Connect with us
European Gaming Congress 2024

Artificial Intelligence

Silverfort Research Finds Two-Thirds of Businesses Sync On-prem Passwords to Cloud Environments, Opening their Cloud to Cyberattack

Published

on

silverfort-research-finds-two-thirds-of-businesses-sync-on-prem-passwords-to-cloud-environments,-opening-their-cloud-to-cyberattack

Company Unveils its Proprietary Identity Underground Report 2024; First Identity Report 100% Dedicated to Exposing Frequency & Prevalence of Identity Threat Exposures (ITEs)
Alphv BlackCat and Lockbit ransomware threat actors abuse gaps in identity to steal credentials, escalate privileges, and move through organizations undetected
TEL AVIV, Israel & BOSTON, March 26, 2024 /PRNewswire/ — Today, Silverfort, the Unified Identity Protection Company, unveiled its Identity Underground report, highlighting the frequency of identity security gaps that lead to successful attacks on organizations across every industry and region. Fueled by Silverfort’s proprietary data, the report is the first of its kind, focusing on identity as an attack vector and offering insights into the Identity Threat Exposures (ITEs) that pave the way for cyberattacks. The data, analysis, and insights help identity and security teams benchmark their security programs, empowering them to make informed decisions on where to invest in identity security. 

The standout – and alarming – finding is that two out of every three businesses (67%) routinely synchronize most of their users’ passwords from their on-premises directories to their cloud counterparts. This practice inadvertently migrates on-prem identity weaknesses to the cloud, which poses substantial security risks by creating a gateway for attackers to hack these environments from on-prem settings. The Alphv BlackCat ransomware group is known to use Active Directory as a stepping stone to compromise cloud identity providers.
Over the past decade, there has been a rush to migrate to the cloud – and for a good reason. Simultaneously, however, security gaps stemming from legacy infrastructure, misconfigurations, and insecure built-in features create pathways for attackers to access the cloud, significantly weakening a company’s resilience to identity threats.
“Identity is the elephant in the room. We know that identity plays a key role in nearly every cyberattack. Lockbit, BlackCat, TA577, Fancy Bear – they all use identity gaps to break in, move laterally, and gain more permissions,” said Hed Kovetz, CEO and Co-founder of Silverfort. “But we need to know how common each identity security gap is so we can start methodically fixing them. Finally, we have concrete evidence outlining the frequency of identity gaps, which we can now classify as Password Exposers, Lateral Movers, or Privilege Escalators, and they’re all vehicles for threat actors to complete their attacks. We hope that by shining a light on the prevalence of these issues, identity and security teams will have the hard numbers they need to prioritize adequate security investments and eliminate these blind spots.”
Key findings include:
Two-thirds of all user accounts authenticate via the weakly encrypted NTLM protocol, providing attackers easy access to cleartext passwords. Easily cracked with brute-force attacks, NT Lan Manager (NTLM) authentication is a prime target for attackers looking to steal credentials and move deeper into an environment. Recent research from Proofpoint security shows threat actor TA577 using NTLM authentication information to steal passwords.A single misconfiguration in an Active Directory account spawns 109 new shadow admins on average. Shadow admins are user accounts with the power to reset passwords or manipulate accounts in other ways. Attackers use shadow admins to change settings and permissions and gain more access to machines as they move deeper into an environment. 7% of user accounts inadvertently hold admin-level access privileges, giving attackers more opportunities to escalate privileges and move throughout environments undetected.31% of user accounts are service accounts. Service accounts are used for machine-to-machine communication and have a high level of access and privileges. Attackers target service accounts as security teams often overlook them. Only 20% of companies are highly confident that they have visibility into every service account and can protect them.13% of user accounts are categorized as “stale accounts,” which are effectively dormant user accounts that the IT team may have forgotten. They are easy targets for lateral movement and evading detection by attackers.Silverfort’s research team has meticulously categorized Identity Threat Exposures (ITE) into four distinct classes. Their goal is to arm the cybersecurity industry with a framework to classify and understand the diverse spectrum of identity issues and misconfigurations that enable credential theft, privilege escalation, and lateral movement by malicious actors.
The four ITE categories
Password Exposers: Enable an attacker to discover users’ passwords by exposing the password hash to common compromise techniques. Examples include NTLM authentication, NTLMv1 authentication, and admins with SPN.Privilege Escalators: Allow an attacker to gain additional access privileges. Typically Privilege Escalators are the result of a misconfiguration or insecure legacy settings. Examples include shadow admins and unconstrained delegation.Lateral Movers: Allow an attacker to move laterally undetected. Examples include service accounts and prolific users.Protection Dodgers: Potentially open legitimate user accounts up for attackers to use. Protection Dodgers stem from human error or mismanaged user accounts; they are not inherently security flaws or misconfigurations. Examples include new users, shared accounts, and stale users.Join Silverfort’s identity threat experts on April 16th in partnership with Hacker News for a deep dive into the report findings. Visit Identity Underground to access the complete report.
About Silverfort
Silverfort, the Unified Identity Protection company, pioneered the first and only platform that enables modern identity security everywhere. We connect the silos of enterprise identity infrastructure to unify identity security across all on-prem and the cloud environments. Our unique architecture and vendor agnostic approach, takes away the complexity of securing every identity, and extends protection to resources that cannot be protected by any other solution, such as legacy systems, command-line interfaces, service accounts (non-human identities), IT/OT infrastructure, amongst others. Silverfort is a top-tier Microsoft partner and was selected as Microsoft’s Zero Trust Champion of the Year. Hundreds of the world’s leading enterprises trust Silverfort to be their identity security provider, including multiple Fortune 50 companies. Learn more by visiting www.silverfort.com or on LinkedIn.
Media Contact:Jill [email protected]
Logo – https://mma.prnewswire.com/media/2321859/Silverfort_Logo.jpg

View original content:https://www.prnewswire.co.uk/news-releases/silverfort-research-finds-two-thirds-of-businesses-sync-on-prem-passwords-to-cloud-environments-opening-their-cloud-to-cyberattack-302098654.html

Continue Reading
Advertisement
Stake.com

Artificial Intelligence

Lucinity’s AI Copilot Wins Innovation in Financial Crime Prevention at ICA Compliance Awards 2024

Published

on

lucinity’s-ai-copilot-wins-innovation-in-financial-crime-prevention-at-ica-compliance-awards-2024

REYKJAVIK, Iceland, July 1, 2024 /PRNewswire/ —  Lucinity has received the 2024 ICA Award for Innovation in Financial Crime Prevention, recognizing its exceptional AI innovations, including the Luci copilot. The ICA Compliance Awards celebrate excellence in compliance and financial crime prevention, and Lucinity’s Generative AI copilot, Luci, stood out for its significant impact on operational efficiency.

 
Luci, launched in 2023, transforms complex financial data into actionable insights using generative AI. It reduces case investigation times from an average of three hours to just 30 minutes, resulting in substantial cost savings. A Tier 1 bank can potentially save up to $36 million annually in training and recruitment costs and boost productivity by $100 million yearly.
Luci includes out-of-the-box skills such as case summarization, business validation, adverse media and negative news searches, money flow visualizations, transaction summaries, writing and sending requests for information (RFI), generating Suspicious Activity Reports (SARs), and address checks. These features allow compliance teams to shift their focus from manual tasks to higher-level decision-making.
To further enhance its offerings, Lucinity recently launched the Luci plugin, enabling seamless integration with any web-based application. The plugin is platform agnostic, allowing it to be incorporated into various tech stacks, including case management systems and CRMs. Financial institutions can immediately benefit from AI and automation, leading to a more efficient and consistent workforce and productivity boosts of up to 90%.
Lucinity continues to ensure maximum security and responsible AI development through its integration with Microsoft’s OpenAI on Azure. Lucinity also recently launched the Luci Studio where users can customize their AI copilots in a no-code, drag-and-drop user interface, providing full explainability for the actions that AI takes. 
Founder and CEO of Lucinity, Guðmundur Kristjánsson, expressed his gratitude, stating, “2023 and 2024 have been transformative years for Lucinity. With seven large banks now requesting to trial Luci and widespread interest in our AI copilot, we’ve received numerous accolades and media attention. Luci is proving to be an essential tool in financial crime operations.”
This award follows several other achievements by Lucinity in 2024, such as the inclusion in the Fintech100 list, winning the Microsoft Partner of the Year Awards, and acknowledgment in Chartis Research’s FinCrime and Compliance 50 Ranking for 2024.
The full list of winners for the ICA Compliance Awards 2024 can be found here.
Contact:Celina [email protected] +354 792 4321
Logo: https://mma.prnewswire.com/media/2208676/4791561/Lucinity_Logo.jpg

View original content:https://www.prnewswire.co.uk/news-releases/lucinitys-ai-copilot-wins-innovation-in-financial-crime-prevention-at-ica-compliance-awards-2024-302187195.html

Continue Reading

Artificial Intelligence

Vivity AI Applauded by Frost & Sullivan for Addressing Inefficiencies and Risk Mismanagement in Heavy Industry and its Market-leading Position

Published

on

vivity-ai-applauded-by-frost-&-sullivan-for-addressing-inefficiencies-and-risk-mismanagement-in-heavy-industry-and-its-market-leading-position

Vivity is expanding globally, landing customers in the United States, Southeast Asia, and the Middle East, as heavy industry customers span geographies yet work similarly around the world.
SAN ANTONIO, July 1, 2024 /PRNewswire/ — Frost & Sullivan assessed Industrial AI for heavy industry, and based on its findings, recognizes Vivity AI Inc. with the 2024 Global Entrepreneurial Company of the Year Award. The company offers industry-specific AI products with its data expertise in the heavy industry. It developed an end-to-end AI platform based on 3 pillars: Vivity Edge to identify and track processes, Vivity Analytics to analyze data and obtain actionable insights, and Vivity Studio to manage and operate AI. It offers incremental steps—from Edge to Analytics to Studio, helping customers set up their own data science or AI team once they are ready to proceed. Vivity Edge is lightweight and focuses on point use cases initially so that customers can quickly deploy it in a few months without having to set up a whole data collection pipeline.

Vivity Edge provides highly reliable failure detection with a low false alarm rate and cost-effective deployment, whereas Vivity Analytics comes with state-of-the-art generative AI and LLM. The built-in data quality analyzer of Vivity Analytics relies on understanding the heavy industry’s metal working processes. Focused on heavy industry customers, Vivity has found a blue space opportunity where it leverages AI to help transform this sector. Vivity’s multiple algorithms work in extreme video stabilization under different conditions, such as sunlight, shade, and extreme vibration because the environment is often harsh. The company leverages its connections and expertise to create good reference cases and develop its AI technology for heavy industry.
Sankara Narayanan, Industry Director, Frost & Sullivan, observed “General-purpose MLOps or out-of-the-box AI platforms designed for the manufacturing sector cannot solve the kind of problems that heavy industries face. Here is where Vivity excels. The company built its AI platform from the ground up for particular verticals of heavy industry, making many of the technologies’ core features competitive differentiators, including extreme video stabilization, multi-modal response, smart and dynamic ROI computation, operation condition identification, and hyper-feature detection.”
Vivity has a fairly large computer vision team with staff from leading companies such as Cognex and Samsung, and technologies horizontally applicable in construction and logistics. Its data science team focuses on predictive analytics and uses data for tracking and optimization of product quality and workflow. From cloud and micro-servers to on-premises deployment, Vivity offers a wide range of customizable options to meet its customers’ various infrastructure needs. Its drone-based image analysis and sensor technology enable real-time awareness and advanced ML-driven scheduling optimization while a highly scalable industry approach supports the company’s coherent vision.
“Vivity’s customizable deployment options; seamless AI adoption journey; task-oriented, domain-specific AI modules and user-driven use cases such as workplace safety and critical equipment monitoring, enhance customers’ operational efficiency and value proposition. The company has grown significantly in the last 18 months and continues to expand globally on its way to become the AI platform of choice for heavy industry customers worldwide,” added Sankara Narayanan. Vivity earns Frost & Sullivan’s 2024 Global Entrepreneurial Company of the Year Award for its strong overall performance in the industrial AI for heavy industry space.
Each year, Frost & Sullivan presents a Company of the Year award to the organization that demonstrates excellence in terms of growth strategy and implementation in its field. The award recognizes a high degree of innovation with products and technologies, and the resulting leadership in terms of customer value and market penetration.
Frost & Sullivan Best Practices awards recognize companies in various regional and global markets for demonstrating outstanding achievement and superior performance in leadership, technological innovation, customer service, and strategic product development. Industry analysts compare market participants and measure performance through in-depth interviews, analyses, and extensive secondary research to identify best practices in the industry.
About Frost & SullivanFor six decades, Frost & Sullivan has been world-renowned for its role in helping investors, corporate leaders, and governments navigate economic changes and identify disruptive technologies, Mega Trends, new business models, and companies to action, resulting in a continuous flow of growth opportunities to drive future success. Contact us: Start the discussion.
Contact:Lindsey WhitakerP: 1.210.477.8457E:[email protected]
About Vivity AI Inc.
Founded in 2022 by experienced industry professionals, Vivity AI Inc. is at the forefront of AI applications within heavy industry. Providing solutions to world-leading enterprises in shipbuilding, energy, heavy manufacturing, construction and beyond, Vivity AI is advancing a more efficient and sustainable future for all. Contact us: Revolutionize Heavy Industry.
Contact:Divya J. SinghP: 1.925.523.0007E: [email protected]
Photo – https://mma.prnewswire.com/media/2451155/Frost_abd_Sullivan__Vivity_AI_Award.jpg 

View original content:https://www.prnewswire.co.uk/news-releases/vivity-ai-applauded-by-frost–sullivan-for-addressing-inefficiencies-and-risk-mismanagement-in-heavy-industry-and-its-market-leading-position-302186344.html

Continue Reading

Artificial Intelligence

AMI Becomes the First IFV to Achieve NVIDIA System Software Validation Toolkit Compliance on NVIDIA MGX AI Servers

Published

on

ami-becomes-the-first-ifv-to-achieve-nvidia-system-software-validation-toolkit-compliance-on-nvidia-mgx-ai-servers

ATLANTA, July 1, 2024 /PRNewswire/ — AMI®, the global leader in Dynamic Firmware for worldwide computing, today is pleased to announce the complete validation and compliance of its MegaRAC® SP-X manageability solution with the NVIDIA Validation Suite (NVVS) and on NVIDIA MGX modular platforms, powered by the NVIDIA GH200 Grace Hopper Superchip.

AMI’s industry-leading MegaRAC SP-X Server Management Solution offers unparalleled remote management capabilities for server platforms. Its seamless performance and reliability consistently ensure the stability, safety, and security of managed servers.
NVVS serves as a purpose-built, system-level tool intended for use in production environments to evaluate cluster-readiness levels prior to workload deployment. The validation procedure aims to address hardware defects, software and system configuration issues, diagnostic and logging deficiencies, performance degradation, and much more. Its meticulous execution helps resolve these issues, facilitating the seamless deployment of cloud-ready AI platforms.
AMI continues to deploy its global resources to support CSPs/OEMs/ODMs worldwide, powering its NVIDIA GH200 Grace Hopper Superchip-based server platforms designed for high-performance computing (HPC) and AI applications.
AMI is a member of the NVIDIA Partner Network.
“By adding compliance for the NVIDIA Validation Suite to our MegaRAC SP-X Server Management Solution, we are delivering high levels of confidence and compatibility to CSPs, OEMs, and ODMs as they roll out their latest NVIDIA MGX server platforms with NVIDIA Grace CPU and NVIDIA Grace Hopper Superchips,” says Anurag Bhatia, SVP – Global Manageability Solutions Group at AMI.
Follow AMI on LinkedIn and X/Twitter to receive the latest news and announcements.
AMI® and MegaRAC® are registered trademarks of AMI in the US and/or elsewhere. All other trademarks and registered trademarks are the property of their respective owners.
About AMI
AMI is Firmware Reimagined for modern computing. As a global leader in Dynamic Firmware for security, orchestration, and manageability solutions, AMI enables the world’s compute platforms from on-premises to the cloud to the edge. AMI’s industry-leading foundational technology and unwavering customer support have generated lasting partnerships and spurred innovation for some of the most prominent brands in the high-tech industry.
Logo – https://mma.prnewswire.com/media/1327926/AMI_Logo2023.jpg 

View original content:https://www.prnewswire.co.uk/news-releases/ami-becomes-the-first-ifv-to-achieve-nvidia-system-software-validation-toolkit-compliance-on-nvidia-mgx-ai-servers-302186343.html

Continue Reading
Advertisement
Stake.com
Advertisement

Latest News

Trending