{"id":35733,"date":"2019-11-26T11:58:17","date_gmt":"2019-11-26T11:58:17","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2019\/11\/26\/fortinet-reveals-findings-of-latest-quarterly-global-threat-landscape-report\/"},"modified":"2019-12-03T09:34:02","modified_gmt":"2019-12-03T09:34:02","slug":"fortinet-reveals-findings-of-latest-quarterly-global-threat-landscape-report","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/11\/26\/fortinet-reveals-findings-of-latest-quarterly-global-threat-landscape-report\/","title":{"rendered":"Fortinet reveals findings of latest quarterly Global Threat Landscape Report"},"content":{"rendered":"\n<p>Fortinet, a global leader in broad, integrated and\nautomated cybersecurity solutions, has announced the findings of its latest\nquarterly&nbsp;<em><a href=\"https:\/\/www.fortinet.com\/resources\/resources-campaign.html?utm_source=direct&amp;utm_medium=asset-video&amp;campaign=power-of&amp;utm_term=q3fy19tlr#ufh-i-503778344-quarterly-threat-landscape-report\">Global Threat Landscape Report<\/a><\/em>.\n<\/p>\n\n\n\n<p>The research reveals that cybercriminals continue to look\nfor new attack opportunities throughout the digital attack surface. At the same\ntime, they are shifting attack vectors such as targeting publicly available Edge\nservices to counter training and education efforts by organisations that\naddress popular tactics such as phishing. <\/p>\n\n\n\n<p>The Threat\nLandscape Index remained relatively consistent during the quarter. There\nwere fluctuations but no significant swings. Regardless, organisations should not\nlet their guard down, instead the index demonstrates consistent and sustained cybercriminal\nactivity.<\/p>\n\n\n\n<p>Derek Manky, Chief, Security Insights and Global Threat Alliances, Fortinet, said: \u201cCybercriminals continue to attempt to be a step ahead of cybersecurity professionals. While they develop new malware and zero-day attacks, they also redeploy previously successful tactics to maximise opportunity across the entire attack surface.<\/p>\n\n\n\n<p>\u201cIn addition to essential strategies like patching,\nsegmenting and training, organisations also need to embrace automation and AI\nto enhance their ability to correlate threat intelligence and respond to\nthreats in real time. This approach will only be successful, however, when organisations\nintegrate all of their security resources into a security fabric that can see\nacross and adapt to their rapidly expanding network.\u201d<\/p>\n\n\n\n<p><strong>Highlights of the report<\/strong><\/p>\n\n\n\n<p><strong>Shifting tactics to catch organisations by surprise:<\/strong> The majority of malware is delivered via email, therefore many organisations have been aggressively addressing phishing attacks with end user training and advanced email security tools. As a result, cybercriminals are expanding their ability to deliver malicious malware through other means. These include targeting publicly facing Edge services such as web infrastructure, network communications protocols, as well as bypassing ad blocker tools to open attack vectors that don\u2019t rely on traditional phishing tactics. <\/p>\n\n\n\n<p>For example, this quarter FortiGuard Labs saw attacks against vulnerabilities that would allow the execution of code remotely targeting edge services, at the top in terms of prevalence amongst all regions. Although this tactic is not new, changing tactics where defenders may not be as closely watching can be a successful way to catch organisations off guard and increase chances for success. This can be especially problematic ahead of a busy online shopping season when online services will experience increased activity.<\/p>\n\n\n\n<p><strong>Maximising\nearning potential:<\/strong> Following in the footsteps of the lucrative <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/gandcrab-threat-actors-retire.html\">GandCrab\nransomware<\/a>, which was made available on the Dark Web as a Ransomware-as-a-Service\n(RaaS) solution, cybercriminal organisations are launching new services to expand\ntheir earning potential. By establishing a network of affiliate partners, criminals\nare able to spread their ransomware widely and scale earnings dramatically in\nthe process. FortiGuard Labs observed at least two significant ransomware\nfamilies \u2013 Sodinokibi and Nemty \u2013 being deployed as RaaS solutions. These are potentially\njust the beginning of what could be a flood of similar services in the future.<\/p>\n\n\n\n<p><strong>Refining\nmalware for success:<\/strong> Expanding on these approaches, cybercriminals\nare also refining malware to evade detection and deliver increasingly\nsophisticated and malicious attacks, such as the evolution of the Emotet\nmalware. This is a troubling development for organisations as cybercriminals increasingly\nuse malware to drop other payloads on infected systems to maximise their\nopportunities for financial gain. Recently, attackers have begun using Emotet\nas a payload delivery mechanism for ransomware, information stealers and\nbanking trojans including TrickBot, IcedID and Zeus Panda. In addition, by\nhijacking email threads from trusted sources and inserting malicious malware\ninto those email threads, attackers are significantly increasing the likelihood\nthat those malicious attachments will be opened. <\/p>\n\n\n\n<p><strong>Maximising opportunity with older vulnerabilities and botnets:<\/strong> Targeting older, vulnerable systems that have not been properly secured is still an effective attack strategy. FortiGuard Labs discovered that cybercriminals target vulnerabilities 12 or more years old more often than they target new attacks. And in fact, they target vulnerabilities from every subsequent year since then at the same rate as they do current vulnerabilities. <\/p>\n\n\n\n<p>Similarly, this trend of maximising existing opportunity also extends to botnets. More so than any other type of threat, the top botnets also tend to carry over from quarter to quarter and region to region globally with little change. This suggests the control infrastructure is more permanent than particular tools or capabilities and that cybercriminals not only follow new opportunities, but like legitimate businesses, also leverage existing infrastructure whenever possible to increase efficiency and reduce overhead. <\/p>\n\n\n\n<p><strong>Protecting for the unexpected: Broad, integrated and automated security<\/strong><\/p>\n\n\n\n<p>The expanding attack surface and shifting attack strategies of cybercriminals means organisations cannot afford to over-focus on a narrow set of threat trends. It is essential that organisations adopt a holistic approach to securing their distributed and networked environments. This requires the deployment of a security fabric that is broad, integrated and automated. <\/p>\n\n\n\n<p>This approach will enable organisations to reduce and manage the expanding attack surface through broad visibility across integrated devices, stop advanced threats through AI-driven breach prevention and reduce complexity through&nbsp;automated operations and orchestration. In addition, threat intelligence that is dynamic, proactive and available in real-time plays a crucial role in identifying trends by following the evolution of attack methods targeting the digital attack surface and then pinpointing cyberhygiene priorities.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fortinet, a global leader in broad, integrated and automated cybersecurity solutions, has announced the findings of its latest quarterly&nbsp;Global Threat Landscape Report. The research reveals that cybercriminals continue to look for new attack opportunities throughout the digital attack surface. At the same time, they are shifting attack vectors such as targeting publicly available Edge services [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":35903,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6617,93],"tags":[13960,13961,2097,2338,2411,278,6852,13962],"class_list":["post-35733","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-top-stories","tag-chief","tag-derek-manky","tag-edge","tag-fortinet","tag-global-threat-landscape-report","tag-network","tag-research","tag-security-insights-global-threat-alliances"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/35733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=35733"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/35733\/revisions"}],"predecessor-version":[{"id":35870,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/35733\/revisions\/35870"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/35903"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=35733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=35733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=35733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}