Ransomware and IoT Malware Detections Surge by Over 60%

Ransomware and IoT Malware Detections Surge by Over 60%

Last year saw a double-digit surge in ransomware, IoT threats, new malware and cryptojacking, in what SonicWall has described as a “tipping point” in the cyber-arms race.

The security vendor’s 2021 SonicWall Cyber Threat Report is compiled from data taken from over one million global sensors and cross-vector threat information shared among SonicWall security systems.

Ransomware threats spiked 62% globally and 158% in North America as more sophisticated variants like Ryuk targeted larger organizations with multi-staged attacks. The retail (365%), healthcare (123%) and government (21%) sectors were particularly badly hit during the pandemic.

Elsewhere, there were nearly 82 million cryptojacking detections, a 28% increase from 2019 figures, driven by the rising value of digital currency.

IoT malware detections surged 66% as attackers targeted home networks and remote workers, and overall there was a 74% increase in previously undetected malware variants.

The shift to remote work may also be behind the 67% increase in malicious Office files, which overtook malicious PDFs to claim top spot.

SonicWall CEO, Bill Conner, argued that organizations must remain “vigilant and proactive” in improving their cybersecurity posture.

“There is no code of conduct when it comes to cyber-criminals, their methods of attacks and the selection of their targets,” he added. “Technology is moving at an unprecedented rate. Threats that were once thought to be two or three years away are now a reality, with do-it-yourself, cloud-based tools creating an army of cyber-criminals armed with the same devastating force and impact of a nation state or larger criminal enterprise.”

Intrusion attempts also evolved due to the unique circumstances that unfolded last year thanks to the pandemic. In 2020, directory traversal tactics (34%) took the top spot after tying with remote code execution (21%) in 2019, the report claimed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft One-Click Tool Mitigates Exchange Server Attacks

Microsoft One-Click Tool Mitigates Exchange Server Attacks

Microsoft has released a “one-click” tool to help organizations with limited resources to temporarily mitigate the threat posed by recent global attacks on Exchange servers.

The “Microsoft Exchange On-Premises Mitigation Tool” has been designed for customers without dedicated IT or cybersecurity resources to help them patch the four zero-days being exploited in the wild, now know as “ProxyLogon” attacks.

“By downloading and running this tool, which includes the latest Microsoft Safety Scanner, customers will automatically mitigate CVE-2021-26855 on any Exchange server on which it is deployed,” Microsoft said.

“This tool is not a replacement for the Exchange security update but is the fastest and easiest way to mitigate the highest risks to internet-connected, on-premises Exchange Servers prior to patching.”

Once it has been run, the tool will mitigate attacks exploiting the above CVE, using a “URL rewrite configuration.” It will also run the Microsoft Safety Scanner and attempt to reverse any changes made by identified threats.

However, the Redmond giant was at pains to point out the tool shouldn’t be used as a replacement for patching, as it only works against attacks seen so far, and “is not guaranteed to mitigate all possible future attack techniques.”

Check Point Research claimed yesterday that it had seen a sixfold increase in exploit attempts targeting the zero-days in Exchange Server Microsoft patched out-of-band at the start of the month.

Although initially Microsoft attributed attacks to a Chinese state-backed actor, dubbed Hafnium, researchers have since claimed that multiple APT groups have been attempting to exploit the same vulnerabilities for remote control, data theft, ransomware and more.

Microsoft warned last Friday that it had detected a new ransomware variant, DearCry, being used in attacks.

The firm has released new updates to cover end-of-life Exchange Server products, and cumulative updates which it said cover 95% of all versions exposed on the internet. As of Friday, around 80,000 servers were still unpatched globally.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

MoD Contractor Security Incidents Double in a Year

MoD Contractor Security Incidents Double in a Year

Cybersecurity incidents at Ministry of Defence (MoD) contractors appear to have doubled over the past year, with email data leaks a particular cause for concern, according to a new report.

Sky News was able to piece together some of the puzzle from Freedom of Information (FoI) requests sent to the ministry for 2020 and 2019.

They relate to the Warning, Advice and Reporting Point (WARP) system, which requires all contractors that process MoD information to report suspected or actual breaches of security policy, procedures or legislation, as well as other hostile activity and incidents on corporate networks.

The report claimed that 2020 saw a record 151 such incidents reported, versus just 75 the year before.

Although much of the detail in the FOI report was redacted, there were apparently “numerous” incidents when sensitive data was emailed to personal inboxes, where it could have been exposed to state-sponsored attackers.

Other incidents included a physical breach to a perimeter fence at an unknown location, misconfigured IT systems and “data sent to unauthorized domain.”

Tim Sadler, CEO of security firm Tessian, argued that remote working has made the problem of data loss prevention even more challenging.

“According to our data, employees send company sensitive information to personal email accounts 38 times more often than their IT and security leaders expect,” he added.

“While it might seem harmless, highly sensitive information in those emails now sits in an environment that is not secured by the company, leaving it vulnerable to cyber-criminals.”

The MoD news comes ahead of the government’s Integrated Review today which promises the biggest shake-up to British defense and security policy in decades.

Number 10 trailed the news on Sunday by revealing that the country’s new offensive National Cyber Force, combining intelligence and defense industry operatives, will be headquartered in the north of England.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk