Malicious Actors Depend on Your Unknowns. Disappoint Them!
Brian Contos (Mitiga · Field CISO)
SAINTCON 2025 · Day 1 · Main Track 3
Overview
In an era of rapidly evolving technology and expanding digital attack surfaces, Brian Contos, Field CISO at Mitiga, and Patrick "Pio" Zakowski, an expert in security automation, delivered a compelling talk at SAINTCON, highlighting critical blind spots that malicious actors routinely exploit. Titled "Malicious Actors Depend on Your Unknowns. Disappoint Them!", the presentation systematically dissects the pervasive lack of visibility and outdated security paradigms prevalent in three key domains: wireless networks, extended IoT (X-IoT) environments, and cloud infrastructure. The speakers argue that while traditional security approaches have focused on known endpoints and network segments, the explosion of new, often unmonitored, devices and interconnected cloud services creates vast "shadows" where attackers can operate undetected.

Key moments
- 0:00 Introduction to talk: wireless, IoT, cloud unknowns
- 2:00 Pio's background and motivation for "shadows" topic
- 4:00 Malicious actors exploit unknowns due to poor visibility
- 6:00 Wireless security: ubiquitous devices and new hacking tools
- 7:45 Example: Solar-powered cameras as sneaky wireless offenders
Malicious Actors Depend on Your Unknowns. Disappoint Them!
Speakers: Brian Contos, Field CISO, Mitiga
Conference: SAINTCON
YouTube: https://www.youtube.com/watch?v=ft1TtAi7uUQ
Overview
In an era of rapidly evolving technology and expanding digital attack surfaces, Brian Contos, Field CISO at Mitiga, and Patrick "Pio" Zakowski, an expert in security automation, delivered a compelling talk at SAINTCON, highlighting critical blind spots that malicious actors routinely exploit. Titled "Malicious Actors Depend on Your Unknowns. Disappoint Them!", the presentation systematically dissects the pervasive lack of visibility and outdated security paradigms prevalent in three key domains: wireless networks, extended IoT (X-IoT) environments, and cloud infrastructure. The speakers argue that while traditional security approaches have focused on known endpoints and network segments, the explosion of new, often unmonitored, devices and interconnected cloud services creates vast "shadows" where attackers can operate undetected.
The core message of the talk resonates deeply with modern cybersecurity challenges: prevention, while foundational, is insufficient. Attackers are constantly innovating, leveraging the very advancements that drive business efficiency. By shining a light on these "unknowns"—from surreptitious wireless devices to vulnerable industrial robots and complex cloud attack chains—Contos and Zakowski aim to equip defenders with the knowledge and strategies necessary to detect, respond to, and ultimately disappoint the adversaries who thrive in obscurity. Their insights are crucial for any organization grappling with the complexities of securing an increasingly distributed and diverse technological landscape.
Background
▶ Watch: Introduction to talk: wireless, IoT, cloud unknowns (0:00)
The premise of "Malicious Actors Depend on Your Unknowns" stems from a stark reality: the traditional cybersecurity model, built around endpoint agents, firewalls, and Security Information and Event Management (SIM) systems, is struggling to keep pace with modern technological shifts. As Patrick Zakowski (Pio) articulated, many new attack surfaces, particularly in X-IoT and cloud, do not generate the "normal endpoint logs" or "raw logs" that security teams have historically relied upon. This lack of inherent visibility creates significant "shadows" that attackers actively seek to exploit.
Pio, drawing from 25 years of experience spanning the Symantec SOC, defense and intelligence communities (including red teaming satellite systems), and building architectures for large Managed Detection and Response (MDR) providers like DeepWatch, emphasized that these unknowns are a fascinating, yet dangerous, frontier. Brian Contos, with over 24 years in security across startups and large enterprises, echoed this sentiment, noting that technological advancements, while beneficial, invariably introduce new avenues for exploitation. Attackers are "hopeful that you aren't kind of looking at this," relying on organizations to perpetuate legacy approaches and remain under-resourced in detection and response capabilities. The talk posits that the pervasive reliance on preventative controls alone is a critical vulnerability, as "prevention is fine, foundational... but it will fail and is failing every day." The discussion then delves into why this problem exists across wireless, X-IoT, and cloud, setting the stage for specific examples and actionable defensive strategies.
Key Findings
▶ Watch: Pio's background and motivation for "shadows" topic (2:00)
The talk unveiled several critical findings regarding the "unknowns" exploited by malicious actors:
- Ubiquitous and Vulnerable Wireless: Wireless networks are everywhere, and devices like the Flipper Zero make exploitation easy. Attacks such as the Evil Twin remain highly effective due to users automatically connecting to known SSIDs. Sneaky devices, like solar-powered cameras with SIM cards, can bypass traditional network security controls entirely, streaming sensitive data without ever touching the corporate network.
- **X-IoT: A "Sh*tshow" of Vulnerabilities: The X-IoT landscape, encompassing everything from rack mounts and printers to medical devices and industrial robots, is exploding, with estimates of 125 billion devices by 2030. These devices are essentially Linux servers without keyboards, often running end-of-life firmware (nearly 75%) and plagued by default passwords (50%) or easily guessable, unchanged credentials. The white-labeling phenomenon means a single vulnerability can affect a multitude of different devices, making them low-hanging fruit for attackers, often with CVSS scores of 8, 9, or 10**.
- Cloud's Interconnected Complexity: Cloud environments are dramatically different from on-premise, characterized by highly meshed services, federated identities, and extensive use of SaaS and IaaS. This interconnectedness creates complex, multi-stage attack paths where a compromise in one service (e.g., GitLab) can quickly pivot to others (e.g., Octa, Slack, AWS S3). Visibility is a "serious issue," as traditional SIMs struggle with the volume and diversity of cloud logs, and cloud providers often throttle access or retain logs for insufficient periods (e.g., Microsoft 365's 7-day API limit for logs).
- The Deceptive Nature of Cloud Threats: Attackers leverage cloud-specific vectors such as malicious Amazon Machine Images (AMIs) containing cryptominers (like Monero), and exploit misconfigured services (e.g., MongoDB bound to
0.0.0.0). Critically, ransomware actors often lie about data exfiltration, demanding payment for data they never actually copied, as demonstrated in a MongoDB incident. - Third- and Fourth-Party Risk Escalation: The interconnectedness of cloud services extends risk exponentially. The compromise of a single third-party application (e.g., DeepSource, or the Salesforce Drift hack involving unexpired authentication tokens) can grant attackers broad access to customer data, source code, and secrets, leading to massive business disruptions and financial losses.
- The Imperative for a Modern SOC: To counter these threats, the speakers advocated for a "modern SOC strategy" built on Autonomous, Agentic, and Agile (the "3 A's") principles. This includes leveraging AI agents for consistent response, enabling rapid technology replacement, and adopting an Automation Pyramid of Pain to automate everything from basic integrations to fully automated remediation. Tools like Moroi for wireless anomaly detection and Nomi for IoT telemetry are crucial for gaining visibility into these "unknowns."
Technical Deep Dive
▶ Watch: Malicious actors exploit unknowns due to poor visibility (4:00)
The talk provided concrete technical examples across wireless, X-IoT, and cloud, illustrating the mechanisms of attack and the underlying vulnerabilities.
Wireless Attack Vectors
Wireless environments are a prime target due to their ubiquity and often overlooked vulnerabilities. The speakers detailed two common attack types:
- Evil Twin Attack: This classic attack remains highly effective. An attacker sets up a rogue Access Point (AP), often using a device like a Wi-Fi Pineapple, mimicking a legitimate AP's SSID and MAC address. The attacker then sends deauthentication packets to disconnect legitimate users from the actual AP. The victim's device, configured to automatically connect to known SSIDs, then sees the strong signal of the rogue AP and connects to it, unknowingly placing the attacker in a Man-in-the-Middle (MitM) position. All traffic between the victim and their intended destination then flows through the attacker, allowing for interception and monitoring without the victim's knowledge.
- Nearest Neighbor Attack: This sophisticated pivot technique demonstrates how attackers can leverage physical proximity. In one case, a Russian threat actor failed to compromise Organization A directly. Instead, they identified a geographically close Organization B with a vulnerable VPN. After compromising Org B via RDP to a Wi-Fi-connected laptop, they used stolen credentials to access Org A's Wi-Fi network (which lacked MFA on the access point). When Org B patched its VPN, the attackers simply moved to another proximate Organization C and repeated the process, highlighting the ease of lateral movement through adjacent, less secure entities.
X-IoT Vulnerabilities and Exploitation
The X-IoT landscape is characterized by an explosion of devices that present a unique security challenge:
- Device Characteristics: X-IoT devices, including industrial robots, cameras, printers, and medical equipment, are often purpose-built but fundamentally run embedded operating systems like Linux (BusyBox, Android, BSD) or real-time operating systems (RTOS) like VxWorks. They are essentially computers without keyboards, some even more powerful than laptops.
- White Labeling: A significant issue is white labeling, where manufacturers use shared libraries and firmware across diverse product lines. This means a vulnerability discovered in one device type (e.g., a camera) can often be exploited in many others (e.g., a door controller), providing attackers with a broad target surface.
- Default and Weak Credentials: A staggering 50% of X-IoT devices ship with default passwords. The other half often have simple, unchanged passwords set years ago, making them trivial to compromise.
- End-of-Life Firmware: Nearly 75% of X-IoT devices run end-of-life firmware, leaving them exposed to known, unpatched vulnerabilities.
- High CVSS Scores: Approximately 70% of X-IoT devices have vulnerabilities with CVSS scores of 8, 9, or 10, indicating critical severity and ease of exploitation, often requiring minimal technical sophistication.
Robot Hack Demo: The speakers demonstrated an X-IoT hack on an industrial robot used in manufacturing.
- Discovery: The robot, taken out of its box with default configurations, was found to be network-connected and running a web server (described as a "1992 web server").
- Vulnerability Identification: Exploration of the web server revealed an anonymous FTP service, allowing unauthenticated access to the robot's file system, confirmed by the user manual.
- Exploitation:
- The attackers accessed the file system via anonymous FTP.
- They downloaded a program file (
CAN.LS) that instructed the robot to gently tap a can. - Using a simple text editor (Notepad), they modified the Z-axis set point from 205mm to 305mm, which would make the robot descend further.
- The modified file was saved as
CRUSH.LSand uploaded back to the robot's file system via anonymous FTP. - Finally, through the robot's virtual IP pendant (accessible via the web server), they changed the robot's default program (
defrag) to executeCRUSH.LS.
- Impact: Upon reboot, the robot executed the modified program, forcefully crushing the can instead of gently tapping it. This demonstrated how easily an attacker could cause physical damage, subtle malfunctions leading to product failures, or even sabotage critical manufacturing processes without detection.
Cloud Environment Exploits
Cloud environments introduce highly interconnected and dynamic attack surfaces:
- Federated Identity Compromise: Attackers often target the interconnectedness of cloud services. A compromise of GitLab (source code repository) can lead to a pivot to Octa (SSO), then to Slack (internal communications), then to Google Workspace or Windows Workspace (email forwarding, settings changes), and finally to AWS EC2 instances or S3 buckets for data exfiltration. This illustrates how a single initial breach can cascade across an entire cloud ecosystem.
- Third-Party Application Risk (DeepSource & Salesforce Drift):
- DeepSource Hack: A developer installed DeepSource (a code testing security tool) with their permissions, then forgot about it. When DeepSource was compromised, attackers gained access to all its customers' integrated third-party applications, including GitHub, allowing them to download customer source code and AWS secrets. This led to massive disruptions, service suspensions for over half the affected company's customers, and increased cyber insurance premiums.
- Salesforce Drift Hack: This sophisticated, multi-stage, cloud-first attack exploited a third-party application whose authentication tokens never expired and were exposed. Attackers rapidly compromised 700 Salesforce customers within 4-5 days, exfiltrating vast amounts of sales and financial data. Salesforce initially placed responsibility on customers for granting permissions, highlighting the need for vigilance over third-party integrations.
- Malicious AMIs: AWS allows users to deploy unsupported or end-of-life AMIs (e.g., Windows 2008, NT4.0). Moreover, AMIs can be sourced from untrusted third-party marketplaces. Attackers embed malware, such as Monero cryptominers, directly into these AMIs. Once deployed, these miners can operate in two modes:
- Smash and Grab: Aggressively mine crypto, causing noticeable spikes in cloud bills, expecting rapid detection.
- Sneaky/Turtle: Mine crypto slowly and subtly over long periods, hoping to evade detection, especially in large, multi-party cloud environments where cost spikes might be attributed elsewhere.
- Microsoft 365 Log Inadequacy: Microsoft 365 logs are retained for 90 days, but only the first 7 days are easily accessible via API. Days 8-90 require cumbersome and throttled PowerShell queries, which can take "more than a month" for 30 days of logs. This intentional throttling severely impedes incident response. Attackers exploit this by configuring email forwarding, filtering rules to hidden folders, and registering fake domains to masquerade as legitimate senders/receivers. In one instance, attackers maintained a presence in a legal firm's 365 environment for months, facilitating a $50 million wire transfer theft by acting as a MitM.
- Misconfigured MongoDB: A test database was set up with a dangerous configuration, binding to
0.0.0.0(listening for connections from anywhere). Engineers compounded this by populating it with real production data for convenience. When this MongoDB instance was encrypted by ransomware, the company initially dismissed it due to it being a "test" database. However, the ransomware actors claimed data exfiltration. Forensic investigation revealed they were lying and had not copied the data, saving the company from a costly data disclosure incident, but highlighting the risk of misconfigurations and the need for verification.
Modern SOC Strategy and Tools
To combat these threats, the speakers advocated for a modernized SOC:
- The 3 A's:
- Autonomous: Building automated workflows (even with open-source tools) to handle repetitive tasks.
- Agentic: Leveraging AI agents with defined roles (e.g., "hunter role") to perform tasks like querying VirusTotal or searching for specific SQL queries, achieving consistent outcomes about 80% of the time.
- Agile: The ability to rapidly rip and replace technology and reinvent processes, rather than being locked into year-long renewals.
- Automation Pyramid of Pain:
- Level 1 (Basic Integrations): Integrate with every API in the stack, case management, automated reporting, and KPIs.
- Level 2 (Basic Automated Response): Isolate and contain compromised hosts.
- Level 5 (Fully Automated Remediation): The aspirational goal of end-to-end, human-free remediation for Tier 1/2 use cases.
- Specific Tools and Concepts:
- Moroi: Used for detecting wireless anomalies (SSID, RSS), malicious SSIDs, and triggering automated containment workflows.
- Nomi: Essential for X-IoT device telemetry, default credential scanning, and firmware vulnerability checks.
- SOAR (Security Orchestration, Automation, and Response): Critical for automated network quarantine and firmware rollback actions, especially in manufacturing where downtime is costly.
- Data Lakes: Necessary for ingesting and analyzing the massive volume of cloud data, as traditional SIMs cannot handle the scale and cost.
- Enrichment: Correlating data from various sources (e.g., Nomi telemetry, VirusTotal, CrowdStrike, Salesforce APIs) to provide context and accelerate automated hunting, as demonstrated by a 4-minute workflow to detect the Salesforce Drift hack.
Demo / Proof of Concept
▶ Watch: Wireless security: ubiquitous devices and new hacking tools (6:00)
The most engaging demonstration involved the exploitation of an industrial robot, vividly illustrating the vulnerabilities inherent in X-IoT environments.
The speakers acquired a standard industrial robot, typically used in manufacturing for tasks like drilling or shaving. They configured it with its default settings, making no changes from its out-of-the-box state. For baseline functionality, they created a simple program, named "CAN," that instructed the robot to gently descend and tap the top of a soda can.
Their exploration of the robot began by discovering it was network-connected. A quick ping revealed its presence, and further investigation uncovered an active, albeit rudimentary (described as a "1992 web server"), web interface. Within this interface, they located configuration settings, firmware version details (dated 2023), and a list of active programs, including their "CAN.LS" program with its specific X, Y, and Z axis set points (notably, a Z-axis value of 205mm).
Crucially, they found a "remote pendant" feature—a virtual interface that mirrored the physical hand controller used to operate the robot, also accessible via the web server. Digging deeper, they discovered that the robot supported FTP (File Transfer Protocol), and startlingly, it allowed anonymous FTP connections without any credentials. This was even documented in the user manual, which stated, "if you see an anonymous username, you may be able to connect through FTP without credentials."
Exploiting this, they connected to the robot via anonymous FTP and successfully listed its directory, revealing a massive flat file system. Within this, they located their CAN.LS program file. They then downloaded this file and, using a simple text editor like Notepad, modified the critical Z-axis set point from 205mm to 305mm. This change would cause the robot's arm to descend an additional 100mm, far enough to exert significant force. They renamed the modified file to CRUSH.LS and, to their surprise, were able to upload it back to the robot's file system via the anonymous FTP.
The final step involved activating the malicious program. Through the virtual IP pendant in the web interface, they navigated to the system information and variables. Identifying the default program, likely labeled something intuitive like "defrag," they changed its configuration to execute CRUSH.LS as the new default. Since industrial robots often reboot periodically (weekly, bi-weekly), and the default program is persistent across reboots, the change was permanent. Upon rebooting the robot, instead of gently tapping, the naughty little robot proceeded to crush the can, demonstrating the ease with which a critical industrial process could be subtly or overtly sabotaged with minimal technical effort and exploiting readily available vulnerabilities.
Defensive Implications
▶ Watch: Example: Solar-powered cameras as sneaky wireless offenders (7:45)
The insights from "Malicious Actors Depend on Your Unknowns" provide a clear roadmap for strengthening security postures against modern threats:
Wireless Security
- Enhanced Detection: Implement systems capable of detecting SSID anomalies and RSS (Received Signal Strength) anomalies to identify rogue access points or unusual wireless activity. Actively scan for malicious SSIDs.
- Automated Containment: Develop and deploy automated workflows (e.g., via SOAR) to trigger network containment actions. If a host is compromised via a wireless attack (like Evil Twin or Nearest Neighbor), automatically move it to a contained VLAN.
- EDR Integration: Leverage endpoint detection and response (EDR) solutions (e.g., Microsoft Defender, CrowdStrike, SentinelOne) for host isolation and to conduct forensics on contained systems, preventing lateral movement.
- Shadow IT/IoT Discovery: Actively hunt for unauthorized wireless devices, especially those that operate outside the traditional network (e.g., solar-powered cameras with SIM cards, Bluetooth microphones).
X-IoT Security
- Visibility First: Deploy specialized tools like Nomi to gain comprehensive telemetry from X-IoT devices. These tools can identify default credentials, scan for known vulnerabilities, and detect anomalous behavior that traditional security tools miss.
- Network Segmentation and Air Gapping: Where possible, implement strict network segmentation or even air gapping for critical OT networks to limit attack surfaces. While challenging in practice, this remains a crucial defense.
- Firmware Management and Rollback: Prioritize patching and upgrading X-IoT device firmware. For manufacturing or critical infrastructure, establish SOAR-based firmware rollback capabilities to quickly revert malicious or faulty updates, minimizing downtime.
- Secure Configurations: Mandate changing all default passwords immediately upon deployment. Implement robust password policies and consider non-password authentication methods where available.
- Continuous Monitoring: Regularly audit X-IoT devices for end-of-life firmware, high-CVSS vulnerabilities, and misconfigurations (like open FTP ports with anonymous access).
Cloud Security
- Beyond Posture Management: While CSPM (Cloud Security Posture Management) and CASB (Cloud Access Security Broker) are foundational, they are purely preventative. Organizations must invest in robust Cloud Detection and Response (CDR) capabilities to gain real-time visibility into attacks across IaaS, SaaS, and federated identities.
- Comprehensive Log Management: Prioritize collecting and retaining cloud logs for a minimum of three years, not just the typical 90 days offered by some providers. Utilize data lakes to store raw cloud data, as traditional SIMs are cost-prohibitive for this volume. Develop efficient methods (bypassing throttled APIs or painful PowerShell scripts) to access all available logs.
- API Security and Identity Governance: Implement stringent controls over API capabilities between integrated tools. Move beyond simple SSO and enforce non-human identity role-based access control for every API connection, ensuring least privilege.
- Third- and Fourth-Party Risk Management: Thoroughly vet all third-party applications and integrations. Implement policies to disable or remove unused applications. Conduct regular audits of integration permissions and authentication tokens, ensuring they expire properly.
- AMI Vetting and Monitoring: Avoid deploying unsupported or untrusted AMIs from unofficial sources. Implement a strict vetting process for all AMIs. Monitor AWS bills for anomalous spikes that could indicate cryptomining activity.
- Automated Hunting and Response: Develop automated hunting workflows (e.g., using AI agents in a SOAR platform) for known cloud attack patterns (like the Salesforce Drift hack indicators of compromise: specific IPs, SQL queries). These workflows can significantly reduce response times from hours or days to minutes.
- Upskill SOC Teams: Address the critical skills gap in cloud security. Invest in training for AWS, Azure, Office 365, and GCP expertise, as these specialized skills are in high demand and short supply.
- Leverage AI: Adopt AI agents and Agentic AI within the SOC to match the speed and sophistication of AI-enabled attacks. AI can assist with threat hunting, correlation, and automated response, making the SOC more autonomous and agile.
Key Takeaways
- Visibility is Paramount: Malicious actors thrive in environments with poor visibility. Wireless, X-IoT, and cloud present unique challenges to traditional monitoring, creating "unknowns" that must be actively illuminated.
- Prevention Alone Will Fail: While foundational, preventative controls are insufficient. Organizations must build robust detection, response, and hunting capabilities across all attack surfaces, particularly in the cloud where interconnectedness creates complex attack paths.
- X-IoT is a Critical Blind Spot: The exploding number of X-IoT devices, characterized by default passwords, end-of-life firmware, and high-CVSS vulnerabilities, represents a massive, easily exploitable attack surface that can lead to physical damage or subtle sabotage.
- Cloud Complexity Demands Modern SOC Strategies: The highly meshed nature of cloud environments, coupled with challenges in log access and retention, necessitates a shift to Autonomous, Agentic, and Agile (AAA) SOCs that leverage AI agents, extensive automation, and specialized cloud security expertise.
- Third-Party Integrations are High-Risk: Compromise of third-party cloud applications or malicious AMIs can lead to widespread data exfiltration, service disruptions, and significant financial and reputational damage. Strict vetting, permission management, and continuous monitoring of integrations are essential.
- Log Retention and Enrichment are Non-Negotiable: Insufficient log retention (e.g., 7 days for critical cloud logs) severely hampers incident response. Organizations must aim for multi-year log retention in data lakes and enrich this data from diverse sources to enable effective threat hunting and forensic analysis.
About the Speaker(s)
The talk was delivered by two seasoned cybersecurity professionals, Brian Contos and Patrick "Pio" Zakowski.
Brian Contos serves as the Field CISO at Mitiga, a company specializing in cloud detection and response, managed incident response, and threat hunting. With over 24 years of experience in the security industry, Brian has a diverse background encompassing both large corporations and numerous startups. He is also an advisor at Yel Ventures and has built award-winning podcasts, including "Security on Cloud" and "IoT Security Podcast," which are widely available on platforms like Spotify and Apple. His expertise spans strategy, marketing, and deeply technical security insights.
Patrick "Pio" Zakowski brings 25 years of extensive experience in cybersecurity. He began his career at the Symantec SOC and later transitioned into the defense and intelligence community, where he gained hands-on experience in blue teaming, forensics, network detection and response, and even red teaming satellite systems for organizations like the NRO, NSA, and CIA. Pio then moved into telecommunications, focusing on big data and SIM technologies, before becoming a founding employee at DeepWatch, a large Managed Detection and Response (MDR) provider, where he helped build their architecture for a decade. He is currently with Torque, a company focused on security automation, and is particularly interested in securing "things in the shadows" where traditional logs are often absent.