WatchGuard’s Threat Lab cybersecurity research team forecast headline-stealing hacks involving LLMs, AI-based voice chatbots and VR/MR headsets. They also assess the impact of the war on talent, AI spear phishing and QR codes.
Watchguard leading on Cybersecurity
WatchGuard Technologies, a global leader in unified cybersecurity, offers an annual batch of predictions covering the most prominent attacks and information security trends that the WatchGuard Threat Lab research team believes will emerge each year. This year, these include malicious prompt engineering tricks targeting large language models (LLMs), managed service providers (MSPs) doubling down on unified security platforms with heavy automation, ‘Vishers’ scaling their malicious operations with AI-based voice chatbots, hacks on modern VR/MR headsets, and more…
“Every new technology trend opens up new attack vectors for cybercriminals,” said Corey Nachreiner, chief security officer at WatchGuard Technologies. “In 2024, the emerging threats targeting companies and individuals will be even more intense, complicated, and difficult to manage. Therefore, with an ongoing cybersecurity skills shortage, the need for MSPs, unified security, and automated platforms to bolster cybersecurity and protect organisations from the ever-evolving threat landscape have never been greater.”
Cybersecurity predictions
The following is a summary of the WatchGuard Threat Lab team’s top cybersecurity predictions for 2024:
Prompt Engineering Tricks Large Language Models (LLMs)
Companies and individuals are experimenting with LLMs to increase operational efficiency. However, threat actors are learning how to exploit LLMs for their own malicious purposes as well. During 2024, the WatchGuard Threat Lab predicts that a smart prompt engineer ‒ whether a criminal attacker or researcher ‒ will crack the code and manipulate an LLM into leaking private data.
MSPs Double Down on Security Services Via Automated Platforms
There are approximately 3.4 million open cybersecurity jobs, and fierce competition for available talent. More SMEs will turn to trusted managed service and security service providers, known as MSPs and MSSPs, to protect them in 2024. To accommodate growing demand and scarce staffing resources, MSPs and MSSPs will double down on unified cybersecurity platforms with heavy automation using artificial AI and Machine Learning.
AI Spear Phishing Tool Sales Boom on the Dark Web
Cybercriminals can already buy tools on the underground that send spam email, automatically craft convincing texts, and scrape the Internet and social media for a particular target’s information and connections. However, a lot of these tools are still manual and require attackers to target one user or group at a time. Well-formatted procedural tasks like these are perfect for automation via AI and machine learning. This makes it likely that AI-powered tools to combat cybersecurity will emerge as best sellers on the dark web in 2024.
AI-Based Vishing Takes Off in 2024
Voice over Internet Protocol (VoIP) and automation technology make it easy to mass dial thousands of numbers. Once a potential victim has been baited onto a call, it still takes a human scammer to reel them in. This system limits the scale of vishing operations. But in 2024 this could change. The combination of convincing deepfake audio and LLMs capable of carrying on conversations with unsuspecting victims will greatly increase the scale and volume of vishing calls. What’s more, they may not even require a human threat actor’s participation.
VR/MR Headsets Allow the Recreation of User Environments
Virtual and mixed reality (VR/MR) headsets are finally beginning to gain mass appeal. However, wherever new and useful technologies emerge, criminal and malicious hackers follow. In 2024, cybersecurity researchers forecast that either a researcher or malicious hacker will find a technique to gather some of the sensor data from VR/MR headsets to recreate the environment users are playing in.
Rampant QR Code Usage Results in a Headline Hack
Quick response (QR) codes provide a convenient way to follow a link with a device such as a mobile phone. They have been around for decades, but mainstream usage has exploded in recent years. Furthermore, Threat Lab cybersecurity analysts expect to see a major, headline-stealing hack in 2024 caused by an employee following a QR code to a malicious destination.
- Cybersecurity in FinTech