Palo Alto Networks' threat intelligence team Unit 42 noticed a significant uptick in cloud attacks over the past three years and anticipates more than 80% of cyberattack cases will have a cloud aspect by the end of next year.
“We've identified that companies are adding up to four new cloud instances per week, which means ultimately that so many of those instances are simply adding vulnerabilities to the environment and increasing the attack surface for potential attacks,” said Wendi Whitmore, SVP and Unit 42 team lead at Palo Alto Networks.
Unit 42 has seen a 188% increase in cloud incident response cases, and more than one-third of its non-cloud cases “touch cloud assets in one way or another,” Whitmore said during her keynote at this week’s Ignite conference.
“Because cloud environments are inherently designed to be dynamic and scalable, even simple mistakes can lead to expensive, complicated incidents with outsized impact,” she warned.
Global enterprises found new serious vulnerabilities in their cloud infrastructure twice a day on average, with causes spanning from misconfigurations, insecure remote access, exposed account credentials, to unpatched vulnerabilities, Whitmore said, citing the 2021 Cortex Xpanse Attack Surface Threat Report.
“This highlights the ephemeral nature of today's IT infrastructure where not only the infrastructure changes, but so does the vulnerability footprint,” she said “And when a cloud breach happens, they happen fast, and investigation, response, and recovery is hard.”
Because of that, Unit 42 doubled down on its cloud incident response practice to “provide an optimized approach for each stage of the cloud incident lifecycle resulting in faster recovery,” Whitmore noted. The team will tap Palo Alto Networks’ own cloud security technologies to identify attack vectors, including the Cortex XDR, Cortex Xpanse, and Prisma Cloud platforms.
Ransomware Represents Over One-Third Unit 42 CasesAs cloud attacks continue to rise, ransomware increasingly dominates the landscape but it's not the only culprit.
Ransomware attacks account for more than one-third of Unit 42 responding cases, and its team identifies new ransomware variants weekly. Meanwhile, “the volume of ransomware cases has continued to grow,” Whitmore said.
Unit 42 introduced a ransomware readiness assessment program in May, as the team was getting at least five new ransomware cases per week, and “threat actors were becoming more coordinated and building a distributed ransomware-as-a-service business model”, she said. “We needed to help clients get ahead of this before it was too late.”
Assessments are based on real-time threat intelligence and a methodology built from “best practices and real-world scenarios our team has documented from the cases they have worked,” Whitmore added.
What Is Unit 42?The name “Unit 42” is a nod to the number 42 in “the Hitchhiker’s Guide to the Galaxy” because it focuses on providing “the Answer to the Ultimate Question of Life, the Universe, and Everything” — for cyberthreats, according to Whitmore.
Whitmore has led the group since February and previously served as VP of IBM’s X-Force threat hunting group.
The current Unit 42 team combines Palo Alto Networks’ original threat hunting team, which was founded in 2014, with Crypsis security consultants and incident response specialists. Palo Alto Networks acquired Crypsis for $265 million last summer.
“The team is made up of incident responders who respond to thousands of major breaches every year; proactive consultants who are focused on cyber-risk management; and threat researchers and analysts who are helping join those two capabilities together, and in particular, really focus on building a best-of-breed threat intelligence,” Whitmore said.
Unit 42 team produces three new pieces of threat research a week on average, and analyzes data from over 85,000 Palo Alto Networks’ clients around the globe, “that's including network, data, cloud, and really every industry vertical and size of company that exists,” she added.
“We are here to help you tackle the most complex and challenging cybersecurity issues, not just during a tactical and reactive investigation, but as your strategic cybersecurity partner of choice through our cyber-risk management and incident response services,” Whitmore said.
Comments