Cybersecurity leaders and experts from Google Cloud and Mandian forecast that in 2024, cyberthreats will continue to grow in sophistication, with a surge in professionalized phishing attempts and scalable information operations driven by generative AI (genAI) and large language models (LLMs), the exploitation of zero-day vulnerabilities, and the maturation of attacks on hybrid and multicloud environments.
GenAI and LLMs are anticipated to revolutionize phishing, short messaging services (SMS) and other social engineering operations. Cybercriminals can use these technologies to make the content and material, including voice and video, appear more legitimate. They can also use LLMs to clean up translations. All of these make it more difficult for users to identify fraud and spot phishing attempts.
Additionally, with the help of genAI, attacks will be able to scale up their campaigns to target a larger number of individuals with highly personalized and convincing content, Google Cloud and Mandiant noted.
“With the scalability of these types of information operations comes the risk of reducing public trust in news and (online) information, to the point where everyone will become more skeptical,” security experts wrote. “This could make it increasingly difficult for businesses and governments to engage with their audiences in the near future.”
As adversaries continue to experiment with genAI and LLMs, experts expect more of these tools to be developed and offered as a service, similar to other underground as-a-service offerings like ransomware.
“While our frontline investigators saw very limited use of attackers using AI in 2023, in 2024 we expect attackers to use genAI and LLMs to personalize and slowly scale their campaigns,” said Google Cloud CISO Phil Venables. “They will use anything they can to blur the line between benign and malicious AI applications, so defenders must act quicker and more efficiently in response.”
Using genAI and LLMs for cyber defenseOn the other hand, for cyber defenders, gen AI, LLMs and related technologies can be used to bolster their time-consuming tasks, including detection and response, adversary attribution at scale, analysis and reverse engineering capabilities, Google Cloud and Mandiant noted.
These technologies are expected to significantly enhance human ability to analyze and act upon large data sets. Security experts forecast the big use case of genAI in cybersecurity — synthesizing and contextualizing large amounts of data in threat intelligence and providing actionable analysis — to come to fruition next year.
“We will see new ways of overlaying customer-specific data in a highly confidential way, giving organizations the ability to take significant action at speed and scale,” they wrote.
“AI is already providing a tremendous advantage for our cyber defenders, enabling them to improve capabilities, reduce toil and better protect against threats,” Venables echoed. “We expect these capabilities and benefits to surge in 2024 as the defenders own the technology and thus direct its development with specific use cases in mind.”
Evolving threats in hybrid and multicloudIn 2024, the attacks targeting hybrid and multicloud are expected to continue to become more sophisticated and impactful.
Earlier this year, Mandiant worked with VMware to address a zero-day vulnerability that allows adversaries to execute code on guest virtual machines. This isolated incident underscored a broader trend: threat actors were targeting cloud environments looking for ways to establish persistence and move laterally, the vendor noted.
Security experts projected to see attackers looking to exploit misconfiguration and vulnerability to move laterally across boundaries between cloud environments.
They also predict that in 2024, both cybercriminal groups and nation-state cyber operators will increase their use of zero-day vulnerabilities to maintain persistent access to the environment for as long as possible and increase the number of victims, as well as serverless technologies in the cloud for greater scalability, flexibility, and automation.
“Right now, we see organizations running their data in a combination of multicloud, on-premises and hybrid environments — and while it is unrealistic to expect these organizations to host their assets solely in one place, it does make unified, comprehensive security operations and overall risk management particularly challenging,” said Sunil Potti, VP and GM of Google Cloud on the convergence of cloud and enterprise SecOps.
“In 2024, I expect we’ll see more convergence in cloud and enterprise security operations as customers increasingly demand integrated risk and threat management across all their cloud and on-prem silos — all powered via a modern, AI-infused platform,” he added.
Comments