Firmware-based attacks are some of the hardest to detect, which is what makes them so dangerous; once someone has control over your hardware, they can do just about anything. In this episode of Cyber Security Inside, CEO and founder of Eclypsium Yuriy Bulygin joins Tom and Camille to share his expertise on the topic, offering a comprehensive view of vulnerabilities and how threat groups exploit them.

They cover:

  • Why firmware attacks are so brutal, and how the known vulnerabilities are being exploited by threat groups

  • How people can tell if they’ve been a victim of a ransomware attack and/or if it’s gotten down to the firmware level

  • Whether or not ransomware attacks should be paid

  • How the new model of working from home during the pandemic has shifted the threat landscape

  • What advice companies should consider securing their platforms

... and more. Tune in for some next-level insight.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Firmware attacks have become more and more common as user and software protection have improved; adversaries needed to find a way of going undetected, which is why they began to target actual devices and equipment.

  • In fact, NIST reports that device vulnerabilities have increased five-fold in the past four years alone.

  • One of the biggest problems with firmware attacks is that that ransomware can come back even after a device has been cleaned because that’s how deeply embedded things are.

  • While it’s not good to incentivize successful ransomware attacks, there are certain cases where it becomes necessary; for example, a recent hospital attack led to the deaths of patients, and that would be a scenario where it would make sense to pay.

  • With more and more people working from home, remote endpoints have become a major target for threat groups.

  • It’s crucial to be able to authenticate users, have a strong understanding of devices, secure the applications and software stack used on remote endpoints, and protect the overall remote infrastructure to prevent attacks.

  • Bringing visibility into devices and equipment is essential to be able to make risk-based decisions.

Some interesting quotes from today’s episode:

“They started looking for other ways they could enjoy being hidden, being persistent, not being detected. And we started seeing a spike of attacks against devices, against the actual equipment and everything that comes with that equipment that organizations use.”

“I think we, as an industry, should be adopting a risk and threat-centric approach where we’re going to cover the fundamental pieces of devices or the software, firmware on those devices that are actually high risk for being attacked.”

“A very typical example is that a ransomware has attacked one of the companies that we’ve talked to, and they cleaned up that ransomware, but after a very short period of time, it came back.”

“They shifted and started exploiting the remote endpoints -- the home devices that those remote endpoints are connected to and the network infrastructure that those remote devices are connecting through, like those VPN appliances and ADC appliances and so on and so forth.”

“There need to be new types of security solutions that protect those remote access infrastructure devices.”

“Some of these devices might need to be inspected for breaches even before they’re being used.”