THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Monday, July 31, 2023
WatchGuard Technologies unveils report on cybersecurity threat landscape, focusing on new malware, network and endpoint security, living-off-the-land attacks, and phishing trends.
FREMONT, CA: "Organizations need to pay more active, ongoing attention to the existing security solutions and strategies their businesses rely on to stay protected against increasingly sophisticated threats," said Corey Nachreiner, chief security officer at WatchGuard. "The top themes and corresponding best practices our Threat Lab have outlined for this report strongly emphasize layered malware defenses to combat living-off-the-land attacks, which can be done simply and effectively with a platform for unified security run by dedicated managed service providers."
One of the leaders in unified cybersecurity, WatchGuard Technologies, reveals its Internet Security Report findings on malware and network and endpoint security threats. According to WatchGuard's findings, cyber attacks largely take the form of phishing attacks that undertake browser-based social engineering strategies. The report also observes that new malware attacks target nation-states, high amounts of zero-day malware, increasing living-off-the-land attacks, and more.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The cybersecurity landscape in the first quarter of 2023 has witnessed several emerging trends and concerning developments. Attackers adapt to enhanced browser protections by exploiting browser notification features, shifting their focus from pop-up abuse to targeting browser notification features. Another noteworthy addition to the list of malicious domains is a new destination engaging in SEO-poisoning activities.
China and Russia are responsible for 75 percent of all new threats on WatchGuard's top ten malware list. Three of the four new threats it discovered have strong links to nation-states, even though this does not necessarily mean they are state-sponsored.
Document-based threats targeting Office products persist as a widespread malware concern. Surprisingly, there have also been many exploits against the End-of-Life Microsoft ISA Firewall, a discontinued and unsupported product.
Living-off-the-land attacks are rising, with malware like ViperSoftX leveraging built-in tools within operating systems to achieve their objectives. This underscores the need for robust endpoint protection to distinguish between legitimate and malicious use of popular tools such as PowerShell.
Linux-based systems have not been spared, as evidenced by the detection a malware dropper specifically aimed at them. Organizations must not overlook non-Windows machines like Linux and macOS when implementing Endpoint Detection and Response (EDR) solutions.
Zero-day malware poses a significant threat, accounting for most encrypted and unencrypted web traffic detections. Robust host-based defenses, like WatchGuard EPDR, are essential to counter these sophisticated attacks.
On ransomware, the Threat Lab identified 852 victims published on extortion sites and discovered 51 new variants. Some of the victims belong to renowned organizations in the Fortune 500. Continued tracking and analysis of ransomware trends will be integral to WatchGuard's quarterly Threat Lab research.
More in News