Sony Pixel Power calrec Sony

Cisco Midyear Security Report Highlights Weak Links in Increasingly Dynamic reat Landscape

08/05/2014

Cisco Midyear Security Report Highlights Weak Links in Increasingly Dynamic Threat Landscape Expanding Attack Surface Allows Attackers to Exploit Known Weaknesses within Low Risk Targets and Low Profile Legacy Applications and Infrastructure

Cisco CSO John N. Stewart Shares Top Insights from 2014 Cisco Midyear Security Report

LAS VEGAS, Aug. 5, 2014 The Cisco 2014 Midyear Security Report, released today at Black Hat U.S. (Cisco Booth #611), examines the weak links in organizations that contribute to the increasingly dynamic threat landscape. These weak links which could be outdated software, bad code, abandoned digital properties, or user errors contribute to the adversary's ability to exploit vulnerabilities with methods such as DNS queries, exploit kits, amplification attacks, point-of-sale (POS) system compromise, malvertising, ransomware, infiltration of encryption protocols, social engineering and life event spam.

The report also shows that focus on only high-profile vulnerabilities rather than on high-impact, common and stealthy threats puts these organizations at greater risk. By proliferating attacks against low-profile legacy applications and infrastructure with known weaknesses, malicious actors are able to escape detection as security teams focus instead on boldface vulnerabilities, such as Heartbleed.

Key Findings

Researchers closely examined 16 large multinational organizations, who, as of 2013, collectively controlled over $4 trillion in assets with revenues in excess of $300 billion. This analysis yielded three compelling security insights tying enterprises to malicious traffic:

Man-in-the-Browser attacks pose a risk for enterprises: Nearly 94 percent of customer networks observed in 2014 have been identified as having traffic going to websites that host malware. Specifically, issuing DNS requests for hostnames where the IP address to which the hostname resolves is reported to be associated with the distribution of Palevo, SpyEye, and Zeus malware families that incorporate man-in-the-browser (MiTB) functionality.

Botnet hide and seek: Nearly 70 percent of networks were identified as issuing DNS queries for Dynamic DNS Domains. This shows evidence of networks misused or compromised with botnets using DDNS to alter their IP address to avoid detection/blacklist. Few legitimate outbound connection attempts from enterprises would seek dynamic DNS domains apart from outbound C&C callbacks looking to disguise the location of their botnet.

Encrypting stolen data: Nearly 44 percent of customer networks observed in 2014 have been identified as issuing DNS requests for sites and domains with devices that provide encrypted channel services, used by malicious actors to cover their tracks by exfiltrating data using encrypted channels to avoid detection like VPN, SSH, SFTP, FTP, and FTPS.

The number of exploit kits has dropped by 87 percent since the alleged creator of the widely popular Blackhole exploit kit was arrested last year, according to Cisco security researchers. Several exploit kits observed in the first half of 2014 were trying to move in on territory once dominated by the Blackhole exploit kit, but a clear leader has yet to emerge.

Java continues its dubious distinction as the programming language most exploited by malicious actors. Cisco security researchers found that Java exploits rose to 93 percent of all indicators of compromise (IOCs) as of May 2014, following a high point of 91 percent of IOCs in November 2013 as reported in the Cisco 2014 Annual Security Report.

Unusual upticks in malware within vertical markets. For the first half of 2014, the pharmaceutical and chemical industry, a high-profit vertical, once again placed in the top three high-risk verticals for Web malware encounters. Media and publishing led the industry verticals posting nearly four times the median Web malware encounters, and aviation slid into third place with over twice the median Web malware encounters globally. The top most affected verticals by region were media and publishing in the Americas; food and beverage in EMEAR (Africa, Europe and the Middle East) and insurance in APJC (Asia-Pacific, China, Japan and India).

About the Report

The Cisco 2014 Midyear Security Report examines threat intelligence and cybersecurity trends for the first half of 2014 and was developed by security research experts who are part of the Cisco Collective Security Intelligence (CSI) ecosystem. Cisco CSI is shared across multiple security solutions and provides industry-leading security protections and efficacy. In addition to threat researchers, CSI is driven by intelligence infrastructure, product and service telemetry, public and private feeds and the open source community.

The Cisco CSI ecosystem includes the newly combined Talos Threat Intelligence and Research Group, which is a combined team from the previous Cisco Threat Research and Communications (TRAC) team, the Sourcefire Vulnerability Research Team (VRT) and Cisco Security Applications (SecApps) group. Talos' expertise spans software development, reverse engineering, vulnerability triage, malware investigation and intelligence gathering and maintains the official rule sets of Snort.org, ClamAV, SenderBase.org and SpamCop.

Supporting Quote

John N. Stewart, senior vice president, chief security officer, Cisco, said: Many companies are innovating their future using the Internet. To succeed in this rapidly emerging environment, executive leadership needs to embrace and manage, in business terms, the associated cyber risks. Analyzing and understanding weaknesses within the security chain rests largely upon the ability of individual organizations, and industry, to create awareness about cyber risk at the most senior levels, including Boards making cybersecurity a business process, not about technology. To cover the entir
LINK: http://newsroom.cisco.com/press-release-content?type=webcontent&articl...
See more stories from cisco

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

03/03/2026

LIV Golf, Beyond Sports Elevate Online Gaming Ecosystem with Launch of LIV Golf Fantasy and LIV X

Beyond Sports, a Sony group company, and LIV Golf, the world's golf league, ...

03/03/2026

Ilitch Sports + Entertainment Announces Launch of Detroit SportsNet

Ilitch Sports + Entertainment announces the launch of Detroit SportsNet (DSN), a year-round broadcast home for two of Detroit's franchises. With flexible op...

03/03/2026

Advanced Systems Group Promotes Gretchen Taipale to Vice President, Managed Services

Advanced Systems Group, LLC (ASG), a technology and services provider for media ...

03/03/2026

PGA of America, NBC Sports, and USA Sports Extend Media Rights Agreement Through 2033

The PGA of America, NBC Sports and USA Sports extend their media rights agreemen...

03/03/2026

HONOR, ARRI Announce Technical Collaboration to Bring ARRI Image Science into Next-Gen Consumer Devices

AI device ecosystem company HONOR enters into a strategic technical collaboratio...

03/03/2026

Telos Alliance Partners with College Radio Foundation to Support College Broadcasters

Cleveland's Telos Alliance, pioneers in broadcast technology for 30 years, l...

03/03/2026

Sennheiser Relaunches MD 9235 Wireless Mic Head

The MD 9235 microphone head for wireless handhelds has been a firm favorite with many engineers and artists for its ability to cut through high on-stage levels ...

03/03/2026

Haivision to Showcase Private 5G and Live Video Contribution Innovations at MWC 2026

Haivision Systems Inc. (Haivision), a global provider of mission-critical, real-...

03/03/2026

BMG Expands Washington Broadcast Center with 3 New TV Studios and Podcast Studio for Media Clients

Broadcast Management Group (BMG) announces the expansion of its 62,000-square-fo...

03/03/2026

Closing the Loop: Maroon 5 and the End of the Analog Era

Maroon 5's musical tour in 2025 marked a leap forward in live audio as Monitor Engineer Dave Rupsch utilized Sennheiser's all-digital Spectera wireless ...

03/03/2026

SVG in Indy: Pacers Sports & Entertainment Finds Production Sweet Spot in ST 2110-Based Control Center

Designed specifically for pro basketball, the renovated space at Gainbridge Fiel...

03/03/2026

Lawo Appoints Jamie Dunn CEO

As part of the move, former CEO Phillipp Lawo joins the broadcast-tech provider's Supervisory Board Lawo has announced appointment of Jamie Dunn as chief e...

03/03/2026

NBC Turns Back the Clock to 1990s for NBA Coast 2 Coast' Tuesday

A team of legendary announcers and analysts and a classic graphics look will bring the past to life NBC Sports and Peacock will return to yesteryear for tonigh...

03/03/2026

Sundance Film Festival: CDMX 2026 Returns for Its Third Edition

From April 30 to May 3, Sundance Film Festival: CDMX 2026 will offer a selection of exciting independent cinema. Mexico City, March 3, 2026 - At a moment of he...

03/03/2026

How Multi-Format Readers' Are Redefining Reading in the UK's National Year of Reading

For many, finding time or headspace to pick up a book can feel out of reach, but...

03/03/2026

Rohde & Schwarz and Realtek demonstrate first test solution for Bluetooth LE High Data Throughput (HDT)

Rohde & Schwarz and Realtek demonstrate first test solution for Bluetooth LE Hi...

03/03/2026

Sediba Scriptwriting Training Programme - Matatiele (Eastern Cape)

The National Film and Video Foundation (NFVF) invites aspiring and emerging filmmakers from Matatiele and surrounding areas to apply for the Sediba Scriptwritin...

03/03/2026

Clear-Com Supplies Cloud-based Communications System for SaxaVord Spaceport

eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({ content_source:......

03/03/2026

Magellan AI Integrates Nielsen DMA Data to Bring Local Market Measurement to Podcast Attribution

Nielsen's DMA data gives Magellan AI users a standardized way to measure th...

03/03/2026

Lawo Promotes Jamie Dunn to CEO

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Elements To Showcase Newly Unveiled GRID NAS Platform At 2026 NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Moments Lab To Feature Agentic AI For Video Workflows At 2026 NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Marshall Electronics Launches Compact CV356-10X Full HD C...

Marshall Electronics premieres the CV356-10X, its latest compact 10X camera that offers Full HD with simultaneous SDI and HDMI outputs, at NAB 2026 (Booth C8339...

03/03/2026

farmerswife and Cirkus to Showcase Smarter Media Workflow...

farmerswife, the industry-leading enterprise operations platform for broadcast and post-production, today announced it will exhibit at NAB Show 2026 in Las Vega...

03/03/2026

Manfrotto ONE Hybrid Tripod Wins iF Design Award 2026

Manfrotto has announced that the Manfrotto ONE Hybrid tripod has won the iF DESIGN AWARD 2026, one of the world's most respected design honours. Selected ...

03/03/2026

DHD to Introduce Latest Generation Broadcast Audio Mixers...

DHD is expanding the capabilities of its DX2, RX2, SX2 and TX2 broadcast audio mixers, RM1 portable production unit and XC3/XD3/XS2 processing cores with the in...

03/03/2026

Synamedia and MoMe launch first streaming CDN in Spain

Leading video software provider Synamedia and MoMe, a leading Spanish consultancy and systems integrator, today announced the launch of Spain's first stream...

03/03/2026

Long-Awaited ATSC 3.0 Rulemaking Overshadows NAB Show Expectations

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Audio Tech at NAB Show: Are We in the Second Wave' of IP?

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

IP's Impact on Imaging Tech on Full Display at NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Live Production Over IP in 2026: Software-Defined Everything

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

NAB Show Leverages Revitalized LVCC To Reflect M&E Transformation

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Home Post Production Strengthens Factual and Natural Hist...

Home Post Production has further expanded its factual, unscripted, and entertainment capabilities with the acquisition of Picture Shop Bristol, a leading post h...

03/03/2026

Full Year 2025 Results

Luxembourg, 2 March 2026 -- SES S.A. fully consolidates Intelsat from 17 July 2025 and announces financial results for the year ended 31 December 2025 FY25 Pe...

03/03/2026

Iyuno Taps Dante AV to Sync Audio and Video Content

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

HBO Max and Paramount+ Streamers to Merge

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Survey: 70% of CTV Advertisers Plan to Boost Spending in 2026

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

XGN Global, X1 Mobile Show New 5G Broadcast Smartphone

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Scripps Completes Sale of WFTX to Sun Broadcasting

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

HbbTV Association Formally Integrates DRM into Core Specification

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

VEON and MeetKai Expand Collaboration to Explore Sovereign AI Infrastructure Partnerships

03 Mar 2026 VEON and MeetKai Expand Collaboration to Explore Sovereign AI Infra...

03/03/2026

Ryan Reynolds and Rob Mac land first ever live commentary gig exclusively on Sky Sports for Wrexham vs Swansea

Tuesday 3 March 2026 Ryan Reynolds and Rob Mac land first ever live commentary ...

03/03/2026

The Dyers Caravan Park reopens for a second season after a hit launch on Sky

Tuesday 3 March 2026 The Dyers' Caravan Park reopens for a second season after a hit launch on Sky The Dyers' Caravan Park JPEG (510KB) Sky books a ...

03/03/2026

Kai Ko and Wang Po-chieh Unleash Divine Glory in Electrifying Agent from Above' Teaser

Back to All News Kai Ko and Wang Po-chieh Unleash Divine Glory in Electrifying ...