Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: AI Memory Exploits, Salt Typhoon Telecom Breach & Cybercrime News

Varonis
07/30/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hey, everybody. How's it going? Hey, Matt. Good to see you. Hi, David. It's great to be here again and to connect with our audience from all over the world. Yeah, definitely. We got a lot of cool topics today. Yeah, well, I guess we should probably get into it, huh? We could sit here and talk to everybody for the whole time. Yes, we could, but let's do it. So, hello, everybody. Again, my name is Matt Relak. I'm joined by our co-host, David Gibson, and we are here for State of Cybercrime. We're going to go over our usual segments today. We're going to talk about and cover a little bit of good news, as there always often is some good news to share. We'll head on to our newest segment, AIVay, which is going to make you all say the same thing. We'll talk about some vulnerable vulnerabilities, jump on the highway to the danger zone. And I think I need to reshare it real quick to make sure that I'm sharing sound. So just give me one second or our producers, they get real. They like to remind me while the show's going on. So let me take care of that really quick. Is there any good news? You know, oftentimes in cybersecurity, it's all doom and gloom. And everybody, including us, only wants to talk about the things that are, you know, one step away from our demise to our robot overlords. But there often is a lot of good news to say in cyber. And that's why we always like to kick off the show with talking about some of that good news. And it seems, David, like we've got something pretty big to talk about. What's going on here? So cooperation between the U.S. government and Microsoft. And they didn't take down all of Star Blizzard, which is also known as Callisto or Cold Driver as well. And this is a hacking group linked to the FSB. It's not taken down, but they did manage to disrupt 100 or actually more than 100 hacker domains. Now, this group targets military personnel, government folks, think tanks, a lot of folks that have a relationship into politics. The way they work is they pose as trusted individuals, do a lot of research to figure out who they might be able to fool people into clicking on a spear phishing link. So two, I think, really positive things that came out of this, even though the group is going to spin back up rather quickly, as they always do, it's disrupted enough infrastructure in a short enough amount of time to slow them down a bit, hopefully. And given the timing of the election, it's fortunate that they're able to do that at this time and probably plan that way. The other cool thing that I think came out of it is that Microsoft and the government have learned to cooperate a little bit more quickly, so they may be able to take out more of these domains more quickly in the future. Yeah, and we'd even start to think where maybe even, and I won't give too much of a hint to our AI vague segment, that maybe AI will eventually be able to learn how to spot things like the U.S. government or like Microsoft is, and help us to preemptively strike against some of these actor groups that are spinning up and spinning down domains and infrastructure to carry out their attacks. That's not the only good news we have, but it must be an election year, because it does seem like all the APT groups that have to deal with interfering with elections are coming on strong, as somebody might say. The U.S. Department of Justice actually has charged three Iranian hackers for their involvement in a hack and leak campaign aimed at influencing the outcome of the 2024 election. Now, these hackers reportedly were a member of Iran's Islamic Revolution Guard Corps, or IRGC, that's known to be tasked with hacking into U.S. government personnel and political campaigns. And what the indictment alleges is that they infiltrated various different computer systems, stole sensitive information, and leaked it in an effort to maybe manipulate public opinion and disrupt the electoral process. That's scary stuff, although I've got to say, I'm not sure they need any help this year. I think we kind of got it, right? You know, we try not to make the show about politics, David, and so I almost don't want to respond to that. But I don't know if it can get any worse in terms of interfering with the election, more so than what we're experiencing firsthand here in the States. Now, that's not the only bit of good news that we have, though. Somebody got taken down that was doing some stuff with some Office 365 accounts. You want to talk about that? Yeah, yeah, yeah. So, UK national Robert B. Westbrook was caught, and he was charged after he made, allegedly, $4 million by trading on insider information. So how he got this information was kind of the interesting part and the tie-in to our show. He was hacking executive mailboxes and getting in there, you know, setting up the forwarding rules so he could get the draft of the financial information, the earnings release, etc., and trade ahead of that information being public. And how he was able to get those passwords or get into those accounts was by abusing some of the password reset mechanisms that are in 365, particularly those when you're using information to reset your password, you know, verify your identity by answering all these questions, you know, that probably only the real person would know. Well, he was able to guess those answers with online services, right, like genealogy sites, etc., and some of the public information that's out there to actually get the password and then get into the accounts. He also was pretty, pretty deliberate about covering his tracks, you know, paying for all these services with Bitcoin, masking all his traffic with VPNs, pretty sophisticated scheme, and go-good guys caught, charged, and we'll see what happens now. Yeah, and I think, you know, if there's anything to take away from this, it's that trading on insider information is definitely a way to get you spotted by a lot of law enforcement agencies around the world. And Carrie from our chat, how did they figure it out? It's amazing that they got him. You know, I think sometimes when we think of some of the most prolific, you know, SEC investigations over time, ultimately the evidence was pretty clearing that someone knew something and made a move on the market a certain time. And there are mechanisms in the markets, in the financial markets to find those events and spot those events and investigate those events. And so probably not the best place for a cyber criminal to try to make a quick buck. Yeah, and also, you know, we're seeing over the past few months, I'd say, more stories that involve tracking and tracing the transactions of Bitcoin. Yeah, in our last episode, actually, we did cover that. It was a South American authority, if I remember correctly, that was able to trace back over 15 million in Bitcoin that was being washed all back to the original source addresses. I don't know if one of our producers wants to drop a link to that episode, but that's pretty interesting. Now, let's go on to our next segment. I know one that's got you all saying AI May. And one thing that I really noticed, people are starting to speak up about the limitations of AI. And Apple is one company that usually is very pro privacy and talks a lot and advocates a lot for privacy. It's also now advocating in publishing a study around some of the flaws in large language models, like the ones that come from meta and open AI. And what this research from Apple found is that these models really struggle with basic reasoning tasks. And so what they've done to try to counteract that is they've introduced this new benchmark that they call GSM symbolic in order to measure the reasoning capabilities. And this stemmed from what they found was that small changes in query wording can lead to different answers. Now, we've covered on the show before that, you know, like chat GBT is non determinative, meaning that, you know, two people can put in the exact same prompt and receive different responses. But what the study from Apple underlines is how unreliable the results then be on whether or not you can then use those or follow through some objective reasoning tests to say that those were reasonable conclusions to come to. Another side part about this study that I found really interesting is that they found if they added in irrelevant information to a math problem, that drastically reduced the likelihood that the chat GBT or the copilot could serve up the correct answer to that math problem. Whereas maybe a mathematician would have ignored the erroneous additions to the formula. Now, you know, as I walked through this, I thought to myself, I still find, you know, chat GBT and models from open AI and copilots. I still find them to be helpful, you know, and I think, David, you had a pretty snarky comment around some people that might suffer from reasoning. Anything you wanted to add? Yeah, I was just thinking, you know, basic reasoning tasks are difficult, gets confused easily by lots of information. I mean, it sounds like a lot of people I know, right? You know, it could be harder to tell AI from real people all the time. Now, and yeah, they may not have reason, right? But apparently they do have a memory. This story is really interesting. Researchers found a way to manipulate the chat GPT application, at least the OS 10 applications memory, so that every prompt and response was logged to a server that they controlled. So I learned a lot in this story. A couple things. First of all, I didn't, you know, I never really thought about it, but you can have chat GPT analyze a website so you can point to a URL within the prompt. Now, what this researcher did was had a malicious image that they directed the prompt to go look at. And that image implanted a memory in the application. Now, if you want to see what chat GPT remembers about you, go to profile, like you click on your name in the application, go to settings and personalization and manage memory. And there's a whole list of things if you've let it, you know, remember stuff about you. And I don't remember saying, yeah, go ahead. But I must have at some point because it had when I looked at it, it's like, oh, yeah, I've got all this stuff in there. But by using this technique, the attacker managed to plant the code that's on the slide in the memory, which would run every time you asked a question. So I didn't realize this was possible easily. I didn't realize this was possible, too, and easy to do. So, you know, kudos to the researcher. I think it opens up a whole lot of possibilities. And, you know, I thought that was pretty interesting, you know, just if you're a chat GPT user to be able to go and see that. We're also starting to see AI get used in attacks. And so in a campaign with the async rat malware that targeted victims, mostly in France, hackers were able to leverage AI to customize the payload for various platforms. So think the malware was originally written for, say, Windows computers. And what AI is helping them do is develop a payload for Linux and Mac OS X computers. And what this represents is like a shift in the toolkit for cyber criminals. You know, what my prediction is, is that AI generated malware will lower the technical acumen required by a person to become a cyber criminal. And I don't really know that anyone didn't see this coming, you know, nor do I think that do you really need AI to repackage malware for another operating system? But I guess, you know, it proves to be helpful. And if it lowers the bar for cyber criminals to become cyber criminals, it's definitely something we should be concerned about. Yeah, definitely. It's, you know, think about, you know, not just the OS, but probably the version of the OS, you know, all the libraries loaded, there are all kinds of things that they can do. Kind of speaking of AI powered malware, Radimantus has been rewritten and re-released. And this malware uses AI to recognize specific information in images. So think of it a little bit like OCR, optical character recognition, with a little AI sprinkled on top. But the interesting thing is it was built to recognize C phrases like those used in your crypto wallet, right? So, you know, that's kind of one of the key pieces of information to be able to steal the data there. It also steals information from cookies, financial information, even the CVC code of your credit card. And, you know, so it's a way to get this important information out of a victim. I thought one of the really interesting things about it is the way it tricks users into installing the malware is by posing as a capture. You know, all these capture things that we're having to click through to prove we're human. And they're getting harder and harder and a little bit weirder and weirder, I would say. This one actually made you manually copy and execute PowerShell code to prove you were human. And that's what installed the malware, then running in that user's context. And so now it's able to look at the images, also even bypass some of the newer security mechanisms like the one in Chrome, the app-bound encryption. So interesting story there. I thought it was also interesting when I looked at this one, David, that some of this code specifically is getting banned on various hacker forums. And so it made me think, like, are hackers getting robbed from this? Because they're filling out the capture and then their crypto wallets are being emptied. You know, thieves stealing from thieves. It's not a bad target, right? I mean, they probably do have pretty hefty crypto wallets. Yeah, I think that's pretty interesting. Don't use this. Don't use this. You'll lose all your crypto. Now, what's going on with the glasses, though? There's, like, the meta glasses? Is this, like, something to deal with, like, some researchers from Harvard or something? Yeah, and I kind of got to give kudos to them. I mean, the story got legs, I think, you know, because there was this tie-in to the new meta Ray-Ban glasses there. They look pretty cool. And the idea is they wrote a program where they would record, you know, take a picture of somebody and then get all the information about them really quickly. And the way this worked was, is it would take the video or image capture, pipe it to Instagram. And then along with the name, it would use all sorts of public records and, you know, some of these services to get all sorts of information about the person, kind of a dossier. And, you know, it's kind of scary. You know, you could walk around, look at a person and see a whole manifest of everything that was available for them on the Internet or one of these, you know, potentially, you know, think about the other story, right? Some of these services that have more personal information about you. But I think, you know, one of the points that they made is it's not really about the glasses. You know, you think about how many times we're on camera every day, you know, walking by or, you know, if somebody takes a picture of you with a picture and a name, a lot of information that you would want private is pretty easily available. I mean, yeah, even if you just do a Google search, right? Like with your picture and your name, you're going to find a lot about the two of us. I'm sure all the episodes of State of Cybercrime, all the YouTubes and times we've spoken to various events at Varonis, I'd at least find all that out. So in our next segment, Vulnerable Vulnerabilities, we'll talk about a couple of vulnerabilities that probably got you on the edge of your seat, including one in an automobile. Yeah, this one makes me really glad that my car doesn't have any internet connectivity. I know there are computers in it, but at least maybe it's a little bit tougher to have to be hacked. But a lot of cars these days are internet connected. I know some people have like software features they have to pay for, that diagnostic information is collected, can be, you know, preventive. And apparently dealers have a little bit more access to your car software than you might realize. And researchers discovered that they could use the Kia's web portal to register themselves as a dealer pretty easily. Then with only a license plate or a VIN number, they had dealer powers over the car so they could turn it on and off, unlock the windows, even like activate the horn. Figure out where the car is. So this, you know, this is one of these web portal vulnerabilities that I think, you know, has been fixed luckily. But, you know, it kind of reminds me of all the scary possibilities with this. It also reminded me of that old movie Repo Man. I don't know if anybody's actually seen that, but it seems like that person's job got a lot easier now. You could just remotely maybe even have the car drive itself back to the dealer if you missed it. Yeah, so there's only a matter of time before the car drives itself back. Yeah, exactly. Now, that wasn't the only vulnerability that was pretty widespread. A critical vulnerability was also found in the NVIDIA container tool kit. Now, this one's important, especially if you're running AI applications in the cloud. Known as a CVE-2024-0132. This toolkit impacts all AI applications that rely on GPUs for processing. And what the flaw does is it allows attackers to perform what's called a container escape attack. Potentially giving them full access to the host system. And so once they're able to escape that container, they could execute commands. They could steal sensitive information or establish methods of persistency. And according to Wiz, more than a third of cloud environments are likely impacted by this vulnerability. So it is quite widespread. Well, next we jump on to the dangers. And we just talked about some threat actors or attacks that we think people should know about. And what's this Gorilla Botnet? This one kind of reminds me of Mirai. But researchers found a new botnet family. It's called Gorilla, Gorilla Bot. I think what's interesting about it is how busy it is. It's so many DDoS attacks every day, over 100 countries. It has the kitchen sink in terms of the capabilities, right? You've got the ACT floods, UDP floods. It's even got a valve source engine flood, which was sort of new to me, right? But I guess that's something in the gaming engine there. SYN floods using lots of UDP connections with spoofed IPs. It also can spoof a fairly recent security flaw about a year old, I think, in Apache Hadoop. To achieve remote code or to do remote code execution. I assume that that is to get more victims, more nodes in the botnet. Gets persistence, then downloads a script, right? And it also provides for long-term control over IoT devices as well as some cloud hosts. So this one's pretty busy and pretty powerful, it looks like. Yeah, and another one I thought was really interesting, and this one from Microsoft, is about the Embargo ransomware group. So they've been identified and they're being tracked as Storm0501. This alleged group with Russian ties has been targeting critical infrastructure and government entities across the US and Europe. And what I thought was interesting about it is this particular group has leveraged other ransomware toolkits in the past. So Black Cat, Hive, LockBit, now leveraging Embargo. And what the actor does is they exploit weak credentials. They take over privileged accounts. They steal data. They drop their ransomware payload. And just for those that kind of track like, well, I'm worried about that actor. I'm one of those kind of companies. Are there particular vulnerabilities that I should be concerned about? Yeah, Zoho, Manage Engine, Citrix, NetScaler, and ColdFusion are all vulnerabilities they've been known to leverage. And in terms of command and control, they're typically using ImpactKit and CobaltStrike. And one of the things that they'll do when they do that is masquerade as legitimate Windows processes, especially PowerShell. And so your overall PowerShell governance and just awareness for credential type attacks is definitely something, if you're a critical infrastructure or government entity in the US and Europe and you're here today, you should think about your threat actor profiles, including Storm 0501. You know, some just occur to me, Matt. These exploits like this one I'm going to talk about, too, seem to be so complete and make use of so much of the past knowledge. I almost wonder whether, you know, how AI is helping people write, you know, this kind of malware. Because it seems like they're thinking of everything. This one is called PerfControl, right? Named that way because of the Unix or Linux command perf, right? That does the perf monitoring and things like that. And, of course, command and control. But this is some new Linux malware that's pretty scary. It's scary because it gets in by exploiting any of a combination of 20,000 or more known misconfigurations, as well as a vulnerability in RocketMQ. But once it's there, it is really stealthy and it's really hard to clean. Ultimately, what it's doing right now and could certainly do a lot more seems to be crypto mining and also act as a proxy for hire, right? So it becomes a proxy node that people can route traffic through for money. But people are only noticing it because their CPU is pegged, but not when they log in. It stops whatever it's doing to peg the CPU, the mining or whatnot, when you log in. So it's definitely built for stealth. It uses Unix sockets to communicate out to the Internet. The binaries, they're packed, they're stripped, they're encrypted. Basically makes them harder to reverse engineer. It's watching for the different temp files to see activity and kind of keep hiding itself. And it's really persistent as well. People are really struggling to erase it. There are some IOTs. I'm going to paste that link in the chat. But some IOCs to look at. But one to definitely look at. There's definitely a lot of IOTs out on the Internet. Yeah, that version of Linux. But there's some IOCs there from AquaSec that if you're curious, if you want to go look for those, could do that. But also then patch the vulnerability in RocketMQ, which is CVE-2023-33-246. Now, before we go on to our last story and talk about Salt Typhoon, I wanted to comment on something that you talked about with embargo and ransomware actors. You know, the barrier to entry for a cyber criminal seems to be getting lower, right? AI could make these tools better. It does seem like the threat actor playbook is kind of one in the same. You just change the actor name and they go after credentials. They target privileged accounts. They go after data. They encrypt, steal information. And AI might make that easier. But what it draws me back to, and I wonder if we have any pen testers in the audience now, in version 3 of Metasploit, there was a command called dbautopwn, which basically tried every single exploit in the toolkit on every single target host that you had loaded. And I guess it's only a matter of time before AI gets smart enough to have their own version or some AI-enabled version of Metasploit has the ability to do something better than dbautopwn, or at least maybe it performs some type of scan of the services. And then it tries to try all known exploits against those services. But I guess it's really only a matter of time or some actor group that gets the motivation to create some type of AI-enabled hacking toolkit. Yeah, I mean, I think it's not so much... To me, I think it definitely will lower the barrier to entry, but it'll also make the people that are already there that much more sophisticated that much more quickly, right? Like you can throw in that library and say, okay, what are the DBs that we missed, right? And what are some vulnerabilities for these DBs? It definitely seems to be able to accelerate the development. And I know a lot of people are here because they're thinking about that salt typhoon actor, this Chinese threat actor that got identified exploiting wiretap systems that were mandated by the CALEA or the 1994 Communications Assistance for Law Enforcement Act. And what CALEA did was force telecommunications companies to make their systems accessible for lawful surveillance. Now, as a result of unintended consequences of this, they've also made it susceptible to attackers too. And news recently broke that salt typhoon has targeted U.S. broadband providers potentially for months. And really kind of what it brings up for me is these legally required backdoors might be causing more harm than good, especially if you think in the macro sense that like U.S. intellectual property and PII is falling into the hands of Chinese threat actors. When I got into this, and I've even had conversations with some many of our customers that are concerned about this particular actor, I think the real danger here is that there probably were links, maybe in your MPLS network, where you otherwise trusted that link. And maybe you didn't encrypt it or put security controls in place in that link. I think often of like, let's say you have an office, say, in New York City, and you have a data center in New Jersey, you might not encrypt that link because you trust the telecode that you have a dedicated link between the telecommunication provider that you use and contract between your office and your data center. And encryption, you know, costs money for performance, also costs money to have the hardware that you need to encrypt it and unencrypt it on both links. And so if a threat actor was able to sniff that link and wiretap that link, that does pose a real threat to anyone that used a telco provider. And I think this is why a lot of security researchers are kind of digging their teeth into this to figure out, well, what actions on objectives, other than just knowing that these threat actors, you know, misused this wiretap functionality, what were they able to do with it is a question that I don't think we know the answer to yet. And maybe we'll cover on another episode in the future of State of Cybercrime. Yeah, definitely. Those private links, always be wary that they may not be as private as you think. I think that pretty much covers it for today, everyone. Thank you so much for being here for State of Cybercrime. It is made possible by you, our audience, and by our lovely hosts, David Gibson and myself and our production team. So thanks so much for being here and we look forward to connecting with you on the next episode of State of Cybercrime.

TL;DR

  • Microsoft and U.S. government disrupted 100+ Russian hacker domains ahead of the 2024 election, demonstrating improved public-private cooperation against state-sponsored threats.
  • Researchers discovered ChatGPT's memory feature can be manipulated through malicious images to exfiltrate all user prompts and responses to attacker-controlled servers.
  • Apple's research reveals major LLMs struggle with basic reasoning and produce inconsistent results when query wording changes slightly or irrelevant information is added.
  • Salt Typhoon, a Chinese threat actor, exploited legally mandated telecom wiretap systems to potentially access U.S. broadband networks for months.
  • AI is lowering the barrier to entry for cybercriminals, enabling malware adaptation across operating systems and potentially accelerating exploit development.

Government Takedowns and Election Security Wins

The episode opens with positive developments in cybersecurity enforcement. Microsoft and the U.S. government collaborated to disrupt over 100 domains operated by Star Blizzard, a Russian FSB-linked hacking group targeting military personnel, government officials, and political think tanks through spear phishing campaigns. The timing ahead of the 2024 election was strategic, and the improved cooperation between Microsoft and federal agencies suggests faster future responses. Additionally, the Department of Justice charged three Iranian IRGC hackers for a hack-and-leak campaign targeting the 2024 election, while a UK national was caught making $4 million through insider trading by hacking executive Office 365 mailboxes using password reset vulnerabilities.

AI Vulnerabilities and Weaponization Trends

A significant portion of the discussion focuses on emerging AI security concerns. Apple published research revealing that large language models from OpenAI and Meta struggle with basic reasoning tasks, with small wording changes producing inconsistent results. More alarming, researchers demonstrated how attackers can manipulate ChatGPT's memory feature by directing it to analyze malicious images, planting persistent code that exfiltrates all prompts and responses. The hosts explain how users can check their ChatGPT memory settings and emphasize the unexpected attack surface this creates. Meanwhile, cybercriminals are using AI to adapt malware like AsyncRAT for multiple operating systems, lowering the technical barrier to entry for threat actors.

Critical Infrastructure and Telecom Threats

The episode concludes with analysis of Salt Typhoon, a Chinese threat actor that exploited legally mandated wiretap systems in U.S. broadband providers. The CALEA-required backdoors intended for lawful surveillance created unintended vulnerabilities that attackers accessed for potentially months. The hosts highlight the broader implications for organizations trusting unencrypted MPLS links between offices and data centers, noting that the full scope of data exposure remains unknown. Additional threats covered include the Gorilla botnet launching massive DDoS attacks across 100+ countries, the Embargo ransomware group targeting critical infrastructure, and PerfControl Linux malware that evades detection by stopping activity when administrators log in.

Chapters

0:00 - Introduction
1:18 - Good News: Star Blizzard Disruption
3:26 - Iranian Hackers Charged
4:40 - Insider Trading via Email Hacking
7:20 - AI Segment: LLM Reasoning Flaws
9:34 - ChatGPT Memory Manipulation
11:27 - AI-Powered Malware Development
12:38 - Radamanthys Malware and Fake CAPTCHAs
14:37 - Meta Ray-Ban Privacy Concerns
16:27 - Kia Web Portal Vulnerability
18:01 - NVIDIA Container Toolkit Flaw
18:52 - Gorilla Botnet
20:03 - Embargo Ransomware Group
21:21 - PerfControl Linux Malware
25:32 - Salt Typhoon Telecom Breach

Key Quotes

2:34 "It's disrupted enough infrastructure in a short enough amount of time to slow them down a bit, hopefully. And given the timing of the election, it's fortunate that they're able to do that at this time."
9:52 "Researchers found a way to manipulate the chat GPT application, at least the OS 10 applications memory, so that every prompt and response was logged to a server that they controlled."
12:00 "My prediction is that AI generated malware will lower the technical acumen required by a person to become a cyber criminal."
15:49 "It's not really about the glasses. You think about how many times we're on camera every day. With a picture and a name, a lot of information that you would want private is pretty easily available."
26:01 "News recently broke that salt typhoon has targeted U.S. broadband providers potentially for months. And really what it brings up for me is these legally required backdoors might be causing more harm than good."

FAQ

How can I check what ChatGPT remembers about me and protect against memory manipulation attacks?

Navigate to your profile in the ChatGPT application, then go to Settings, Personalization, and Manage Memory. There you can view and delete stored memories. Be cautious about directing ChatGPT to analyze external URLs or images, as this is the attack vector researchers used to plant malicious code in the memory feature.

What should organizations do to protect against threats like Salt Typhoon targeting telecom infrastructure?

Organizations should not assume that dedicated MPLS links or private connections through telecom providers are inherently secure. Encrypt all traffic between offices and data centers regardless of whether the link is supposedly private. Review your threat actor profiles if you're in critical infrastructure or government sectors, and monitor for the specific vulnerabilities mentioned including Zoho ManageEngine, Citrix NetScaler, and ColdFusion.


Categories:
  • » Webinar Library » Varonis
  • » Cybersecurity » Network Security
  • » Cybersecurity » Data Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • AI & Machine Learning
  • Network Security
  • Data Privacy
  • Security Operations
  • ChatGPT memory manipulation
  • Salt Typhoon APT
  • AI security vulnerabilities
  • LLM reasoning limitations
  • Election security
  • Ransomware groups
  • Botnet attacks
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: AI Memory Exploits, Salt Typhoon Telecom Breach & Cybercrime News

              Industry Events (Sponsor Hosted)

              • Aug
                03

                Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                08/03/202611:00 AM ET
                • Aug
                  06

                  Safeguarding Sensitive Data in the Era of Public AI Platforms

                  08/06/202604:00 AM ET
                  • Aug
                    06

                    Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks

                    08/06/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/03/2026
                      11:00 AM
                      08/03/2026
                      Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                      https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Era of Public AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-public-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks
                      https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-speed-ai-agents-impact-on-identity-attacks/
                    • 08/07/2026
                      11:30 AM
                      08/07/2026
                      Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                      https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights and Strategies with Cyera
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version