Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

Category: Trends

DNS attacks increase by 170%

Posted on January 23, 2013December 30, 2021 by admini

The shift from single-server attacks to the use of multiple servers in different geographic locations has allowed attackers to quickly and effectively launch more powerful DDoS attacks than ever before. Just a few attacking servers can produce the same attack traffic as a large number of client botnets, with the 24/7 availability of servers allowing for greater reliability as well as command-and-control. In 2013, Radware expects this method to gain in popularity, requiring that organizations make sure their defense architecture can withstand these scaled up attacks.

The numbers are staggering – with 58 percent of attacks scoring a 7 or higher in complexity (out of 10), as compared to just 23 percent of attacks in 2011. Though conventionally associated with security on the web, hackers have managed to weaponize the encryption layer, using it to launch application-level and SSL attacks that can escape detection and remain hidden until its already too late.

With some of the worlds largest institutions victimized by cyber attacks in 2012, the question remains as to why many of these organizations continue to be vulnerable. The fact remains that less than a quarter of all organizations surveyed invest their efforts in mitigating attacks as they’re happening – a fact exploited by hackers. In 2013, Radware recommends that organizations dedicate resources to creating a “security war room” equipped to dynamically respond to and handle persistent security attacks during all phases of an attack and adopt a three-phased security approach.

The supply chain includes took kits and for-hire services that are available to anyone with minimal coding or advanced hacking skills for as little as $10 for a ransomware attack tool.

Key findings include:
– Server-based botnets represent a new and more powerful order in the DDoS environment.
– The number of DDoS and DoS attacks lasting more than one week doubled in 2012.
– Encrypted layer attacks fly below the radar – and can’t be ignored.
– In today’s security environment, most organizations are bringing a knife to a gunfight.
-The DIY phenomenon.

Link: http://www.net-security.org/secworld.php?id=14285

Read more

Two-thirds of banks suffered a DDoS attack in 2012

Posted on January 22, 2013December 30, 2021 by admini

Banks are still predominately relying on previously deployed traditional technology, in particular firewalls (35%), to protect their organisation from today’s sophisticated attacks according to the survey, further raising concerns about the extent of board-level buy-in.

Morgan Chase & Co., Bank of America and Wells Fargo were just a few high-profile victims of cyber attacks in 2012 – a year which raised serious concerns regarding the safety of financial institutions – and Meyer says this is prompting banks into action. “We are seeing a tonne of activity in terms of engagement of the number of banks who are searching for information about DDoS mitigation, so I actually think there is going to be a ramped amount of spending in 2013,” he said.

We have met with a few banks already this year and all of them have a budget for DDoS, and many of them for on-premise DDoS.”

Link: http://www.insurancetimes.co.uk/two-thirds-of-banks-suffered-a-ddos-attack-in-2012/1400637.article

Read more

Number of Malicious Sites Increase by 240% in 2011

Posted on February 14, 2012December 30, 2021 by admini

The Blue Coat Security Labs team first discovered the existence of these malicious networks early in 2011 and presently is the only company to specifically identify, track and block them.

Malnets are distributed network infrastructures within the Internet that are built, managed and maintained by cybercriminals for the purpose of launching a variety of attacks against unsuspecting users over extended periods of time.

The Blue Coat 2012 Web Security Report details the strategies and tactics that malnet operators deploy to snare users and funnel them to dynamic malware payloads, or software which surreptitiously installs on users computers designed for malicious or criminal purposes.

“With the average business now facing 5,000 threats per month, identifying and tracking malnets to block attacks at the source before they are launched is the most effective protection.

According to the report, the most common entry point into these malicious infrastructures rely on the path of least resistance, utilizing entry points that are easy to exploit, such as search engines/portals and email, or are utilized by large, diverse populations of users.

The 2012 Web Security Report examines the malnet ecosystem in depth, examining user behavior, malnet strategies and tactics, as well as highlighting the best defenses against these aggressive infrastructures.

WebPulse is a cloud-based, real-time analysis and ratings service that unites users in a common defense.

Delivered via Blue Coat ProxySG® appliances and the Blue Coat Cloud Service, WebPulse receives one billion Web requests each day from 75 million globally diverse users.

http://www.it-analysis.com/technology/security/news_release.php?rel=29754

Read more

M86 Security Labs report provides insight to plan security for 2012

Posted on February 10, 2012December 30, 2021 by admini

Targeted attacks have grown more sophisticated, with evidence that cybercriminals are pursuing not only commercial organizations, but also government and infrastructure targets. Moreover, with the growing use of fraudulent and/or stolen digital certificates, these attacks have become more successful and evasive.

The exploit kit market has shifted dramatically toward the Blackhole exploit kit, which has the capability to update frequently and rapidly to take advantage of application vulnerabilities.

Even though there has been a precipitous drop in spam volumes, more spam messages are likely to contain malicious links or attachments.

There has been a significant increase in fraud and malware proliferation using social networks as a conduit. While targeted attacks are not new, the serious growth in incidents during the second half of 2011 is real cause for concern, not just for companies but for entire countries.

According to the report, targeted attacks became sophisticated and pursued a wider range of organizations, including commercial, national critical infrastructure and military targets.

One of the new attack vectors researchers identified is the use of fraudulent digital certificates. The report indicates the DigiNotar intrusion resulted in the “fraudulent issuance of hundreds of digital certificates for a number of domains, including Google, Yahoo!, Facebook, and even for some intelligence agencies, such as the CIA, the British MI6 and the Israeli Mossad.”

M86 Security stresses that organizations must plan and deploy a multi-layered security policy to minimize risks of a successful targeted attack. The exploits monitored during the second half of the year targeted a variety of products, including Microsoft Internet Explorer, Oracle Java, Microsoft Office products and, quite commonly, Adobe Reader and Adobe Flash.

What’s really astonishing is that some of the top vulnerabilities that criminals continue to exploit have not only been known for years, but fixes have also been available for years. For example, M86 found that the most exploited Web-based vulnerability is Microsoft Internet Explorer RDS ActiveX, which was both discovered and patched in 2006. Here we are, six years later, and this vulnerability still affects 17.7% of the pages that contain Web exploits as observed by M86 Secure Web Gateway.

The M86 report states the obvious: “Many users and organizations do not patch all their installed software in a timely manner, and attackers leverage this weakness to their advantage.”

The report also indicates that exploits shifted focus from malicious attachments to malicious links that led to exploit kits, in particular, the Blackhole exploit kit.

There’s good news and bad news in the spam observations. By the end of 2011, 5% to 10% of all spam contained links or attachments which redirected users to malicious or compromised sites that delivered a malware payload.

A troubling trend is cybercriminals exploiting the popularity of social media and the apparent blind trust of the users by duping them with fake (and infected) notification messages to “Friend Me” on Facebook or inviting them to join a LinkedIn network. For instance, a campaign last August led people to a fake Facebook login page and ultimately to the Blackhole exploit kit and a Zbot Trojan.

Source: http://www.networkworld.com/newsletters/techexec/2012/021012bestpractices.html

Read more

Cybersecurity Is The Way To Play Defense Spending Read more: http://stocks.investopedia.com/stock-a

Posted on February 9, 2012December 30, 2021 by admini

However, despite the growing need for preventing these sorts of attacks, actual spending and preparedness in the area is nonexistent. A recent survey by Bloomberg of network managers at 21 energy companies, found that these firms only spend an average of $45.8 million a year on IT security. … However, analysts estimate that to prevent 95% of all attacks, it would take an average annual budget of $344.6 million per company.

To put that into context, the U.S.’s largest utility, Southern Company (NYSE:SO), only made around $277 million in profit last year. Nationwide, the U.S. would need to spend a total of $46.6 billion to prevent 95% of all attacks. Given how vital our infrastructure is to national security and under-funded nature of the sector, cybersecurity will undoubtedly get a larger share of the shrinking defense budget.

With cyber threats continuing to mount and the reliance on computer networks growing, adding an IT security component to a portfolio makes sense. Both the PowerShares Aerospace & Defense (ARCA:PPA) and iShares Dow Jones US Aerospace (ARCA:ITA) follow some of the largest defense contractors and could be used as proxy for the defense sector.

Communications defense contractor Harris (NYSE:HRS) has been increasing its security offerings in the space and could be great way to play the need for secured data systems.

http://stocks.investopedia.com/stock-analysis/2012/Cybersecurity-Is-The-Way-To-Play-Defense-Spending-SO-ITA-PPA-PCP0209.aspx?partner=YahooSA#axzz1lzqFqWJl

Read more

Cybersecurity Is The Way To Play Defense Spending Read more: http://stocks.investopedia.com/stock-a

Posted on February 9, 2012December 30, 2021 by admini

However, despite the growing need for preventing these sorts of attacks, actual spending and preparedness in the area is nonexistent. A recent survey by Bloomberg of network managers at 21 energy companies, found that these firms only spend an average of $45.8 million a year on IT security. … However, analysts estimate that to prevent 95% of all attacks, it would take an average annual budget of $344.6 million per company.

To put that into context, the U.S.’s largest utility, Southern Company (NYSE:SO), only made around $277 million in profit last year. Nationwide, the U.S. would need to spend a total of $46.6 billion to prevent 95% of all attacks. Given how vital our infrastructure is to national security and under-funded nature of the sector, cybersecurity will undoubtedly get a larger share of the shrinking defense budget.

With cyber threats continuing to mount and the reliance on computer networks growing, adding an IT security component to a portfolio makes sense. Both the PowerShares Aerospace & Defense (ARCA:PPA) and iShares Dow Jones US Aerospace (ARCA:ITA) follow some of the largest defense contractors and could be used as proxy for the defense sector.

Communications defense contractor Harris (NYSE:HRS) has been increasing its security offerings in the space and could be great way to play the need for secured data systems.

http://stocks.investopedia.com/stock-analysis/2012/Cybersecurity-Is-The-Way-To-Play-Defense-Spending-SO-ITA-PPA-PCP0209.aspx?partner=YahooSA#axzz1lzqFqWJl

Read more

Posts pagination

  • Previous
  • 1
  • …
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • …
  • 56
  • Next

Recent Posts

  • Security Operations Weekly — July 19, 2026
  • Security Operations Weekly — July 19, 2026 — Interactive Topic Map
  • DevSecOps Weekly — July 19, 2026

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme