惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
博客园 - 聂微东
博客园_首页
人人都是产品经理
人人都是产品经理
N
News | PayPal Newsroom
云风的 BLOG
云风的 BLOG
U
Unit 42
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
Security Archives - TechRepublic
Security Archives - TechRepublic
T
The Blog of Author Tim Ferriss
Stack Overflow Blog
Stack Overflow Blog
The Register - Security
The Register - Security
The Hacker News
The Hacker News
博客园 - Franky
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
F
Fortinet All Blogs
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Check Point Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
有赞技术团队
有赞技术团队
TaoSecurity Blog
TaoSecurity Blog
博客园 - 司徒正美
GbyAI
GbyAI
G
Google Developers Blog
B
Blog
G
GRAHAM CLULEY
Y
Y Combinator Blog
雷峰网
雷峰网
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
V
V2EX
罗磊的独立博客
Know Your Adversary
Know Your Adversary
AWS News Blog
AWS News Blog
T
Troy Hunt's Blog
S
SegmentFault 最新的问题
P
Privacy & Cybersecurity Law Blog
T
Threat Research - Cisco Blogs
H
Help Net Security
N
Netflix TechBlog - Medium
Help Net Security
Help Net Security
L
LangChain Blog
D
Docker

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations UK's Cyber Security and Resilience Bill makes Parliamentary debut Cyber insurers paid out over twice as much for UK ransomware attacks last year Cyberpunks mess with Canada's water, energy, and farm systems Trump's workforce cuts blamed as America's cyber edge dulls Feds flag active exploitation of patched Windows SMB vuln How malware vaccines could stop ransomware's rampage Salesforce refuses to pay ransomware crims' extortion demand Germany slams brakes on EU's Chat Control snoopfest Germany slams brakes on EU's Chat Control snoopfest Employees regularly paste company secrets into ChatGPT Oracle tells Clop-targeted EBS users to apply July patch Red Hat repos raided, claims cybercrew, files stolen Suspected Chinese spies broke into 'numerous' enterprises UK gov acknowledges 'strong case' for JLR financial support JLR extends shutdown – again – as toll on workers laid bare UK chancellor blames cyberattacks on Russia despite evidence Fortra discloses 10/10 severity bug in GoAnywhere MFT Entra ID bug could have granted access to every tenant UEFI Secure Boot for Linux Arm64 – where do we stand? JLR says cyber cleanup to take additional week Insider blamed for FinWise data breach affecting nearly 700K Nork snoops whip up fake military ID with help from ChatGPT UK government dragged for incomplete security reforms Church of England abuse victims exposed by lawyer's email US spy chief claims UK backdown on Apple backdoor demand Workday confirms CRM breach via social engineering Black Hat/DEF CON: AI more useful for defense than hacking Ex-White House cyber guru talks Microsoft security fails CISA releases malware analysis for Sharepoint Server attack China: US spies used Microsoft Exchange 0-day to steal info Security pros drowning in threat-intel data Identity attacks surge 156% as phishermen get craftier Organizations can’t keep up with supply chain security musts Amazon CISO: Iranian hacking crews ‘on high alert’ UK data watchdog fines 23andMe £2.3M over 2023 breach Employers are demanding too much from junior cyber recruits FCA warned four staffers who pocketed regulator data Ransomware just wrecked your network – now what? Ivanti RCE attacks 'ongoing,' exploitation hits clouds Ex-NSA listened to Scattered Spider's calls: 'They're good' Why CVSS is failing us and what we can do about it Infosec pros still aren't nailing the basics of AI security Ransomware crims targeting systems between IT and operations Why aggregating asset inventory leads to better security NCSC and industry at odds over how to tackle shoddy software Powerschool extortionists may not have deleted stolen data CrowdStrike trims workforce by 5 percent, aims to rely on AI NSO Group must pay Meta $168M in WhatsApp spy case Ghost in the shell script: Boffins seek code correctness How Intruder finds what others miss in cloud security Linux malware can avoid syscall-based endpoint protection Infosec pro blabs about alleged malware mishap on LinkedIn The future of AI in cybersecurity in a word – optimistic CVE board 'kept in the dark' on funding, members say Security snafus caused by third parties up from 15% to 30% Blue Shield shared 4.7M people's health info with Google Ads Who needs phishing when your login's already in the wild? US cyber defenses are being dismantled from the inside Bug hunter obtains an SSL cert for Alibaba Cloud in 5 steps
Snowflake CISO talks lessons learned from breaches, improv
Jessica Lyons Jessica Lyons · 2025-05-15 · via The Register - Security: CSO

INTERVIEW Being the chief information security officer at Snowflake is never an easy job, but last spring it was especially challenging.

In May 2024, some of the cloud storage and data analytics firm's major customers, including Ticketmaster and banking giant Santander, disclosed significant data breaches. Attackers, the companies reported, had accessed their Snowflake-hosted environments and exfiltrated terabytes of data affecting hundreds of millions of individuals.

The breaches weren't the result of a compromise in Snowflake's infrastructure. Instead, more than 160 customer accounts were accessed using previously exposed credentials – many of which had been harvested by infostealer malware from customer systems and never rotated. None of the compromised accounts had multi-factor authentication enabled, a safeguard that likely would have prevented unauthorized access to the databases.

While incident response firms, including Mandiant and CrowdStrike, ultimately concluded that the attacks weren't Snowflake's fault – its enterprise environment was not breached, nor were employee credentials used to infiltrate customer environments – the whole security snafu left its mark on everyone involved.

And, according to Snowflake CISO Brad Jones, it made him and the company rethink the whole shared-responsibility security model.

"It was an unfortunate situation that our customers went through, and we've really pivoted from a shared-security model to more of a shared-destiny model with our customers," Jones told The Register.

"If something's in the news on Snowflake, or a customer that happens to involve Snowflake, it's negative for both," Jones continued. "So we're trying to pivot as much as possible to play a proactive role with our customers to ensure they're in the best security posture as possible."

Shared destiny

In a shared-responsibility model, the cloud provider is responsible for protecting the infrastructure, while it's up to the customer to secure their data and apps in the cloud, and to make sure that everything is configured properly to avoid any data leaks and the like.

In theory, this is a good idea for divvying up who is responsible for securing the different aspects of a cloud computing environment. But it still proves difficult for many customers to understand, and in the case of a large breach associated with a single third-party provider, it's not going to keep the stain entirely off the cloud provider.

Moving from shared responsibility to shared destiny gives Snowflake a more proactive role in its customers' security posture, and it makes things easier for the end users, too, according to Jones.

"From a shared-security model, there are certain controls that are under the control of our customers," he said. "We provide those controls to implement security practices, but we believe we need to be strong partners with them to ensure that they're leveraging these technologies and that we have this shared destiny."

If something's in the news on Snowflake or a customer that happens to involve Snowflake, it's negative for both

First off: Snowflake became significantly more stringent in its authentication posture, enabling mandatory multi-factor authentication by default for all new accounts starting in October 2024. It also began a phased deprecation of single-factor password logins, with a full block scheduled to take effect by November 2025.

In addition to stronger authentication and identity management, this shared-destiny model also includes uniform security controls across multiple cloud service providers, private networking connectivity to Snowflake services to ensure customer traffic doesn't traverse the public internet, and default encryption for all files stored internally within Snowflake.

It also incorporates "things like benchmarking controls against our CIS Benchmark, which has 31 controls that we think are best practices to leverage on the platform, [and] making sure that our account teams have visibility into the security posture of their customers," Jones said.

Additionally, in the fall, Snowflake launched a leaked password protection service that scours the dark web for stolen Snowflake account credentials. "We go in and proactively validate if they're still active credentials. If they are, we pivot immediately to locking that account and asking questions later," Jones noted.

In addition to fighting old fires like stolen credentials and single-factor authentication, a slew of new security challenges are on the horizon, and "it's always the unknowns" that keep Jones and his fellow CISOs awake at night.

March of the AI agents

"AI is a perfect example of something that you have to keep on top of because it's changing so rapidly," he said.

The two primary security challenges with AI involve data protection, which Jones admits isn't a new problem. 

"Probably the most primary concern that folks have is: How do they ensure that the data that they have is staying secure, or they're not exposing data in unexpected ways? This could be with third-party services that may be capturing prompts or data that's uploaded," Jones said, noting DeepSeek is a perfect example. 

"They said they weren't capturing data, turns out they were capturing data," he noted. "And beyond that, they accidentally exposed that data through poor security practices."

The second security concern du jour around AI involves the pace of evolution, especially when it comes to agentic AI. "Getting to the point where it's starting to think and do things on its own behalf without directly taking direction from a human – it's both powerful and scary at the same time," Jones said. 

He pointed to Microsoft's roadmap for the three stages of agentic AI [PDF]. These start with the chatbot phase: fetching information, answering questions, and summarizing and analyzing data. Next is taking action to automate workflows and replace repetitive tasks – but only when triggered by a human. And finally: operating independently and orchestrating other AI tools and systems.

"The third phase is where people will just be managing teams of agents, and you have to think a lot about the governance of how that will operate," Jones said. "The more that you have that in a confined ecosystem with standard controls and governance, the easier that will be to accomplish."

When asked if AI agents are a bad idea, security-wise, Jones said that "security [can't] say whether it's a good or bad idea. Security has to adapt. Security Teams can never be the team of no."

He likened it to improv's "yes, and" rule. "You can't say no. You need to say yes, and here are the controls, or the right way to do it," Jones continued. 

"It's important for security leaders to understand that they have to help the business in their business needs," he said. "AI will be a part of that, whether security teams want it or not." ®