
According to security researcher Keren Elazari's lecture at the SecTor conference, ethical hackers can help companies improve their cybersecurity.
Elazari provided an overview of current cybersecurity challenges, including unauthorized cryptocurrency mining, ransomware attacks , SMS phishing, and problems with weak and reused passwords.
With unauthorized cryptocurrency mining, also referred to as crypto-jacking, attackers profit by injecting code into systems, according to Elazari.
Another issue Elazari addressed at SecTor is that companies need to do a better job of managing passwords, which are at the heart of many data breaches. Passwords are commonly reused, she said, which is a real problem given the large data breaches in recent years, including LinkedIn in 2012.
Instead of using passwords, which can be cracked by attackers, Elazari advocates using passphrases, which can be harder for third parties to guess while being easier to remember.
Attackers are also increasingly using automation tools, such as the new AutoSploit tool. AutoSploit integrates with the vulnerability search engine Shodan, which can help identify potential targets. AutoSploit also integrates with the Metasploit penetration testing framework, to automatically trigger exploits for vulnerable targets identified by Shodan.
Elazari further noted that while AI can help, ultimately the cybersecurity challenge requires some human intelligence. To that end, she suggests that organizations need to create a strong security culture that embraces the mindset of ethical hackers.
This mindset, which will include hackers as a security measure, also entails attracting them through bug bounty programs. With these programs, hackers are encouraged and rewarded when they hack systems, with the ultimate goal of trying to improve security.
