Karim Hijazi is CEO of Prevailion, a cyber intelligence company that monitors and detects active threats by infiltrating hacker networks. Hijazi is also a former director of intelligence for Mandiant and a former contractor for the US intelligence community.
Ransomware has taken the spotlight lately following a string of brazen attacks on major U.S. companies.
And as bad as this kind of malware is, businesses and investors can expect to face a growing number of sophisticated cyber threats that could be even more disruptive and difficult to prevent.
Here are five emerging threats to watch:
Tani Currin holds an "anti-selfie" mask during the Black Hat USA 2014 hacker conference at the Mandalay Bay Convention Center in Las Vegas, August 5, 2014. REUTERS/Steve Marcus
Wipers are a type of malware that can be even more destructive than ransomware because they are designed not for extortion they're for the sole purpose of erasing data.
Wipers havent been widely used up to today, but that is likely to change. As nation-states become more active and emboldened in cyberspace, we can expect to see more digital clashes that involve destructive cyber attacks.
There is nation-level precedent: Iran has been implicated in an ongoing series of wiper attacks against Israel amid an outbreak of cyber skirmishes between the two countries that escalated in 2020.
Iran has also been implicated in other wiper attacks over the years, including the 2012 Shamoon attack on Saudi Aramco, which destroyed over 30,000 computers, and the 2014 wiper attack on Las Vegas Sands Corp. North Korea also used wiper malware in its infamous attack on Sony Pictures back in November 2014.
And wiper malware is an equal playing field, meaning that it will not be limited to state actors. While wipers have less financial value for criminals, they are a potent weapon for terrorists, political activists, and lone wolves who are only interested in causing damage.
The logo of Aramco is seen as security personnel stand before the start of a press conference by Aramco at the Plaza Conference Center in Dhahran, Saudi Arabia November 3, 2019. REUTERS/Hamad I Mohammed
The emerging field of artificial intelligence (AI) could be a future gold mine for cybercriminals and nation-state hacking groups.
AI will lead to smarter and autonomous malware that can adapt to changing circumstances and learn how to improve its tactics to pull off more advanced attacks.
Story continues
Researchers have also recently demonstrated that early-stage AI is already significantly better than humans at launching phishing attacks and crafting viral tweets and social media phishing that can infect users.
It will also make it easier for hackers to hijack online accounts by predicting passwords and beating CAPTCHAs.
While deepfake videos are well known by now, an even more compelling use case for cybercriminals will be audio deepfakes which impersonate CEOs to trick employees into sharing sensitive information or authorizing payments.
Furthermore, deepfakes could potentially trigger political crises and incriminate innocent people.
A woman in Washington, DC, views a manipulated video on January 24, 2019, that changes what is said by President Trump and former president Obama, illustrating how deepfake technology can deceive viewers. (Photo by Rob Lever/AFP)
For the last 25 years, most cyber attacks have targeted software rarely venturing below the operating system level of a device.
That is now beginning to change.
Hackers are figuring out how to target firmware with malware in order to gain God-level access to these devices and even physically sabotage them. A recent survey found that 83% of enterprises have already started to experience firmware attacks.
So what is firmware?
For high-functioning electronics, like a computer or smartphone, firmware is the code that runs beneath the operating system and is the bridge between the software and the hardware.
However, it is even more critical for lower-functioning embedded devices (i.e., the Internet of Things or Industrial Internet of Things) where firmware is often used in place of an operating system.
In a nutshell, if a hacker can gain control over the firmware, they can control the device. That is especially alarming for the embedded devices and industrial controllers that are used in safety-critical systems like the power grid, water treatment plants, nuclear plants, manufacturing, oil and gas pipelines, etc.
Downtown Los Angeles is seen behind an electricity pylon through the morning marine layer in Los Angeles, California, U.S., August 20, 2019. (REUTERS/Lucy Nicholson)
An attack on the firmware of those devices could lead to dramatic incidents of physical sabotage. For instance, this is how a hacker could trigger a months-long power outage, disrupt the water supply, cripple manufacturing plants, and even brick gas station pumps, ATMs, hospital ventilators, and office buildings.
These types of attacks are not as far-fetched as they may sound: In 2016, Russian hackers used a special malware called CrashOverride to disrupt Ukraines power grid.
Supply chain attacks have become a buzzy term as of late, thanks to the high-profile breaches of SolarWinds, Microsoft Exchange, Kaseya, and Codecov.
The reality is that we are still in the early stages of supply chain exploitation, and these attacks will become more frequent, sophisticated, and brazen in the coming years.
Advanced nation-states like Russia and China will go further by breaching more sensitive, backbone IT services think ISPs, chipmakers, app stores, security tools, source code libraries, etc. to better infiltrate and persist inside of critical companies and organizations in the U.S.
Microsoft President Brad Smith testifies during a Senate Intelligence Committee hearing on Capitol Hill in Washington, U.S., February 23, 2021. Drew Angerer/Pool via REUTERS
Cybercriminals will do the same with lower-hanging fruit, such as retail systems and e-commerce platforms, and have already been busily exploiting supply chains: Various Magecart gangs have wreaked havoc on e-commerce sites by exploiting the open-source Magento platform.
In the coming years, hackers will also infiltrate millions of Internet of Things (IoT) devices (from smart thermostats to cars) by exploiting their software/firmware supply chains, such as source code libraries or the update processes of key vendors.
Far from being a minor inconvenience, these attacks could lead to widespread physical disruption if the hackers use that access to disable the devices.
While many consumers may be somewhat underwhelmed by the current 5G rollout, internet connectivity is undergoing dramatic changes that will take time to develop.
This is just the beginning of a new future where wired-connection Internet speeds will be available via wireless delivery methods, ranging from cellular towers to satellites and high-altitude vehicles.
The capacity for higher, faster wireless speeds also has a downside: Hackers will learn to exploit the higher bandwidth, and we can expect to see a wide range of attacks such as increasingly powerful botnets, data theft at a massive scale, and device-on-device attacks.
Botnets are large networks of enslaved devices which a hacker uses to disrupt services and Internet connections by overwhelming them with a flood of bogus data requests. In 2016, a college student was able to knock out a huge slice of the Internet by creating a simple botnet consisting of thousands of insecure IoT devices.
And since future data transfer speeds will only continue to multiply (5G is already expected to be 10 times that of 4G speeds), these botnets will become exponentially more powerful.
Future botnet attacks could be used to disrupt Internet services for a large percentage of the population. They could endanger public safety by blocking emergency services throughout a state. They could even hold entire countries for ransom, similar to the 2016 attack on Liberia.
An example of a botnet operation. (FBI.gov)
Data theft will also get a boost. The higher data transfer speeds will make it easier for hackers to harvest and exfiltrate large quantities of stolen data before victims are able to shut them down. This means data breaches will become significantly more expensive for companies and harder to recover from.
As devices become smarter and more autonomous in the wake of these greater connection speeds, hackers will also leverage these capabilities to attack other devices. For instance, a hacker who breaches a smart traffic light could then use that access to hack into every car that passes by.
Similarly, an infected self-driving car could be used to infect other vehicles within range of its radio signal. A compromised drone could be weaponized to sniff out other connected devices as it flies overhead and spread an infection over vast distances.
A prototype of Goodle's own self-driving vehicle is seen during a media preview of Google's prototype autonomous vehicles in Mountain View, California September 29, 2015. (REUTERS/Elijah Nouvelage)
This tactic could also be used by hackers for targeting high-level executives and government officials as well as for carrying out more sophisticated island hopping attacks to breach corporate networks through overlooked transient connections between various smart devices.
The bottom line is that cybersecurity will become increasingly complicated in the coming years, as hackers develop greater capabilities to launch attacks. Ransomware will continue to be a serious problem for the foreseeable future, but there are many new attacks that are equally concerning and are likely to catch many companies off-guard.
Karim Hijazi is CEO of Prevailion, a cyber intelligence company that monitors and detects active threats by infiltrating hacker networks. Hijazi is also a former director of intelligence for Mandiant and a former contractor for the US intelligence community.
Follow Yahoo Finance on Twitter, Facebook, Instagram, Flipboard, LinkedIn, YouTube, and reddit
See original here:
5 emerging cybersecurity threats facing the U.S. - Yahoo Finance
- Carmelo Anthony makes the most of his return to the Garden - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Direct-to-consumer entrepreneur explains the importance of physical stores - Yahoo Finance [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Inpixon's CEO Nadir Ali Interviewed Today on Yahoo! Finance LIVE On the Move Program - GlobeNewswire [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- We're Denton Dammit: The one where some yahoo takes aim with an air rifle - Denton Record Chronicle [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Marshawn Lynchs Beast Quake, as told by a Saint who 'melted like soft butter' trying to tackle him - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- 2019 Yahoo Sports MMA Fight of the Year - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- For the Bears and Anthony Miller, the 2020 offseason already feels like dj vu - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Oscar Colas, the Cuban Ohtani, is coming to MLB and everybody's going to want him - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Domino's Pizza CEO: A shakeout is coming in the third-party food delivery space - Yahoo Finance [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Amanda Bynes resurfaces on Instagram with what appears to be a large face tattoo - Yahoo Celebrity [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- One year later, AEW has disrupted pro wrestling and there's no plan to stop - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Rep. Peter King: There was 'no offensive briefing of Congress' ahead of airstrike that killed Soleimani - Yahoo Finance [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Can Deshaun Watson rise to the challenge as Texans face Bills on Yahoo Sports app? - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Sources: Jason Garrett is talking with players as if he's still going to be with the Dallas Cowboys - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Quarterback Exit Interview: Can Lamar Jackson beat the regression bug? - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- What the Iran strike means for gas prices - Yahoo Finance [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Carson Wentz faces another 'biggest game' as Eagles face Seahawks on Yahoo Sports app - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- The best fantasy players of the last decade, according to 'The People' - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Why Trump will lose in 2020 - Yahoo Finance [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Dalvin Cook's return could be huge for Vikings as they face Saints on Yahoo Sports app - Yahoo Sports [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- Iran has the capability to launch cyber attacks on very short notice, expert says - Yahoo Finance [Last Updated On: January 4th, 2020] [Originally Added On: January 4th, 2020]
- One Million Moms starts petition against 'irresponsible and tasteless' Burger King ad featuring a curse word - Yahoo Food [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Canada's Trudeau: Iran plane victims would be alive had there been no regional tensions - Yahoo News [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- During impeachment trial, Trump will be chilling in Swiss resort - Yahoo News [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- 10 insights into Netflixs Aaron Hernandez documentary from executive producer - Yahoo Sports [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Odell Beckham Jr. handing out wads of cash to LSU players is one of the best celebrations ever - Yahoo Sports [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Why US Attorney General William Barr's attacks on Apple are being ignored by investors - Yahoo Finance [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- How Ed Orgeron persevered through all the jokes, firings and failure to win it all at LSU - Yahoo Sports [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Chicago Bears get Jake Fromm in the latest Mock Draft from Yahoo Sports - Windy City Gridiron [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- 'Jeopardy! GOAT': James Holzhauer and Ken Jennings battle it out down to the final clue - Yahoo Celebrity [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Parnas said he is speaking out because he is afraid of William Barr - Yahoo News [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Robert Downey Jr. explains why he picked 'Dolittle' for his first non-Marvel movie in 6 years - Yahoo Celebrity [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- The economy is continuing to catch up to the stock market: Morning Brief - Yahoo Finance [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- 'You have not seen anything yet,' climate activist Greta says ahead of Davos - Yahoo News [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Kyrie Irving is back, but what does it mean for the Nets? - Yahoo Sports [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Rand Paul Slams the Bidens over Alleged Corruption: It Smells to High Heaven - Yahoo News [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Trump should 'absolutely' get credit for changing the China conversation: analyst - Yahoo Finance [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Why traders playing oil like its 2010 are 'getting their heads handed to them' - Yahoo Finance [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Israel's F-35I Adir Is Taking America's Stealth Fighter To A Whole Other Level - Yahoo News [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Consumers are starting to feel streaming fatigue, analyst says - Yahoo Finance [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Damn straight the NBA needs him: Why Zion Williamsons debut is so important - Yahoo Sports [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Baby dies after eating dishwashing powder while mum went on partying spree - Yahoo News Australia [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- A.J. Styles on 2016 WWE debut: 'It couldn't have been any better' - Yahoo Sports [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Curt Schilling doesn't deserve to be in the baseball Hall of Fame - Yahoo Sports [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Trump's Apple threat would put every iPhone on Earth at risk - Yahoo Finance [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Crypto Exchange Binance to Partner With Yahoo's Japanese Divisions - Bitcoinist [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Verizon introduces OneSearch a new privacy-focused search engine - The Verge [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Trump has discredited the American experiment: Robert Kennedy Jr. - Yahoo Finance [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Shopify, Bed Bath & Beyond, Google, Apple: Companies to Watch - Yahoo Finance [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- Trump is elevating judges who could gut the Voting Rights Act - Yahoo News [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- Tesla Bruises Another Hedge Fund With Bearish GMT Facing Losses - Yahoo Finance [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- How to fix the Lions: Keep Matthew Stafford and draft Tua Tagovailoa - Yahoo Sports [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- Lululemon exec: Mental health is the 'next major step in our journey' - Yahoo Finance [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- How Barbie has survived for over 60 years in a 'volatile' toy industry - Yahoo Finance [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- Olivia Wilde wants to change the way sex scenes are filmed: 'Demand this new standard' - Yahoo Celebrity [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- Did Iran Manage to Find a Weak Spot in the F-35's Stealth? - Yahoo News [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- Cans suck the THC buzz out of pot drinks. Where does that leave Canopy Growth? - Yahoo Sports [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- Coronavirus updates: The latest from around the world - Yahoo Finance [Last Updated On: February 14th, 2020] [Originally Added On: February 14th, 2020]
- The 10 richest Americans are just beginning to take sides in the 2020 presidential race - Yahoo News Canada [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Coronavirus in China may have severely stunted one of Walmart's hottest businesses - Yahoo Finance [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- 3 NFL teams that should try to sign Teddy Bridgewater - Yahoo Sports [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Kate Middleton Is Reportedly 'So Happy' to Have More Royal Duties - Yahoo Lifestyle [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Lakers eke out win over Celtics by a pinkie - Yahoo Sports [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Pope appears to give thumbs down to Trump's Mideast peace plan - Yahoo News [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- The 'skull breaker challenge' is trending on TikTok. Why doctors say it could be fatal. - Yahoo Food [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Packers aggressively committed to bringing future NFL draft to Green Bay - Yahoo Sports [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- What will the coronavirus do to cruise ships - Yahoo Finance [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Tyson Fury holds all the power in heavyweight division after crowning performance - Yahoo Sports [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Warren Buffett reveals a big change to this year's annual shareholder meeting - Yahoo Finance [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Coronavirus, consumer sentiment, GDP, retail earnings: What to know in the week ahead - Yahoo Finance [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Rohrabacher tells Yahoo he discussed pardon with Assange for proof Russia didn't hack DNC email | TheHill - The Hill [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Yahoo Sports rips on Indy, arguing All-Star Game should be moved - Fox 59 [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Here's what makes the coronavirus similar to and deadlier than SARS - Yahoo Finance [Last Updated On: February 24th, 2020] [Originally Added On: February 24th, 2020]
- Pete Davidson Revealed Why He and Kaia Gerber Broke Up - Yahoo Lifestyle [Last Updated On: February 27th, 2020] [Originally Added On: February 27th, 2020]
- Beyond Meat, Best Buy earnings: What to know in markets Thursday - Yahoo Finance [Last Updated On: February 27th, 2020] [Originally Added On: February 27th, 2020]
- Lost ancient kingdom uncovered in Turkey after farmer finds stone with strange inscriptions - Yahoo News UK [Last Updated On: February 27th, 2020] [Originally Added On: February 27th, 2020]
- No, the Astros' league-leading HBPs in spring training are not retaliation for their cheating - Yahoo Sports [Last Updated On: February 27th, 2020] [Originally Added On: February 27th, 2020]
- The 25 best-performing large cities in the US: Milken Institute - Yahoo Finance [Last Updated On: February 27th, 2020] [Originally Added On: February 27th, 2020]
- Yahoo Sports rips on Indy, urging for All-Star game to be moved - CBS 4 Indianapolis [Last Updated On: February 27th, 2020] [Originally Added On: February 27th, 2020]
- Joe Burrow's hand measurement is going to be a big topic of conversation - Yahoo Sports [Last Updated On: February 27th, 2020] [Originally Added On: February 27th, 2020]