Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

Moveworks and Simpplr Partner to Give Enterprises Greater Flexibility in the Digital Workplace

DeepScientist: Advancing Frontier-Pushing Scientific Findings Progressively – Takara TLDR

Google’s Gemini-powered smart home revamp is here with a new app and cameras

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Crunchbase AI

The Billion-Dollar Security Threat: All Industries On Guard

By Advanced AI EditorOctober 1, 2025No Comments5 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


By Jason Martin

The costs are piling up from a three-year running cybersecurity threat that shows no signs of abating as it spreads to more industries.

The likely culprit: a hacking collective known as “Scattered Spider.” The playbook: get into a company’s internal systems via hacked employee credentials, cause havoc, demand ransom.

Just recently, Jaguar Land Rover was targeted in an attack by the group. The company hasn’t been able to make cars for a month as a result. Before that, Qantas reported that annual executive bonuses would be cut by 15% after Scattered Spider targeted them in a July cyber attack.

Jason Martin is a co-founder and co-CEO of Permiso Security
Jason Martin

Clorox sued its help desk provider, Cognizant Technology Solutions, for $380 million in damages, alleging that Cognizant improperly reset passwords for Scattered Spider hackers posing as employees. A few weeks earlier, Whole Foods supplier United Natural Foods estimated it lost up to $400 million in sales when hackers disrupted systems. Three years ago, casinos were hit.

This is real money, and a real threat that most companies are not well prepared to guard against. Today, hackers don’t just bust into corporate systems, they log in — like thieves walking in through open household doors. Almost nine of 10 (88%) of breaches via basic web applications involve use of stolen credentials, indicates Verizon’s 2025 Data Breach Investigations Report.

In the case of Scattered Spider, culprits do such things as ask for password resets, change phone numbers tied to multifactor authentication solutions, or add phone numbers to reset passwords, and more.

The rise of AI and AI agents make securing identities even more critical. As AI agents spread, they’re a new class of “non-human identities” that vastly increase the attack surface. As with most cybersecurity threats, Scattered Spider changes tactics all the time and we are seeing indications of AI use supporting and augmenting their social engineering tactics.

Putting up speed bumps

When modeling approaches to increase resilience against their attacks it’s best to think of the worst case, which is: “assume breach.” Then evaluate how quickly you could detect attacks matching their approach and what your teams would do. While keeping them out is an admirable goal, it is very difficult since they exploit the processes you’ve set up to support your own enterprise users or contractors. The most realistic goal is to set up speed bumps to slow hackers down so they’re stopped before doing much damage.

Steps to bolster defenses include:

Teamwork. Most companies have “security teams.” A lot of companies now have “identity teams.” Identity refers to employees — or AI agents — with access to company assets via passwords and other credentials.

Given the rise of identity-based cybersecurity threats, it’s imperative that these teams fuse or work more closely together to find shared solutions. Company assets are now also highly fragmented, with some in the cloud, some on-premise and some via software-as-a-service providers like Slack. There’s also shadow IT and shadow AI, like ChatGPT, that employees use that security or identity people may not know they’re using. Every organization needs to be clear on who owns what from a security and identity perspective so that guidelines, policies and solutions are more airtight.

Awareness. How exposed are you? How much “identity sprawl” do you have? Identity sprawl occurs over time, just like data sprawl. New hires get digital identities and access to company data. In almost all cases when it comes to the cloud, identity access management policies are too lenient, research finds, which means employees have access to things they don’t really need — which can add security risk. There’s also risk when people leave a company, voluntarily or not, if digital identities don’t get quickly or properly shut down.

With Scattered Spider, we’re seeing criminals access things that real employees haven’t opened in more than a year. Identity management is not one and done. Identities have a life cycle and need to be managed through the whole thing.

Observability. How well can you see what’s going on inside your company? An attack via a network sets off bells and whistles. But when an “employee” logs in who’s not an actual employee, there’s no bell or whistle. Instead, you want to detect threats via signals of suspicious and malicious activity.

Basic Training/Testing. Nearly 70% of organizations recently surveyed “believe their employees lack critical cybersecurity knowledge.” This needs to change because employees, while one of your biggest cybersecurity risks, will also be one of your best lines of defense. Of course, training must extend to third-party vendors.

In its lawsuit, Clorox alleges that a hacker got a multifactor authentication reset by simply telling the help desk worker that the MFA wasn’t working and that he or she was “on my old phone.” Beyond training, test vendor performance so that you’re not blindsided if they’re not doing what they’re supposed to be doing.

Like good insurance

No doubt, companies will eventually take the right steps to curb Scattered Spider-like attacks. The bad news is that cybercriminals will adjust to launch new tactics. Companies that make cybersecurity defense a priority will be like people who have good insurance. They will never totally prevent risk, but they’ll mitigate damage.

Jason Martin is a co-founder and co-CEO of Permiso Security, a leader in identity security, providing advanced solutions to help organizations detect and respond to threats targeting human and nonhuman identities across cloud environments. His extensive background includes leadership roles at FireEye, where he contributed to product strategy and engineering. Martin is also an active investor and adviser, supporting various startups in the security domain, and has authored multiple publications that contribute to the understanding of security analytics and risk assessment.

Related Crunchbase query:

Illustration: Dom Guzman


Stay up to date with recent funding rounds, acquisitions, and more with the
Crunchbase Daily.



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSalesforce launches enterprise vibe coding product, Agentforce Vibes
Next Article The Download: OpenAI’s caste bias problem, and how AI videos are made
Advanced AI Editor
  • Website

Related Posts

The AI Value Chain Has Shifted. Here’s How Founders Can Still Build A Sustainable Business

September 30, 2025

Here’s How To Stay Ahead Of It

September 29, 2025

Biotech Share Of US Funding Hits Lowest Point In Crunchbase History

September 29, 2025

Comments are closed.

Latest Posts

Smithsonian Museums to Remain Open Amid Government Shutdown

Statue Left Behind by Grave Robbers Unearthed in Saqqara, Egypt

Security Guards Accuse de Young Museum of Abusive Workplace Culture

Vancouver Art Gallery Taps Canadian Firms to Co-Design New Building

Latest Posts

Moveworks and Simpplr Partner to Give Enterprises Greater Flexibility in the Digital Workplace

October 1, 2025

DeepScientist: Advancing Frontier-Pushing Scientific Findings Progressively – Takara TLDR

October 1, 2025

Google’s Gemini-powered smart home revamp is here with a new app and cameras

October 1, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Moveworks and Simpplr Partner to Give Enterprises Greater Flexibility in the Digital Workplace
  • DeepScientist: Advancing Frontier-Pushing Scientific Findings Progressively – Takara TLDR
  • Google’s Gemini-powered smart home revamp is here with a new app and cameras
  • IBM: Betting Big On AI, Delivering Strong Margins But At A Price
  • The Download: OpenAI’s caste bias problem, and how AI videos are made

Recent Comments

  1. Theresia Weeks on C3 AI and Arcfield Announce Partnership to Accelerate AI Capabilities to Serve U.S. Defense and Intelligence Communities
  2. Andrewfex on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  3. Davidglavy on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  4. Darrick Acken on Class Dismissed? Representative Claims in Getty v. Stability AI | Cooley LLP
  5. Donaldvon on New MIT CSAIL study suggests that AI won’t steal as many jobs as expected

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.