Sony Pixel Power calrec Sony

Cisco Midyear Security Report Highlights Weak Links in Increasingly Dynamic reat Landscape

08/05/2014

Cisco Midyear Security Report Highlights Weak Links in Increasingly Dynamic Threat Landscape Expanding Attack Surface Allows Attackers to Exploit Known Weaknesses within Low Risk Targets and Low Profile Legacy Applications and Infrastructure

Cisco CSO John N. Stewart Shares Top Insights from 2014 Cisco Midyear Security Report

LAS VEGAS, Aug. 5, 2014 The Cisco 2014 Midyear Security Report, released today at Black Hat U.S. (Cisco Booth #611), examines the weak links in organizations that contribute to the increasingly dynamic threat landscape. These weak links which could be outdated software, bad code, abandoned digital properties, or user errors contribute to the adversary's ability to exploit vulnerabilities with methods such as DNS queries, exploit kits, amplification attacks, point-of-sale (POS) system compromise, malvertising, ransomware, infiltration of encryption protocols, social engineering and life event spam.

The report also shows that focus on only high-profile vulnerabilities rather than on high-impact, common and stealthy threats puts these organizations at greater risk. By proliferating attacks against low-profile legacy applications and infrastructure with known weaknesses, malicious actors are able to escape detection as security teams focus instead on boldface vulnerabilities, such as Heartbleed.

Key Findings

Researchers closely examined 16 large multinational organizations, who, as of 2013, collectively controlled over $4 trillion in assets with revenues in excess of $300 billion. This analysis yielded three compelling security insights tying enterprises to malicious traffic:

Man-in-the-Browser attacks pose a risk for enterprises: Nearly 94 percent of customer networks observed in 2014 have been identified as having traffic going to websites that host malware. Specifically, issuing DNS requests for hostnames where the IP address to which the hostname resolves is reported to be associated with the distribution of Palevo, SpyEye, and Zeus malware families that incorporate man-in-the-browser (MiTB) functionality.

Botnet hide and seek: Nearly 70 percent of networks were identified as issuing DNS queries for Dynamic DNS Domains. This shows evidence of networks misused or compromised with botnets using DDNS to alter their IP address to avoid detection/blacklist. Few legitimate outbound connection attempts from enterprises would seek dynamic DNS domains apart from outbound C&C callbacks looking to disguise the location of their botnet.

Encrypting stolen data: Nearly 44 percent of customer networks observed in 2014 have been identified as issuing DNS requests for sites and domains with devices that provide encrypted channel services, used by malicious actors to cover their tracks by exfiltrating data using encrypted channels to avoid detection like VPN, SSH, SFTP, FTP, and FTPS.

The number of exploit kits has dropped by 87 percent since the alleged creator of the widely popular Blackhole exploit kit was arrested last year, according to Cisco security researchers. Several exploit kits observed in the first half of 2014 were trying to move in on territory once dominated by the Blackhole exploit kit, but a clear leader has yet to emerge.

Java continues its dubious distinction as the programming language most exploited by malicious actors. Cisco security researchers found that Java exploits rose to 93 percent of all indicators of compromise (IOCs) as of May 2014, following a high point of 91 percent of IOCs in November 2013 as reported in the Cisco 2014 Annual Security Report.

Unusual upticks in malware within vertical markets. For the first half of 2014, the pharmaceutical and chemical industry, a high-profit vertical, once again placed in the top three high-risk verticals for Web malware encounters. Media and publishing led the industry verticals posting nearly four times the median Web malware encounters, and aviation slid into third place with over twice the median Web malware encounters globally. The top most affected verticals by region were media and publishing in the Americas; food and beverage in EMEAR (Africa, Europe and the Middle East) and insurance in APJC (Asia-Pacific, China, Japan and India).

About the Report

The Cisco 2014 Midyear Security Report examines threat intelligence and cybersecurity trends for the first half of 2014 and was developed by security research experts who are part of the Cisco Collective Security Intelligence (CSI) ecosystem. Cisco CSI is shared across multiple security solutions and provides industry-leading security protections and efficacy. In addition to threat researchers, CSI is driven by intelligence infrastructure, product and service telemetry, public and private feeds and the open source community.

The Cisco CSI ecosystem includes the newly combined Talos Threat Intelligence and Research Group, which is a combined team from the previous Cisco Threat Research and Communications (TRAC) team, the Sourcefire Vulnerability Research Team (VRT) and Cisco Security Applications (SecApps) group. Talos' expertise spans software development, reverse engineering, vulnerability triage, malware investigation and intelligence gathering and maintains the official rule sets of Snort.org, ClamAV, SenderBase.org and SpamCop.

Supporting Quote

John N. Stewart, senior vice president, chief security officer, Cisco, said: Many companies are innovating their future using the Internet. To succeed in this rapidly emerging environment, executive leadership needs to embrace and manage, in business terms, the associated cyber risks. Analyzing and understanding weaknesses within the security chain rests largely upon the ability of individual organizations, and industry, to create awareness about cyber risk at the most senior levels, including Boards making cybersecurity a business process, not about technology. To cover the entir
LINK: http://newsroom.cisco.com/press-release-content?type=webcontent&articl...
See more stories from cisco

Most recent headlines

09/11/2025

Dalet Unveils Agentic AI Media Workflows at IBC2025

Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...

03/11/2025

How Will the FCC's Busy Fall Agenda Impact Broadcasters?

In less than two weeks during late September and early October, the Federal Communications Commission acted on two proposed rulemakings that could have an enorm...

03/11/2025

NAB's Josh Miely Named VP of Technology, Programming and Education

Josh Miely is returning to a more hands-on radio and TV role with the National Association of Broadcasters....

03/11/2025

All You Need to Know About MXL

Broadcasters have spent years trying to integrate different vendor technologies in their facilities. As the industry has moved closer to software, that struggle...

03/11/2025

The Battle to Protect Broadcast Content From AI Has Just Begun

As the malevolent siege against broadcasters' interests intensifies from the far reaches of artificial intelligence misuse to relentless innovation in the m...

03/11/2025

Gary Snow Plans to Retire From Wheatstone

Wheatstone founder and owner Gary Snow will retire from the company by the end of next year....

03/11/2025

Hybrid, AI Are Guiding the Measurement of TV Viewership

In ye olde days of traditional television, when U.S. TV viewing options were limited to ABC, CBS, NBC and PBS, Nielsen's paper diaries were sufficient for t...

03/11/2025

Brand New RT Documentary Series Tonight New RT Documentary Series Trackers: The People v The Banks

They've made that decision and ruined an awful lot of people's lives. ...

02/11/2025

Space42 Expands Earth Observation Constellation, Foresight, with Launch of Three New SAR Satellites

Abu Dhabi, UAE November 2, 2025: Space42 (ADX: SPACE42), the UAE-based AI-powe...

01/11/2025

Thunderbolt 3 and Symphony MkII

Thunderbolt 3 Now Standard on Symphony MkII - Starting November 11 Beginning November 11, all new Apogee Symphony I/O MkII units will ship with Thunderbolt 3 as...

01/11/2025

Expanding Symphony Desktop Using ADAT

How to Expand the Apogee Symphony Desktop with Cranborne 500ADAT Want to expand your Symphony Desktop beyond two inputs? Whether you're tracking a full drum...

01/11/2025

aconnic AG releases Half Year Financial Report 2025 and implements Change Measures

aconnic AG (ISIN: DE000A0LBKW6), Munich, has published the Financial Report for ...

01/11/2025

tvONE and Matrox Video Partner to Deliver Flawless AV-ove...

tvONE is proud to announce a strategic partnership with Matrox Video, combining CALICO PRO's high-performance video processing with the Matrox ConvertIP Ser...

01/11/2025

CJP Broadcast Joins Grass Valley Partner Programme to Str...

CJP Broadcast has joined the Grass Valley partner programme as both a Systems Integration Partner and AMPP Partner. The collaboration enhances CJP's ability...

01/11/2025

TAG Video Systems Earns Dual Recognition for ESG Initiati...

TAG Video Systems, the leader in software-based IP end-to-end workflow monitoring, deep probing, and real-time visualization, has earned a higher-rated DPP Comm...

01/11/2025

Operative Announces New CEO to Drive Next Phase of Growth

Michael Napodano Appointed New CEO Of Operative Media Operative today announced the appointment of Mike Napodano as Chief Executive Officer, marking the next s...

01/11/2025

Cine Gear Expo Atlanta 2025 Success at Trilith Studios

Film industry professionals flocked to Cine Gear Expo Atlanta 2025 at celebrated Trilith Studios in Fayetteville, Georgia, on October 3 and 4. Back for its 6th ...

01/11/2025

Christopher Ross BSC and 300 Asteras Light the Border Cro...

Photo courtesy of Peacock and Sky Christopher Ross, BSC, began his cinematic obsession early. He cites reading Scorsese on Scorsese as a teenager with teaching...

01/11/2025

ITN, Magnite Launch New Private Marketplace for Local Linear TV

NEW YORK ITN and the sell-side advertising company Magnite have announced the launch of what they are billing as the industrys first Local Linear TV Private Mar...

31/10/2025

FanDuel Sports Network To Deliver Selected Live NBA, NHL Games to Major Streaming Services for In-Market Viewers

FanDuel Sports Network To Deliver Selected Live NBA, NHL Games to Major Streamin...

31/10/2025

NBC Jumps Out of the Gate in Extended Breeder's Cup Deal With Dual Drones, Jockey Cams, RF Super-Mo

NBC Jumps Out of the Gate in Extended Breeder's Cup Deal With Dual Drones, J...

31/10/2025

Tribute: Remembering Segomotso Keorapetse (28 May 1968 22 October 2025)

FOR IMMEDIATE RELEASE 30 October 2025 It is with great sadness that we mourn the passing of Segomotso Keorapetse, an award- winning South African television d...

31/10/2025

Nexstar Extends Chairman and CEO Perry Sook Through 2029

IRVING, Texas As station groups move into an era that promises rapid tech, regulatory and economic changes, Nexstar Media Group said its board has extended chai...

31/10/2025

Late Night Thrives on Social Media With Billions of Views in 2025

While some analysts have questioned the ongoing economic viability of broacast-TV late night shows amid ongoing declines in linear viewing, new data from Tubula...

31/10/2025

Disney Programming Dropped From YouTube TV

The contentious contract negotiations between The Walt Disney Co. and YouTube TV have resulted in a blackout of Disney-owned programming on the pay TV operator....

31/10/2025

tvONE Integrates CALICO PRO Video Processing With Matrox ConvertIP Series

CINCINNATI Video conversion and AV signal distribution specialist tvONE and Matrox Video have struck a strategic partnership, combining CALICO PRO's video p...

31/10/2025

IAB Urges Standards for CTV Ad Measurement

NEW YORK The Interactive Advertising Bureau (IAB) today released a new industry guide that discusses the urgency of adopting new standards that will help advert...

31/10/2025

Late Night Shows Thrive on Social Media with Billions of Views in 2025

While some analysts have questioned the ongoing economic viability of late night shows on broadcast TV amid ongoing declines in linear viewing, new data from Tu...

31/10/2025

Berklee Celebrates the Inauguration of President Jim Lucchese

Berklee Celebrates the Inauguration of President Jim Lucchese In his inaugural address, Lucchese shared an optimistic vision for Berklee's future as a for...

31/10/2025

Family, Food, and Films: Netflix's 'Dining with the Kapoors' Arrives November 21

Back to All News Family, Food, and Films: Netflix's Dining with the Kapoors...

31/10/2025

DPA 4055 Featured in Technologies for Worship Magazine

The review highlights DPA 4055 Kick Drum Microphone for its compact design, ease of placement, and authentic tone that captures the true character of the drum p...

31/10/2025

RT Raidi na Gaeltachta Award 2025 to be presented to Piln N Chiarin

The RT Raidi na Gaeltachta Award 2025 will be presented to journalist P il n N Chiar in at the Oireachtas na Samhna in Belfast tomorrow, Saturday 1 November,...

31/10/2025

Share the magic: RT lyric fm Choirs for Christmas Competition 2025 open for submissions

RT lyric fm is calling for choirs across Ireland to share their festive music-m...

31/10/2025

Dnall Mac Ruair, Cuan Seireadin and Ts ite among the winners at the Oireachtas Communications Awards 2025

Three awards were presented to RT Raidi na Gaeltachta broadcasters at the Oire...

31/10/2025

RT is Supporting 29 Arts and Cultural Events across Ireland this November

RT continues its proud tradition of championing Ireland's vibrant arts and cultural landscape through its RT Supporting the Arts initiative. This November...

31/10/2025

RT selects Irish independent production company to produce Christian Worship on RT One and RT Player

RT selects Irish independent production company to produce Christian Worship on...

31/10/2025

Korea Joins AI Industrial Revolution: NVIDIA CEO Jensen Huang Unveils Historic Partnership at APEC Summit

Amidst Gyeongju, South Korea's ancient temples and modern skylines, Jensen H...

30/10/2025

Midwich Secures UK & Ireland Distribution Deal with X2O Media To Revolutionize Hybrid Learning

Midwich has signed a UK and Ireland distribution deal with X2O Media, a worldwid...

30/10/2025

SVG Students To Watch: Sam Newitt, Kansas State University

SVG Students To Watch: Sam Newitt, Kansas State UniversityThe South Dakota native thrives in many roles behind the scenes at K-StateHD.TVBy Brandon Costa, Direc...

30/10/2025

SVG Sit-Down: Swerve Sports' Christy Tanner Explores the Young FAST Channel's Early Success

SVG Sit-Down: Swerve Sports' Christy Tanner Explores the Young FAST Channel&...

30/10/2025

SVG Campus Shot Callers: Andy Liebsch, Senior Director, Video Services, Kansas State University

SVG Campus Shot Callers: Andy Liebsch, Senior Director, Video Services, Kansas S...

30/10/2025

Diversified Names Paul Lidsky CEO, Expanding Leadership Role After Serving as Board Chairman

Diversified Names Paul Lidsky CEO, Expanding Leadership Role After Serving as Bo...

30/10/2025

NBA, Cosm Enter Long-Term Partnership for Shared Reality Production, Distribution

NBA, Cosm Enter Long-Term Partnership for Shared Reality Production, Distributio...

30/10/2025

FanDuel Sports Network to Deliver Select Live NBA, NHL Games to Major Streaming Services for In-Market Viewers

FanDuel Sports Network to Deliver Select Live NBA, NHL Games to Major Streaming ...

30/10/2025

If I Had Legs, I'd Kick You, East of Wall, and More Sundance Institute-Supported Films Nominated for 35th Gotham Awards

As the year comes to a close, we can feel the invigorating wind sweeping in for ...

30/10/2025

Give Me the Backstory: Get to Know Max Walker-Silverman, the Writer-Director of Rebuilding

By Bailey Pennick One of the most exciting things about the Sundance Film Festi...

30/10/2025

Excellent training at SGL Carbon's Bonn site

The SGL Carbon site in Bonn has a long tradition of training. For many years, young talent has been successfully trained here, regularly achieving excellent exa...

30/10/2025

SBS, NITV and Screen Australia announce 2025 Digital Originals Shortlist

SBS, NITV and Screen Australia announce 2025 Digital Originals Shortlist 29 October, 2025 Media releases SBS, NITV and Screen Australia are excited to unve...

30/10/2025

Remarks for the 2025 APEC CEO Roundtable

Jon Rambeau, President of Integrated Mission Systems at L3Harris Technologies, speaks about industrial collaboration at the Asia-Pacific Economic Cooperation (A...