Cyber Security Basics 📂 Slides · 3 of 11 49 min read

Insider Threats, Zero-Day Attacks & Real Cyber Incidents — Interactive Slides

An interactive 18-slide walkthrough of the two most dangerous attack categories in modern cybersecurity — trusted insiders and unknown zero-days. Covers Snowden, Levandowski, Capital One and Tesla insider cases; Stuxnet, Log4Shell, MOVEit and XZ Utils zero-days; the SolarWinds SUNBURST and Cosmos Bank heist case studies; the 2026 threat landscape including deepfake fraud, RaaS and post-quantum risks; plus a Zero Trust defence playbook and 8 enterprise golden rules.

🕵️

Insider Threats, Zero-Days & Real Cyber Incidents

Snowden, SolarWinds, Log4Shell, Cosmos Bank, MOVEit — the incidents that redefined modern cybersecurity, and the patterns behind every one of them.
Insider Threats Zero-Day Attacks Supply Chain Real Incidents

Press Next → or use ← → arrow keys

Section 01

The Enemy Inside

Edward Snowden — 1.5 million classified files walked out on a USB
In 2013, a 29-year-old NSA contractor called Edward Snowden exfiltrated an estimated 1.5 million classified files using ordinary USB drives. The NSA had some of the world's most advanced cyber defences — but Snowden already had the badge, the login, and the trust.

Firewalls face outward. Antivirus scans for malicious code. But insider threats already have the keys, know the layout, and are trusted by the security controls themselves.
44%Rise in insider incidents (3-yr)
$16.2MAvg annual cost per org
86 daysAvg time to contain
55%Caused by negligence

Source: Ponemon Institute Insider Risk Report, 2024

Section 02

Three Categories of Insider Threats

Not every insider is a spy. Most damage comes from ordinary employees making ordinary mistakes.

😈
Malicious Insider
deliberate
Sets out to cause harm — motivated by revenge, greed, or ideology. Rare, but catastrophic when it happens. Snowden, Levandowski, Harold Martin.
🤷
Negligent Insider
~55% of incidents
Careless — weak passwords, laptops left unlocked, sensitive files emailed to personal accounts. No malice, just no attention.
🎭
Compromised Insider
hardest to detect
A legitimate account hijacked by an outsider through phishing or credential theft. The activity looks internal — because it is.
⚖️
The Trust Paradox

Every access credential you grant is a bet on trust — one that enables both productivity and potential damage. The goal isn't to eliminate trust; it's to make trust verifiable.

Section 03

The Insider Threat Kill Chain

01 Grievance motive forms 02 Recon maps crown jewels 03 Escalate steals admin 04 Exfiltrate data leaves 05 Depart cover-up 🕵️ 📦

Most malicious insider attacks follow the same 5-stage progression — often over months.

⛓️ THE 5-STAGE INSIDER PROGRESSION
Stage 1
Recruitment / Grievance — motive forms quietly. A denied promotion, a bad review, an external recruiter offering a fat bonus for a source-code drop.
Stage 2
Reconnaissance — the insider uses existing access to map where the crown jewels live. Nothing yet looks abnormal.
Stage 3
Escalation — grabs elevated permissions via shared credentials, a "quick favour" from a colleague, or fake service-desk requests.
Stage 4
Staging & Exfiltration — data leaves via USB, personal Google Drive, WhatsApp Web, or a stealth email forward rule.
Stage 5
Cover-Up & Departure — logs deleted, browsers wiped, resignation letter often submitted before the exfiltration is discovered.
Section 04

Insider Incidents That Changed the Rules

YearInsiderWhat HappenedOutcome
2013Snowden (NSA)1.5M classified files revealed mass-surveillance programsGlobal fallout
2016Harold Martin (NSA)Stashed 50 TB of classified data at home over 20 years9 years prison
2018Levandowski (Google→Uber)Downloaded 14,000 Waymo self-driving files before quitting$179M judgment
2019Capital OneEx-AWS engineer exploited misconfigured firewall106M records; $270M+
2022Twitter (Zatko)Whistleblower disclosed excessive employee access & security failuresSEC probe
2023Tesla (Germany)Two ex-employees leaked 100 GB internal data to Handelsblatt75,000+ affected
🇮🇳
India Context

IT service firms have quietly tightened controls after multiple engineers stole client source code (2019). In 2022, a Paytm employee was arrested for leaking KYC data. The pattern is global — the players are local.

Section 05

Zero-Day Attacks — Defined

"Zero days to prepare"
A zero-day is a software vulnerability the vendor doesn't yet know about, with no patch available. The attacker has a working exploit before defenders even know the flaw exists.

The name literally means: from the moment it becomes public, defenders have had zero days to prepare for it.
🚫
Why Traditional Defences Fail

Antivirus and IDS depend on known signatures. Zero-days have none — no hash, no rule, no signature file. Only behaviour-based detection and defence-in-depth work.

⏱️
The Timeline Reality

Google Project Zero (2024): average zero-day is exploited in the wild for 44 days before disclosure, then another 32 days before a patch ships. That's ~76 days of open season.

Section 06

The Zero-Day Lifecycle

Safe no attacker yet ⚠ DANGER ZONE ~76 days: 44 exploited + 32 to patch Patched now an N-day Attacker finds it first Exploited in the wild Vendor alerted Patch shipped time →
01
Bug is born
A developer ships buggy code. The flaw exists but nobody knows.
02
Attacker finds it first
A researcher, criminal group or nation-state discovers the vulnerability — silently.
03
Window of exposure
Weaponised and used in the wild. Every victim is a "zero-day victim". Detection is near-impossible.
04
Vendor alerted
A researcher, victim, or leak brings it to the vendor. The clock starts on the patch.
05
Patch shipped — the "danger zone"
Now it becomes an "N-day". Attacks skyrocket as criminals race to hit anyone who hasn't patched yet.
Section 07

Famous Zero-Days That Made History

YearExploitWhereImpact
2010StuxnetWindows + Siemens PLCsPhysically destroyed Iranian centrifuges — opened cyber-physical warfare
2017EternalBlueWindows SMB (stolen from NSA)Powered WannaCry & NotPetya — $14B+ damage
2021Log4Shell (CVE-2021-44228)Log4j logging libraryCalled "internet's worst vuln" — millions of Java apps affected
2021ProxyLogonMS Exchange Server60,000+ orgs compromised (HAFNIUM)
2023MOVEit (CVE-2023-34362)File-transfer softwareClop ransomware hit 2,600+ orgs, 90M+ people (BBC, BA, US DoE)
2024XZ Utils BackdoorLinux compression libSupply-chain zero-day planted over 2 years — caught days before deployment
Section 08

The Zero-Day Marketplace

Zero-days are traded like currency across three very different markets.

🤝
White Market
bug bounties
Legal reporting via HackerOne, Bugcrowd, Google VRP. Payouts from hundreds to $100k+. Apple pays up to $2M for a full iPhone chain.
🕶️
Grey Market
brokers & govts
Zerodium, Crowdfense resell to Western intelligence agencies. Full Android chain: $2.5M+. Legal — but ethically contested.
🕳️
Black Market
criminal forums
Dark-web bazaars and private Telegram groups. Lower prices, constant demand. Where most enterprise zero-days get weaponised.
💰
Price Reality

Remote-code-execution zero-days in Chrome, iOS, or Windows fetch $1M–$2.5M in grey markets — more than most researchers earn in a decade. This is why zero-days go to buyers, not vendors.

Section 09

Real-World Cyber Incidents

YearIncidentHow It Got InConsequence
2013Target (USA)HVAC vendor credentials → pivoted to POS40M cards; CEO resigned; $202M
2016Bangladesh BankSWIFT credentials + malware$81M stolen (a typo saved $850M more)
2017EquifaxUnpatched Apache Struts (patch was 2 months old)147M SSNs; $1.4B+
2018Cosmos Bank (India)Malware in the ATM switch₹94 cr — 12,000 fake ATM txns across 28 countries
2021Kaseya VSARansomware via MSP tool1,500 businesses in one day, 17 countries
2024CrowdStrike OutageFaulty security update8.5M Windows machines bricked; $10B+ losses
Section 10

Case Study — SolarWinds SUNBURST (2020)

One update. 18,000 victims. 100 real targets.
Attackers compromised the SolarWinds build environment and injected the SUNBURST backdoor into legitimate, digitally-signed Orion updates. 18,000 customers installed it — including US Treasury, State Dept, DHS, Justice Dept, Microsoft and FireEye.

The backdoor slept for 2 weeks to evade sandboxes, then attackers hand-picked ~100 real targets. Discovered only when FireEye noticed a strange second login on an employee phone. Attribution: Russia's SVR (APT29 / "Cozy Bear").
🔗
The Lesson

Your security is only as strong as the weakest vendor in your software supply chain. Every automatic update from every vendor is an act of trust — and trust needs receipts (SBOMs, reproducible builds, third-party audits).

Section 11

Case Study — Cosmos Bank Heist (India, 2018)

₹94 crore stolen in 8 hours across 28 countries
On the weekend of 11 August 2018, attackers who had implanted malware in the ATM authorisation switch of Pune-based Cosmos Bank triggered 12,000 fraudulent transactions across 28 countries in ~8 hours. A parallel SWIFT transfer attempted another $2M to a Hong Kong shell account.

The initial vector? A single phishing email to bank IT staff months earlier.
❌ What Failed
ATM switch connected to admin network — no segmentation
Weekend alert systems unmonitored
Legacy SWIFT terminals, shared credentials, no MFA
Pre-positioned money mules in 28 countries
✅ What Should Have Been There
24/7 SOC with automated alerting
Strict network segmentation
Behaviour-based fraud detection
MFA on all SWIFT and privileged systems
Regular red-team exercises
Section 12

Emerging Threats — 2026 Landscape

🤖
AI-Powered Attacks
LLMs write flawless phishing in any language, mimic executive writing styles for whaling. Grammar is no longer a reliable red flag.
🛒
Ransomware-as-a-Service
LockBit, ALPHV/BlackCat, Clop sell subscriptions. Affiliates launch enterprise-grade attacks with zero coding skill.
🧬
Supply-Chain Attacks
One vendor breach = thousands of victims. SolarWinds, Kaseya, MOVEit, 3CX, XZ Utils — growing every year.
👤
Deepfake Fraud
2024: a Hong Kong finance clerk wired $25M to an AI-generated "CFO" on a video call. Voice and video cloning is production-ready.
Critical Infrastructure
Power grids, water utilities, hospitals, railways all now under nation-state attack. 2023 Israeli water plant; 2022 Ukraine grid.
🔮
Post-Quantum Threats
"Harvest Now, Decrypt Later" — attackers collecting encrypted data today, betting quantum computers will crack RSA/ECC tomorrow.
Section 13

Anatomy of a Supply-Chain Attack

🏢 Compromised Vendor signs & ships poisoned update 🏛️ 🏥 🏦 🏢 🎓 🏭 🏬 …and 17,993 more downstream victims

One vendor breach = thousands of victim breaches. This is why supply-chain attacks are the 2020s' fastest-growing category.

01
Compromise the trusted vendor
Attackers breach a software vendor's build environment or steal signing keys.
02
Poison the update
Inject a backdoor into a legitimate, digitally-signed update. Everything looks authentic.
03
Auto-update ships to thousands
18,000+ customers install the malicious update automatically — bypassing every external-threat defence.
04
Sleep & select
Backdoor lies dormant for weeks to evade sandboxes, then attackers cherry-pick their high-value targets.
05
Objective
Data exfiltration, long-term espionage, ransomware deployment — all under the umbrella of a "trusted" vendor.
Section 14

Defence Playbook — Modern Controls That Work

🚫
Zero Trust Architecture
never trust, always verify
Verify every request, not just login. Micro-segment networks. Assume the attacker is already inside.
📊
UEBA
behaviour analytics
Baseline normal user behaviour, flag deviations: unusual downloads, impossible-travel logins, off-hours activity.
🔑
Least Privilege
just enough, just in time
Only the permissions strictly needed for the role — and only as long as needed. Quarterly reviews.
🛑
DLP
Data Loss Prevention
Monitor & block sensitive data leaving the network — email, USB, cloud uploads, printers. ML catches images and code.
🛰️
EDR / XDR
endpoint detection
Watch system behaviour — suspicious process chains, memory injections, weird network calls. Essential for zero-day defence.
📜
SBOM & Vendor Vetting
supply-chain hygiene
Software Bill of Materials lists every dependency. When Log4Shell 2 drops, you know your exposure in minutes — not weeks.
Section 15 · Part 1

Golden Rules for Enterprise Defence — 1 to 4

🛡️ 8 COMMANDMENTS · RULES 1–4
1
Assume breach. Design systems as if the attacker is already inside. Micro-segmentation and encryption at rest matter more than a perfect perimeter.
2
Least privilege, always. Review permissions quarterly. Nobody — not the CEO, not the DBA — needs universal access. Enforce just-in-time elevation.
3
Patch fast, measure it. Track MTTP (Mean Time To Patch) as a real KPI. Critical patches within 72 hours. Equifax happened because a patch existed for 2 months.
4
Watch humans, not just machines. Deploy UEBA and DLP. Anomalous behaviour is the earliest warning of a compromised insider — often weeks before any exfiltration.
Section 15 · Part 2

Golden Rules — 5 to 8

🛡️ 8 COMMANDMENTS · RULES 5–8
5
Vet every vendor. Require SBOMs, third-party audits and contractual security clauses from every SaaS and open-source dependency. SolarWinds was preventable.
6
Rehearse disaster. Tabletop exercises and red-team drills twice a year. An incident-response plan that has never been practised is fiction, not a plan.
7
Log everything. Retain for years. Insider incidents surface an average of 86 days after they start. Without long-tail logging you have no forensic story to tell.
8
Treat departing employees as high risk. Revoke access on the notice day, not the last day. Audit downloads and cloud activity in the 30-day pre-departure window.
FINAL

Security Is an Attention Problem

86 daysTo contain insider breach
76 daysAvg zero-day exposure
18,000SolarWinds victims
$14B+EternalBlue damage
$25MLost to a deepfake CFO
72hTarget for critical patches
🎯
The Closing Insight

Every incident in this tutorial was preventable in hindsight. The controls existed at the time. Security is rarely a technology problem — it is an attention problem.

📚
Keep Learning

Read the Verizon DBIR and Ponemon Insider Risk Report yearly. Follow Krebs on Security, Bleeping Computer and The Hacker News. The playbook changes every quarter — your defences should too.

🕵️ End of tutorial · Press to review, or click Restart