ElevenPaths, Telefonica’s Cybersecurity Unit, recently released a new report that summarizes the latest cybersecurity insights from the second half of 2019 — covering everything from relevant incidents and vulnerabilities to cyber risk ratings by sector. The information presented is mostly based on the collection and synthesis of internal data that has been contrasted with public information from high-quality sources, including Bitsight Security Ratings.
In today’s ever-evolving cybersecurity landscape, understanding the latest threat actors and trends is critical to ensuring you have the right security performance management strategy in place. Here’s an overview of how the key findings from the report highlight that it’s more important than ever to regularly monitor and assess your cybersecurity program.
Understanding the cybersecurity landscape
During the second half of 2019, ransomware continued to be a key form of attack in the cybersecurity space. As ElevenPaths highlighted, this is likely due to the renewed strength of Emotet — a form of malware that proliferates within a network by brute force to obtain sensitive information.
As the ransomware threat continues to rise, various governmental figures are defining their response strategy. For example, during their annual meeting in July, the United States Conference of Mayors decided that ransomware demands should not be paid. This decision came in light of the fact that 170 governmental systems had been attacked since 2013.
Complex and selective attacks are on the rise
Magecart — a group of hackers that specializes in digital credit card theft — kept innovating their attacks on both minor and relevant websites over the latter half of 2019. The group changed its strategy slightly; in some cases, they redirected targets to a fake website to enter their credit card information. Thanks to its new formula (due to exploits in AWS buckets), Magecart has managed to infect an alarming 17,000 domains.
Another notable attack was that on WhatsApp, which experienced its second code execution issue for 2019. During the second half of the year, Facebook fixed a serious security flaw that allowed code execution on any platform running WhatsApp, simply by sending an MP4 file.