PP105: Cybercrime Has Gone Industrial: Insights from HPE Threat Labs (Sponsored)
HPE's VP Mundani Adjali discusses the formation of HPE Threat Labs from the merger of Juniper and HPE Aruba threat research teams. The conversation covers cybercrime professionalization, AI's impact on threats, network visibility challenges, and the critical need for better patch management across enterprise systems.
Summary
This sponsored episode features Mundani Adjali, VP of Product Management for SASE and Security at HPE Networking, discussing the newly formed HPE Threat Labs. The team combines Juniper's threat research capabilities with HPE Aruba's product security focus following their July 2025 acquisition. Adjali explains that while Juniper focused on external threat research, HPE Aruba concentrated on product security and vulnerability testing.
A major theme from their threat research is that many attacks exploit old, unpatched vulnerabilities rather than new threats. Organizations struggle with patch management, leaving systems vulnerable to attacks using exploits that are 10-15 years old. AI is accelerating threat actors' capabilities, making them more efficient and enabling smaller teams to launch more sophisticated attacks, though humans remain essential for targeting decisions.
The discussion covers HPE's device fingerprinting technology, evolved from behavioral analytics acquired through the Neara company. This technology identifies devices based on behavior patterns rather than static classifiers, addressing challenges like MAC randomization and generic DHCP signatures. The telemetry from access points, switches, firewalls, and cloud services provides comprehensive network visibility.
Adjali emphasizes the blurred lines between networking and security teams, noting that network engineers often implement security policies without receiving proper credit. He advocates for intent-based configuration tools that help administrators express goals in natural language rather than complex technical commands. The conversation also touches on the persistent need for network access control despite the rise of endpoint agents, particularly for headless devices and IoT systems.
About this episode
Threat actors are behaving more like professional organizations in an effort to launch more effective and profitable attacks. We explore this and other themes from the latest Threat Labs report from HPE, our sponsor for today’s Packet Protector episode. We also look at how older vulnerabilities are still contributing to today’s exploits, why security organizations<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/packet-protector/pp105-cybercrime-has-gone-industrial-insights-from-hpe-threat-labs-sponsored/" title="ReadPP105: Cybercrime Has Gone Industrial: Insights from HPE Threat Labs (Sponsored)">... Read more »</a>
Key Insights
- HPE Threat Labs was formed by combining Juniper's external threat research team with HPE Aruba's product security team, creating complementary capabilities that were previously separate
- Organizations typically underestimate their device count by 25-50%, with unknown devices including shadow IT, printers, and sensors that weren't properly inventoried
- Many current cyber attacks exploit vulnerabilities that are 10-15 years old rather than new threats, indicating widespread patch management failures across enterprises
- AI is making threat actors more efficient and enabling smaller teams to launch sophisticated attacks, though human decision-making remains essential for targeting and strategy
- Network engineers are actually implementing most security policies in organizations but don't receive credit for their security work, creating an artificial separation between networking and security teams
- Device identification has evolved from static classifiers to behavioral analysis due to MAC randomization and generic DHCP signatures making traditional methods ineffective
- The convergence of networking and security telemetry across access points, switches, and firewalls enables better threat detection for both north-south and east-west traffic flows
- Intent-based configuration tools are needed to help administrators express security goals in natural language rather than requiring mastery of complex technical syntax and acronyms
Topics
Transcript
Hey, everybody, welcome to Packet Protector, the podcast at the intersection of networking and security. I'm Drew Connery-Murray here with JJ. We are on site at RSA 2026. We have a sponsored episode today with HPE Networking. Our guest is Mundani Adjali. You are VP of Product Management for SASE and Security at HPE Networking? Yes, I am. Okay. So apparently, this is new for HPE, right? You guys are doing some threat research, and you've just put out a new report? So I'd actually, you know, phrase it a little differently in the sense that Juniper Networks had a threat research team. And that's not to say that HPE didn't, but I think our focus was very different, right?…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)
Rekha Shenoy and Irfan Kimji from Backbox discuss how the exponential growth of vulnerabilities (49,000 CVEs annually) has made manual network operations unsustainable, and how AI-powered automation can help network teams manage patches and security updates at scale while maintaining human control and oversight.
HN840: How to Make a Technology Buying Decision
Sean Morgan, a research director at Deloro Group, discusses how technology buying decisions should extend beyond engineering specifications to include business alignment, ROI calculations, and understanding total cost of ownership. Engineers must shift from viewing IT as a cost center to positioning it as a business enabler by connecting technical decisions to revenue impact and organizational objectives.
IPB207: Flying Blind: Monitoring Might Not See IPv6
The IPv6 Buzz hosts discuss critical gaps in IPv6 monitoring across enterprise networks, highlighting that many monitoring platforms lack IPv6 awareness, vendor parity, and advanced analytical capabilities. They emphasize that while basic IPv6 data ingestion has improved, sophisticated features like cross-protocol event correlation, extension header analysis, and device identity tracking remain significant industry challenges.
N4N063: Link Layer Discovery Protocol
Link Layer Discovery Protocol (LLDP) is a standardized Layer 2 protocol that enables network devices to announce information about themselves to directly connected neighbors, facilitating network topology discovery and device identification in multi-vendor environments. The protocol uses Ethernet frames with special multicast destination MAC addresses to ensure frames don't propagate beyond immediate neighbors, and includes mandatory TLVs (Type-Length-Values) like chassis ID, port ID, and TTL alongside optional ones for extended information.
TCG083: Superintelligence for Everyone: Who Actually Holds the Power?
Three technology experts discuss Mark Zuckerberg's manifesto on distributed superintelligence, examining whether his promises of universal access and individual empowerment align with infrastructure realities. They conclude that while decentralized AI is theoretically safer than centralized control, the manifesto fails to account for human complexity, existing inequalities, and the enormous capital requirements that will likely concentrate power rather than distribute it.