- AI phishing and the threat-intel attribution fight
Quick recap. The session ranged across AI-assisted phishing, threat-intel attribution, and cloud cost control. It began with introductions for new attendees, including Kelsey from Minimus and Daniel, a recent Information Technology and Informatics graduate from Rutgers University. The group discussed how AI interacts with phishing emails, with Daniel explaining the various stages of phishing campaigns enabled by AI. A significant portion of the conversation centered on a reported lawsuit involving Palo Alto Networks and Koi Security over a threat intelligence report that a startup alleges wrongly identified it as a Chinese espionage front. The discussion then shifted to the importance of attribution in threat intelligence, with participants debating whether attribution helps or hinders security efforts. Shawn shared updates about the Cloud Security Office Hours website, including new labs and the fact that it had received over 4,000 unique visitors in the last 30 days. The group also discussed cloud architecture and cost management strategies, with participants sharing experiences about accidental expenses and best practices for optimizing cloud deployments. The conversation ended with plans for an upcoming breakfast gathering at Black Hat conference in Las Vegas.
Show 4 discussion topics
Cloud Security Office Hours Meeting
Shawn welcomed new attendees Kelsey Jones and Daniel to the Cloud Security Office Hours meeting. Kelsey introduced herself as a marketing professional from New York working at Minimus security company, while Daniel shared that he recently graduated from Rutgers University with a degree in Information Technology and Informatics and was interested in learning about cloud security. Shawn emphasized that the meeting follows an open format where participants can ask questions freely, and Neil mentioned that he had previously met Daniel at a conference where they had an extended discussion about security topics.
AI and Phishing Email Interactions
The team discussed how AI interacts with phishing emails, with Daniel explaining that AI can effectively scan for vulnerable targets and customize phishing campaigns, making mass phishing more targeted and efficient. Daniel noted that while autonomous follow-up responses to phishing emails are possible, he hasn't tested this functionality himself and believes it's still emerging in the cybersecurity space. The conversation concluded with team members sharing experiences about not remembering everything they learn, with Stryker and Matt emphasizing that asking questions and knowing where to find information is more important than memorizing details.
Threat Intelligence Report Legal Dispute
The group discussed a reported lawsuit in which a startup is suing Palo Alto Networks and Koi Security over a threat intelligence report that, the startup alleges, wrongly identified it as a Chinese espionage front. The allegations have not been tested in court, and nothing here should be read as a finding about any party. Using the case as a prompt, members argued that threat-intel publications need stronger corroboration and review before attribution claims go out, and discussed where legal review belongs in that process.
Cybersecurity Attribution and Cloud Security
The group discussed attribution in cybersecurity, with opinions divided on its relevance and usefulness. Neil shared his experience as an incident responder where attribution helped inform investigations, while Matt questioned whether sufficient investigation was done before including domains in IOCs. The conversation then shifted to cloud security topics, including cloud architecture decisions between vertical and horizontal scaling, with Don providing an analogy using Mario characters to explain the concepts. Shawn updated the group on new labs added to the Cloud Security Office Hours website, highlighting cost-saving strategies for cloud deployments. The conversation ended with discussions about upcoming security conferences like Black Hat and DEF CON, where several participants planned to attend.
