The Five Most Dangerous New Attack Techniques You Need to Know About
RSA Conference 2024 · West Stage Keynote
Overview
This article delves into the critical insights shared during the 15th annual SANS panel at RSA Conference 2024, titled "The Five Most Dangerous New Attack Techniques You Need to Know About." Led by Ed Skoudis, President of the SANS Technology Institute College, the panel brought together leading experts from the SANS community to dissect emerging threats and, crucially, explore "the art of the possible defenses" against them. The discussion highlights a landscape where established vulnerabilities intersect with rapidly advancing technologies like artificial intelligence, creating a complex and urgent challenge for cybersecurity professionals.

Key moments
- 0:00 Welcome and panel introduction
- 2:30 15 years of SANS Top Five Attacks Panel
- 4:10 Introduction of the expert panelists
- 10:07 First attack: Security impact of technical debt
- 11:10 Legacy code and developer scarcity vulnerability
- 11:45 Technical debt examples in security products
The Five Most Dangerous New Attack Techniques You Need to Know About
Speakers: Dr. Johannes Ullrich, Dean of Research, SANS Technology Institute College; Heather Barnhart, Senior Director, Community Engagement, Cellebrite; Terrence Williams, Security Engineer, AWS; Stephen Sims, Offensive Operations Curriculum Lead & Fellow, SANS Institute
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=aHqk2SksV8o
Overview
This article delves into the critical insights shared during the 15th annual SANS panel at RSA Conference 2024, titled "The Five Most Dangerous New Attack Techniques You Need to Know About." Led by Ed Skoudis, President of the SANS Technology Institute College, the panel brought together leading experts from the SANS community to dissect emerging threats and, crucially, explore "the art of the possible defenses" against them. The discussion highlights a landscape where established vulnerabilities intersect with rapidly advancing technologies like artificial intelligence, creating a complex and urgent challenge for cybersecurity professionals.
The panel's unique strength lies in its collaborative approach, drawing on data from the Internet Storm Center, insights from SANS authors and students, and the collective experience of its curriculum leads. This year's installment focuses on a diverse array of threats, ranging from the insidious impact of technical debt within enterprise and security products to the societal and security implications of AI-driven deepfakes, sextortion, and the weaponization of AI in offensive operations and election interference. The goal is not merely to identify dangers but to equip defenders with practical, actionable strategies to secure their organizations and communities.
The insights presented underscore a pivotal moment in cybersecurity, where the speed and scale of attacks are being dramatically amplified by automation and AI. The panelists articulate how these advancements are lowering the barrier to entry for adversaries, making sophisticated attacks more accessible and cost-effective. Consequently, the article aims to provide a comprehensive understanding of these top five threats, offering a deep dive into their technical underpinnings and delivering concrete recommendations for bolstering defenses in this evolving threat landscape.
Background
▶ Watch: Welcome and panel introduction (0:00)
The SANS Institute, celebrating its 35th anniversary, was founded on the principle of information sharing and collaboration to combat cybersecurity threats. A quarter-century ago, SANS established the Internet Storm Center (ISC), a volunteer organization of incident handlers monitoring global internet attacks 24/7. Building on this legacy, the annual SANS panel on "The Five Most Dangerous Attacks" has become a cornerstone of the RSA Conference for the past 15 years, serving as a vital community forum to identify and address the most pressing cybersecurity challenges.
This panel's methodology involves a rigorous process of gathering intelligence from the SANS community, including insights from course authors, summit discussions, student research, and real-world data from the ISC. The selection of the "top five" threats reflects a consensus on the most impactful and emerging attack vectors that organizations need to prioritize. This year's conference theme, "The Art of Possible," significantly influenced the panel's focus, emphasizing not just the identification of threats but also the exploration of practical, implementable defenses. The historical context of SANS' commitment to community-driven intelligence underpins the panel's authority and relevance, providing a unique perspective on the evolving threat landscape.
Key Findings
▶ Watch: Introduction of the expert panelists (4:10)
The panel identified five critical areas representing the most dangerous attack techniques and challenges for 2024:
- Security Impact of Technical Debt: Dr. Johannes Ullrich highlighted how accumulated technical debt, particularly in older software and even critical security products, leads to fragility, unpatchable vulnerabilities, and a severe shortage of developers capable of maintaining legacy codebases.
- AI-Driven Impersonation and Identity Fraud: Ullrich further emphasized that the game-changer in impersonation is not the quality of deepfakes but their dramatically reduced cost and accessibility. This enables widespread synthetic identity fraud, bypassing traditional verification methods like CAPTCHAs and even government ID checks.
- Sextortion as an Edgy Threat: Heather Barnhart revealed sextortion as a rapidly growing and under-addressed threat, amplified by AI deepfakes. It targets individuals, including children, and poses significant risks to organizational security through employee compromise and reputational damage.
- AI's Impact on Elections and Trust: Terrence Williams discussed the profound implications of AI on global elections, stressing the delicate balance between innovation, security, and public trust. AI-powered misinformation (deepfakes, robo-calls) and targeted campaigns threaten to erode the integrity of democratic processes.
- Offensive AI as a Force Multiplier: Stephen Sims showcased how AI and automation are transforming offensive capabilities, drastically increasing the speed and scale of vulnerability discovery and weaponization. This shift challenges traditional defensive paradigms and demands a proactive, AI-informed defensive strategy.
Technical Deep Dive
▶ Watch: First attack: Security impact of technical debt (10:07)
The panel provided a granular look into the technical aspects of each identified threat:
Technical Debt in Security Products
Dr. Johannes Ullrich underscored that technical debt is not just an enterprise application problem but increasingly affects core security products. He cited examples of products dating back to 1998 and 2002, revealing codebases built with a spaghetti of languages like Perl, Python, Java, and even legacy .NET and Excel macros. The critical issue arises when these products are maintained by developers who may not understand all the underlying languages, or when original developers have retired. This leads to fragile software stacks that are difficult to patch, especially when multiple incremental updates have been skipped. Ullrich stressed the importance of incremental patching as releases occur, preventing the accumulation of complex interdependencies that make future security fixes arduous. The challenge is compounded when "new" security products are merely rebranded older solutions, carrying forward their inherent technical debt.
AI-Driven Impersonation and Identity Fraud
Ullrich identified the cost reduction of creating realistic fake videos and audio as the primary driver behind the surge in AI-driven impersonation. While sophisticated impersonation was once expensive, it now costs "a couple thousands of dollars," making it accessible to a broader range of attackers. He referenced Peter Schneider's 1993 quote on online identity, highlighting its continued relevance. Traditional human verification methods like CAPTCHAs are increasingly ineffective, with machine learning models now outperforming humans in solving them. The panel presented onlyfake.com as a stark example, a website that generates not only fake IDs but also realistic background images (e.g., carpets, wood) to mimic genuine photos taken in a home environment. These synthetic identities have already been used to defraud financial systems. The challenge for organizations is to balance robust initial identity verification (where significant effort and cost are required) with risk-based incremental authentication for returning users, all while navigating regulatory requirements like Know Your Customer (KYC) and avoiding customer backlash, as seen with the IRS's problematic use of ID.me.
Sextortion
Heather Barnhart brought to light the alarming rise of sextortion, where individuals are coerced, often financially, through the threat of releasing compromising images or videos. The threat is global and growing, with the FBI issuing warnings about targeting teens. A critical technical aspect is the role of AI deepfakes: even if a victim has never provided a compromising image, AI can generate highly convincing ones based on publicly available photos or videos. This makes everyone, especially those with an online presence (like security professionals speaking at conferences), a potential target. The psychological manipulation, or grooming, often involves forming a relationship (friendly or threatening) before demanding further images or financial payment. The "threat of sharing" can extend to professional networks, impacting an individual's career and an organization's reputation. Barnhart noted that boys aged 10-14 are currently the greatest target, often responding to financial threats. She mentioned the Report Act and Defiance Act as legislative efforts to combat child sexual abuse material (CSAM) and trafficking, providing a legal framework for intervention.
AI's Impact on Elections and Trust
Terrence Williams elucidated the complex interplay of AI in modern elections, framing it as a balance between innovation, security, and trust. AI facilitates better-targeted political ad campaigns and faster content generation, but it also magnifies the efficiency of misinformation dissemination, similar to the early days of social media. The core technical concern is how AI makes adversaries "more lethal," accelerating their ability to discover and exploit vulnerabilities within days or weeks. This rapid advancement means that organizations delaying AI adoption for security reasons risk falling behind attackers who are already leveraging it effectively. Williams highlighted the importance of collaboration between tech companies (e.g., Tech Accords), political parties, academia, and grassroots foundations. Academia is researching AI detection methods (for images/videos), tech companies are integrating safety nets into new solutions, and legislation is emerging at federal and state levels. The non-discriminatory nature of AI means it can generate both beneficial targeted ads and malicious targeted attacks on infrastructure, emphasizing the need for robust accountability to maintain public trust in electoral processes.
Offensive AI as a Force Multiplier
Stephen Sims provided a chilling perspective on how AI is acting as a force multiplier for offensive operations. He demonstrated ShellGPT as an example of an AI tool that empowers attackers by generating complex code, such as specific SQL queries for different database types. Sims distinguished between adversarial AI (attacking AI models themselves, e.g., prompt injection) and offensive AI (using AI to aid traditional attacks). He referenced the DARPA Cyber Grand Challenge from 2016, which aimed to automate vulnerability identification, patching, and exploitation. While early attempts were basic, the technology has evolved dramatically. The most significant threat is speed: AI accelerates vulnerability discovery (reverse engineering, fuzzing, static/code analysis) and weaponization. A recent paper noted that LLM agents can autonomously exploit one-day vulnerabilities (vulnerabilities for which a patch is available, but exploitation occurs before widespread patching). While these may currently function as "glorified search engines" for web app exploits, the future points to AI automating binary exploitation through patch diffing, leveraging vast datasets, and using Retrieval Augmented Generation (RAG) for threat intelligence. The vision is a chain of AI agents automating debugging, weaponization, and even virtual machine generation, drastically reducing the manual effort and time required for sophisticated attacks.
Demo / Proof of Concept
▶ Watch: Legacy code and developer scarcity vulnerability (11:10)
The SANS panel format at RSA Conference is primarily a discussion and presentation of research findings rather than a live demonstration of tools or exploits. While the speakers referenced specific tools like ShellGPT and websites like onlyfake.com, the talk did not include any live demos or proofs of concept. The impact of the discussed threats was conveyed through illustrative examples and theoretical explanations of how these techniques are being, or could be, leveraged by adversaries.
Defensive Implications
▶ Watch: Technical debt examples in security products (11:45)
The panel's insights offer critical guidance for defenders:
- Address Technical Debt Proactively: Organizations must audit their existing software, including critical security products, for signs of technical debt. Ask vendors about their approach to legacy code, their history of vulnerability responses, and request pen test reports. Prioritize incremental patching of all software, as delaying updates creates a complex, vulnerable environment that is exponentially harder to secure later.
- Strengthen Identity Verification: In an era of cheap deepfakes and synthetic identities, invest heavily in robust initial identity verification processes. Move beyond easily spoofed methods and adopt risk-based authentication for subsequent interactions, adapting security measures to the criticality of the accessed resources. Be aware of advanced fraud techniques that mimic real-world identity verification scenarios (e.g., fake IDs with realistic backgrounds).
- Implement Extortion Awareness Training: Integrate extortion awareness training into existing security awareness programs, not just for employees but also for their families. This training should cover the psychological tactics used in grooming, the dangers of sharing personal information, and the role of AI deepfakes. Emphasize that victims are not at fault. Provide clear reporting mechanisms and support resources, such as the National Center for Missing and Exploited Children (NCMEC) and its
takeitdown.orgservice, which can remove compromising images and videos. - Foster Collaboration and Verify Information: For voters, the mantra for upcoming elections must be "trust but verify." Actively seek out fact-checking platforms and diverse news sources. For organizations, advocate for and participate in cross-sector collaboration between tech companies, government bodies, and academia to develop detection mechanisms for AI-generated content and establish accountability frameworks. Ensure internal systems are resilient against targeted misinformation campaigns.
- Leverage AI for Defense: Defenders must not shy away from AI; instead, they should embrace it as a strategic tool. Implement AI-driven automation in defensive operations, including purple teaming, penetration testing, and red teaming. Use AI to instrument environments, analyze threat intelligence (e.g., via RAG), and automatically generate defensive artifacts like YARA rules or Sigma rules. The speed and intelligence of offensive AI demand a proportional response from the blue team, ensuring that defensive capabilities evolve at the same pace to avoid complacency.
Key Takeaways
- Technical Debt is a Hidden Security Crisis: Legacy codebases, even within security products, are increasingly vulnerable due to complexity and a scarcity of developers proficient in older languages, demanding a rigorous focus on incremental patching and vendor accountability.
- AI Democratizes Impersonation: The dramatically reduced cost of creating high-quality deepfakes and synthetic identities fundamentally alters the threat landscape for identity verification, necessitating advanced, risk-based authentication strategies.
- Sextortion is a Pervasive and AI-Enhanced Threat: This "edgy" but growing crime, amplified by AI's ability to create convincing fake images, poses significant psychological, financial, and organizational risks, requiring targeted awareness training and robust support systems.
- AI Challenges Electoral Integrity and Public Trust: The deployment of AI for targeted misinformation, deepfakes, and robo-calls in elections threatens to erode public trust in democratic processes, underscoring the critical need for cross-sector collaboration and voter vigilance.
- Offensive AI is a Force Multiplier for Adversaries: AI and automation are drastically accelerating the speed of vulnerability discovery and exploitation, transforming offensive capabilities and requiring defenders to leverage AI themselves to maintain parity.
- Defenders Must Embrace AI and Avoid Complacency: To counter the rapidly evolving, AI-driven threat landscape, cybersecurity professionals must proactively integrate AI and automation into their defensive strategies, focusing on rapid response, continuous learning, and intelligent threat detection.
About the Speaker(s)
The panel featured a distinguished group of cybersecurity experts, each bringing unique insights to the discussion:
- Dr. Johannes Ullrich: Dean of Research at the SANS Technology Institute College. He is the founder of D-Shield.org, the first and longest-running global sensor network for detecting current attacks, and the Director of the Internet Storm Center, overseeing over 40 volunteer handlers. Dr. Ullrich supports over 2,000 college students in cybersecurity research.
- Heather Barnhart: Senior Director of Community Engagement at Cellebrite and a SANS Faculty Fellow. She is an author, curator, and Capture The Flag (CTF) creator, known for her work with global organizations including law enforcement and government agencies on mobile device forensics. She is also a recognized social media contributor to the cybersecurity community.
- Terrence Williams: A Security Engineer with AWS and a SANS certified instructor specializing in Digital Forensics and Incident Response (DFIR). His extensive experience includes safeguarding Meta's family of applications during global elections from 2020 to 2022, protecting billions of users worldwide, and working in military and large tech environments.
- Stephen Sims: Offensive Operations Curriculum Lead and Fellow with the SANS Institute. He is a community contributor, co-author of a book on Grey Hat Hacking, and hosts the technically in-depth "Off By One Security Podcast" with an accompanying YouTube channel. Stephen is a renowned security researcher who has discovered numerous vulnerabilities in widely used applications, including web browsers, the Windows kernel, and point-of-sale devices.