Seriously Risky Business Newsletter
May 01, 2025
Security Vendors Are Constantly Being Attacked
Presented by

Policy & Intelligence
Security firm SentinelOne has published a new report that takes a deep dive into all the weird and wonderful ways threat actors are targeting it. Attacks against security vendors are nothing new, but they've scaled up and are now a constant threat. And as best we can remember, this is the first time a security company has publicly described the range of threats they're facing in detail.
The report first looked at the North Korean (DPRK) IT worker threat, where North Koreans use fake identities to apply for legitimate remote jobs, is evolving and occurring at "staggering volume":
Instead of just deleting the applications and moving on, the company turned the tables on the North Korean applicants. In an effort to learn more about their fraudulent job application techniques, it strung them along in tailored recruitment processes. SentinelOne says it was able to make its detection processes more effective by bringing frontline teams such as recruiting and sales into the tent. By sharing potential threat information, recruiters were able to identify suspicious patterns. Those patterns were then used in automated systems to identify and even block dodgy applications. A kind of virtuous cross-team circle.