right? And, and you've got a lot of investment there. You get good points on that for your business deal, but this is gonna have to be looked at.
So yes, there, there are certain MSPs that have concentrations of this, right, of, of these types of problems, right? They, and they're not all gonna be the same, right? So we are gonna be deep in masonic walls. Some are gonna be deep with FortiGate, some are gonna be kind of a mix. Um, some are not gonna have any, um, the, the trick is you should always assume that data exfiltration is happening, right? Mm-hmm. It may not, but it's, it is really a, a good going in, right?
Just like we assume breach, right? We should assume that somebody's going to try and exfil our data if they can get a hold of one of these devices, right? Whether that's a misconfiguration just punching a hole in your firewall, pulling the data down, right? Whatever. Um, there, you should assume that data is going out because that's really the important part of that double exfiltration scheme. That's, or like the double extortion scheme that we're seeing.
Just curious, are, is any of this potentially, like, are you seeing any, um, I don't know, blo, uh, I guess for lack of a better word, holes in the logging data? Like, is there any of that going on where you can't, you know, part of this, um, you know, you know, the, the, the, the reason they're doing this is to, you know mm-hmm. Uh, obfuscate, uh, exfiltration because they have access to these configs. Is any of that possible, Aaron, that, that this is part of it?
So are we seeing that currently? No. Is that something that a moderate to advanced attacker could do and does do? Yes. Um, they, they will definitely send your logging to the ground, right? They'll inject bogus data, um, things like that, that, that is certainly possible. Um, and especially when you're controlling these boundary devices, right? One of the, the powers of modern EDR Sims, right? Everything that we're sending everything up to the cloud, all that's gotta route through.
And if we can modify DNS at a boundary device, right? We can, we can send that to ground right now. That's, that's an advanced hacker that's doing that, but that, that is certainly possible. Um, and then that kind of, I think where you're going with that, that raises the possibility of yeah, we're not seeing everything, right? Yeah. And, and, and by we, I mean the industry, right? Right. They're, they're, are we seeing that currently? I don't think so.
We we're seeing attackers that are good enough to get the job done, and they kind of don't care. Okay. Right. Okay. Um, but a more advanced attacker, somebody like a salt typhoon or something like that. Yeah, that's totally possible. Okay. Got it. Alright, Mr. Miller, back to you.
All right, so let's, we're gonna talk a little bit tactical now, McKenzie, because I mean, you guys are a threat intelligence organization, and, and I don't think most people understand the process of actually building that threat intelligence, right? Because I don't think they know about the volume of telemetry that you're getting when you're actually pursuing an event like this, right? To determine what the, what, you know, what the depth and the complexity is.
Could you, I mean, can you talk a little bit about, I, I know how many volumes of records are pouring in, right? Because, you know, we have a, so, so we see the same sorts of things, but making any kind of sense of that is the thing that I think is the magic when it comes to people who really know how to do threat intelligence.
So how do you guys, you know, what, what do you look for in prioritize in telemetry when you're first taking a look at an event like this to figure out, you know, try to start establishing what the, what the framework and the foundation of the attack is, because you gotta know that before you can go figure out how to, you know, run it to ground. So what kind of things do you look for and prioritize when you're doing this? Well, I'd say from the Intel side of the house, right?
The, our first phase is understanding what we're looking at in the, in, in general in front of us. Um, if it's something like this being a zero day, how is it exploited? What does that actually mean? How common is this? Or is this kind of like a new technique versus what we see all the time for half the exploits that are getting thrown out there? Can we blow it up? Um, and then because you know, we're Black point, we, our MSPs are our partners, right?
We are looking at the MSP side of the house. Why does this matter? So criticality of the thing in question, is this something that MSPs commonly use? If we're seeing things released into the environment that are interesting to us as far as like the S3 buckets for AWS and how those could be potentially tackled, that may not necessarily hit all of our enterprises.
And I'm sure Aaron could actually, I'm just thinking of all the other ones in the past week we've looked at where we're like, do MSPs really care about that right now? And how much of an impact is it? So it's really first addressing why does this matter and what is the impact? And then also getting the temperature of the equities process and where you're at with it. As far as disclosure, who found it are there POCs out there right now to exploit it.
All of that kind of bundles together as far as we've contextualized what is in front of us, we are able to define what it does and how, what the impact could be. And then for us, it's phase two, what is the actual impact to our partner base? Um, a lot of these get hit and you see Matt Lee out there all the time doing it, and I love it as the first place we go is showdown, you know, especially in a lot of these cases is what is the general impact to society just off the bat.
And usually it's pretty big, but for us, we need to narrow it down to our partner base. And then we need to filter out from our scanning procedures, who's actually impacted by this specific right. Outdated version, this specific vulnerability. Like who is impacted and how do we define remediation steps that are plausible and realistic? Giving them a whole list of, right, everything we've talked about today as far as trusted ips and do this, that would be great.
We could absolutely sit on the phone with them and do that, but we're going to find the most reasonable remediation steps for them off the bat. And those tend to be sometimes redundant after a while because they are the remediation steps we recommend.
So from an intelligence is we are looking at what's going on out in the wild, we're comparing it to what's going on in our soc because a lot of the things that we're talking about now, with the edge being targeted, we're concerned about postex, exploit, traversal, uh, they're gonna gain a lot off of this just from what we're talking about, right. Um, from a discovery perspective, um, uh, privilege escalation.
But we are going to really focus on the trade craft that we commonly see, which is that lateral movement. So there's one aspect, how, what is our soc scene, how we can, how can we empower and educate our analysts? Are we all, we all have a pulse on what's in the wild? What's going on? Have we been able to now take all of this information and make it actionable?
And that's really the, what the goal of intelligence is, is we have the research aspect and the cool collection aspect and the reporting and dissemination of it, but it's how do we make it actionable? Because that's what MSPs I know really want is action. So how are we providing steps? How are we keeping the conversation hot? How are we tracking historical relevance of other vulnerabilities that could be connected to this?
Like what we've been saying with one vendor, how can we predict they're going to potentially change? How can we predict from a business perspective, MSPs, like you said, moving off of specific vendors and that's gonna change a whole lot of pathways, right? They're gonna move from one vendor, they have to go to someone else, and that's a new target. And everything that we're looking at from an intel, I always just assume adversarial groups are doing the same exact thing. Oh yeah.
They're understanding where we're at in this thought process. And so action actionable intelligence is what our gain is in this, in this respect. Yeah. Alright. So I, and you know, the, we keep talking about this patching and updating. So I mean, I I, I keep trying to come up with some sort of equation to tell me what percentage of people are just not any good at this, but it's so, you know, it's so depressing to think about, to be honest with you.
But I, I, you know, the point of doing these measurements though is to be, is to look at a relative statistic. Are we getting better at it or not? Right? So from, from black point's perspective, um, are we seeing, you know, what are you seeing? What does the trend look like? Because look, the break-ins are happening. I mean, we see 'em all day every day. But I think the question is, are we getting better at this particular aspect of running, you know, our operations or, or is or are we not?
You know, and the only way to really know that is to kind of look at it from when, when the flames are lick in the ceiling, that tells you that's not getting handled and how many flames are lick in the ceiling over what period of time is kind of an indicator.
So from you guys perspective, years and errands, do you feel like that's getting to be, is that being addressed better or the same because I'm not gonna say worse 'cause I don't, I don't know how much worse it could actually get to be honest with you. So I'm gonna say the same or better from your pers from your opinion. Uh, I really, how could I be optimistic? I I would probably say the same. I don't think it's getting worse.
I think it's getting a little bit better, but the level of improvement, not enough. We're, we're still seeing things unpatched and exposed. I mean management interfaces exposed to the internet. This is insane. Yeah. From years ago. And this cuts the time. This cuts, yeah. From years ago. And that cuts the threat actor's time to execute.
And then everything Aaron was talking about, all the other vast opportunities a threat actor has once they're in, yeah, that could be persistence mechanisms, selling initial access to brokers, data dumps, and exfiltration. Now we're seeing all of these file transfer based softwares getting hit 'cause LIO wasn't the first one.
Like, we're seeing all these patterns, but we're not, I don't, I don't know if it's a, it's a matter of improvement versus what you, what you said relativity and really saying, okay, how can we improve? 'cause people are still exposing themselves. Hopefully that doesn't get like clipped, but like they're still exposing themselves to the Outside. What a great hot take be sure and get that one. We Need to be more, I know what my LinkedIn post is tomorrow, Mac. Yeah. Everyone's flashing each.
But yeah, I, I would say if I was to really look at it the same 'cause the conversations our soc analysts are having with partners probably on the phone to manage some of these things, it's the same thing. We're just recommending the same stuff and I think, um, things get overlooked, right? You scale it just like you'd scale a business. You're gaining more customers or clients, you're gaining more network environments.
That's a lot to handle, like you said, resource constraints consistently to keep up with all of these things that we have to manage. Um, secure configuration and having some sort of baseline is, is the ideal goal. But people still, you know, realistically struggle with that. And MSPs absolutely were struggle with that.
So I mean, you, you'd think auto updates would be something we could point to say, Hey, but you just do auto updates, but we've seen what that's done to us over the last few months, right? So you can't even really depend on that. You know, it just, it, it is just such a cognitive load to understand the scale and the scope and to manage that in a, in a realistic way. And, and that workload's not getting any easier. Like you point out Absolutely not. Andrews back over to you, sir. Yeah.
Aaron, last few minutes here. Hey, it wouldn't be a webinar or a podcast these days without using the term ai, would it, Aaron? Um, but, but again, you know, LLMs, you know, I was fortunate enough to do a webcast with you, which was awesome.
Um, but I am curious, you know, whether it's file transfer, you know, software or these, you know, firewall, internet facing, you know, um, management, uh, or uh, that this commonality is, is there any, in your estimation, you know, going back to your threat intel, you know, your intelligence days, right? Do you feel LLMs are being used? Like, you know, it's like, hey, there's some fire here, let's just keep pounding on this thing with machine learning.
Because I mean, it would seem that if I'm a threat actor and I keep churning at this over and over and over, because that's what I mean, just my layman's brain is thinking is, is is it possible that, that they're using some of that and, you know, type of technology now to help them with this? Short answer is yes. Um, longer answer is right. Not only LLMs, but you kind of hit on it there. Machine learning, right? All the subsets of artificial intelligence are, are being leveraged.
Are they autonomous? And are the terminators gonna get us tomorrow? Not in my opinion, are they speeding up some workflows like you talked about and augmenting the adversary as well as the defenders. Yes. Right? So again, I I think we talked about it on the last one, right? This is the 10 foot wall, 11 foot ladder problem, right? Where, you know, we've, the defenders built in some AI to help trade craft, right? Speed them up on some things.
They built that 10 foot wall and the adversary saw some of that and said, Hey, that's awesome. Let me build something that's gonna speed me up, right? And now they've got the 11 foot ladder. Um, I, I think, I don't think, in my opinion, AI is never gonna become sentient, right? We're not gonna have, you know, the, the terminators walking down the road, but we are going to see a bit of an acceleration and, and pattern matching is gonna become very important, right?
That's, that's really what machine learning is great at, right? It's finding those patterns, right? And those things, those, those trade craft screw ups by the adversary, right? Where they come in, where they beacon out every five minutes instead of randomizing it, right? Things like that. So, short answer, yes. Got it. Um, so, so in closing, here's, here's what I'm wanting.
You know, if there's kind of the, you know, nugget recommendation, you know, for the business leaders, um, that, that are on the MSPs that are on, you know, to, to deal more effectively with this common thread that we're seeing with these internet, you know, facing devices, again, whether it's firewalls, um, whether it's, you know, file transfer protocol type things, what, what would the guess one nugget you'd leave them with Aaron? Don't assume you're not a target.
Um, I still hear it far too often. People say, oh, nobody care about me. I'm just a little old business down in Louisiana with Bob, right? Who, who could possibly care about me. Um, the, the Internet's worldwide, it's global. You are a target. It doesn't matter how many people you have. You may be a means to an end, you may be the end state, but just don't assume you're not a Target. Yeah.
And isn't that possibly, I guess isn't that what automate, like in other words there, automation isn't looking specifically at company X, right? Automation is just being opportunistic. Isn't that Exactly. For sure. For sure. Yeah. Awesome. Mac Aaron, that was phenomenal. Really, really, uh, insightful. Great views, Bob and uh, yours as well. Really great stuff today from you as always. Um, alright, thanks. Yeah, thank you so much everybody, and, and, uh, the, uh, our attendees.
Thanks a million for all the, the fantastic comments and, um, really appreciate you guys as always as our community, um, helping out each other, um, and, and, you know, making the best of, uh, making each other better. So with that, um, have a awesome week. We'll look forward to seeing you next Monday and make it a great day, everybody. Take care. Thanks everybody. Thanks Roy.


