According to Joel Moses, VP of Strategic Engineering at F5, identity has become the new target of attackers. In his recent video, Moses explains how attackers use identity instead of breaking through it, using the 2022 Uber breach as an example. The breach, which exposed sensitive information of over 7 million users, demonstrates the vulnerability of identity-based attacks. Moses highlights the importance of multi-factor authentication (MFA) and session token management in protecting against these threats.
One of the key tactics used by attackers is MFA fatigue. By repeatedly requesting MFA, attackers can wear down users and make them more susceptible to phishing attacks. This tactic is often used in conjunction with session token theft, where attackers steal and exploit session tokens to gain unauthorized access to systems. Additionally, the misuse of consent can also be exploited by attackers, who may obtain consent from users to install malicious applications on their devices.
Moses also emphasizes the importance of maintaining a strong identity-based defense. This includes implementing robust MFA policies, regularly reviewing and updating session token management, and ensuring that users are aware of the risks associated with identity-based attacks.
In the video, Moses provides actionable advice on how to protect against identity-based threats. He recommends using F5's advanced identity-based security solutions to detect and prevent identity-based attacks. By following Moses' recommendations, security professionals can help maintain a strong identity-based defense and protect against the growing threat of identity-based attacks.