Loading summary
Andrew Morris
Foreign.
Katalin Campano
This is Katalin Campano and this is a Risky Business news sponsor interview with Gray Nose founder Andrew Morris. Welcome, Andrew.
Andrew Morris
Hey, Catalyn. It's great to be here. Good to see you.
Katalin Campano
Andrew. Your company operates a gigantic network of Internet honeypots. So how bad is it now?
Andrew Morris
It's bad. So the we're seeing an increase in sort of the volume of. Net new vulnerabilities that are being disclosed against edge devices. We're seeing zero days that are being used against edge devices thrown across the Internet exploited en masse. We're seeing shorter periods of time between vulnerability disclosure and automated mass exploitation. And we're seeing vulnerabilities being weaponized not only against sort of for old vulnerabilities, but even kind of for end of life devices where the manufacturer's just not going to do anything about it. Like the Zyxel vulnerability recently, like the guidance from the vendor is get rid of the thing. Right. Like they're basically just like, hey, sorry, we're not going to do anything about this. Buy a new product. And so how bad is it? It's pretty bad. And to tack on top of all of that, we're seeing an increase in the amount of vulnerabilities being exploited in security products themselves. So the products that are supposed to be tasked with protecting users and protecting systems, secure gateways, VPN gateways, things like that, bad guys are exploiting those. So I'm not sure exactly where we're to go from here, but the answer is it's pretty rough. It's pretty rough.
Katalin Campano
Yeah. My second question was if your customers are still coming to you because of edge device attacks. So that would be a resounding yes?
Andrew Morris
That would be a resounding yes. Yes, that is right.
Katalin Campano
I know you have your yearly thread report coming soon. Can you give us a preview on what's going to be in it?
Andrew Morris
Yeah. So, I mean a lot of it summarizes what I just captured. We've got a lot of hard stats in there about sort of the average time of exploitation of given vulnerabilities. We have some color on what on how to tell if a vulnerability is likely to be mass exploited. So basically just some statistics about the vulnerabilities that adversaries like to target as well as some sort of statistics about what families of vulnerabilities people like and the types of devices that they like going after. And then we've even got a little bit of color about sort of some of the botnets and the devices or the endpoints or rather the the devices on the Internet that we're seeing this kind of exploitation from. For example, we've seen certain campaigns coming out of a large network of hacked Android devices. Part of what makes this so big and hairy is that. And we've seen this corroborated by write ups on Volt Typhoon. Lots of the exploitation itself comes from existing devices that are hacked inside of these botnets to grow them and then, and then be used for, you know, other interactive operations by bad guys, so to speak. So these are some of the things that we talk about in the mass exploitation report. It's, I would say, you know, probably a good percentage is net new vulnerabilities that have just been disclosed, but a very large percentage is old vulnerabilities as well, showing that there is a lot of value to attackers in weaponizing old vulnerabilities.
Katalin Campano
If I understood this correctly, we now have mobile devices being used as orbs to disguise traffic.
Andrew Morris
Not necessarily mobile devices, but smart TVs. Smart devices, yes, exactly. Yep. So think any kind of device that's gonna be running in a household or gonna be running maybe on an edge that's running Android, these are very much being hacked and used for some of these sort of mass exploitation campaigns, which just adds to more complexity. It's hard to put, for example, an EDR on these products, maybe impossible, because.
Katalin Campano
I'm thinking because of CPEs, you have many ISPs now that run tighter router and modem networks. So if you want to be in your residential ip, you got to go after the smart TV instead of the router these days.
Andrew Morris
Yeah, exactly. So it just adds even more sort of hairiness and complexity, especially when you look at like whose responsibility is it to do something about this? Because the buck can kind of stop in a couple of places. It could be the manufacturer's responsibility, it could be the Internet service provider and the hosting provider's responsibility, and it could be the security company's responsibilities or the software manufacturers, you know, themselves. So it's a hard, hairy problem.
Katalin Campano
You're talking about seeing a particular trend in what type of vulnerabilities threat actors like to exploit. Let me guess, is this path traversal by any chance?
Andrew Morris
Path traversal is one of them for sure. Anything that can yield remote code execution, lots of OS command injection, lots of insufficient access controls, lots of chained exploits with atomic, relatively low sophistication vulnerabilities that together can be chained to compromise a device fully. So, for example, a unauthenticated file disclosure may not be a big deal. And A authenticated file upload vulnerability may not be a big deal, but those two vulnerabilities together may yield complete device takeover. So those are some of the kinds of things that we're seeing.
Katalin Campano
So basically everything that can either retrieve a config file or just run the malicious code right away?
Andrew Morris
Yeah, exactly. And attackers are clever and they're very fast. More and more of this stuff is being automated. More and more of this stuff is being simplified to very small exploit payloads. And then beyond that, everything old is new again. People have been hacking edge devices for a long time using relatively unsophisticated methods. But yeah, it's not stopping or slowing down. If anything, it's speeding up.
Katalin Campano
We have a pretty competent and smart team over there. I believe you're probably tracking the time from disclosure to exploit, right?
Andrew Morris
We are, we're tracking that really closely.
Katalin Campano
Do you see a big reduction this year?
Andrew Morris
Yes, and it has been reducing every year for the last few years since we've been tracking it. It's down to same day at this point. And then in certain cases, sometimes even before disclosure, which is to say the attacker gets some kind of advance heads up that there is a vulnerability. Or perhaps they're the ones who identify it. Maybe it goes onto a forum, maybe it goes into a chat. Maybe the attackers are paying attention to some of the same channels that defenders are getting this, this information to or where the information is getting out? We don't know. But yes.
Katalin Campano
Do you have any theories why they're so fast now?
Andrew Morris
I think it's a few, and I don't have any sort of like tinfoil hat theories on it per se. I think that certainly it's basically just.
Katalin Campano
A few mega gangs that are getting better at the job with the years, right?
Andrew Morris
Yeah, yeah, exactly. I mean, just more automation. So attackers are lazy just like everybody else, and attackers are going to take advantage of automation just like anybody else. I don't think that the one sole answer is AI, but I do think that that could be a component of it. For example, we at Gray Noise are using AI to triage vulnerabilities as they're being disclosed to try to figure out whether or not like just skimming the list of CVEs that are being disclosed to everybody and trying to find, you know, basically vulnerabilities that are likely to be used by bad guys to exploit devices and gain access to edge devices. I think it's very possible that bad guys are doing stuff like that too. I don't think that that's the Sole reason, I really just think that this is a muscle and that bad guys are just exercising this muscle over and over and over again and just getting better and better at it.
Katalin Campano
You also mentioned a rise in the exploitation of EOL devices or dead devices. Is there any particular, I don't know, vendor or type of product that this is a problem?
Andrew Morris
I wouldn't say that.
Katalin Campano
It's mostly routers, modems. Right.
Andrew Morris
It's mostly routers, modems. So things that are gonna be running in a office, a small office, a home network, maybe in the sort of Internet backbone, so to speak. We're seeing a lot of stuff against NAS's so QNAP devices, things like that, Synology, maybe SoHo routers, our home and business network routers, things like that.
Katalin Campano
I don't know if this is relevant to you, but I'm interested in. In the volume of exploitation overall over years. Has this increased or has it gone down as they got better at it?
Andrew Morris
I regret to inform you that it has increased. So the Internet is definitively noisier than it was a few years ago.
Katalin Campano
Is this because now we have more honeypots and can see more, or is it just increased naturally?
Andrew Morris
I was actually. I was actually thinking about that a few minutes before I hopped on this podcast to talk to you. You know, certainly we've gotten better at it. We've gotten better at learning about reality. So I don't have a good answer for you. I don't know. We have gotten better at learning the state of things, so it's possible that we just know about more. But if I were a betting man, I would say that it's a little bit of both. And I don't want to speak for the entire security community, but I would say that we, as we Gray noise, are getting better at tracking these things. But at the same time, I think that attackers are increasingly looking at compromising edge devices. I think edge devices are just really juicy targets for a lot of different reasons. And I also think that it's just gotten more difficult, more expensive to compromise. Devices running Windows, for example. Right. Like they're just. It's just harder. Windows is more secure today than it's ever been and the EDR ecosystem is better than it's ever been.
Katalin Campano
Yeah. And most Windows systems are behind the edge devices, so you're not going to get them anyway. Your primary customer group is SOC teams, right?
Andrew Morris
Yep, that's right. So our. So we've got a few different large buckets of customers. We sell really well to security operations centers that are dealing with lots of alerts and would like to deal with a smaller amount of alerts. We also work with incident response teams, we work with threat hunting teams, and we work with vulnerability management teams as well. And then the types of sort of customers that we work with generally fall into three buckets. One is any enterprise that's large enough to have its own soc, its own IR team, its own threat hunting team. Two is gonna be global governments. So computer emergency response teams, hunt teams, things like that, that are government organizations, perhaps maybe intelligence organizations, and militaries that are tasked with identifying compromise systems, protecting their sort of sovereign governments. And then the third bucket is other security companies that want to take subsets of our data and incorporate it into the products that they sell to people.
Katalin Campano
Well, the reason I asked that was because of the nature of a SOC team. They usually see new types of threats that or emerging trends. It was interesting if they provided particular feedback or feature requests that hinted where exploitation might be going in the near future.
Andrew Morris
Yeah, so we do get. We get a lot of asks from our customers about. I would just put it in a bucket of like, strategic things. So like sort of strategic trends as well as sort of like you told.
Katalin Campano
Me earlier about attacks against antivirus system. This probably came from a SOC team, right?
Andrew Morris
Yeah. Yeah. So we will, as much as we possibly can, we'll get feedback and guidance from our customers on the sort of delta between the things that we see and what they're seeing, as well as gaps in things that we're not providing that would be helpful for helping them triage stuff or hunt stuff down.
Katalin Campano
Okay, when is this report coming out?
Andrew Morris
I think we're releasing it early next week.
Katalin Campano
The report is going to be out by the time this podcast goes. There's going to be a link on our website where you can access it.
Andrew Morris
Great.
Katalin Campano
Andrew, thank you very much.
Andrew Morris
Katalyn, always a pleasure talking to you. Thank you so much for having me. Until next time.
Episode Summary: "Sponsored: GreyNoise on 2024's Mass Internet Scan Trends"
Risky Bulletin presents an insightful discussion with Andrew Morris, founder of GreyNoise, hosted by Katalin Campano. This episode delves into the escalating challenges in cybersecurity, particularly focusing on mass internet scan trends, the proliferation of vulnerabilities in edge devices, and the sophisticated tactics employed by threat actors in 2024.
Andrew Morris opens the conversation by painting a concerning picture of the current cybersecurity environment. He emphasizes the alarming increase in both new and existing vulnerabilities targeting edge devices. "We're seeing an increase in the volume of net new vulnerabilities that are being disclosed against edge devices," he states (00:24). This surge is compounded by the rapid exploitation of zero-day vulnerabilities, often within days of their disclosure—or even before—signifying a critical lag in defensive measures.
Furthermore, Morris highlights the troubling trend of vulnerabilities being exploited in security products themselves. "The products that are supposed to be tasked with protecting users... bad guys are exploiting those," he explains (00:24). This underscores a paradox where the very tools designed to safeguard systems are becoming attack vectors.
Katalin Campano probes into how these threats affect GreyNoise's clientele. Morris confirms that the rise in edge device attacks has driven increased demand for GreyNoise's services. "Our customers are still coming to you because of edge device attacks. So that would be a resounding yes," he affirms (02:01). GreyNoise assists security operations centers (SOCs), incident response teams, and vulnerability management units in navigating this complex threat landscape.
Anticipation builds as Morris provides a preview of GreyNoise's upcoming annual threat report. The report is set to offer comprehensive statistics and analyses, including:
Morris elaborates, "We've seen certain campaigns coming out of a large network of hacked Android devices... a lot of value to attackers in weaponizing old vulnerabilities" (02:11). This indicates a persistent exploitation of both new disclosures and longstanding, unresolved vulnerabilities.
The discussion shifts to the specific methodologies employed by attackers. Morris outlines that attackers are leveraging simple yet effective tactics to compromise devices. "Path traversal is one of them for sure. Lots of OS command injection... yes, exactly," he confirms (05:05). He further explains how combining seemingly minor vulnerabilities can lead to full device takeover, enhancing the attackers' ability to infiltrate networks seamlessly.
A pivotal point in the conversation is the accelerated pace at which vulnerabilities are being exploited. Morris reveals a stark reduction in the window between vulnerability disclosure and exploitation: "It's down to same day at this point. And then in certain cases, sometimes even before disclosure" (06:20). This rapid exploitation is attributed to:
Morris sheds light on the vulnerability of end-of-life (EOL) devices, particularly routers, modems, and Network Attached Storage (NAS) systems. "We're seeing a lot of stuff against NAS's like QNAP devices, things like that, Synology... home and business network routers," he notes (08:16). These devices often lack ongoing security updates, making them low-hanging fruit for attackers seeking to maintain persistent access within networks.
Addressing the overall trend, Morris confirms a significant uptick in exploitation activities. "The Internet is definitively noisier than it was a few years ago," he states (08:55). This increase is partly due to improved detection capabilities but largely driven by attackers intensifying their focus on edge devices, which offer lucrative entry points compared to the more fortified Windows systems.
GreyNoise serves a diverse clientele, including large enterprises with dedicated SOCs, global government agencies, and other security firms integrating GreyNoise data into their offerings. "Our primary customer group is SOC teams... we also work with incident response teams, threat hunting teams, and vulnerability management teams," Morris explains (10:13).
The feedback from these customers is instrumental in shaping GreyNoise's strategies and offerings. "We get a lot of asks from our customers about... strategic trends... gaps in things that we're not providing," he adds (11:52). This collaborative approach ensures that GreyNoise remains responsive to the evolving needs of the cybersecurity community.
As the conversation wraps up, Morris announces the imminent release of GreyNoise's mass exploitation report. "We're releasing it early next week... there’s going to be a link on our website where you can access it," he confirms (12:18). This report is poised to be a valuable resource for cybersecurity professionals aiming to stay ahead of emerging threats.
Andrew Morris (00:24): "We're seeing an increase in the volume of net new vulnerabilities that are being disclosed against edge devices."
Andrew Morris (05:05): "Path traversal is one of them for sure. Lots of OS command injection... lots of insufficient access controls."
Andrew Morris (06:20): "It's down to same day at this point. And then in certain cases, sometimes even before disclosure."
Andrew Morris (08:55): "The Internet is definitively noisier than it was a few years ago."
Andrew Morris (11:52): "We get a lot of asks from our customers about... strategic trends... gaps in things that we're not providing."
Rapid Exploitation: The time from vulnerability disclosure to exploitation has drastically decreased, sometimes occurring within the same day.
Focus on Edge Devices: Attackers are increasingly targeting edge devices like routers, modems, and NAS systems due to their widespread use and often limited security.
Automation and AI: The use of automated tools and AI is enhancing attackers' ability to identify and exploit vulnerabilities swiftly.
End-of-Life Device Vulnerabilities: Devices no longer supported by manufacturers remain significant targets, posing ongoing risks to network security.
GreyNoise's Strategic Role: By providing detailed threat reports and analytics, GreyNoise aids cybersecurity teams in understanding and mitigating emerging threats.
This episode of Risky Bulletin underscores the escalating challenges in cybersecurity, highlighting the need for continuous vigilance and advanced defensive strategies to combat the sophisticated tactics of modern threat actors.