Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Infiltration by Design
Articles

Infiltration by Design

ISBuzz TeamBy ISBuzz TeamJanuary 5, 2016Updated:April 30, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Infiltration by Design
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Major data breaches make headlines too frequently, reinforcing the fact that even if organizations deploy top of the line security products, threat agents can still find a way to infiltrate.

By bypassing common security solutions, there are four standard ways attackers can still “Infiltrate by Design”:

  1. Leveraging Design Vulnerabilities: An attacker can leverage an unexpected software’s functionality flow in order to compromise the underlying system. A perfect example is Sandworm, a design vulnerability found in a component of Windows which enabled a threat actor to abuse its functionality in order to download files and execute malicious code. Many major targets were affected by the Sandworm vulnerability including the EU, NATO, Poland, Ukraine, and the European energy sector and telecoms. Since the program’s functionality was kept intact, the attackers were able to bypass infiltration-detection solutions.
  1. Data-Only Attacks: This exploit is based on vulnerabilities such as Buffer-Overflow and User-After-Free in order to perform remote code execution. The exploit itself has no malicious payload and involves only manipulating existing data, which makes it extremely hard to detect. Generally speaking, the exploit alters the behavior of the application by manipulating the data in the application address scope.
  1. Infecting Devices Early in the Supply Chain: In this case, threats against third-party components come in the form of pre-installed software aimed at promoting various services such as anti-theft and targeted advertising. A threat actor will infect this component when it is shipped with an operating system. The major threat is that these components are designed as persistent “extra packages,” meaning that they will stay on a device even after a system clean-up or hard drive replacement. Furthermore, due to their high-level of privilege, they are able to perform virtually any function on a device, so any security measure implemented by the OS will be useless against these packages. Such a concern was raised when Superfish, an advertising component which OEM’ed with laptop manufacturers, was found vulnerable to threat actors aiming to launch man-in-the-middle-attacks.

There have also been various situations where software packages have doubled as a backdoor, such as last year’s exposure of spying programs found on computing products of major manufacturers.

  1. Infecting via Cloud Services. In these scenarios, a threat actor infects a common file-sharing service with malware. Organization employees will unknowingly sync with the service, and will inevitably be infected. Dropbox is one company that warns against this risk, and encourages its users to take additional precautions when syncing files.

As these scenarios show, it is impossible to prevent “infiltration by design”. However, that does not mean we need to succumb to cyber-attacks. In fact, making the analogy to a chronic illness, we need to work towards controlling and managing an uncured illness. Once we accept that network compromise is inevitable, we can instead understand how to manage the consequences of an infiltration.

And, similar to a chronic illness, the right treatment will benefit organizations that are constantly faced with the threat of a compromised network, allowing the business to continue as usual while keeping their data secure, despite the infiltration. Once this approach is taken, companies and organizations can focus on stopping even the most creative of external threat actors from compromising proprietary systems and stealing valuable data.

[su_box title=”About Roy Katmor” style=”noise” box_color=”#336588″]Roy KatmorRoy is a 12-year seasoned product manager and security market strategist, combining strong technical knowledge with proven sales and marketing skills. Prior to enSilo, Roy led Akamai’s security strategy. Before that, he managed Imperva’s data security products and architecture management. Additionally, Roy held various product management and R&D leading roles at several international public and privately-held companies. Roy holds a BSc in Information Systems from the Technion, Israel Institute of Technology, and MBA in finance and business strategy from the Hebrew University. Roy is a DIY master, enjoying fixing anything from cars to home improvement.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}