Sony Pixel Power calrec Sony

Cisco Midyear Security Report Highlights Weak Links in Increasingly Dynamic reat Landscape

08/05/2014

Cisco Midyear Security Report Highlights Weak Links in Increasingly Dynamic Threat Landscape Expanding Attack Surface Allows Attackers to Exploit Known Weaknesses within Low Risk Targets and Low Profile Legacy Applications and Infrastructure

Cisco CSO John N. Stewart Shares Top Insights from 2014 Cisco Midyear Security Report

LAS VEGAS, Aug. 5, 2014 The Cisco 2014 Midyear Security Report, released today at Black Hat U.S. (Cisco Booth #611), examines the weak links in organizations that contribute to the increasingly dynamic threat landscape. These weak links which could be outdated software, bad code, abandoned digital properties, or user errors contribute to the adversary's ability to exploit vulnerabilities with methods such as DNS queries, exploit kits, amplification attacks, point-of-sale (POS) system compromise, malvertising, ransomware, infiltration of encryption protocols, social engineering and life event spam.

The report also shows that focus on only high-profile vulnerabilities rather than on high-impact, common and stealthy threats puts these organizations at greater risk. By proliferating attacks against low-profile legacy applications and infrastructure with known weaknesses, malicious actors are able to escape detection as security teams focus instead on boldface vulnerabilities, such as Heartbleed.

Key Findings

Researchers closely examined 16 large multinational organizations, who, as of 2013, collectively controlled over $4 trillion in assets with revenues in excess of $300 billion. This analysis yielded three compelling security insights tying enterprises to malicious traffic:

Man-in-the-Browser attacks pose a risk for enterprises: Nearly 94 percent of customer networks observed in 2014 have been identified as having traffic going to websites that host malware. Specifically, issuing DNS requests for hostnames where the IP address to which the hostname resolves is reported to be associated with the distribution of Palevo, SpyEye, and Zeus malware families that incorporate man-in-the-browser (MiTB) functionality.

Botnet hide and seek: Nearly 70 percent of networks were identified as issuing DNS queries for Dynamic DNS Domains. This shows evidence of networks misused or compromised with botnets using DDNS to alter their IP address to avoid detection/blacklist. Few legitimate outbound connection attempts from enterprises would seek dynamic DNS domains apart from outbound C&C callbacks looking to disguise the location of their botnet.

Encrypting stolen data: Nearly 44 percent of customer networks observed in 2014 have been identified as issuing DNS requests for sites and domains with devices that provide encrypted channel services, used by malicious actors to cover their tracks by exfiltrating data using encrypted channels to avoid detection like VPN, SSH, SFTP, FTP, and FTPS.

The number of exploit kits has dropped by 87 percent since the alleged creator of the widely popular Blackhole exploit kit was arrested last year, according to Cisco security researchers. Several exploit kits observed in the first half of 2014 were trying to move in on territory once dominated by the Blackhole exploit kit, but a clear leader has yet to emerge.

Java continues its dubious distinction as the programming language most exploited by malicious actors. Cisco security researchers found that Java exploits rose to 93 percent of all indicators of compromise (IOCs) as of May 2014, following a high point of 91 percent of IOCs in November 2013 as reported in the Cisco 2014 Annual Security Report.

Unusual upticks in malware within vertical markets. For the first half of 2014, the pharmaceutical and chemical industry, a high-profit vertical, once again placed in the top three high-risk verticals for Web malware encounters. Media and publishing led the industry verticals posting nearly four times the median Web malware encounters, and aviation slid into third place with over twice the median Web malware encounters globally. The top most affected verticals by region were media and publishing in the Americas; food and beverage in EMEAR (Africa, Europe and the Middle East) and insurance in APJC (Asia-Pacific, China, Japan and India).

About the Report

The Cisco 2014 Midyear Security Report examines threat intelligence and cybersecurity trends for the first half of 2014 and was developed by security research experts who are part of the Cisco Collective Security Intelligence (CSI) ecosystem. Cisco CSI is shared across multiple security solutions and provides industry-leading security protections and efficacy. In addition to threat researchers, CSI is driven by intelligence infrastructure, product and service telemetry, public and private feeds and the open source community.

The Cisco CSI ecosystem includes the newly combined Talos Threat Intelligence and Research Group, which is a combined team from the previous Cisco Threat Research and Communications (TRAC) team, the Sourcefire Vulnerability Research Team (VRT) and Cisco Security Applications (SecApps) group. Talos' expertise spans software development, reverse engineering, vulnerability triage, malware investigation and intelligence gathering and maintains the official rule sets of Snort.org, ClamAV, SenderBase.org and SpamCop.

Supporting Quote

John N. Stewart, senior vice president, chief security officer, Cisco, said: Many companies are innovating their future using the Internet. To succeed in this rapidly emerging environment, executive leadership needs to embrace and manage, in business terms, the associated cyber risks. Analyzing and understanding weaknesses within the security chain rests largely upon the ability of individual organizations, and industry, to create awareness about cyber risk at the most senior levels, including Boards making cybersecurity a business process, not about technology. To cover the entir
LINK: http://newsroom.cisco.com/press-release-content?type=webcontent&articl...
See more stories from cisco

Most recent headlines

04/08/2024

Dalet Appoints Santiago Solanas as CEO to Lead Next Era of Growth and Innovation

Dalet, a leading technology and service provider for media-rich organizations, is excited to announce Santiago Solanas as its new Chief Executive Officer (CEO)....

03/06/2024

Dalet and Veritone Reach Agreement to Distribute, Transact and Monetize Media Archives

Dalet, a leading technology and service provider for media-rich organizations, a...

18/05/2024

If Bundling Is Back, What's the Ideal Bundle?

PORTSMOUTH, N.H. Bundling is back in a big way, with all the major streaming companies and many pay TV operators exploring ways to simplify the consumer experie...

18/05/2024

FCC to Vote on LPTV Rules during June Open Meeting

WASHINGTON, D.C. Federal Communications Commission Chairwoman Jessica Rosenworcel has announced a tentative agenda for the June Open Commission Meeting schedule...

18/05/2024

Matthews Launches New Multipurpose Grip Rail Telescopic Grid Pipe Solution

Matthews Studio Equipment has introduced Grip Rail, which the company said offers a better way to mount equipment on location, in the studio, or on the fly....

18/05/2024

IAB Tech Labs, Google Partner on New First Party Data Solution

In a notable development in the industry-wide effort to address privacy concerns while improving efficacy of marketing efforts in a cookieless ad landscape, IAB...

18/05/2024

TV Tech Weekly Product Wrap-Up

Missed any of our product coverage during your busy week? The TV Tech weekly product and services news wrap-up provides links to all of our coverage from May 13...

18/05/2024

DHD Elevates the Art of Podcast Production

DHD Elevates the Art of Podcast Production Brie Clayton May 17, 2024 0 Comments Hero image: the DHD DX2 base and expansion modules Latest-generation ...

17/05/2024

Aerojet Rocketdyne's Camden Site Leverages Modernization Investments to Accelerate Solid Rocket Motor Production

Aerojet Rocketdyne has worked to modernize facilities at its Camden, Arkansas, l...

17/05/2024

FCC Plans to Revise LPTV Rules

The FCC has issued a Notice of Proposed Rulemaking (NPRM) that would revise rules governing low power TV stations (LPTV) in a number of areas, including online ...

17/05/2024

Demystifying Post-Production: Introducing Cinema 4D Particles Week 4

Demystifying Post-Production: Introducing Cinema 4D Particles Week 4 Brie Clayton May 17, 2024 0 Comments With the spring release of Maxon One, we&#...

17/05/2024

Takashi Yamazaki Film Godzilla Minus One Graded with DaVinci Resolve Studio

Takashi Yamazaki Film Godzilla Minus One Graded with DaVinci Resolve Studio Brie Clayton May 17, 2024 0 Comments Hero image credit: 2023 TOHO CO., LT...

17/05/2024

Sterling Event Group Streamlines Live Event Productions with AJA

Sterling Event Group Streamlines Live Event Productions with AJA Brie Clayton May 17, 2024 0 Comments Live event productions only happen once, which ...

17/05/2024

Meet the product manager

Muster Ngobi, product manager at LYNX Technik tells TVBEurope how the ever-evolving media industry provides a truly dynamic working environment By Matthew Corr...

17/05/2024

TV, Streaming Schedule for 2024 NFL Regular Season Is Released

NEW YORK As declines in linear TV viewing make the ongoing popularity of live sports, particularly football, central to financial success of the TV industry, th...

17/05/2024

Netflix Ad Tier Hits 40M Monthly Active Users

During Netflixs second Upfront presentation to advertisers, Amy Reinhard, Netflix's president of advertising, walked advertisers through the continued growt...

17/05/2024

Scripps Promotes Jeff Kiernan to VP, Local News

CINCINNATI The E.W. Scripps Company has added to its leadership team for news by promoting Jeff Kiernan a veteran journalist and general manager of Scripps'...

17/05/2024

Survey: New Disney-Fox-WBD Sports Streamer May Hurt Pay TV Sub Counts

Top executives from Disney, Fox and Warner Bros. Discovery have consistently insisted that their joint venture to launch the Venu Sports streaming bundle in the...

17/05/2024

Caitlin Clark's WNBA Debut Set Viewing Records

ESPN has announced that its coverage of Caitlin Clark's WNBA debut in the Indiana Fever versus the Connecticut Sun season opener was the most-watched WNBA g...

17/05/2024

ATEM Mini Extreme ISO switcher and Blackmagic Pocket Cinema Camera 4K

ATEM Mini Extreme ISO switcher and Blackmagic Pocket Cinema Camera 4K Brie Clayton May 16, 2024 0 Comments Blackmagic Design announced today that Yoic...

17/05/2024

Pixomondo's Virtual Production Academy Expands with Programs at Sony PCL, Vook, and Vancouver Film School

Pixomondo's Virtual Production Academy Expands with Programs at Sony PCL, Vo...

17/05/2024

WBD Upfront Show Offers Peeks at House of the Dragon,' White Lotus,' Biden-Trump Debate

The Warner Bros. Discovery upfront presentation took place Wednesday, May 15 at ...

17/05/2024

The Black Keys, Jelly Roll, Kate Hudson Set To Perform on The Voice' Finale

Season 25 of The Voice wraps on NBC Tuesday, May 21, with performances from The Black Keys, Jelly Roll, Kate Hudson, Lainey Wilson, Muni Long, Thomas Rhett and ...

17/05/2024

CNN Boss Mark Thompson's Plan Includes More News in More Categories on More Devices (Upfronts)

New CNN CEO Mark Thompson spelled out his plan for the struggling news network d...

17/05/2024

Netflix To Launch In-House Advertising Tech Platform

Netflix, a newcomer to the advertising business, said it plans to launch an in-house advertising technology platform....

17/05/2024

Netflix Plots TV Takeover at Upfront Presentation

Netflix shared some programming projects at an upfront presentation in New York. Those include the basketball-themed comedy series Running Point, a Mindy Kaling...

17/05/2024

Plex Geek Week Sale Offers 20% Off Plex Lifetime Pass

Plex is offering movie and music collectors a 20% discount off its Lifetime Plex Pass as part of its Geek Week sale....

17/05/2024

GroupM Names Toby Jenner as President, GroupM Clients

Giant media buyer GroupM said it named Toby Jenner as global president, Group M Clients, a new position at the company....

17/05/2024

Clients of Independent Agencies Boost Programmatic Buying

Smaller advertisers are increasingly buying connected TV programmatically, according to a new report from FreeWheel, Comcast's ad-tech unit....

17/05/2024

TCLtvPlus Adds Streaming Music Channels From Vevo

TCLtvPlus, the streaming app on smart TVs made by TCL, has added live linear channel from music-video programmer Vevo....

17/05/2024

StackAdapt Adopts Data From Samba TV for Programmatic Campaigns

StackAdapt said it made a deal to integrate data from Samba TV into its programmatic advertising platform....

17/05/2024

Tonight on House of Zwide: Dorothy is blown away by Ona's sketches for her wedding dress

Tonight on House of Zwide: Dorothy is blown away by Ona's sketches for her w...

17/05/2024

Tonight on Scandal: Dintle has a visit from her past that leaves her very unsettled

Tonight on Scandal: Dintle has a visit from her past that leaves her very unsett...

17/05/2024

Save Time and Money with WO Traffic v24.0

WO Traffic provides a solid foundation from which stations can manage, execute, and scale end-to-end ad trafficking and sales, both today and into the future. W...

17/05/2024

Broadcast Innovation in India: How AI and Automated Production Helps Smaller Sports Grow

Broadcast Innovation in India: How AI and Automated Production Helps Smaller Spo...

17/05/2024

SVG Sports Cloud Production Forum Gives Refresher Course on Cloud-Based Tools, Ecosystem

SVG Sports Cloud Production Forum Gives Refresher Course on Cloud-Based Tools, E...

17/05/2024

WNBA Tip-Off 2024: Scripps Sports Constructs New Studio for Second Season of WNBA Friday Night Spotlight on ION

WNBA Tip-Off 2024: Scripps Sports Constructs New Studio for Second Season of WNB...

17/05/2024

SVG College Summit 2024: Auburn's War Eagle Productions Breaks Down How They Produce Live Gymnastics Broadcasts

SVG College Summit 2024: Auburn's War Eagle Productions Breaks Down How They...

17/05/2024

Netflix & Shondaland Announce the Song List and Soundtrack for 'Bridgerton' Season 3: Part 1

Back to All News Netflix & Shondaland Announce the Song List and Soundtrack for...

17/05/2024

Skeem Saam: Thursday's episode, 16 May 2024 [video]

Skeem Saam: Thursday's episode, 16 May 2024 [video]Missed an episode of Skeem Saam? No problem! Watch the latest episode of your favourite South African soa...

17/05/2024

Prison Journalism: Letter to my mothers

Prison Journalism: Letter to my mothersThabo Mthembu was incarcerated in Pollsmoor Prison from 2014 to 2019. Read Thabo's story by Thabo Mthembu 17-05-20...

17/05/2024

Paul McCartney becomes UK's first billionaire musician

Paul McCartney becomes UK's first billionaire musicianMusic icon Paul McCartney has become the UK's first billionaire musician, according to the Sunday ...

17/05/2024

Tonight on Smoke and Mirrors: Sakhile advises Tiny against sabotaging Petunia

Tonight on Smoke and Mirrors: Sakhile advises Tiny against sabotaging PetuniaDon't miss Friday, 17 May's riveting episode of South African soapie Smoke ...

17/05/2024

RT'S Operation Transformation comes to a close after 17 seasons

RT has today announced that Operation Transformation (OT) is to end after 17 seasons. As series come to an end each year, RT undertakes an editorial review to...

17/05/2024

Studio One: Your Binaural Beats Lab

By Craig Anderton When I heard about binaural beats, I was interested-I like beats, and I'm into binaural audio. But this has nothing to do with either o...

17/05/2024

May 16, 2024

Scripps Research chemist Donna Blackmond elected to the Royal Society of the U.K. Blackmond's wide-ranging work has shaped origin of life theories, our unde...

16/05/2024

Power Provokes Vital Questions About the Role of Police

PARK CITY, UTAH - JANUARY 18: Director Yance Ford introduces the Power premiere at Library Center Theatre. (Photo by Chad Salvador/Shutterstock for Sundance F...

16/05/2024

Mental Health Matters: Embrace Self-Care With These Audiobook and Podcast Listens

May is Mental Health Awareness month, a time to recognize those living with ment...

16/05/2024

ABC and SBS bring digital radio (DAB+) services to the Gold Coast

ABC and SBS bring digital radio (DAB ) services to the Gold Coast 15 May, 2024 Media releases ABC and SBS today announced that audiences on the Gold Coast ...

16/05/2024

Clear-Com Communication Solutions Enhance Oregon State University's PRAx Building

eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({...