THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Saturday, January 08, 2022
Several cyberattack campaigns and cyber threat actors became household names as the impacts of cyberattacks were felt far beyond their target companies.
FREMONT, CA: Every year, specific dangers intensify quickly as hackers concentrate their efforts on an especially successful or profitable attack strategy, like ransomware or cryptojacking. However, the expansion of cybercrime, in general, was one of the most unsettling themes this year.
Cyberattacks as a whole climbed by 50 per cent compared to the previous year. However, several sectors—including education, research, and healthcare—were more severely impacted than others. This suggests that cyber threat actors are concentrating their efforts on regions that are relying on technology more and more and are less equipped to defend themselves from cyber threats.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The frequency and severity of attacks will only increase as cyber threat actors hone their methods and use automation, machine learning, and automation. Supply chain attacks have become more common and will be a significant concern in the following years. The SolarWinds hack's discovery set the pace for this development.
Threat actors introduced backdoor code into SolarWinds' Orion network monitoring product while compromising the development environment. An extensive investigation revealed the specifics of the SolarWinds hack, numerous malware variants, and an attack campaign that impacted over 18,000 public and private sector companies was launched by discovering the Sunburst malware.
A rise in supply chain attacks began with SolarWinds and persisted through 2022. Another highly visible supply chain vulnerability was the connections between managed service providers (MSPs) and customers to disseminate ransomware through MSPs' remote monitoring and management software. A few months later, the malware was placed on the PCs of anybody who downloaded and utilised the malicious version of a popular library (ua- parser.js) to a code modification made by an attacker with access to the npm account of the library.
While all of the supply chain hacks had a significant impact, exploiting the Log4j zero-day vulnerability is probably the most well-known. The widely-used Apache logging library Log4j contained a zero-day vulnerability that permitted remote code execution for an attacker accessing the log message's content or arguments. Supply chain issues have shown that they are a practical and possibly lucrative attack channel for cyber threat actors. In order to broaden the scope and impact of their attacks, cyber threat actors will probably use supply chain attacks more frequently.
More in News