Connect with us

Tech Features

Making Sense of Identity Threat Risks

Published

on

phishing

By David Warburton, Director, F5 Labs

The growing maturity of cloud computing, including shifts towards decentralized architectures and APIs, has highlighted the complexity of managing credentials in increasingly interconnected systems. It has also underlined the importance of managing non-human entities like servers, cloud workloads, third-party services, and mobile devices.

F5 Labs’ 2023 Identity Theft Report defines identity as an artifact that an entity uses to identify itself to a digital system – such as a workload, a computer, or an organization. Examples of digital identities include username/password pairs and other personally identifiable information or cryptographic artifacts such as digital certificates.

Digital identities cannot stand on their own. They require a system to accept and validate them. In other words, for a digital identity to function there must be at least two parties involved: an entity and an identity provider (IdP) that are responsible for issuing and vetting digital identities. However, not all organizations that provide resources are IdPs—many digital services rely on third-party IdPs such as Google, Facebook, Microsoft, or Apple to vet identities.

Based on our recent analysis, the three most prominent forms of attack in the identity threat arena currently are credential stuffing, phishing, and multi-factor authentication (MFA) bypass.

Credential stuffing

Credential stuffing is an attack on digital identity in which attackers use stolen username/password combinations from one identity provider to attempt to authenticate to other identity providers for malicious purposes, such as fraud.

It is a numbers game that hinges on the fact that people reuse passwords,
but the likelihood that any single publicly compromised password will work on another single web property is still small. Making credential stuffing profitable is all about maximizing the number of attempts, which requires automation.

Phishing

Phishing is perhaps rivaled only by denial of service (DoS) attacks in being fundamentally different from other kinds of attacks. It is an attack on digital identity, to be sure, but since it usually relies on a social engineering foothold, it is even more difficult to detect or prevent than credential stuffing.

Phishing attacks have two targets: there is the end user who is in possession of a digital identity, and there is the IdP, which the attacker will abuse once they’ve gotten credentials. Depending on the motives of the attacker and the nature of the system and the data it stores, the impact of a successful phishing trip can land primarily on the user (as in the case of bank fraud), solely on the organization (as in the case of compromised employee credentials), or somewhere in the middle.

On the attacker side, phishing can range from simple, hands-off solutions for unskilled actors to custom-built frameworks including infrastructure, hosting, and code. The most hands-off setup is the Phishing-as-a-service (PhaaS) approach in which the threat actor pays to gain access to a management panel containing the stolen credentials they want, and the rest is taken care of by the “vendor.”

Dark web research indicates that the most popular subtype of phishing service is best described as phishing infrastructure development, in which aspiring attackers buy phishing platforms, infrastructure, detection evasion tools, and viable target lists, but run them on their own.

Brokering phishing traffic, or pharming, is the practice of developing infrastructure and lures for the purposes of driving phishing traffic, and then selling that traffic to other threat actors who can capitalize on the reuse of credentials and collect credentials for other purposes.

Finally, the attacker community has a niche for those who exclusively rent out hosting services for phishing.

The most important tactical development in phishing is undoubtedly the rise of reverse proxy/ man-in-the-middle phishing tools (sometimes known as real-time phishing proxies or RTPPs), the best known of which are Evilginx and Modlishka.  This is largely because it grants attackers the ability to capture most multi-factor authentication codes and replay them immediately to the target site facilitating MFA bypass but also making it less likely that the user victim will detect anything is amiss.

Multi-factor authentication (MFA) bypass

Recent years have seen attackers adopt a handful of different approaches to bypassing multi-factor authentication. The differences between these approaches are largely driven by what attackers are trying to accomplish and who they are attacking.

Nowadays, the reverse proxy approach has become the new standard for phishing technology, largely because of its ability to defeat most types of MFA.

MFA bypass tactics include:

  • Malware. In mid-2022, F5 malware researchers published an analysis of a new strain of Android malware named MaliBot. While it primarily targeted online banking customers in Spain and Italy when it was first discovered, it had a wide range of capabilities, including the ability to create overlays for web pages to harvest credentials, collect codes from Google’s Authenticator app, capture other MFA codes including SMS single-use codes, and steal cookies.
  • Social engineering. There are several variations of social engineering for bypassing MFA. Some target the owner of the identity, and some target telecommunications companies to take control of phone accounts.
  • Social Engineering for MFA Code—Automated. These are attacks in which attackers make use of “robocallers” to make phone calls to the target, emulating an identity provider and asking the victim for an MFA code or one-time password (OTP).
  • Social engineering for MFA code—Human. This is the same as the above approach except that the phone calls come from humans and not an automated system.
  • SIM swaps. In this kind of attack, a threat actor obtains a SIM card for a mobile account that they want to compromise, allowing them to assume control of the victim’s phone number, allowing them to collect OTPs sent over SMS. There are several variations of this approach.

So, what does it all mean?

Identity threats are constant and continuous. Whereas a vulnerability represents unexpected and undesirable functionality, attacks on identity represent systems working exactly as designed. They are therefore “unpatchable” not only because we can’t shut users out, but because there isn’t anything technically broken.

This brings us back to the question of what digital identity really is. To go from real, human identity to digital identity, some abstraction is inevitable (by which we mean that none of us is reducible to our username-password pairs). We often teach about this abstraction in security by breaking it down to “something we know, something we have, and something we are.” It is this abstraction between the entity and the digital identity that attackers are exploiting, and this is the fundamental basis of identity risk.

By thinking about digital identities in this way, what we are really saying is that they are
a strategic threat on par with, but fundamentally different from, vulnerability management. With nothing to patch, each malicious request needs to be dealt with individually, as it were. If modern vulnerability management is all about prioritization, modern identity risk management is essentially all about the ability to detect bots and differentiate them from real human users. The next logical step is quantifying the error rate of detecting these attacker-controlled bots. This is the basis on which we can begin to manage the risk of
the “unpatchables.”

Tech Features

Role of Digital Citizenship in Countering Misinformation and Protecting Social Cohesion in UAE

Published

on

Dr. Soumaya Abdellatif, Head of Sociology Department, Associate Professor, College of Humanities and Sciences, Ajman University

The greatest challenge of our time is not merely that people believe false information. It is that the very boundary between truth and opinion, fact and emotion, credibility and visibility, has become increasingly vague.

This shift signals a transformation in symbolic authority itself. Trust has not simply declined – it has been displaced. Traditional institutions no longer monopolize credibility, while digital platforms have multiplied voices without necessarily strengthening legitimacy.

In societies such as the UAE – built on coexistence, institutional trust, and the delicate management of cultural diversity, this challenge carries particular strategic weight. This is where digital citizenship ceases to be an educational slogan and becomes a matter of national importance.

Beyond Media Literacy

At its core, digital citizenship is a contemporary form of civic responsibility. It deals with how individuals participate in the digital public sphere, how they interpret information, and how they contribute – consciously or unconsciously, to the production of collective trust.

(1)As Manuel Castells once stated, power in network societies increasingly operates through control over communication flows. The question is no longer simply who speaks, but whose voice becomes visible, amplified, and believed.

Trust as Social Infrastructure

In the UAE, misinformation is not merely a media concern – it is also a matter of social architecture. The country’s model of stability rests on institutional credibility, intercultural coexistence, and high levels of public trust.

This explains why the UAE has invested heavily, not only in digital transformation, but also in institutional clarity and communication governance. (2) Federal Decree-Law No. 34 of 2021 on combating rumours and cybercrime reflects an important principle: digital stability is inseparable from social stability. The objective is not merely punitive regulation, but the protection of public confidence itself.

Youth, Families and the Transformation of Authority

Young people are not passive consumers of information; they are producers of narratives, identity, legitimacy, and influence. They shape public conversations long before institutions respond to them.

In previous generations, legitimacy flowed vertically: from institutions, schools, family structures, and recognised expertise. Today, authority is increasingly negotiated horizontally- through peers, influencers, networks, and algorithmic visibility.

In addition, families act as the first school of civic trust. Long before formal media literacy programs, individuals learn how to relate to truth, disagreement, and legitimacy inside the home.

Why Social Sciences Matter

The response to misinformation cannot be reduced to fact-checking mechanisms or technical media literacy alone. What is required is a deeper intellectual infrastructure – one that social sciences are uniquely positioned to provide.

Sociology, communication studies, political science, and anthropology do not merely teach individuals how to verify information; they teach them how power operates, how legitimacy is constructed, how public opinion is shaped, and how collective trust is sustained or eroded.

A National Priority

The UAE has positioned itself as a global leader in artificial intelligence, digital governance, and future-oriented policy. This ambition is both necessary and admirable.

In this scenario, digital citizenship is not a secondary educational concern. It is part of national security, social sustainability, and the long-term legitimacy of institutions.

The UAE is not only managing digital transformation; it is helping to define what responsible digital modernity should look like.

Because in the end, the future of social cohesion will not be decided by technology itself, but by who is trusted to interpret reality in the digital age.

Continue Reading

Spotlight

Clarity Before Compute: Why AI Strategy Must Come Before Infrastructure

Published

on


Enterprise AI has entered a new phase. The conversation is no longer centred on whether organisations should invest in artificial intelligence, but on how they can transform that investment into measurable business value.

By: Mohammed Hilili – General Manager, Lenovo Gulf

Across the GCC, enterprises are moving beyond experimentation. Pilot projects are giving way to enterprise-wide deployments as organisations seek to integrate AI into customer experiences, business operations, software development, cybersecurity and decision-making. Yet despite growing investment, many AI initiatives continue to struggle to deliver the outcomes leadership teams expect.

In my experience, the reason is rarely the technology itself. More often, organisations begin with the wrong conversation.

Too many AI discussions start with infrastructure specifications, GPU availability or the latest foundation models. These are undoubtedly important decisions, but they are not the first ones organisations should make.

The first question is much simpler.

What business problem are we trying to solve?

Without a clear answer, AI initiatives often remain isolated demonstrations of technical capability rather than platforms capable of delivering sustainable business value.

From AI Pilots to Enterprise Platforms

Across industries, organisations have spent the past two years experimenting with generative AI. Many have successfully launched departmental pilots that demonstrate what AI can achieve within a controlled environment. The greater challenge now lies in scaling those experiments across the enterprise.

That transition requires far more than additional computing power. It demands clear governance, high-quality data, well-defined business objectives and an architecture capable of supporting continuous growth. Successful AI adoption is increasingly becoming an organisational transformation exercise rather than simply another technology deployment.

Business Strategy Before Infrastructure

I recently worked with a leading regional financial institution looking to strengthen its research and development capabilities through AI. The ambition was clear, but many practical questions remained unanswered.

How much computing capacity would the organisation require? Which GPU architecture would support both current and future workloads? How could the environment remain scalable as AI adoption expanded across the business?

These may appear to be technology questions. In reality, they are strategic business decisions with long-term operational consequences.

Instead of beginning with hardware selection, we started by understanding the organisation’s objectives. Together with the leadership team, we assessed AI readiness, identified priority business outcomes and defined what success would look like before discussing infrastructure.

Only after establishing that foundation did we determine the appropriate compute resources, architectural approach and deployment model required to support long-term growth.

The result was not simply a successful implementation but an AI platform capable of evolving alongside the organisation’s ambitions.

AI Readiness Extends Beyond Technology

Many organisations still view AI readiness primarily through the lens of infrastructure. In reality, readiness begins much earlier.

Leadership alignment, data quality, governance frameworks, cybersecurity, skills development and measurable business outcomes all influence whether an AI initiative succeeds or stalls. Infrastructure remains essential, but it should support strategy rather than define it.

The organisations achieving the strongest results are those treating AI as a long-term business capability rather than a series of disconnected technology projects.

Building for a Hybrid AI Future

Enterprise AI environments are also becoming increasingly hybrid. Certain workloads will remain on-premises to address latency, compliance or data sovereignty requirements, while others will leverage the scalability of public cloud environments.

This makes architectural flexibility increasingly important. Organisations need infrastructure strategies capable of supporting multiple deployment models while allowing AI workloads to evolve alongside changing business priorities.

Selecting technology is therefore no longer simply about purchasing hardware. It is about building an adaptable foundation capable of supporting continuous innovation over many years.

The GCC Opportunity

The GCC is uniquely positioned to accelerate enterprise AI adoption. Governments across the region continue investing heavily in digital transformation, sovereign AI capabilities and next-generation cloud infrastructure while strengthening regulatory frameworks around data governance and cybersecurity.

These investments provide organisations with an increasingly mature environment in which to deploy AI at scale. However, long-term success will depend less on access to technology than on the ability to align AI investments with clear operational priorities and measurable business outcomes.

As AI becomes embedded within core enterprise operations, leadership decisions made today will determine competitive advantage for years to come.

Why Clarity Still Comes Before Compute

Technology will continue evolving at remarkable speed. New AI models, specialised processors and deployment approaches will continue reshaping the enterprise landscape.

What will remain constant is the importance of making the right decisions before investing.

At Lenovo, this philosophy shapes how we work with customers. We believe AI is not simply a product to deploy, but an organisational capability that develops over time. By combining advisory expertise with infrastructure, lifecycle services and long-term planning, organisations can reduce uncertainty, optimise investment and build AI platforms that continue creating value as business needs evolve.

The organisations that lead in the AI era will not necessarily be those with the largest AI budgets or the most powerful infrastructure. They will be those that begin with business clarity, build the right foundations and scale with purpose.

Because in enterprise AI, infrastructure enables transformation—but clarity makes it possible.

Continue Reading

Tech Features

Why UAE organisations cannot afford to get their AI storage strategy wrong

Published

on

BY: Owais Mohammed, Regional Lead & Sales Director at WD for the Middle East, Africa, Turkey, and the Indian Subcontinent

The UAE’s ambition to become a global AI powerhouse is well established. Government investment is flowing, infrastructure is scaling, and organisations across every sector are accelerating their AI programs. But beneath the strategic announcements and the technology deployments, a fundamental question goes unanswered: is the data storage infrastructure underpinning all this built for what comes next?

For many organisations, the honest answer is: not yet. Storage is rarely the first conversation in an AI strategy discussion. It tends to be treated as a commodity decision made late in the planning cycle, long after the headline architecture choices like GPUs/CPUs have been made. That approach made sense in simpler times, but not in today’s data-driven AI economy.

The scale of what is coming

To understand why, organisations need to understand the sheer data volume that is coming their way. Global data creation is forecast to rise to 718.5 Zettabytes (ZB) through 2030 (IDC source: Market Forecast: IDC Global DataSphere Forecast, 2026-2030, June 2026, Doc #US53425426), more than tripling in five years.

AI is both a driver and a consumer of this growth. Every model trained, every inference run, every data pipeline operating continuously across a distributed architecture is generating and demanding access to data at a scale that earlier generations of infrastructure were not designed to support.

Businesses that will absorb this growth successfully are not those with the fastest individual components. They are those with architectures designed to handle volume, variety, and velocity simultaneously, at a cost that remains economically sustainable as scale increases. That is the storage strategy challenge that needs to be addressed upfront and not as an afterthought.

Why a single technology cannot solve it

A common mistake is to frame the storage decision as a technology choice: SSDs versus HDDs, flash versus spinning disk, performance versus capacity. The world’s most sophisticated storage operators, including hyperscalers and major cloud service providers, have already moved past this framing. They do not choose one technology. They deploy multiple of them, in a tiered architecture that places data on the medium best suited to its requirements.

The logic is straightforward. SSDs deliver the high IOPS and low latency that real-time, performance-critical applications demand. HDDs provide the massive capacity and cost efficiency required for the vast middle tier of active and warm data, and currently continue to represent approximately 63% of worldwide installed storage capacity through 2030. Tape generally handles archival, regulatory, and compliance workloads where retrieval times of hours or days are acceptable, representing just under 8% of worldwide installed cloud storage capacity in 2025.

These are not competing technologies. They are complementary ones, each serving a distinct purpose within a coherent architecture. The question is how each is deployed where it delivers the greatest value.

Making tiered architectures work in practice

Knowing that tiered storage is the right model and implementing it effectively are two different things. At the scale hyperscalers operate, where storage volumes are measured in hundreds of exabytes, manual allocation of data across tiers is neither practical nor efficient.  Nor can all data live on cost prohibitive flash. The mechanism that makes tiered architecture manageable is software-defined storage (SDS), which pools resources centrally and provisions capacity dynamically based on demand. Rather than pre-allocating fixed capacity to individual applications, SDS responds to where data needs to be, improving overall utilisation and reducing waste.

Together, tiered architecture and SDS provide the flexibility and economic efficiency that hyperscale environments depend on. But this model is not the exclusive preserve of the world’s largest operators. For emerging infrastructure providers, including Neoclouds that are expanding rapidly across the region, the same principles apply. Architecture decisions made today will determine whether future growth is economically sustainable or structurally constrained. The window to get this right is earlier than many organisations assume.

Innovation at the storage level

Architectural thinking also changes how storage technology itself must evolve. An organisation that understands its workloads, plans for data growth, and builds tiered infrastructure will eventually reach the limits of what current storage innovations can deliver. That is why, manufacturers like WD are approaching HDDs not only as a mature, reliable product but as a technology with significant headroom remaining to help increase capacity, lower power and cost effectively scale AI data. They are advancing recording technologies, exploring novel materials, and embedding intelligence at the drive level. The aim is not incremental improvement. It is expanding the boundary of what high-capacity storage can deliver for the architectures customers are building today and the workloads they will run tomorrow.

The leadership dimension

The organisations that navigate the AI era most effectively will not be those that simply procure the latest hardware. It will be those that understand the architectural decisions that determine long-term performance, cost and scale, ask better questions earlier in the planning process, and treat storage infrastructure strategy as a source of competitive advantage rather than a procurement exercise.

Storage sits at the foundation of every AI workload, every data pipeline, and every digital service an organisation delivers. Getting the architecture right is not a technical detail. It is a leadership decision. And in a market moving as quickly as the UAE’s, it is one that deserves to be made with the same rigour and strategic intent as any other.

Continue Reading

Trending

Copyright © 2023 | The Integrator