AI makes Lateral Movement Simple and Screws Security

AI makes Lateral Movement Simple and Screws Security
AI Makes Lateral Movement Simple and Screws Security (Image Credit: AI-generated by Ian Murphy using Adobe Firefly)Lateral movement driven by AI tools now happens in 27 seconds, leaving 80% of enterprise servers exposed to AI-driven attacks. Security teams must now prioritise containment over perimeter defence or risk a major breach. This is the key finding from The Zero Networks Lateral Movement Exposure Report (registration required). Based on 54 trillion activities tracked across 312 enterprise environments, it shows that you cannot “assume breach” without containment. If you are a CISO, you need to rethink your network architecture and traffic management.

A phishing link is no longer just a potential risk. In 27 seconds, an AI has found its next target and is on its way to mapping your network, exposing credentials and escalating privilege. It’s impossible for the SOC to react in that time.

Dr Chase Cunningham, Strategic Security, Cyberbridge Partners (Image Credit: LinkedIn)
Dr chase cunningham, strategic security, cyberbridge partners

Dr Chase Cunningham, Strategic Advisor, Cyberbridge Partners, wrote in the foreword, “The numbers are the kind that should make executives sit up straight. The fastest recorded breakout time was 27 seconds. Eighty-seven percent of monitored servers accepted inbound RDP or SSH from many internal sources. Seventy-eight point seven percent were reachable over SMB or WinRM.

Forty-three point two percent of observed internal authentication still relied on NTLM. And 12.2% of organizations showed direct user-to-server administrative pathways — the kind of paths that let a compromised laptop become a direct route to high-value systems.”

Linear defences are unprepared for AI

Cunningham’s statement shows that the linear defence has collapsed. Defences are designed for the sequential reconnaissance that humans carry out. Humans probe, map the next target, look for credentials and escalate privileges. Each target is compromised in isolation – wash, rinse, repeat. These types of attacks are historically characterised by dwell times of days, weeks and even months.

AI-driven linear movement (AILM) changes the attack dynamic, taking control away from security. There are two ways that it does this.

The first is AI tools that carry out the attack. These tools use parallel streams rather than the sequential attack of a human. They identify multiple targets, find weaknesses and compromise systems at machine speed. There is no longer a dwell time. By the time security teams spot an attack and respond, AI has compromised dozens of other systems.

According to the report, “one compromised host can reach a median of 85% of internal systems on the first hop.” It goes on to say that “the ratio of attacker speed to defender speed is now 771,200 to 1.”

The second approach exploits how organisations use AI agents. These agents have privileges and access to systems. First-generation agents impersonated users with all their privileges and access. The second generation has their own identities. From an attack perspective, that just makes them another account to compromise.

That compromise comes through the manipulation of the AI agents you have installed. Using prompt injection or tool poisoning, the attacker gets the AI agent to do its work. The report gives a detailed look at how this happens and the consequences.

The Legacy Trust Gap

Cunningham highlights how we still hold on to old approaches even when trying to address the evolution of attacks. He writes, “Too many environments still say ‘assume breach‘ in the strategy deck while operating ‘assume trust’ in the network. Inside still means trusted.”

The report puts numbers on that trust:

  • 87% of enterprise servers accept inbound RDP or SSH connections from broad internal sources (page 10). This gives attackers wide access pathways once inside the network.
  • 78% of enterprise servers are reachable over SMB or WinRM (page 10). Attackers commonly exploit these same administrative protocols for ransomware spread and lateral movement.
  • 43% of internal authentication traffic still relies on NTLM (page 18). This is a legacy protocol frequently abused for credential replay and privilege escalation attacks. While Microsoft has deprecated it, its use is still widespread and often ignored in security audits.
  • 12% of organisations maintain direct user-to-server administrative pathways (page 22). It allows a single compromised employee device to provide immediate access to high-value systems.

These Are Known Historical Issues

None of these are new issues. They have been highlighted in multiple reports over the years. This report calls out lateral movement posture management (LMPM). It highlights how the problem is complex because attacks look like legitimate movement. It cites Mandiant’s 2010 M-Trends report, which set out to define the APT and how attacks unfold.

More importantly, the report says that lateral movement techniques haven’t changed over two decades. It lists five different incidents where attackers exploited lateral movement:

  • APT1 (2006–2013)
  • Operation Aurora (2009)
  • Stuxnet (2010)
  • Conti Ransomware (2019–2022)
  • SolarWinds Supply Chain Attack (2020)

The question that security teams need to ask themselves is: how do they address lateral movement? This is what the report looks to address. It says shift to enforcement from detection. Once you can see it, you can block it. If you don’t block it, you are part of the problem.

How do we address this?

The report addresses the problem in multiple ways. Better governance, remove the assumed trust gap and eliminate legacy protocols.

For example, treat every internal connection as untrusted and implement micro-segmentation. This will help define the connections between the machine and applications down to the port level. This significantly limits the attack surface.

Zero Networks is not the only vendor that sees micro-segmentation as key here. Other vendors, such as Illumio, also see this as a key way to significantly reduce risk.

You must also address the issue of admin protocols (page 10). These protocols are core to operations and business continuity. But if security teams leave them open, they are highways for attackers to exploit.

The elimination of legacy protocols is another step. With 43.2% still using NTLM (page 18), it is time for an overhaul of networks. Kerberos, OAuth2, and OIDC provide better and more manageable ways to handle authentication.

Remove the standing privileges that administrators have. Too many people have access to admin access by default, which is easily abused. Change authentication processes to require just-in-time elevation. While some will see this as additional friction, it is about hardening security and will easily cease to be an unwanted step.

Agents need to be better governed. That is beginning to happen with the use of first-class identities. However, the same issues over privilege and just-in-time access need to be applied here as to users (pages 25 and 26).

Enterprise Times: What does this mean?

This report pulls no punches. It highlights the risk to organisations with historical context and examples. It also provides ways for organisations to mitigate the risk. Some of these will require a serious overhaul of how organisations operate and their existing security controls. They will also require a review of governance processes, especially for AI agents.

To help organisations understand their risk exposure, Zero Networks has also launched its Breach Map, a free tool that shows security leaders their own blast radius before attackers do. Breach Map is available on Zero’s website, and will be demoed live on June 11th during their upcoming webinar, “Mythos and Daybreak: What Boards Are Asking and What to Actually Do About It.

It will be interesting to see how organisations react to this report. For many, it will require a thorough review of their network and security architecture. What it doesn’t require is a massive spend on new tools. Mitigation is not always about more tools.

The post AI makes Lateral Movement Simple and Screws Security appeared first on Enterprise Times.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading