Submind YouTube summaries
Thumbnail for 84% of Commerce DDoS Attacks Hit Retail. Is Your Defense Ready? | Steve Winterfeld, Akamai

84% of Commerce DDoS Attacks Hit Retail. Is Your Defense Ready? | Steve Winterfeld, Akamai

Watch on YouTube

Video summary

The transcript highlights that retail commerce is the primary target for application layer DDoS attacks, accounting for a staggering 84% of all such incidents in the sector. Cybercriminal groups are increasingly employing sophisticated multi-vector approaches that combine AI-assisted malware with Internet of Things (IoT) botnets, a tactic referred to as "turbo malware." These evolved attacks have escalated in scale from gigabytes to multiple terabytes, forcing Chief Security Officers to significantly upgrade their defensive capabilities. A key example provided is how everyday devices like refrigerators can be co-opted into massive botnets, allowing attackers to simultaneously target specific commerce sites with unprecedented volume and complexity. Beyond traditional denial-of-service tactics, the discussion emphasizes a shift toward logic exploits facilitated by generative AI agents. Unlike standard AI models, these agents possess decision-making capabilities that allow them to manipulate systems in novel ways, such as honoring expired promotional codes, authorizing fraudulent returns, or leaking proprietary inventory data. The transcript notes that while vulnerabilities like those seen in "Project Glass Wing" have been identified, they are not yet widely operationalized by criminals; however, the integration of AI introduces new attack surfaces specifically targeting chatbots and autonomous agents used for customer service and transaction processing. The speaker also addresses the concept of token freeloading within malware, where attackers leverage tokens to bypass security controls and gain persistent access to accounts. This evolution means that threats now extend beyond simple credential theft to include complex fraud enablement and data exfiltration driven by AI-driven decision logic. Although many theoretical vulnerabilities exist, the real danger lies in how these new AI capabilities are being weaponized to disrupt business operations and cause financial loss. In conclusion, the video urges organizations to look closely at their logs and protective infrastructure to detect these emerging threats before they can be exploited in the wild. While not every identified vulnerability is currently being used by cybercriminals or activists to cause immediate disruption, the landscape is changing rapidly as AI becomes a common vector for exposure. Security teams must adapt their strategies to handle these new logic-based attacks and ensure their defenses are ready for the next generation of commerce-focused cyber threats that blend traditional DDoS methods with advanced artificial intelligence.
Read the full video transcript
Can you also talk about beyond agentic shoppers uh what other trends are you seeing like uh DOS uh and uh other traditional uh attacks as well? Uh so as you know Agamite does a lot around DOS protection and so we have a a ton of insights regional insights industry insights uh but within commerce retail accounted for 84% of all commerce application layer DOS attacks and so you know there are groups out there like the Iran Iraq hackist group 313 that have been really focused on some of this stuff doing multi vector approach combining AI assisted Marai uh internet of things botnet we're calling it turbo marai uh and there are variants of this that have have really peaked the old you know gigabyte to terabyte to multiple terabyte size attacks and so that's requiring csos to go reook their defensive capability ilities with these new peak capabilities of all internet of things. So you know this is the classic uh you know your refrigerator is now part of a a botn net which is just a collection of of different systems and they're all trying to attack one commerce site at the same time. Um you know and and we talked a little bit about there that you know there's AI capabilities being added in here. I haven't seen a ton of these in the wilds. We talk a thing about things like Project Glass Wing, if you've heard about that, where they're just stacking up all these vulnerabilities. I haven't seen a ton of those vulnerabilities be operationalized. So, a lot of them were were real vulnerabilities, but they haven't been used in the wild by cyber criminals or activists to to cause damage or disruption. And so, you know, we think about this, but as AI gets in here, there's this this new vulnerability areas. A lot of us when you go, there's a chatbot there. Can I help you? Well, they're attacking those chat bots. If there's agents, like let's say you go in and you want to get a credit card from your from your shopping store, a lot of that may now be handled by AI agents to make those decisions because again, a Gentic AI is different than your traditional Gen AI and that it makes decisions. And then tokens, tokens are those thing capabilities that let you um leverage all this. In fact, we have a section on our malware talking about token freeloading. So, you know, all of this is now logic exploits honoring expired promotional codes, authorizing fraudulent returns, leaking proprietary inventory data. There's a lot of different types of attacks happening out here with this new AI capabilities beyond just those traditional DOS. And then we do a malware deep dive. You know, we talk about those traditional traditional things, credential theft, uh leading to account takeover, uh fraud enablement, persistent access, and AI is a common vulnerability exposures, numbering authority. So, we we do a lot of this kind of research, but we talk in detail about some of this capability out there and what you should be looking for within your logs and within your protective uh organizations today.