‏إظهار الرسائل ذات التسميات Internet Security. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Internet Security. إظهار كافة الرسائل

Cloudflare Launches Precursor, a First Privacy-First Defense Platform Against Bad Bots

Cloudflare Launches Precursor, a First Privacy-First Defense Platform Against Bad Bots
  • Built on one of the world’s largest networks, Precursor is the only defense of its kind to replace disruptive checkpoints to stop evasive bots without slowing down users
Cloudflare, Inc. (NYSE: NET), the leading connectivity cloud company, today announced the general availability of Precursor, a next-generation, continuous behavioral validation engine for bot management. Built directly on Cloudflare’s edge, Precursor runs seamlessly inside web browsers to monitor entire user sessions in order to detect bot automation. Unlike traditional, static CAPTCHAs, it analyzes ongoing interactions in real time to catch advanced bots, improving detection precision without interrupting legitimate users.


For the first time, automated bot traffic has eclipsed human activity on the Internet, now generating roughly 57% of all web requests. This milestone emphasizes a seismic evolution from an Internet built for human clicks to a digital landscape now dominated by AI agents. For organizations and everyday consumers, this means that legacy defenses are blind to a new breed of automated threats that drive up infrastructure costs, manipulate inventory, and compromise data. While a modern bot can easily fake a single action to pass a one-time security check, replicating an entire human journey remains a massive engineering hurdle. To protect the integrity of the global Internet, organizations must move away from static, point-in-time defenses and embrace continuous behavioral validation - analyzing telemetry across an entire session to unmask automated imposters trying to blend into the crowd.

"Traditional security checks look at a single moment in time, but modern bots have gotten smart enough to fake their way through the front door," said Dane Knecht, CTO of Cloudflare. "Instead of just checking an ID at the gate, we are looking at behavior over the entire visit. This makes life seamless for real users, while making it incredibly difficult and expensive for bad actors to fake human behavior. Cloudflare already protects users billions of times a day at critical moments like login and checkout, but until now, the space between those moments was a black box. With Precursor, we’re now eliminating that blindspot."

Now generally available, Precursor provides a session-level view of site activity by continuously collecting robust browser signals to block unwanted automated traffic through:
  • Privacy-Led Defense: Built to protect end user confidentiality, Precursor logs aggregate behavioral patterns rather than recording specific user inputs. For example, keyboard activity is recorded exclusively as timing rhythm and cadence - never capturing actual keystrokes.
  • Zero-Code, One-Click Setup: Precursor is enabled with one click, automatically allowing Cloudflare to inject a compact, dynamic script passing through the network, requiring no modifications to underlying code. The script evaluates interaction trail dimensions such as mouse movement, scrolling rhythm, typing cadence, clipboard activity, and page visibility duration.
  • A Real-Time Analysis Engine: Cloudflare's servers instantly unpack the telemetry data sent from a user's browser and scan it for signs of faked or computer-generated activity. We then validate whether interaction streams map rationally to human behavior, such as cross-referencing that pointer activity aligns with page visibility or text fields are focused during typing events.
  • Session-Long Security Measures: Unlike traditional defense challenges that reset per every request, Precursor continuously evaluates the visitor’s user journey across a web or single page application. Automated agents cannot reset their behavioral signatures by refreshing a page, allowing defensive algorithms to adjust a session's Bot Score with compounding context.
To learn more, please check out the resources below:

Blog: Introducing Precursor: detecting agentic behavior with continuous client-side signals


Cloudflare Precursor

About Cloudflare

Cloudflare, Inc. (NYSE: NET) is the leading connectivity cloud company. It empowers organizations to make their employees, applications and networks faster and more secure everywhere, while reducing complexity and cost. Cloudflare’s connectivity cloud delivers the most full-featured, unified platform of cloud-native products and developer tools, so any organization can gain the control they need to work, develop, and accelerate their business.

Powered by one of the world’s largest and most interconnected networks, Cloudflare blocks billions of threats online for its customers every day. It is trusted by millions of organizations – from the largest brands to entrepreneurs and small businesses to nonprofits, humanitarian groups, and governments across the globe.

Learn more about Cloudflare’s connectivity cloud at cloudflare.com/connectivity-cloud. Learn more about the latest Internet trends and insights at radar.cloudflare.com.

Deloitte UK Reportedly Cyberattacked for 1 TB of Sensitive Data by Ransomware Group

Deloitte UK Reportedly Cyberattacked for 1 TB of Sensitive Data by Ransomware Group

The Brain Cipher Ransomware group has reportedly claimed responsibility for a significant cyberattack on Deloitte UK, alleging that they have exfiltrated over 1 terabyte of data. This breach, if confirmed, could have serious implications for Deloitte's clients and its professional reputation.

However, Deloitte has not confirmed the breach, leaving the claim unverified.

The group claims to have accessed and stolen over 1 terabyte of compressed data, including sensitive client information and internal documents.

According to statements posted by Brain Cipher, the attack has exposed critical vulnerabilities in Deloitte UK’s cybersecurity infrastructure. “Soon we will tell you about this incident. We will provide an example of data that has leaked. The volume of compressed data more than 1tb".

The group has criticized Deloitte for not observing basic information security protocols. "Unfortunately, giant companies do not always do their job well,” the hackers claim.

Brain Cipher emerged in June 2024 and has quickly gained notoriety for targeting high-profile organizations.

Brain Cipher has set a deadline of December 15, 2024, for Deloitte to respond, after which they threaten to release the stolen data.

The impact of this breach could be severe when it comes to client data exposure. Potential exposure of sensitive client information, including financial records, could be affected. Reputational Damage of the "big four" firm is also at stake. As one of the world's leading professional services firms, Deloitte's stature is at stake as it is raising serious concerns about data protection practices.

The breach, if confirmed, could disrupt operations for Deloitte and its clients, eroding trust and confidence.

Deloitte has yet to confirm the incident publicly. This situation underscores the critical need for robust cybersecurity measures in today's digital landscape.

Juice Jacking: A New Cyber Stealing that Empties Bank Account When Smartphones Connect To Charging, RBI Warns

Juice Jacking: A New Cyber Stealing that Empties Bank Account When Smartphones Connect To Charging, RBI Warns

You may have hardly noticed this, but today big-fatvhackers around the world are stealing people's confidential data by planting 'malware' in public cables or USB ports. This is called 'Juice Jacking'.

Cyber ​​thieves are adopting new tactics every day. Some are cheating people by sending messages on WhatsApp, while some are cheating by sending YouTube video links to like. Juice Jacking is also a type of scam about which very few people know. Many of you may already know about it and many may not know, but this juice jacking can destroy your entire life's earnings in a jiffy. India's central bank, Reserve Bank of India (RBI) has issued a warning regarding this.

Let us know what is juice jacking and what is the way to avoid it?

Juice jacking is a type of cyber stealing, where, once your mobile is connected to unknown / unverified charging ports, unknown apps / malware are installed with which, the fraudsters can control / access / steal sensitive data, email, SMS, saved passwords.

Precaution —

Always avoid using public/ unknown charging ports/cables.

When battery of your mobile, tablet or laptop runout at times when you're at public place like a railway station, airport or hotel, and you may start charging the device with the charging cable or USB port you see there, but have you thought that the battery of the device gets charged? Your bank account could be empty or your private messages, emails, mobile passwords or other information could be stolen.

Steps To Follow To Avoid Juice Jacking
  • Never use the pre-installed charging cable in train, airplane or at station-hotels.
  • Don't use the charging cable or port that you get as a promotional gift.
  • Use the original charger and cable that came with your phone.
  • If you are traveling then keep a power bank with you.
  • Use an adapter instead of using the USB port at a charging station.
  • Do not charge phone or any other Gadgets using USB port at hotels. 

Cybercriminals Using 15-year-old Tactics to Target Overlooked Gaps in Security

Cybercriminals Using 15-year-old Tactics to Target Overlooked Gaps in Security
Cybercriminals Exploit Outdated Security Flaws Warns Barracuda

Experts state that cybercriminals are using 15-year-old tactics to target overlooked gaps in security

Barracuda, a trusted partner and leading provider of cloud-first security solutions, has released a Threat Spotlight revealing that cyber attackers are relying on outdated tactics and overlooked security weaknesses to target organizations. These attackers aim to gain remote control of systems, install malware, steal information, disrupt business operations through denial-of-service attacks, and more.

The findings are based on an analysis of three months’ worth of detection data from the Intrusion Detection Systems (IDS) used by Barracuda’s Security Operations Center (SOC), part of Barracuda XDR. The IDS tools provide not just a powerful early warning system of potential attack – they also reveal the weaknesses that attackers are targeting and the most popular tactics they are using to do so.

Top malicious tactics detected by Barracuda's firewall IDS integration
Top malicious tactics detected by Barracuda's firewall IDS integration

Top suspicious network detections detected by Barracuda's IDS tool (in millions)
Top suspicious network detections detected by Barracuda's IDS tool (in millions)

The analysis of the detection data highlights several key points, including:
  • Attackers try to gain remote control of vulnerable systems by using a tactic from 2008 that would let them take advantage of a misconfigured web server to get to data such as application code or sensitive operating system files that they should not have access to.
  • Another tactic designed to achieve the goal of remote-control dates from 2003 and involves trying to inject specially crafted malicious code into a legitimate process which would allow the attacker to read sensitive data, modify operations, and send instructions to the operating system.
  • Other established tactics target bugs in the programming languages that developers use to create applications which are integrated into common web-based systems or into “middleware” that processes data, such as when someone adds an item to their online shopping cart. The potential reach of a successful attack using these tactics is therefore extensive.
  • Attackers try to get hold of sensitive information by targeting vulnerable servers to obtain passwords or lists of users, or by misusing a legitimate process to find out how many computers on a network have an active IP connection. This can help with planning and preparing for a bigger attack.
  • Attackers are also trying to cause general chaos, disruption, and denial of service by messing with online traffic data packets, making them too small or fragmenting them so that the communications channels and destination servers become overwhelmed and crash.
"Security weaknesses do not have an expiration date, and over time they can become deeply embedded, shadow vulnerabilities within a system or application. The tactics used to exploit them do not necessarily have to be new or sophisticated to succeed," emphasized Merium Khalid, Senior SOC Manager, Offensive Security, Barracuda XDR. "A multi-layered approach to protection with multiple levels of detection and scrutiny is essential. Understanding the vulnerabilities present in your IT environment, who may target them, and how they do so is crucial, as is the ability to respond and mitigate these threats."

To learn more about the prevalent attack tactics and targets check out the blog here.

About Barracuda  

At Barracuda we strive to make the world a safer place. We believe every business deserves access to cloud-first, enterprise-grade security solutions that are easy to buy, deploy, and use. We protect email, networks, data, and applications with innovative solutions that grow and adapt with our customers’ journey. More than 200,000 organizations worldwide trust Barracuda to protect them — in ways they may not even know they are at risk — so they can focus on taking their business to the next level. For more information, visit barracuda.com.  

Barracuda Networks, Barracuda and the Barracuda Networks logo are registered trademarks or trademarks of Barracuda Networks, Inc. in the U.S., and other countries.

Cyber Attack on Madhya Pradesh Power Management Co.'s Servers

Cyber Attack on Madhya Pradesh Power Management Co.'s Servers

The power management company in Jabalpur, Madhya Pradesh has been stalled for the last several days. The IT cell of the power management company has filed a complaint in Gorakhpur police station of Jabalpur, considering this problem as a cyber attack.

Cyber attack occurred on the server of MP Power Management Company, which caused the internet to go down in the company's office that made PMC unable to function. The company's account is also threatened. Apart from this, information about buying and selling electricity is also expected to be leaked.

For last 4 days, the company's IT cell has been involved in locating the cyber attack, but has no any firm information on its hand.

Ironically, in September last year Madhya Pradesh become the first state of the country to implement cyber crisis management plan developed by M.P. state load dispatch centre Jabalpur. Notably, Cyber Crisis Management Plan was developed in-house without taking the help of expert consultants and implemented after approval by Computer Emergency Response Team (CERT-India), a government organization that responds to computer security incidents and promotes IT security practices and functions under the Ministry of Electronics & Information Technology

MP Power Management Company is the most important company in Madhya Pradesh's power system, and it takes care of when, where and how much electricity the state needs and where it will be completed.

With electricity, there is a big drawback that it cannot be stored, so electricity has to be supplied at the same time when it is produced. The information on the availability of electricity at different power generation plants across the country are being tracked on the computers of the power management companies, through the Internet. The power management company buys electricity from companies with which it has power agreements.

Earlier officials of the power management company did the investigation, but the internet system was not able to improve. It was then understood that this is not a general technical flaw, but something else has damaged the MP Power Management Company's system. Although no virus or message like previous cyber attacks is displayed to the computer of a power management company, it has been considered a cyber attack.

Madhya Pradesh has a capacity to generate about 6000 MW of electricity and many a times some electricity remain unused by the state so it is then sold to other states. This entire process of buying & selling electricity is done on computer through internet and this buy-sale transactions are worth billions of rupees, But the computer system that has been installed for such an important and extremely important business.

Reportedly, the MP power management company did not take care of security of computer systems and using cyber security solutions like domestic computers. When when the internet stopped providing services, the PMC authorities did not consider it a cyber-attack. The PMC personnels however are not at fault because they are not trained enough in the field of Cybersecurity.

According to an PMC official, the company's servers are unable to do any work due to disturbances. All work from human resources is being affected. Only the IT department can provide information about technical malfunction in the server.


Cyber Attackers Double Down on Social Engineering Techniques and Malicious Functionalities Leading to Sharp Increase in Malware Downloads

Cyber Attackers Double Down on Social Engineering Techniques and Malicious Functionalities Leading to Sharp Increase in Malware Downloads
Netskope: Attackers Double Down on Social Engineering Techniques and Malicious Functionalities Leading to Sharp Increase in Malware Downloads

Researchers Find Attackers Are Successfully Evading Detection By Blending in with Normal Network Traffic Via HTTP and HTTPS

Netskope, a leader in Secure Access Service Edge (SASE), today unveiled new research confirming that attackers are finding new ways to evade detection and blend in with normal network traffic using HTTP and HTTPS to deliver malware. In its latest Cloud & Threat Report: Global Cloud and Web Malware Trends, Netskope identified that on average, five out of every 1,000 enterprise users attempted to download malware in Q1 2023, and new malware families and variants represented 72% of those malware downloads.

Social Engineering and Search Engine Data Voids on the Rise

In the research, Netskope uncovered that nearly 10% of all malware downloads in Q1 were referred from search engines. These downloads mostly resulted from weaponized data voids, or combinations of search terms that have very few results, which means that any content matching those terms is likely to appear very high in the search results. This represents just one of many social engineering techniques that attackers are accelerating.

Social engineering as a whole continues to dominate as a leading malware infiltration technique with attackers abusing not only search engines, but email, collaboration apps, and chat apps to trick their victims. As the top two malware types, Trojans accounted for 60% of malware downloads in Q1 and phishing downloads accounted for 13%.

Evaluation of Primary Communication Channels for Attackers

For the first time in its quarterly cloud and threat reporting, Netskope analyzed attacker communication channels. Researchers found that attackers, in order to consistently evade detection, have used HTTP and HTTPS over ports 80 and 443 as their primary communication channel. In fact, of the new malware executables analyzed by Netskope that communicated with external hosts, 85% did so over port 80 (HTTP) and 67% did so over port 443 (HTTPS). This approach enables attackers to easily go unnoticed and blend in with the abundance of HTTP and HTTPS traffic already on the network.

Additionally, to evade DNS-based security controls, some malware samples sidestep DNS lookups, instead reaching out directly to remote hosts using their IP addresses. In Q1 2023, most malware samples that initiated external communications did so using a combination of IP addresses and hostnames, with 61% communicating directly with at least one IP address and 91% communicating with at least one host via a DNS lookup.

“Job number one for attackers is finding new ways to cover their tracks as enterprises put more resources into threat detection, but these findings indicate just how easy it still is for attackers to do so in plain sight,” said Ray Canzanese, Threat Research Director, Netskope Threat Labs. “As attackers gravitate towards cloud services that are widely used in the enterprise and leverage popular channels to communicate, cross-functional risk mitigation is more necessary than ever.”

Extended Look into Global Cloud and Web Malware Trends

Other notable findings uncovered by Netskope’s research team include:
  • 55% of HTTP/HTTPS malware downloads came from cloud apps, up from 35% for the same period one year earlier. The primary driver of the increase is an increase in malware downloads from the most popular enterprise cloud applications, with Microsoft OneDrive tracked as the most popular enterprise app by a wide margin.
  • The number of applications with malware downloads also continued to increase, reaching a high of 261 distinct apps in Q1 2023.
  • Only a small fraction of total web malware downloads were delivered over web categories traditionally considered risky. Instead, downloads are spread out among a wide variety of sites, with content servers (CDNs) responsible for the largest slice, at 7.7%.
As enterprises work to defend against the onslaught of malware, cross-functional collaboration across multiple teams is required, including network, security operations, incident response, leadership, and even individual contributors. Some of the additional steps organizations can take to reduce risks include:
  • Inspect all HTTP and HTTPS downloads, including all web and cloud traffic, to prevent malware from infiltrating your network
  • Ensure that security controls recursively inspect the content of popular archive files and that high-risk file types are thoroughly inspected
  • Configure policies to block downloads from apps that are not used in your organization to reduce risk surface.
Get the full Netskope Cloud & Threat Report: Global Cloud and Web Malware Trends here.

For more information on cloud-enabled threats and our latest findings from Netskope Threat Labs, visit Netskope’s Threat Research Hub.

About Netskope

Netskope, a global SASE leader, is redefining cloud, data, and network security to help organizations apply zero trust principles to protect data. Fast and easy to use, the Netskope platform provides optimized access and real-time security for people, devices, and data anywhere they go. Netskope helps customers reduce risk, accelerate performance, and get unrivaled visibility into any cloud, web, and private application activity. Thousands of customers, including more than 25 of the Fortune 100, trust Netskope and its powerful NewEdge network to address evolving threats, new risks, technology shifts, organizational and network changes, and new regulatory requirements. Learn how Netskope helps customers be ready for anything on their SASE journey, visit netskope.com

Forescout Unveils Latest Findings on Ransomware Targeting VMware ESXi Servers

The latest threat report by Vedere Labs shares insights into tactics deployed by attackers, and mitigation measures for quick detection and threat hunting

Forescout’s Vedere Labs, today revealed its latest findings on the recent ransomware VMware ESXi virtualization servers. In its new threat briefing report, Vedere Labs also analyzes two payloads used in these attacks: variants of the Royal and Clop ransomware, while also presenting the tactics, techniques and procedures (TTPs) used by attackers in this campaign, discuss mitigation recommendations and list indicators of compromise (IOCs) that can be used for detection or threat hunting.

ESXi servers have grown in popularity of late. As of February 24, 2023 there are close to 85,000 ESXi servers exposed on the internet, according to the Shodan search engine. Forescout’s Device Cloud allowed researchers at Vedere Labs to have deeper insight into organizations deploying ESXi. There are more than 17,000 ESXi servers tracked on the Device Cloud. On February 3, CERT-FR issued a warning about an attack campaign targeting VMware ESXi hypervisors vulnerable to CVE-2021-21974 with the goal of deploying ransomware.

Commenting on the latest threat report, XX from Forescout said, "As cyber threats continue to evolve and proliferate, it's crucial for organizations to remain vigilant and proactive in their approach to cybersecurity. Forescout's latest threat report highlights the growing threat of ransomware targeting VMware ESXi virtualization servers, which can have a devastating impact on organizations' operations and finances. These attacks are becoming more sophisticated and are leveraging multiple attack vectors, including supply chain attacks and social engineering tactics."

VMware ESXi is an enterprise-class hypervisor developed by VMware to deploy and serve virtual computers. It allows the same hardware to be used for multiple virtual machines (VMs), which helps organizations save on hardware and easily scale infrastructure.

Since 2022, ESXi virtualization servers have been one of the main targets of ransomware groups, with the number of attacks targeting these servers tripling between 2021 and 2022. The increasing focus on new types of targets, such as ESXi, may be seen as a response to a decline in successful ransomware attacks or total ransom payouts in 2022. Ransomware groups are ever-changing and willing to adapt to maintain or increase profitability.

Ransomware is just a part of the threat landscape for virtualized infrastructure. Beyond what is discussed in the report, there are known attacks leveraging a custom Python backdoor on ESXi servers, APTs targeting Log4shell vulnerabilities on VMware Horizon, attack tools developed specifically for ESXi and even vulnerabilities allowing attackers to break out of virtual machines and execute code on the host operating system.

The Forescout Platform provides visibility, compliance, segmentation and threat detection against ransomware on ESXi servers.

About Forescout

Forescout Technologies, Inc. delivers cybersecurity automation across the digital terrain, maintaining continuous alignment of customers’ security frameworks with their digital realities, including all asset types. The Forescout Platform provides complete asset visibility, continuous compliance, network segmentation and a strong foundation for Zero Trust. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide automated cybersecurity at scale. Forescout arms customers with data-powered intelligence to accurately detect risks and quickly remediate cyberthreats without disruption of critical business assets. www.forescout.com

Managing cyber risk, together.

eMudhra Launches emSign; Becomes the 1st and Only Indian Provider to Issue SSL/ TLS Certificates Globally

eMudhra Launches emSign; Becomes the 1st and Only Indian Provider to Issue SSL/ TLS Certificates Globally
Issued under the globally accredited Trust Services offering emSign, will help eMudhra compete on a global scale with a state-of-the-art managed PKI offering

eMudhra Limited, (Listed on BSE & NSE, EMUDHRA) a technology, digital identity, and transaction management company, has launched its services to issue its own Secured Sockets Layer (SSL) / Transport Layer Security (TLS) certificates for large enterprises, IoT manufacturers, SMEs and retail customers. eMudhra is the first & only company from India to get accredited by Webtrust, and its offering emSign is recognized by all the major browsers in the world.

SSL/TLS Certificates play a major role in the Cyber Security space, where they help encrypt every communication on the internet. This includes use-cases such as E-commerce websites for secure online transactions, online banking sites, social media and other websites that require login credentials, Email services, online marketplaces, payment gateways, healthcare portals, online government services, mobile applications, OTT streaming portals and apps, API Services including Digital Public Infrastructure Services (e.g.: UPI), and others.

These certificates use PKI (Public key infrastructure) technology and are widely used in the form of SSL (or TLS) issued by global trust service providers. Certificates issued by emSign are trusted by prominent web browsers of today to enable secure, trusted communication between a web server and the website. This enables organizations and consumers to enhance encrypted network connections, thereby protecting both the end users’ information and the service provider. The SSL/TLS certificates issued by emSign – eMudhra’s Global Trust Root, is a fully made in India solution for the world with local data residency capabilities.

V. Srinivasan, chairman of eMudhra said, “With this latest initiative, eMudhra expects to enhance secure encryption across sectors like BFSI, Government, Education, logistics, healthcare, E-commerce, etc. Through our SSL and TLS certificates, customers can ensure accountability while browsing the web for their needs and be confident while making transactions. A seamless and secure digital experience is a priority for everyone, and SSL/TLS certificates issued under emSign will instill confidence and trust amongst businesses and government authorities, as the data stays in India with limited or no reliance on foreign players”.

Operated under the brand “emSign”, Businesses can get the certificates online from the website, or through eMudhra resellers. emSign certificates support modern ACME APIs, as well as web server agents to adopt automation. Domain validated certificates are issued instantly and meet the global compliance requirements. Enterprises/Businesses can also get Organization/Extended validated certificates to display their identity as part of the certificates. This offering is also available in wildcard and Unified Communication Certificates (UCC) categories for multiple website support and is compatible with all major browsers in the world.

About emSign

emSign by eMudhra is a Managed PKI Ecosystem and a Globally Trusted Root to issue X.509 certificates for a multitude of use-cases across industries. From issuance of SSL/TLS certificates that are trusted by all major web browsers to SMIME and Code Sign Certificates, emSign powers businesses to achieve identity assurance through seamless issuance and management of public certificates at scale. Businesses, large enterprises and IoT companies across the globe can deploy certificates issued by emSign to make safe transactions, protect network and device, and all communication from cyber-attacks.

Certificate lifecycle Management (CLM) offered by emSign is best suited for enterprises looking for scale and would like to manage millions of digital identities on an intuitive dashboard. With an end-to-end automation of authentication and encryption, emSign offers to make the digital world secure, trusted and agile.

Barracuda XDR Insight Reveals Threat Severity Rises During Vacation Months

Barracuda XDR Insight Reveals Threat Severity Rises During Vacation Months

1-in-5 cyberthreats detected between June and the end of September 2022 were higher risk, compared to just 1-in-80 in January

The latest threat insight from Barracuda a trusted partner and leading provider of cloud-first security solutions, reveals that between June and September 2022, the top threats were successful Microsoft 365 logins from a suspicious country, accounting for 40% of attacks from suspicious countries. Followed by communication from the network to a known dangerous IP address (15% of attacks), and brute force user authentication attempts (10%).

The research shows the severity of the attacks has witnessed a huge spike as 1 out of 5 (96,428) attacks were highly critical and reported between June to September 2022 as compared to 1 out of 80 (17,500) in January 2022. Experts at Barracuda analysed 4,76,994 threat alarms from June to September out of which 20% amounted to 96,428 were alerted and urged to take remedial actions.

Barracuda XDR Insight Reveals Threat Severity Rises During Vacation Months


Amongst the top detected threats, successful Microsoft 365 login from a suspicious country is classed as ‘high risk’, which have the potential to cause severe damage and demand immediate action. This attack accounted for 40% of all attacks during the 90-day window. The countries that flag an automatic security alert include Russia, China, Iran, and Nigeria. A successful breach of a Microsoft 365 account offers an intruder potential access to all the connected and integrated assets the target has stored on the platform. Among other things, analysts look for evidence of multiple-country logins to the same account.

Barracuda XDR Insight Reveals Threat Severity Rises During Vacation Months

Communication to an IP address to Threat Intelligence and brute force authentication user attempt are classed as ‘medium risk’, which requires mitigation but would not typically lead to substantial impact as a standalone event. The attacks accounted for 15% and 10% respectively, where the former includes any attempt at malicious communication from a device within the network to a website or known command-and-control server etc., and the brute force authentication user attempts are automated attacks trying to penetrate an organization’s defences by simply running as many name/password combinations as they can.

“Cyber attackers target companies and IT security teams during off hours like weekends, overnight, or during a holiday season, such as the summers and festivals”, said Parag Khurana, Country Manager, Barracuda Networks India.

“Businesses should reinforce essential security measures such as enabling multifactor authentication (MFA) across all applications and systems, ensuring all critical systems are backed up, implementing a robust security solution that includes email protection, web application firewall (WAF) and Endpoint Detection and Response (EDR) in order to monitor, detect, and respond to cyberthreats,” he added.

About Barracuda Networks

At Barracuda we strive to make the world a safer place. We believe every business deserves access to cloud-first, enterprise-grade security solutions that are easy to buy, deploy, and use. We protect email, networks, data, and applications with innovative solutions that grow and adapt with our customers’ journey. More than 200,000 organizations worldwide trust Barracuda to protect them — in ways they may not even know they are at risk — so they can focus on taking their business to the next level.

For more information, visit barracuda.com. 

Barracuda Networks, Barracuda and the Barracuda Networks logo are registered trademarks or trademarks of Barracuda Networks, Inc. in the U.S. and other countries.

ESET Threat Report T2 2022: RDP Attacks See Further Drop; India Among Countries with Highest Number of Android Trojan Detections

ESET Threat Report T2 2022: RDP Attacks See Further Drop; India Among Countries with Highest Number of Android Trojan Detections

India was among countries with most detections of Android/Spy.Agent trojan. Such malicious apps have a wide range of spying capabilities including recording audio and video.

India (35%) also ranked second after China (53%) as the geolocation for bots making up the largest IoT botnet ‘ Mozi’

ESET has released its T2 2022 Threat Report, summarizing key statistics from ESET detection systems, and highlighting notable examples of ESET’s cybersecurity research. The latest issue of the ESET Threat Report (covering May to August 2022) sheds light on the changes in ideologically motivated ransomware, spyware trojans, Emotet activity, the most-used phishing lures, how the plummeting cryptocurrency exchange rates affected online threats, and the continuation of the sharp decline of Remote Desktop Protocol (RDP) attacks. ESET analysts think these attacks continued to lose their steam due to the Russia-Ukraine war, along with the post-COVID return to offices and overall improved security of corporate environments.

Key Points of the Report
  • Following a sharp decline observed in T1 2022, the total number of RDP attack attempts declined by a further 89%; the likely reasons for the decline are post-COVID return to offices, improved security, and the Russia-Ukraine war.
  • Politically motivated ransomware declined; operators turned their attention from Russia back to their usual targets such as the United States, China, and Israel.
  • Emotet continued to be active, with detections seen mainly in Japan and Italy; according to ESET telemetry, its operators took time off in August.
  • ESET phishing feeds showed a sixfold increase in shipping-themed phishing URLs, with the most commonly impersonated brands being USPS and DHL.
  • Web skimmer known as Magecart constituted three-fourths of all banking malware detections, leaving far behind the rest of the malware strains in the category.
  • Cryptocurrency threats went down along with the price of bitcoin; however, the previously declining category of Cryptostealers grew by almost 50%.
Even with declining numbers, Russian IP addresses continued to be responsible for the largest portion of RDP attacks. “In T1 2022, Russia was also the country that was most targeted by ransomware, with some of the attacks being politically or ideologically motivated by the war. However, ESET Threat Report T2 2022 shows that this hacktivism wave has declined in T2, and ransomware operators turned their attention towards the United States, China, and Israel,” explains Roman Kováč, Chief Research Officer at ESET.

Android threat detections continued to grow in T2 2022 by 9.5%, with India named among countries with most detections of Android/Spy.Agent trojan with various spying capabilities, including secretly recording audio and video. Behind a large portion of Android spyware detection in the past four months was “GB WhatsApp” – a popular but cloned (and therefore unofficial) third-party version of WhatsApp. The cloned app is not available on Google Play and therefore there are no security checks in place compared with the legitimate WhatsApp, and versions available on various download websites are riddled with malware.

Further, the biggest zombie IoT botnet ‘Mozi’ saw the number of bots drop by 23% from 500,000 compromised devices in T1 to 383,000 in T2. However, China (53%) and India (35%) continued to have the highest number of IoT bots geolocated inside the respective countries. These statistics confirm the assumption that the Mozi botnet is on autopilot, running without human supervision since its reputed author was arrested in 2021.

According to ESET telemetry, August was a vacation month for the operators of Emotet, the most influential downloader strain. The gang behind it also adapted to Microsoft’s decision to disable VBA macros in documents originating from the internet and focused on campaigns based on weaponized Microsoft Office files and LNK files.

The report also examines threats mostly impacting home users. ESET phishing feeds showed a sixfold increase in shipping-themed phishing lures, most of the time presenting the victims with fake DHL and USPS requests to verify shipping addresses. “In terms of threats directly affecting virtual and physical currencies, a web skimmer known as Magecart remains the leading threat going after online shoppers’ credit card details. We also saw a twofold increase in cryptocurrency-themed phishing lures and a rising number of cryptostealers,” explains Kováč.

The ESET T2 2022 Threat Report also reviews the most important findings and achievements by ESET researchers. They uncovered a previously unknown macOS backdoor, and later attributed it to ScarCruft, discovered an updated version of the Sandworm APT group’s ArguePatch malware loader, uncovered Lazarus payloads in trojanized apps, and analyzed an instance of the Lazarus Operation In(ter)ception campaign targeting macOS devices while spearphishing in crypto-waters. ESET researchers also discovered buffer overflow vulnerabilities in Lenovo UEFI firmware and a new campaign using a fake Salesforce update as a lure.

Besides these findings, the report also summarizes the many talks given by ESET researchers in recent months, and introduces talks planned for AVAR, Ekoparty, and many other conferences.

For more information, check out ESET Threat Report T2 2022 on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About ESET

For more than 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint and mobile security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give consumers and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D centers worldwide, ESET is the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003. For more information, visit www.eset.com or follow us on LinkedIn, Facebook, and Twitter.

ESET Research Uncovers New Cyberespionage Group Worok Targeting Companies, Govts Mostly in Asia

ESET Research Uncovers New Cyberespionage Group Worok Targeting Companies, Govts Mostly in Asia
  • ESET researchers have discovered a previously unknown cyberespionage group that they named Worok.
  • Worok has attacked various high-profile companies from the telecommunications, banking, maritime, energy, military, government, and public sectors. The targets are located mostly in Asia, but also in the Middle East and Africa.
  • Worok develops its own tools and leverages existing tools to compromise its targets. The group has used the infamous ProxyShell vulnerabilities to gain initial access in some cases. Its PowerShell backdoor PowHeartBeat has various capabilities, including command/process execution and uploading and downloading files.
yESET researchers recently discovered targeted attacks that used undocumented tools against various high-profile companies and local governments mostly in Asia, but also in the Middle East and Africa. These attacks were conducted by a previously unknown cyberespionage group that ESET has named Worok. According to ESET telemetry, Worok has been active since at least 2020 and continues to be active today. Among the targets were companies from the telecommunications, banking, maritime, energy, military, government, and public sectors. Worok used the infamous ProxyShell vulnerabilities to gain initial access in some cases.

"We believe the malware operators are after information from their victims because they focus on high-profile entities in Asia and Africa, targeting various sectors, both private and public, but with a specific emphasis on government entities,” says ESET researcher Thibaut Passilly who discovered Worok.

Back in late 2020, Worok was targeting governments and companies in multiple countries, specifically:
  • A telecommunications company in East Asia
  • A bank in Central Asia
  • A maritime industry company in Southeast Asia
  • A government entity in the Middle East
  • A private company in southern Africa
There was a significant break in observed operations from May 2021 to January 2022, but Worok activity returned in February 2022, targeting:
  • An energy company in Central Asia
  • A public sector entity in Southeast Asia
Worok is a cyberespionage group that develops its own tools and leverages existing tools to compromise its targets. The group’s custom toolset includes two loaders, CLRLoad and PNGLoad, and a backdoor, PowHeartBeat.

Technical Analysis

While the majority of initial accesses are unknown, in some cases through 2021 and 2022 we have seen exploits used against the ProxyShell vulnerabilities. In such cases, typically webshells have been uploaded after exploiting these vulnerabilities, in order to provide persistence in the victim’s network. Then the operators used various implants to gain further capabilities.

Once access had been acquired, the operators deployed multiple, publicly available tools for reconnaissance, including MimikatzEarthWormReGeorg, and NBTscan, and then deployed their custom implants: a first-stage loader, followed by a second stage .NET loader (PNGLoad).

Unfortunately, the ESET team have not able to retrieve any of the final payloads. In 2021, the first-stage loader was a CLR assembly (CLRLoad), while in 2022 it has been replaced, in most cases, by a full-featured PowerShell backdoor (PowHeartBeat) – both execution chains are depicted in Figure 2. These three tools are described in detail in the following subsections.

Worok compromise chains
Worok compromise chains

CLRLoad is a first-stage loader that was used in 2021, but in 2022 was replaced, in most cases, by PowHeartBeat. PNGLoad is a second-stage loader that uses steganography to reconstruct malicious payloads hidden in PNG images.

PowHeartBeat is a full-featured backdoor written in PowerShell, obfuscated using various techniques such as compression, encoding, and encryption. This backdoor has various capabilities, including command/process execution and file manipulation. For example, it is capable of uploading files to and downloading files from compromised machines; returning file information such as the path, length, creation time, access times, and content to the command and control server; and deleting, renaming, and moving files.

“While our visibility at this stage is limited, we hope that putting the spotlight on this group will encourage other researchers to share information about this group,” adds Passilly.
For more technical information about Worok, check out the blogpost “Worok: the big picture” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

Visual heatmap of the targeted regions and verticals 

Cyberespionage Group Worok Targeting Companies, Govts Mostly in Asia
Map of the targeted regions and verticals




For more than 30 years, ESET® has been developing industry-leading IT security software and services to protect businesses, critical infrastructure and consumers worldwide from increasingly sophisticated digital threats. From endpoint and mobile security to endpoint detection and response, as well as encryption and multifactor authentication, ESET’s high-performing, easy-to-use solutions unobtrusively protect and monitor 24/7, updating defenses in real time to keep users safe and businesses
running without interruption. Evolving threats require an evolving IT security company that enables the safe use of technology. This is backed by ESET’s R&D centers worldwide, working in support of our shared future. 

Spike in Ransomware Threat to More Than 1.2 Mn Per Month, Says Latest Barracuda Threat Report

Spike in Ransomware Threat to More Than 1.2 Mn Per Month - Barracuda Threat Report

New fourth-annual research report analyses ransomware attack patterns that occurred between August 2021 and July 2022

  • In the past 12 months, Barracuda researchers identified and analyzed 106 highly publicized ransomware attacks and found the dominant targets are still five key industries: education, municipalities, healthcare, infrastructure, and financial.
  • Researchers also saw a spike in the number of service providers that have been hit with a ransomware attack.
  • The volume of ransomware threats detected spiked between January and June of this year to more than 1.2 million per month.
Barracuda, a trusted partner and leading provider of cloud-first security solutions, today released its fourth-annual threat research report on ransomware. The new report looks at ransomware attack patterns that occurred between August 2021 and July 2022.

A closer look at ransomware trends

For the 106 highly publicised attacks analysed by the researchers, the dominant targets are still five key industries: education (15%), municipalities (12%), healthcare (12%), infrastructure (8%), and financial (6%):
  • The number of ransomware attacks increased year-over-year across each of these five industry verticals, and attacks against other industries more than doubled compared to last year’s report.
  • While attacks on municipalities increased only slightly, Barracuda analysis over the past 12 months showed that ransomware attacks on educational institutions more than doubled, and attacks on the healthcare and financial verticals tripled.
  • This year, Barracuda researchers dug in deeper on the highly publicized attacks to see which other industries are starting to be targeted. Service providers were hit the most, and ransomware attacks on automobile, hospitality, media, retail, software, and technology organizations all increased as well.
Most ransomware attacks don’t make headlines, though. Many victims choose not to disclose when they get hit, and the attacks are often sophisticated and extremely hard to handle for small businesses. To get a closer look at how ransomware is affecting small businesses, the report details three examples that researchers have seen through Barracuda SOC-as-a-Service, the anatomy of each attack, and the solutions that can help stop these attacks.

Parag Khurana, Country Manager, Barracuda Networks India, said, “Ransomware attackers remain defiant and continue to operate their business with extended extortion attempts. As ransomware and other cyberthreats continue to evolve, the need for adequate security solutions has never been greater. Many cybercriminals target small businesses to gain access to larger organisations. As a result, it is essential for security providers to create products that are easy to use and implement, regardless of a company's size. Additionally, sophisticated security technologies should be available as services, so businesses of all sizes can protect themselves against these ever-changing threats. By making security solutions more accessible and user-friendly, the entire industry can help to better defend against ransomware and other cyberattacks.”

To safeguard their network against this type of attack, businesses should implement execution prevention by disabling macro scripts from Microsoft Office files transmitted via email. They should also carry out a robust network segmentation to help reduce the spread of ransomware if it does get into the system. Additionally, they should identify and remove any unused or unauthorised software, particularly on remote desktops or remote monitoring, as they could be signs of compromise. Organisations should also secure their web applications from malicious hackers and bad bots by enabling web application and API protection services, including distributed denial of service (DDoS) protection.

Resources:
Read the full Threat Spotlight blog post: https://blog.barracuda.com/2022/08/24/threat-spotlight-the-untold-stories-of-ransomware/

Ransomware protection page: https://www.barracuda.com/ransomware

2021 Ransomware Threat Spotlight research: https://blog.barracuda.com/2021/08/12/threat-spotlight-ransomware-trends/

Subscribe to our Barracuda blog to receive recaps by email and get the latest news, research, and more: blog.barracuda.com/subscription/

5 Most Effective Ways To Protect Yourself From A Crypto Scam

Most Effective Ways To Protect Yourself From A Crypto Scam

The craze of cryptocurrencies is getting so high that literally, every single individual is talking about making an investment using it. But, not many have a complete understanding of how it works and can be used. Even more important, not many have any idea of the security in place in the respective system.

There are many who have fallen victim to it. The scammers around the world are targeting people who are just dealing with cryptocurrencies without having much knowledge about the approach and aspects related to them. Today, we all know how crypto-assets are growing and gaining the attention of investors worldwide. But similarly, it is also catching the attention of the scammers as well.

The crypto scammers are working on different techniques and methodologies that can help them exploit the individuals and steal data out of their profiles. This is why when you are looking for digital cryptocurrency companies, the professionals are always recommending checking whether they are powered by blockchain or not. This technology can help them keep track of all the transactions in detail.

Not only this, it is essential that you also check whether they have the suitable facilities or not to get the problems resolved quickly. This can help you reach out to the right company where you can deal with crypto without any hassle. But, still, there are a few things that you need to keep to keep yourself away from the crypto scam. We have it covered for you. Check it out below:

#1 Carry Out Proper Research

The first and the most crucial step that you need to do before taking any other step is doing proper and detailed research work. We all consider going through the recommendations provided by the greats in the business and fall for it. But, this is not the right way to go. You need to build your own understanding about the same as well. This is why you need to examine every single aspect all by yourself and then consider investing your money.

If you are thinking about how you need to start with the same, then we are here to help you with the same. You can consider opting for PC Mag’s manual. This can help you in making the right decision in terms of selling, purchasing, and overseeing a specific bitcoin. It is important that you never take any data available online for granted. You must do proper research and check whether it is genuine or not. This can help you remain away from the traps set by cryptocurrency scammers.

#2 Never Trust:

The next important step that you need to follow to keep yourself safe and secure is ensuring that you never trust anyone in this field. If you do, you are bound to get trapped and face immense loss. If someone is reaching out to you for any kind of investment or offer, make sure you reject them straight away. Trusting someone here is like falling into a trap. It is important that you never fall into someone’s words and make your own decision.

As stated in the above-mentioned point, it is important that you always do your own research rather than trusting someone. Regardless of who they are and what they are trying to prove, it is essential that you never trust the crypto world. Whether someone is calling being government authorities or an expert trader in the business, you must never follow them and do your own research before making any decision.

#3 Boost Security Of Your Crypto Wallet:

The next important step that you need to take is to make sure that the Crypto Wallet you are using for crypto-trading is fully secure. There have been many cases where one has lost bitcoins because of not being able to have a firm grip on their wallets. The first and the most crucial step that you need to follow is to never share any details related to it with anyone. If you do, you never know how who can misuse the same and eventually cost you a big time.

So, when you are trading crypt, it is important that you keep the private key secrete and share it with no one. Yes, no ONE! You need to imply that to ensure that you are falling into any kind of scam. Not only this, but also it is important that you have data backed up in some isolated place offline. This can undoubtedly enhance the chances of better security in your wallet.

#4 Multi-Factor Authentication:

The next important aspect that you need to focus on is using multifaceted verification to trade in your crypto wallet. It is basically an additional layer of security that can keep all the troublemakers out of your wallet. It can help you keep your account safe and secure, and you can know when someone else is trying to enter the application.

Multifaceted verification is basically a process that verifies whether the one who is accessing the application is right or not. It plays a significant role in keeping various attackers out and helps you get your wallet safe and secure all the way through.

#5 Always Assess The URL:

The last and the most important step that you need to keep in mind is keeping one eye on the URL. Yes, there are several fake websites with the name of genuine ones. So, it is important that you check with the URL and then proceed ahead with all the other actions. It has been seen that various phishing experts get the URL duplicated of the genuine traders.

Before working on any site, it is important that you check whether it is secure or not. It is important that you check whether there is a small lock image available on the URL or not. Not only this, but you need to also turn on your antivirus program as well. In this way, you can enhance the chances of being away from the URLs that are basically for trapping and stealing your data.\

Last Words

These are the most effective ways that can help you keep yourself safe from all kinds of crypt scams. It is essential that you follow the above-mentioned steps at all costs to ensure that your crypto data remains safe and sound all the time. Not doing so can lead to data leakage, and eventually, it can prove to the reason behind a big loss. Good luck!

Author Bio

Neha Singh

Neha Singh is the Founder & CEO of Securium Solutions with a demonstrated history of working in the information technology and services industry. Skilled in SOC, Vulnerability Management, Security Information and Event Management (SIEM), Management, and Business Development. She loves traveling and tracking.

ESET Launches Safer Kids Online Platform in India to Safeguard Children’s Cyber Safety

ESET Launches Safer Kids Online Platform in India to Safeguard Children’s Cyber Safety

ESET, a global leader in digital security, today launches its Safer Kids Online platform – a resource site dedicated to building a safer online environment for children in India. The website offers resources - in the form of videos, articles and expert insight - for children, parents and teachers with the aim to enable children to enjoy the full potential of the internet in a secure digital world.

Protecting Kids Online

As a result of the shift to digitalisation that has been accelerated by the pandemic, children today can access digital devices and online platforms for various activities, ranging from online learning and video streaming to online games and social media. However, this also puts them at greater risk of encountering online threats. Against this backdrop, it is critical to provide children with guidance, and equip them with the essential skills to remain safe while navigating in an online environment.

According to the ESET APAC Consumer Cybersecurity Survey 2021, 94% of parents in India take various actions such as using parental control applications, checking internet browser history and limiting screen time to ensure that their children are safe from online threats. Despite the actions taken, 21% of Indian parents said their children had been exposed to inappropriate content online. In addition, 78% of them have not spoken to their children about cybersecurity.

"Cybersecurity can be a relatively new concept for some parents, as it was not taught in schools in the past. The Safer Kids Online initiative aims to empower parents, teachers and children in India to learn more about cyber wellness and how kids can stay safe online by providing free resources and materials. These materials – which are jointly developed by ESET’s cybersecurity experts and child psychologists - are designed to be fun and engaging for children across all ages. Through this initiative, we hope to play a role in protecting the safety and well-being of children online, and we remain committed to keeping the Internet safe for everyone,” said Parvinder Walia, President of Asia Pacific and Japan, ESET.

Resources for children, parents and teachers

The Safer Kids Online website includes a host of resources suitable for younger children, teenagers and their parents, which have all been developed in consultation with a notable child psychologist and ESET’s cybersecurity experts. The resources will provide guidance and advice for children and adults around how to stay safe online and will be geared around key monthly topics. The topics include how to manage screen time, looking out for signs of cyberbullying and protecting children from online predators. Each of these monthly topics will include targeted resources for different ages such as:
  • A video series for kids aimed at ages 7+
  • Animated comics for older children aged 11+
  • An in-depth explanation in the form of expert articles and vlogs for parents
Quizzes and prize contests will also be available in which parents can win attractive prizes for their children.

The Safer Kids Online site will also provide free software, namely ESET Parental Control for Android, which allows parents to look after their children’s online well-being. ESET Parental Control includes the possibility of controlling inappropriate web content and managing the amount of time kids spend on certain devices, as well as the suitability of the applications they’re using. This allows parents to limit their child’s use of certain sites and receive reports on his or her online activities, hopefully becoming aware of any issues before they become entrenched.

Looking to the future

ESET’s future plans include running child online safety initiatives in regions around the world – from Europe and Asia to the USA and Latin America – in cooperation with its partners and local NGOs. With so many resources at the fingertips of families across the globe, ESET will provide parents and schools everywhere with the tools they need to keep their kids safe online – now and in the future.

The first country running such cooperation is the United Kingdom. ESET UK has come on board as a Gold Partner alongside specialist child safety NGO Internet Matters, providing significant contribution to guide policy and to educate. In 2020, ESET also became an official partner of AFC Bournemouth’s Community Sports Trust, which saw ESET specialists providing support for the club’s Safer Kids Online Internet safety project.

75% Indian Children Think a New Phone Is More Secure Than a New Computer


New McAfee Global Research Shows Children and Teens Are More Vulnerable Than Ever to Sophisticated Mobile Threats

  • With device-based consumer behavior changing rapidly in India and around the world, McAfee showcased its Consumer Mindset Survey: Mobile Report ahead of Mobile World Congress (Barcelona)
  • McAfee’s 2022 Consumer Mindset Survey: Mobile Report reveals that as mobile devices have replaced PCs/laptops as the primary device, a high level of trust in smartphone security exists among Indian children and teens, but is coupled with a low level of protection, even though risk is at an all-time high.

Today, McAfee Corp. (NASDAQ: MCFE, “McAfee”), a global leader in online protection, unveiled its Consumer Mindset Survey: Mobile Report ahead of Mobile World Congress (MWC) Barcelona. Globally as well as in India, the report reveals the level of disconnect that exists between generations over how safe mobile devices are and how vulnerable consumers are to threats on those devices.

"Meaningful protection is a personal right for consumers, whether they are connected families or individuals," said McAfee Executive Vice President, Chief Product and Revenue Officer, Gagan Singh. "The common thread linking these two research offerings are that consumers value protection of their data, privacy, and identity. As our use of mobile devices rapidly increases, we must remember that a mobile device is a connected device, just like a computer. McAfee’s world-class Labs Research team works tirelessly to identify and protect consumers from new and emerging threats that impact all ages and connected devices, across the globe."

McAfee’s 2022 Consumer Mindset Survey: Mobile Report - India


In this report, McAfee surveyed parents and children about their mobile behaviors as part of its larger 2022 Connected Families Research to uncover how children are using mobile devices and where their actual behavior differs from their parents’ assumptions, a new area of research in the industry that includes crucial perspective from children. Key findings from the research show:
  •  13 Going on 30: While consumers understand their desktops and laptops need protection, awareness of the need for protection of mobile devices has not kept pace.
    • Globally, children and teens have higher trust in mobile devices. Most children (59%) think a new phone is more secure than a new computer, whereas parents are equally split (49%).
      • In India, most children (75%) think a new phone is more secure than a new computer, whereas only 71% of parents agree.
    • Children’s mobile devices are less protected globally. While the majority of parents (56%) use passwords to protect mobile devices, only 41% of children and teens do, creating safety risks.
      • In India, 57% of parents use passwords to protect mobile devices, while only 43% of children and teens do, creating safety risks.
    • Children are experiencing adult risks. One in 10 parents reported that children had experienced a financial information leak, and 15% of children report that an attempt had been made to steal their online account.
  • Parents Protecting Their Progeny (or not):
    Activities Kids Do on Their Phones Match Up Closely With What Their Parents Think They’re Doing on Their Phones

    Parents demonstrate greater focus and action around protecting young children and teens on their mobile devices. Specifically:
    • In India, 39% of parents of boys aged 10-14 put mobile parental controls software on their children’s devices compared to 33% for girls of the same age.
    • Younger boys report more cyberbullying and online threats than girls of the same age, a pattern that held across all threats examined, as seen in the following:
      • In India, 27% of boys 10-14 reported a threat to their account compared to 21% of girls the same age.
      • In India, 21% of boys 10-14 reported cyberbullying. Mexico (26%), U.S. (28%), Australia (26%) and the UK (19%) reported cyberbullying at some of the highest rates of countries surveyed.
      • In India, 20% of girls 10-14 reported cyberbullying. The U.S. (22%), Australia (21%), and the UK (18%) reported cyberbullying at some of the highest rates of countries surveyed.
  • Mobile Maturity and Gender Parity: While family members nearly all rely on mobile devices, how they use those devices differs greatly by gender.
    • The research showed that globally, at the age of 15, mobile use jumps significantly and stays consistent into adulthood.
    • Girls reported an earlier adoption of mobile usage in many countries studied, particularly in North America and Europe. In these regions, significantly more girls ages 10-14 are using mobile devices than boys of the same age.
    • Usage of social media in India showed significant differences by gender, and girls reported adopting almost all mobile activities at a rate higher than boys:
      • Globally, 53% of girls across all age groups use social networks compared to 44% of boys.
      • In India, 52% of girls 10-14 stream music compared to 42% of boys.
      • In India, 38% of girls online shop compared to 32% of boys.
One noted exception in India is that 55% of boys 10-14 are gaming on mobile compared to 45% of girls the same age.

Find the full report here.

The report demonstrates McAfee’s position as a leader in online protection and underpin the company’s new pure play consumer business strategy to singularly focus on consumer solutions that deliver the future of online protection, today.

Coinminers, Web Shells and Ransomware Made Up 56% of Malwares Targeting Linux Systems in the First Half of 2021


Trend Micro Detected Nearly 13 Million Malware Events Targeting Linux-based Cloud Environments


Bangalore, September 9, 2021 – Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global cybersecurity leader, released a new research on the state of Linux security in the first half of 2021. The report gives valuable insight into how Linux operating systems are being targeted as organizations increase their digital footprint in the cloud and the pervasive threats that make up the Linux threat landscape.

As of 2017, 90% of public clouds workloads ran on Linux. According to GartnerÒ, “Rising interest in cloud-native architectures is prompting questions about the future need for server virtualization in the data center. The most common driver is Linux-OS-based virtualization, which is the basis for containers.” [as per Gartner - Rationalizing Applications and Infrastructure for Cloud Delivery, Philip Dawson, 28 May 2021]

Linux allows organizations to make the most of their cloud-based environments and power their digital transformation strategies. Many of today’s most cutting-edge IoT devices and cloud-based applications and technology run on some flavor of Linux, making it a critical area of modern technology to secure.

“In the industry, we see some very creative attacks and we have to stay ahead. Protecting the company, our employees, and our intellectual property is a priority,” says John Breen, Global Head of Cybersecurity at Flowserve. “We’ll continue to work closely and collaborate with Trend Micro to ensure our people and our company remain protected.”



The report investigates the top malware families affecting Linux servers during the first half of 2021, with the top types of malwares being:
  • 25% Coinminers – The high prevalence of cryptocurrency miners is of little surprise given the clear motive of the seemingly endless amount of computing power the cloud holds, making it the perfect environment.
  • 20% Web shells – The recent Microsoft Exchange Attack, which leveraged web shells, showed the importance of patching against this type of malware
  • 12% Ransomware – The most prevalent detected was the modern ransomware family, DoppelPaymer, however some other notable ransomware families seen targeting Linux systems as well are RansomExx, DarkRadiation, and the DarkSide.

“It’s safe to say that Linux is here to stay, and as organizations continue to move to Linux-based cloud workloads, malicious actors will follow,” said Aaron Ansari, vice president of cloud security for Trend Micro. “We have seen this as a main priority to ensure our customers receive the best security across their workloads, no matter the operating system they choose to run it on.”

The report revealed that most detections arose from systems running end-of-life versions of Linux distributions, including 44% from CentOS versions 7.4 to 7.9. In addition, 200 different vulnerabilities were targeted in Linux environments in just six months. This means attacks on Linux are likely taking advantage of outdated software with unpatched vulnerabilities.

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,000 employees across 65 countries, Trend Micro enables organizations to simplify and secure their connected world. TrendMicro.com.

73% of Indian Organizations Expect to Experience a Breach of Customer Records in the Next Year



Trend Micro Cyber Risk Index shows organizations are at an elevated risk of attack

Bangalore, August 10, 2021 – Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global cybersecurity leader, today revealed that the risk of cyber attacks has increased in the last year. According to a new survey, 73% of organizations in India report they are likely to experience a data breach that impacts customer data in the next 12 months.

The findings come from Trend Micro’s biannual Cyber Risk Index (CRI) report, which measures the gap between respondents’ cybersecurity preparedness versus their likelihood of being attacked. In the first half of 2021, the CRI surveyed more than 3,600 businesses of all sizes and industries across Asia-Pacific, North America, Europe, and Latin America.

The CRI is based on a numerical scale of -10 to 10, with -10 representing the highest level of risk. The current index for India stands at -0.69, which indicates an “elevated” risk.

“Once again we’ve found plenty to keep CISOs awake at night, from operational and infrastructure risks to data protection, threat activity and human-shaped challenges,” said Vijendra Katiyar, Country Manager, India & SAARC, Trend Micro. “To lower cyber risk, organizations must be better prepared by going back to basics, identifying the critical data most at risk, focusing on the threats that matter most to their business, and delivering multi-layered protection from comprehensive, connected platforms."

Indian organizations ranked the top three negative consequences of an attack as lost IP, critical infrastructure damage/disruption, and cost of outside consultants and experts.

Key findings for India from the report include:
  • 57% said it was somewhat to very likely that they’d suffer serious cyber-attacks in the next 12 months.
  • 34% suffered 7+ cyber attacks that infiltrated networks/systems.
  • 20% had 7+ breaches of information assets.
  • 30% of respondents said they’d suffered 7+ breaches of customer data over the past year.

"Trend Micro’s CRI continues to be a helpful tool to help companies better understand their cyber risk,” said Dr. Larry Ponemon, CEO for the Ponemon Institute. “Businesses globally can use this resource to prioritize their security strategy and focus their resources to best manage their cyber risk. This type of resource is increasingly useful as harmful security incidents continue to be a challenge for businesses of all sizes and industries."

Among the top two infrastructure risks was cloud computing. Many respondents admitted they spend "considerable resources" managing third party risks like cloud providers.

In India, the top cyber threats highlighted in the report were as follows:
  • Ransomware
  • Watering hole attacks
  • Botnets
  • Malicious insiders
  • Advanced persistent threats (APT)
The top security risks to infrastructure include malicious insiders, cloud computing infrastructure and providers, organizational misalignment and complexity, as well as negligent insiders.

Sonit Jain, CEO of GajShield Infotech, said - "The report has not come as a surprise to us. With majority of employees still working from home and enterprises still not equipped to handle data security in the current scenario, we will see increased pace in attacks to their network and data. Companies will need to quantify their current risk posture all the time and ensure that their data is well secured even when access to critical data is provided to remote employees. Traditional risk strategies are no longer working. A security framework with contextual visibility and protection of information flow is critical to data security and helps in mitigating the risk from such attacks."

The main challenges for cybersecurity preparedness include organization’s IT security personnel having lack of sufficient knowledge, skill and expertise to protect data assets and IT infrastructure; IT security function complying with data protection and privacy requirements; as well as IT security architecture having high interoperability, scalability and agility.

Read a full copy of the report, by the Ponemon Institute, here: https://www.trendmicro.com/cyberrisk.


About Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,000 employees across 65 countries, Trend Micro enables organizations to simplify and secure their connected world. www.TrendMicro.com.

IT Staffers Receive An Average of 40 Targeted Phishing Attacks in A Year; Reports Barracuda Researchers


New report shows that all employees, not just top executives, need to be prepared for spear-phishing attacks

  • An average organization is targeted by over 700 social engineering attacks each year.
  • 77% of BEC attacks target employees outside of financial and executive roles.
  • 43% of phishing attacks impersonate Microsoft.
India, 29th July 2021: Barracuda, a trusted partner and leading provider of cloud-enabled security solutions, today released key findings about the way spear phishing attacks are evolving and who cybercriminals are targeting with these attacks. The report, titled Spear Phishing: Top Threats and Trends Vol. 6 – Insights into attackers’ evolving tactics and who they’re targeting, reveals fresh insights into recent trends in spear-phishing attacks and what you can do to protect your business.

The report examines current trends in spear phishing, which employees are being targeted the most by different attacks, and the new tricks attackers are using to sneak past victims’ defenses. It also tackles the best practices and technology that organizations should be using to defend against these types of attacks.

A closer look at attack trends

Between May 2020 and June 2021, Barracuda researchers analyzed more than 12 million spear phishing and social engineering attacks impacting more than 3 million mailboxes at over 17,000 organizations. Here are some of the key takeaways from their analysis:
  • 1 in 10 social engineering attacks are business email compromises.
  • 43% of phishing attacks impersonate Microsoft.
  • An average organization is targeted by over 700 social engineering attacks each year.
  • 77% of BEC attacks target employees outside of financial and executive roles.
  • An average CEO will receive 57 targeted phishing attacks in a year.
  • 1 in 5 BEC attacks target employees in sales roles.
  • IT staffers receive an average of 40 targeted phishing attacks in a year.

“Cybercriminals are getting sneakier about who they target with their attacks, often targeting employees outside the finance and executive teams, looking for a weak link in your organization,” said Don MacLennan, SVP, Engineering & Product Management, Email Protection, Barracuda. “Targeting lower level employees offers them a way to get in the door and then work their way up to higher value targets. That’s why it’s important to make sure you have protection and training for all employees, not just focus on the ones you think are the most likely to be attacked.”

Read the full report: https://www.barracuda.com/spearphishing-vol6

About Barracuda

At Barracuda we strive to make the world a safer place. We believe every business deserves access to cloud-enabled, enterprise-grade security solutions that are easy to buy, deploy, and use. We protect email, networks, data and applications with innovative solutions that grow and adapt with our customers’ journey. More than 200,000 organizations worldwide trust Barracuda to protect them — in ways they may not even know they are at risk — so they can focus on taking their business to the next level. For more information, visit barracuda.com. 

Barracuda Networks, Barracuda and the Barracuda Networks logo are registered trademarks or trademarks of Barracuda Networks, Inc. in the U.S. and other countries.


Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved