Understanding Cybersecurity: Nation States and Evolving Threats | Security Boulevard Ep. 4
Mitch Ashley , Tom Hollingsworth and Fernando Montenegro explore key cybersecurity issues, particularly focusing on nation state actors and significant breaches like F5. It highlights the shift in cyber threats from minor attacks to serious intelligence gathering and cyber warfare. The discussion covers the support that nation states offer to cyber groups and the legal hurdles in combating cyber crime. A broader societal approach to cybersecurity is advocated, encouraging listener engagement.
Transcript
Well, well saying, as long as you don't hack us, we, we won't hack you back. Um, it's kind of like saying, if you don't spy on us, we won't spy on you. No.
We're gonna spy on you, and you're gonna spy on us. It's just a fact of matter. Welcome to the Security Boulevard, the cybersecurity podcast from the Futureum Group.
Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube Channel, tech Strong tv, and all of your favorite podcast platforms. We're gonna be talking about nation state actors today.
But before we do that, let's jump in and introduce our hosts for this episode, starting with Mitch. Hi, Mitch. Ashley and I lead the software lifecycle engineering practice at future covering mal things development and cloud native and software security.
Lots of good stuff, and of course, ai. Awesome. And Fernando?
Hi, uh, Fernando Gro. I lead the cybersecurity and resilience practice of everything. Lemme say the word ai, just to get it out of the way.
Ai, ai, ai. Good. Um, and, and, and it's a, it's a true pleasure to work alongside Mitch on covering different things and, and, and with you, Tom as well.
So, Well, thank you. And as Fernando mentioned, I am Tom Hollingsworth security event lead here at Tech Field Day, which is part of the Futurum Group. And, uh, I'm very glad to be joined with, uh, two of my regular co-hosts this week.
As we jump into today's topic, we're gonna be talking about nation state actors, and why is that a big deal? If you have seen the news recently as of October, 2025, you know, that F five suffered from a massive breach. It was rather embarrassing.
Uh, some people got in, they got access to some user information. They may have also gotten access to some patches for zero day exploits that people were putting together to pay, potentially save some egg on the face moments. But one of the things that came out of this that I thought was rather fascinating was the fact that a lot of F five customers are governments, and specifically the US federal government.
And one of the anecdotes that was mentioned in the press releases was that they believe that the group that did this was acting on this behalf of a nation state. And we've seen that a lot recently. If you go all the way back to the massive SolarWinds hack that was done by a nation state actor, we've seen the rise of attackers being backed by organizations that are formal governments as opposed to just hacking collectives or, you know, kids that are out to deface websites for cred.
And, and I wanted to take a moment to pick your brains, because I think we're starting to see the shift from harmless or somewhat, um, harmful, uh, attacks to criminal enterprise, to now hacking as a form of intelligence gathering and maybe even producing outcomes for cyber warfare. Well, uh, I would argue we have to go even back beyond before Solar, solar went, right? Uh, many of us were around when, uh, operation Aurora targeted Google, right?
Or even, uh, or I don't remember the timeline this before or after when, um, our safe security was hit, uh, as a precursor to people attacking, I believe it was Lockheed Martin at the time, right? So, yeah, this has been around, and, and it's, it's on one hand, fascinating on the other. Terrifying, uh, undoubtedly sobering in the sense that, yes, this matters.
And we are increasingly seeing, like, uh, I I, I find myself repeating things because I've, I've, I quote Mark and recent, right? Uh, he said, back in 2011, software is eating the world, right? Yeah.
He was right. And the moment that softer ate the world, how you interact with the world, uh, through software, means that these highly sophisticated actors now have the means, uh, and opportu motive and opportunity to go after these systems in many, many forms. I mean, I mean, you can even argue like stuck net, of course, as another thing.
So yeah, this is, this is all over the place. This is real. So, Fernando, I'm actually glad that you brought up Stuck Net because that's a point that I wanted to call out here, because a lot of people, when I start saying nation states, they're like, oh, yeah, I remember when parties unknown hack the Iranian nuclear program.
I actually draw a distinction at stuck net, because to me, stuck Net has all the fingerprints of a traditional intelligence operation. It was designed for a very specific impact where we were trying to prevent centrifuge from spinning up and things like that. What we're seeing now is effectively, if you wanna call them that contractors, uh, you know, think of all of the various fancy bears or the, uh, the a PT groups that are being, uh, bankrolled by, um, far East organ, uh, countries.
I won't name names 'cause I, I'd rather not get targeted, but, but the fact is, is that we're, essentially what we're saying is as long as you're not hacking us, and you're going after people that we would prefer that you go after companies to get persistence and collect intelligence that we can use to further our aims, we're basically gonna turn a blind eye or offer you refuge, uh, from, you know, international organizations that might be looking to take you down. And, and honestly, we, we've seen that a lot in Eastern Europe for a long time. Um, certain organizations are being effectively shielded from Interpol and other organizations just because, well, you're hacking the people that we want you to hack As well, saying, as long as you don't hack us, we we won't hack you back.
Um, it's kind of like saying, if you don't spy on us, we won't spy on you. No, we're gonna spy on you and you're gonna spy on us. It's just a fact of matter.
I mean, the, you think about the National Security Theaters, yes, it's Land, sea, and Air. It's a fourth one to cyber, and it is, it is active, and you don't, you don't prepare for a cyber war just by building up, you know, skills and, and infrastructure to be able to do cyber attacks. You actually perform 'em, you test, it's just like you do incursions across the border.
Um, these attacks, I think are both intentional, um, as, as intelligence gathering, but they're also tests to say, all right, how vulnerable is this? We really wanted to take down an electrical grid in this country. Could we?
So when we need to do it, we can do it. It's just like we train the Navy Seals to, uh, to go out and do missions and do strikes. That's essentially what we're doing.
We and everyone else is doing in the nation states are doing. And they hire, it's not just them. They hire groups, you know, cozy Bear and all the different groups that, that will do this for them.
So they don't have to have all the skills internally. And I think it's a very active, uh, theater. It's not something where we have sitting there waiting to go, just like we have aircraft carriers patrolling around different parts of the oceans across the globe.
We very much have cyber teams, but internal and external to our government agencies that are active in doing things. And, and I I, I love the topic because I wanted, uh, because it brings to, it brings to the front two things, right? It brings to the front the, the reality of like, that, that software eating the world thing.
In other words, this is affecting everybody. It also brings to the front, okay, what do you do? Or what does this mean to you as a practitioner, right?
Whether you are a, whether you are a, a, uh, uh, an executive, whether you are mid-level management, whether you are an individual contributor, right? What I, I find the topic fascinating because it highlights the changing nature of the threat, uh, the threat environment, right? So when you are going to threat model, right, uh, what your defenses should look like.
Well, exactly as you said, Tom, these, these groups are being supported by nation state actors, which means that these groups have increasing levels of capabilities that target that, that, that are coming to bear on you. And I think that there are two important scenarios, uh, like I know we should doing three, but two important scenarios to consider. One is, what is your role in terms of critical infrastructure?
Is your organization along that critical infrastructure, uh, supply chain, right? Where are you? Right?
Because that dictates how interesting you may be to a nation state level actor. That's, uh, that's one consideration. The other consideration, and I love the fact that you brought up that these are groups being supported, okay?
Can now those groups also use those capabilities outside of the objectives of a nation state actor, Hey, look, I'm going to use this x, y, Z or that in Canada, X, y, z, uh, tool to, to hack a power plant. I'm going to use the same tool to go after some small credit union because hey, I want the, the, I want the money, right? So what does that mean for organizations in terms of the spillage of, of those capabilities, particularly when you're considering, uh, affiliated groups as opposed to, uh, actors that are employed by the defense establishment or the of those respective countries?
You know, go, I, I was just gonna say, thinking about it, threat modeling and, and this is really a strong area of yours, Fernando, is when we talk about nation states for, uh, enterprise or personally, usually security threats are mostly around financial gain, right? Getting information that they can use for financial purposes. Nation states have other interests too, right?
It's disruption of society disrupting the financial markets. It's, uh, if we're gonna attack a country just like we wanna take out their, their radar systems and their satellite systems and GPS, you know, those are those kind of, uh, systems that countries rely on for both operational and also for defense that you wanna be able to take out, or just, so there can be all kinds of reasons, could just also be for misinformation, right? That's part of what this security threat is, is the social media aspect of it.
Or, um, building up a presence in software, open source software teams that they can then inject code into a code base that's distributed widely. Uh, so there's a lot of different purposes when you think about the nation state part of it, that in addition to what the impact is to us individually and to businesses, And I think it's important to point out there that you guys are, are right, that it feels, there's, there's a shift in, in the way that people think, um, your average attacker wants to get paid, right? They, they jump in, they steal as much data as they can, they ransom it back to the organization, or they offer to sell it on the web somewhere.
And it, it's your typical, if you wanna think of it as, uh, from a true crime podcast, it's a, um, it's a smash and grab operation, right? Let's, let's do as much damage as we can and on the way out, and we might get paid and we'll live to do it another day. Nation states don't work that way.
They want persistence, they want intelligence gathering capability. And you know, Fernando, to your point, you, you do have to look at the targets that they've gone after. They've attacked monitoring systems like SolarWinds.
They've gone after inline traffic analysis systems like F five. They want to stick around, they want to be able to examine all the data that's going through and manipulate it. And if we go back to something that was big last year, the salt typhoon, uh, uh, hack that basically was rooted so deeply into the telecom infrastructure that the US federal government had to set aside, uh, money to rip that infrastructure out and replace it.
They, there was even talk of them monitoring telephone calls from political candidates. And, and that's, you know, you think about it like in terms of traditional intelligence, I wanna get an asset inside and keep them there because the longer they can persist inside the organization, the better. But going back to your point, when you have someone, for lack of a better term, a hoodlum that you've hired to go do this, and you've given them these fancy cool tools to see if they work, your supposition is that I will let you use this tool to do the thing that I want so that I have plausible deniability in case you get caught.
But if then that actor turns around and goes and uses that tool somewhere else on a small job and burns it, because now that exploit is gonna be patched and, and, uh, become unavailable, I could see a nation state becoming very angry that, you know, you, you've basically sold out years worth of intelligence gathering for, I don't know, eight Bitcoin, Uh, perfectly valid. Uh, it's, it's a, yes, it's a scenario that I don't have any visibility into, like what happens with those actors. But that is a, that is a, a, uh, uh, a possibility.
And the thing that fascinates, it, fascinates me is that at, if you think about conventional weapons, right? Uh, it's not as if somebody is going to replicate a high-end rifle or a high-end tank or a high-end whatever, software is software, right? So how easy is it to replicate that knowledge and how easy is it for somebody to say, oh yeah, this is what we were doing over at the, the classified side of that.
My, my engagement, I'm gonna build a little one on the side here that, oh, looks just like that, right? So it's, uh, it's, it's becomes difficult to, to, to control for sure, right? The the thing about it though is that regardless of what happens to that, uh, individual or individuals who misuse those tools, I keep going back to what does it matter for the, for the average practitioner, is that we expect to see an increased sophistication of your attackers, right?
Uh, I'm not sure if you guys ever read, uh, do you remember, uh, uh, use next, uh, the, the login magazine? Uh, James Micken had a call back in, I wanna say 2012 at this world of ours where he had the threat model. And that threat model was very simple.
It was, okay, you're trying to prevent a, um, you're trying to prevent against a, um, your, uh, your ex uh, uh, you're trying to prevent your ex from looking at your, at your emails, whatever, okay? That's one level of precaution you're trying to prevent against your typical militias, hoodlum, uh, doing whatever to your finances. That's another level of problem you're trying to protect against.
I'm not gonna name it, but he said, very sophisticated spy agency doing something to you. You are not going to do that. Like you go live or go, go, go buy amulets and go live on a submarine or something like that, because you are going to get hit.
The challenge is that those capabilities are floating down, right? Are, are flowing downstream. So now, uh, and yes, we can bring AI into this, uh, your typical adversary that the, the difference between a sophisticated adversary now and, and the nation state is state potentially shrinking.
So what does that mean for, again, your threat models? How does your organization defend itself against it? Sorry, I, I agree with you.
I think that, that there's a a point where you're effectively saying that no amount of protection is going to keep me out of your network if I work for someone like that. The only hope, of course is that we realize that, you know, every opening in software is, uh, has a finite lifetime. You call them zero days or, or whatever.
But eventually that will get fixed, right? Someone will detect it unless, and this is a co a story we covered a couple years ago. The government has a heavy enough hand in the organizations that it works with to create effectively permanent situations.
And I know everyone's probably nodding at home and, you know, the government that I'm about to say, right? Yeah. What if it was the US NSA, because we know for a fact that there was a suggestion that someone weaken elliptical curve cryptography for a given particular piece of network gear that would allow the NSA to monitor things.
And why do we know about it? Well, because it was detected and reversed and used against us by a foreign government who said, oh, you want us to buy a whole bunch of this gear with this week in cryptography program? What if we did it right back to you?
And, and so it, it's that danger that we saw in 2013 when Edward Snowden reported on all the things that he knew, and a lot of those tools got out under the wild and basically created a new generation of super malware. Um, if you look at what a lot of those hacks in the 2014 through 2018 era were, they were all based on, uh, disassembled, recompiled, re-engineered, CIA hacking tools. I mean, look at all the things we've seen from Pegasus recently.
Um, you know, they were basically exploiting multiple unknown vulnerabilities in iOS and Android software. And the connection to nation state sponsoring was fairly well covered, but the fact that a lot of the people who were Pegasus customers were nation states should scare the crap out of everybody. You know, one, one of the unsettling time things about the times that we're in is with the changing in funding and government organizations within the us you know, CISA getting reduced funding.
And it's hard to know what programs, 'cause there are a lot of programs that they have in place or have had, you know, like Shields up and the Joint Cyber Defense Collaborative. There's a whole, I mean, there are a whole bunch of you in regard all kinds of different organizations that are about public, private, um, cooperation, which is part of what you need in these situations. 'cause as an entity, business entity individual, you're not gonna solve those bigger problems.
But also the government needs our help too. And I don't spend my a hundred percent of my days in security like I used to. So it's, it's a little unsettling to say, what are those things are working?
And if we are attacked right now, or if something happens or if, um, a threat is detected to is a potential to happen, you know, are we preventing those? And, and the thing I, again, I I, I love this topic because it, it helps us, um, it helps us give practitioners a lens into what should you be concerned about, right? Even if it, it's not that you should be concerned about in terms of, um, in terms of this is going to hit you today, but as you are working with your organization and you are discussing with your senior leadership about what's our threat model, right?
You have to understand, you might say, you know what, yes, we're going to bring the level down of nation state attackers down to a, to a manageable level. And, and, and we calculate, uh, we can go into the whole thing about, uh, cyber, uh, risk quantification, uh, about what if the impact of that, uh, of that particular threat on our organization. But you should be aware, the, the, I used to do martial arts, the martial arts practitioners that knows how to fight 10 different styles, but only needs three or three or four.
You need to be able to know what that adversary can potentially do so that you can advise your leadership about, Hey, let's do this, let's do that. And I bring this to bear on the context of what Mitch just said, because as we see changes in public programs for, um, for cybersecurity guidance, one of the things we notice is that there is a lot of, of interest in pushing those things down to the, to the state level, right? State and, and, and county and municipal levels, right?
Well, now those teams are being left to look, we used to come to a, to a national, uh, organization to help us support with things like threat intelligence and whatnot. Now we are left to fend for ourselves. What do we do?
Right? And that is a question that, uh, we should all be helping them answer in some way, shape, or form. Yes.
I, I agree. Um, the other question that I had for you kind of involves what happens when we detect them and how do we fix this? Because one of the tenants, if you wanna call it that of a civilized society, is that breaking the law has consequences.
And if someone does something and we catch them, we should be able to punish them according to our laws. And one of the things that makes cyber crime so difficult is that those rules are not applied equally in all places. Uh, for example, uh, there is a long history of North Korean cyber criminals, cyber hackers who are stealing Bitcoin and laundering it everywhere and violating a lot of norms.
But then, well, how are we gonna go get them out of North Korea? Because that's, you know, that, that's a sovereign nation, right? We can't just invade to, uh, arrest the guy who hacked the president's cell phone.
And we, we run into this problem kind, I alluded to it earlier, when you are backed by a nation state, you effectively have tacit permission from that nation state to do things, provided you follow their rules and such. And we've seen organizations that have been protected by governments. The internet research agency in St.
Petersburg is probably the biggest beneficiary of being affiliated with a nation state. But at the same time, we've also seen nation states turn on these groups where it's like, okay, you have now become too hot for us to deal with. And so they effectively do burn them in the industry and let Interpol raid their organization and take them out to kind of lay down the heat when they maybe attack too big of a target.
Should we be treating these organizations differently because their crimes are not committed on sovereign soil, but instead in cyberspace? Well, I think it's Like the copyright laws. Those are really nice laws.
Not sure I'm gonna follow 'em with your copyrighted movies or whatever. It, it's the ability to enforce those laws. And most of the time, that means you're going through whatever nation that is to, even if you know who the people perpetrated something is, if you're gonna, uh, an attack that you have to work through them to get access to them.
The other side of it is, when you think about the esp espionage part of it, those groups are susceptible to some kind of an attack. Let's be honest about it. If there was a group in whatever country that was being very effective, that hacking into, you know, our national infrastructure and our, our government decided we wanted to take them out, they're not gonna ask for permission.
You know, they're gonna go take them out and it'll look like something else. You know, you can think of the conspiracy theory or the movie that that's gonna happen, but I, you know, I believe those things happen. And that's what you sign up for when you, when you do this, any kind of espionage type of thing.
Yeah, I don't, uh, I don't have enough information on the topic. The thing I'll refer, I'll refer to is that I, I, I wish I had a, a, a law degree so that I could study the, the law to see a little bit better. Because this re this throws us back to the early days of piracy, right?
And, uh, are we going to be issuing letters of mark to, to, to go after, uh, to go after, uh, criminals or, and, and how do we respond? And the other thing is, again, I know it's not an answer, but it's incredible how often I think there's a quote attributed to, uh, Edward Wilson. It's a biologist.
The problem with humanity, or the problem with mankind is that we have paralytic emotions, medieval institutions and God-like technology. And, and that permeates everything that we do. So here we are debating the finer points of how do we use this technology that we have available to us, right?
Surrounded by laws and principles that, that are, uh, uh, decades, centuries old, right? While trying to navigate the, the, the human brain, which is very paralytic like here, we, we have the, the, the tribes and the, that, uh, that we all belong to and, and the fears that we have and the instincts that we have, us versus others, right? Sorry, I know this is completely different from a, a cybersecurity podcast, but it's relevant, right?
If there's one thing I, I, I, I hope we can help, uh, our industry grow is we have to think about these problems in a broader sense, right? It can't be just, okay, let's patch, okay, let's, uh, let's apply, uh, uh, packet filters here, or Next gen firewall over there, right? Or API security or whatever, right?
We have to think about these are broader societal problems, and whether we like it or not, we are smack in the middle of them, right? And it's not gonna get any better, right? There is no, there is no, uh, uh, uh, there is no silver lining at the end of this.
This is modern conflict, and we're into it. I love that there's a, there's a group that have always done some work in this. Like I end the cavalry, right?
It's up to us, right? The cavalry is not coming. Like, how do we improve ourselves?
How do we improve our organizations to incorporate nation state threat actors into our worldview? Right? So, sorry.
It's a, I think it's a fascinating topic. Uh, no, I, I think, uh, sometimes getting a little, uh, poetical closure from Fernando is the way to go here, because this, this is a problem that isn't going to go away. We, we've seen the way that warfare is being prosecuted by people in modern society, and we have a set of conventions that govern the way that we prosecute warfare in physical space.
Um, I've said for years that we need something very similar in the cyber realm because it's only a matter of time before someone figures out how to shut down a power plant or open up a hydroelectric dam and cause some massive problems for people. And, uh, you know, eventually we, we will reach a point where those kinds of things are off limits, so to speak. But I don't know that we're gonna solve that problem today.
Uh, what we will do today though, is wrap up this podcast, and I wanna take a chance for, uh, Mitch and Fernando to tell you some of the stuff that they're working on, because as part of the future and group, they're doing wonderful research, and I know that they're working very hard. So, Mitch, if people, uh, wanna get a hint of what you're working on, uh, what have you got on your plate? Yeah.
One of the areas that I follow real closely is around open standards with ai. You know, things like, everybody's heard about MCP and agent to agent communications, but they're, they're now starting to address more infrastructure types of standards, but also security. And there's a long ways to go.
We have a long ways to go to, you know, to being able to secure not only agents, but LLMs and the software that we build upon that. So it's a nice intersection with Fernando, um, because it hits on multiple fronts, uh, where we talk about AI security, and then just on an ongoing software security supply chain, um, not only the software we build, but the tool chains and the underlying infrastructure and sources of code that are susceptible to, in being injected into attack and become part of that threat service that, uh, they can take advantage of in nation state or not. Yeah, from, from my perspective, like I, I, uh, Mitch, just peer reviewed and I just published a, a, a, a paper on, uh, on software supply chain just recently.
So Mitch, thank you very much. Right? And, um, so that, that just came out.
So the, the, the, the public summary is, uh, I think it was published on Friday, this past Friday. And, um, but beyond that, it's a very busy quarter for us. And one of the things I'm, I'm working on right now is that, um, we have our cybersecurity decision maker survey data rolling in.
A matter of fact is we're, when, when we're do with this recording, uh, one of the things I'll do is, is review some of the data that just came in this morning. And, um, that is, that covers a, a wide range of, of, of topics, uh, including what we call, like organizational impacts to security. So I'm looking forward to seeing what that data looks like and, and publish it.
The other thing is that I'm working on a report, uh, kind of tied to this topic, which is, uh, I'm, I'm horrible with puns, and as, as many people know, uh, one of the, the one I think that the one I'm going to use, I'm gonna go that we are now reaching the, the, it's not the worldwide web, it's the West Fian while, uh, wide web, uh, as a, as a reference to the piece of Alia in 16 hundreds that established a nation that established the role of nation states, right? So it goes right back to this conversation. So when you, when you brought up the topic, my smirking year, right?
Because I think it's relevant, so I have something on, I I I'm writing something along those lines coming up in the next few weeks, right? So yeah, looking forward to it. Outstanding.
com, I'm gonna have some coverage posts from our last Security Field Day event coming up very soon, uh, talking about the presenters and each of the aspects of their presentations that I think are very relevant to the state of modern security. com so you don't miss any of those. We also want to thank you for listening to this episode of the podcast.
If you enjoyed the conversation, please subscribe on YouTube, ring the notification bell, uh, so that you don't miss any episodes or you can listen to us in your favorite podcast application. We would appreciate a rating and a review that helps the show grow and lets people know what we're all about. com and the Futureum Group.
com, the Techstrong TV website, or check us out on your over the top set, top box, apple tv, Roku, or other smart devices. Just look for Techstrong tv. I hope you're following Security Boulevard on X, Twitter and LinkedIn.
Just look for security BLVD, and that will get you all the content that we publish. Thanks very much for tuning in. We hope that you have a great week.