Connect with us

Tech Features

Making Sense of Identity Threat Risks

Published

on

phishing

By David Warburton, Director, F5 Labs

The growing maturity of cloud computing, including shifts towards decentralized architectures and APIs, has highlighted the complexity of managing credentials in increasingly interconnected systems. It has also underlined the importance of managing non-human entities like servers, cloud workloads, third-party services, and mobile devices.

F5 Labs’ 2023 Identity Theft Report defines identity as an artifact that an entity uses to identify itself to a digital system – such as a workload, a computer, or an organization. Examples of digital identities include username/password pairs and other personally identifiable information or cryptographic artifacts such as digital certificates.

Digital identities cannot stand on their own. They require a system to accept and validate them. In other words, for a digital identity to function there must be at least two parties involved: an entity and an identity provider (IdP) that are responsible for issuing and vetting digital identities. However, not all organizations that provide resources are IdPs—many digital services rely on third-party IdPs such as Google, Facebook, Microsoft, or Apple to vet identities.

Based on our recent analysis, the three most prominent forms of attack in the identity threat arena currently are credential stuffing, phishing, and multi-factor authentication (MFA) bypass.

Credential stuffing

Credential stuffing is an attack on digital identity in which attackers use stolen username/password combinations from one identity provider to attempt to authenticate to other identity providers for malicious purposes, such as fraud.

It is a numbers game that hinges on the fact that people reuse passwords,
but the likelihood that any single publicly compromised password will work on another single web property is still small. Making credential stuffing profitable is all about maximizing the number of attempts, which requires automation.

Phishing

Phishing is perhaps rivaled only by denial of service (DoS) attacks in being fundamentally different from other kinds of attacks. It is an attack on digital identity, to be sure, but since it usually relies on a social engineering foothold, it is even more difficult to detect or prevent than credential stuffing.

Phishing attacks have two targets: there is the end user who is in possession of a digital identity, and there is the IdP, which the attacker will abuse once they’ve gotten credentials. Depending on the motives of the attacker and the nature of the system and the data it stores, the impact of a successful phishing trip can land primarily on the user (as in the case of bank fraud), solely on the organization (as in the case of compromised employee credentials), or somewhere in the middle.

On the attacker side, phishing can range from simple, hands-off solutions for unskilled actors to custom-built frameworks including infrastructure, hosting, and code. The most hands-off setup is the Phishing-as-a-service (PhaaS) approach in which the threat actor pays to gain access to a management panel containing the stolen credentials they want, and the rest is taken care of by the “vendor.”

Dark web research indicates that the most popular subtype of phishing service is best described as phishing infrastructure development, in which aspiring attackers buy phishing platforms, infrastructure, detection evasion tools, and viable target lists, but run them on their own.

Brokering phishing traffic, or pharming, is the practice of developing infrastructure and lures for the purposes of driving phishing traffic, and then selling that traffic to other threat actors who can capitalize on the reuse of credentials and collect credentials for other purposes.

Finally, the attacker community has a niche for those who exclusively rent out hosting services for phishing.

The most important tactical development in phishing is undoubtedly the rise of reverse proxy/ man-in-the-middle phishing tools (sometimes known as real-time phishing proxies or RTPPs), the best known of which are Evilginx and Modlishka.  This is largely because it grants attackers the ability to capture most multi-factor authentication codes and replay them immediately to the target site facilitating MFA bypass but also making it less likely that the user victim will detect anything is amiss.

Multi-factor authentication (MFA) bypass

Recent years have seen attackers adopt a handful of different approaches to bypassing multi-factor authentication. The differences between these approaches are largely driven by what attackers are trying to accomplish and who they are attacking.

Nowadays, the reverse proxy approach has become the new standard for phishing technology, largely because of its ability to defeat most types of MFA.

MFA bypass tactics include:

  • Malware. In mid-2022, F5 malware researchers published an analysis of a new strain of Android malware named MaliBot. While it primarily targeted online banking customers in Spain and Italy when it was first discovered, it had a wide range of capabilities, including the ability to create overlays for web pages to harvest credentials, collect codes from Google’s Authenticator app, capture other MFA codes including SMS single-use codes, and steal cookies.
  • Social engineering. There are several variations of social engineering for bypassing MFA. Some target the owner of the identity, and some target telecommunications companies to take control of phone accounts.
  • Social Engineering for MFA Code—Automated. These are attacks in which attackers make use of “robocallers” to make phone calls to the target, emulating an identity provider and asking the victim for an MFA code or one-time password (OTP).
  • Social engineering for MFA code—Human. This is the same as the above approach except that the phone calls come from humans and not an automated system.
  • SIM swaps. In this kind of attack, a threat actor obtains a SIM card for a mobile account that they want to compromise, allowing them to assume control of the victim’s phone number, allowing them to collect OTPs sent over SMS. There are several variations of this approach.

So, what does it all mean?

Identity threats are constant and continuous. Whereas a vulnerability represents unexpected and undesirable functionality, attacks on identity represent systems working exactly as designed. They are therefore “unpatchable” not only because we can’t shut users out, but because there isn’t anything technically broken.

This brings us back to the question of what digital identity really is. To go from real, human identity to digital identity, some abstraction is inevitable (by which we mean that none of us is reducible to our username-password pairs). We often teach about this abstraction in security by breaking it down to “something we know, something we have, and something we are.” It is this abstraction between the entity and the digital identity that attackers are exploiting, and this is the fundamental basis of identity risk.

By thinking about digital identities in this way, what we are really saying is that they are
a strategic threat on par with, but fundamentally different from, vulnerability management. With nothing to patch, each malicious request needs to be dealt with individually, as it were. If modern vulnerability management is all about prioritization, modern identity risk management is essentially all about the ability to detect bots and differentiate them from real human users. The next logical step is quantifying the error rate of detecting these attacker-controlled bots. This is the basis on which we can begin to manage the risk of
the “unpatchables.”

Tech Features

Why UAE organisations cannot afford to get their AI storage strategy wrong

Published

on

BY: Owais Mohammed, Regional Lead & Sales Director at WD for the Middle East, Africa, Turkey, and the Indian Subcontinent

The UAE’s ambition to become a global AI powerhouse is well established. Government investment is flowing, infrastructure is scaling, and organisations across every sector are accelerating their AI programs. But beneath the strategic announcements and the technology deployments, a fundamental question goes unanswered: is the data storage infrastructure underpinning all this built for what comes next?

For many organisations, the honest answer is: not yet. Storage is rarely the first conversation in an AI strategy discussion. It tends to be treated as a commodity decision made late in the planning cycle, long after the headline architecture choices like GPUs/CPUs have been made. That approach made sense in simpler times, but not in today’s data-driven AI economy.

The scale of what is coming

To understand why, organisations need to understand the sheer data volume that is coming their way. Global data creation is forecast to rise to 718.5 Zettabytes (ZB) through 2030 (IDC source: Market Forecast: IDC Global DataSphere Forecast, 2026-2030, June 2026, Doc #US53425426), more than tripling in five years.

AI is both a driver and a consumer of this growth. Every model trained, every inference run, every data pipeline operating continuously across a distributed architecture is generating and demanding access to data at a scale that earlier generations of infrastructure were not designed to support.

Businesses that will absorb this growth successfully are not those with the fastest individual components. They are those with architectures designed to handle volume, variety, and velocity simultaneously, at a cost that remains economically sustainable as scale increases. That is the storage strategy challenge that needs to be addressed upfront and not as an afterthought.

Why a single technology cannot solve it

A common mistake is to frame the storage decision as a technology choice: SSDs versus HDDs, flash versus spinning disk, performance versus capacity. The world’s most sophisticated storage operators, including hyperscalers and major cloud service providers, have already moved past this framing. They do not choose one technology. They deploy multiple of them, in a tiered architecture that places data on the medium best suited to its requirements.

The logic is straightforward. SSDs deliver the high IOPS and low latency that real-time, performance-critical applications demand. HDDs provide the massive capacity and cost efficiency required for the vast middle tier of active and warm data, and currently continue to represent approximately 63% of worldwide installed storage capacity through 2030. Tape generally handles archival, regulatory, and compliance workloads where retrieval times of hours or days are acceptable, representing just under 8% of worldwide installed cloud storage capacity in 2025.

These are not competing technologies. They are complementary ones, each serving a distinct purpose within a coherent architecture. The question is how each is deployed where it delivers the greatest value.

Making tiered architectures work in practice

Knowing that tiered storage is the right model and implementing it effectively are two different things. At the scale hyperscalers operate, where storage volumes are measured in hundreds of exabytes, manual allocation of data across tiers is neither practical nor efficient.  Nor can all data live on cost prohibitive flash. The mechanism that makes tiered architecture manageable is software-defined storage (SDS), which pools resources centrally and provisions capacity dynamically based on demand. Rather than pre-allocating fixed capacity to individual applications, SDS responds to where data needs to be, improving overall utilisation and reducing waste.

Together, tiered architecture and SDS provide the flexibility and economic efficiency that hyperscale environments depend on. But this model is not the exclusive preserve of the world’s largest operators. For emerging infrastructure providers, including Neoclouds that are expanding rapidly across the region, the same principles apply. Architecture decisions made today will determine whether future growth is economically sustainable or structurally constrained. The window to get this right is earlier than many organisations assume.

Innovation at the storage level

Architectural thinking also changes how storage technology itself must evolve. An organisation that understands its workloads, plans for data growth, and builds tiered infrastructure will eventually reach the limits of what current storage innovations can deliver. That is why, manufacturers like WD are approaching HDDs not only as a mature, reliable product but as a technology with significant headroom remaining to help increase capacity, lower power and cost effectively scale AI data. They are advancing recording technologies, exploring novel materials, and embedding intelligence at the drive level. The aim is not incremental improvement. It is expanding the boundary of what high-capacity storage can deliver for the architectures customers are building today and the workloads they will run tomorrow.

The leadership dimension

The organisations that navigate the AI era most effectively will not be those that simply procure the latest hardware. It will be those that understand the architectural decisions that determine long-term performance, cost and scale, ask better questions earlier in the planning process, and treat storage infrastructure strategy as a source of competitive advantage rather than a procurement exercise.

Storage sits at the foundation of every AI workload, every data pipeline, and every digital service an organisation delivers. Getting the architecture right is not a technical detail. It is a leadership decision. And in a market moving as quickly as the UAE’s, it is one that deserves to be made with the same rigour and strategic intent as any other.

Continue Reading

Tech Features

Beyond a Seat at the Table: How Emirati Women Are Leading the UAE’s Next Chapter

Published

on

Every year, Emirati Women’s Day offers a moment to pause and reflect on just how far Emirati women have come, and how much further their ambitions are taking them. Across artificial intelligence and technology, entrepreneurship, sustainability, industry and beyond, Emirati women are no longer simply entering these spaces, they are shaping them, leading critical decisions and setting new benchmarks for what is possible.

This progress has not happened by chance. It is the result of a national vision that has consistently placed women’s empowerment at the heart of the UAE’s development, widely regarded as the driving force behind the advancement of Emirati women. Together, these efforts have built an ecosystem of mentorship, opportunity and structural support that allows Emirati women to move beyond simply having a seat at the table to actively influencing the direction of entire industries.

This Emirati Women’s Day, we spoke to three Emirati women who are doing exactly that, each carving out space in fields as varied as AI infrastructure, entrepreneurship and industrial sustainability. Their stories reflect not only how far the journey has come, but also a shared sense of responsibility: to keep the doors open, and to inspire the next generation of Emirati women to walk through them with confidence.

Amal Almaamari, Program Director at Core42, (a G42 Company)

The UAE has created an environment where women are encouraged to pursue ambitious careers, take on meaningful responsibilities and contribute to sectors that are shaping the country’s future. As an Emirati woman working in AI, I see this opportunity firsthand. At Core42, I am able to contribute to the infrastructure and capabilities helping organizations adopt AI securely, at scale and with greater control over their data and technology.

What is particularly inspiring is seeing Emirati women increasingly take on roles across engineering, product development, strategy and leadership. The opportunities available today allow us not only to participate in the technology sector, but to build expertise, influence decisions and contribute to the UAE’s ambitions in AI and advanced technology.

Emirati Women’s Day is a celebration of that progress and the confidence the UAE continues to place in its women. It also reminds us of our responsibility to build on these opportunities and inspire the next generation of Emirati women to see technology as a field where they can grow, lead and make a lasting impact.

Amreen Iqbal, Founder and Creative Director of Piece of You

What stands out to me about building a business here is how much the UAE actively invests in women being part of its growth story. From mentorship networks to platforms that put Emirati entrepreneurs in front of the right audiences, the opportunities aren’t hypothetical, they’re structural. Piece of You exists because I had the confidence and support to take an idea and turn it into something real. On Emirati Women’s Day, I think about how many doors have opened for women in my generation that weren’t open before, and how many more are opening for the next one.

Hamda Al Shamsi, Admin Assistant at Geocycle Waste Recycling UAE at Holcim UAE

The UAE has created an environment where women are empowered to pursue their ambitions, develop their skills, and contribute meaningfully across every sector. Today, Emirati women are building careers in fields ranging from technology and engineering to sustainability, manufacturing, energy, and leadership.

As an Emirati woman and the only woman currently working at Geocycle UAE, I have personally experienced the importance of having the opportunity to step into a technical and industrial field and prove that there is a place for women in every sector.

For me, Emirati Women’s Day is a celebration of how far we have come, but also a reminder of the opportunities ahead. The support and vision of the UAE leadership, together with the efforts of Her Highness Sheikha Fatima bint Mubarak, have helped create a generation of Emirati women who are confident to pursue their goals and make a difference. I believe the next step is to continue encouraging young Emirati women to explore fields they may not traditionally consider. When women are given the opportunity to learn, lead, and contribute, they do not only build successful careers — they help build a stronger and more sustainable future for the UAE.

Continue Reading

Tech Features

How to Make Data Work for Agentic AI in the GCC

Published

on

By Tejas Mehta, Senior Vice President & General Manager, Middle East & Africa at Qlik

Tejas Mehta

For decades, organizations have worked to use data to make better decisions and drive better outcomes. Data has become the lifeblood of business, and AI now has the power to unlock it in new ways. With AI adoption across GCC organizations surging from 62% in 2023 to 84% in 2025, the paradigm is shifting from dashboards and visual interfaces to AI-driven experiences.

But too much data is still stuck in silos, incomplete, and inaccurate. Many analytics workflows remain manual, which slows time to value, limits insight quality, and raises costs. This challenge is visible across the GCC, where rapid digital transformation agendas are generating vast volumes of data, but organizations still struggle to unify and operationalize it effectively.

A common misstep among organizations is assuming that more AI or better models alone will solve this problem. In reality, the gap is not in intelligence, but in how data, context, and workflows are connected. Without that foundation, even the most advanced AI will fall short of delivering meaningful business impact.

But what if AI could do more of the heavy lifting, safely and reliably?

That’s the promise of agentic AI, and it’s quickly becoming reality. Agentic AI can reason through multi-step problems, adapt its approach, and engage the right capabilities to achieve a goal with minimal human involvement. Done right, it accelerates insight, lowers costs, and allows teams to focus more on running the business rather than managing manual processes.

Rethinking AI in Practice

Today, we are seeing the emergence of AI systems capable of handling structured analytics, unstructured knowledge, anomaly detection, and decision support, all within a unified experience. More importantly, these systems are becoming interoperable, allowing organizations to integrate AI into existing tools and workflows rather than replacing them entirely.

This flexibility is crucial in the GCC, where enterprises often operate across hybrid environments and must balance innovation with governance, compliance, and data sovereignty requirements.

Overall, there are effectively two entry points into this new AI paradigm:

First, embedded AI experiences within enterprise platforms are enabling faster, more contextual insights, grounded in trusted data and existing business logic.

Second, open integration layers are allowing organizations to connect AI capabilities into the assistants and environments they already use, ensuring flexibility while maintaining governance and control.

Making Data Work for AI

To move from fragmented data and isolated AI initiatives to true agentic systems, organizations need a clear operating model that connects data, insights, and action. This is where three practical priorities come into focus:

  • Achieve AI: Organizations need trusted, explainable insights embedded directly into workflows, while maintaining governance and context.
  • Accelerate AI: Many enterprises have already invested heavily in data models and business logic. The focus now is on building on that foundation to prove value quickly and scale efficiently.
  • Adapt AI: The future will not belong to a single assistant, vendor, or ecosystem. Interoperability will define success, allowing organizations to evolve without starting over.

Across the GCC, this adaptability is especially important as governments and enterprises push for AI leadership while maintaining flexibility to adopt global innovations.

Lessons from Early Adoption

Early adopters of agentic AI are already demonstrating tangible value.

A commercial leader can ask what changed in renewals this quarter, and immediately see the drivers, segments, and recommended next steps in one place.

An operations team can move from identifying a spike in service issues to understanding where it is concentrated, what factors are correlated, and what actions to prioritize, without switching between multiple tools.

A finance team can reconcile narrative and numbers while maintaining traceability, ensuring every insight is backed by clear evidence.

These use cases are highly relevant in the GCC, where sectors such as banking, telecom, and government are under increasing pressure to deliver faster, data-driven decisions while maintaining transparency and accountability.

A Regional Perspective on What Comes Next

AI conversation is moving beyond models. The real challenge lies in making AI dependable, explainable, and useful within the flow of work.

If organizations cannot connect analytics with knowledge, they don’t have agentic AI. They simply have automation without accountability.

For the GCC, where trust, governance, and strategic national initiatives play a central role, this distinction is critical. AI must not only be powerful; it must be responsible, transparent, and aligned with long-term economic visions.

Ultimately, the opportunity is clear: organizations that can successfully unify their data, embed intelligence into everyday workflows, and enable AI to act with context and accountability will define the next era of digital leadership in the region.

Continue Reading

Trending

Copyright © 2023 | The Integrator