{"id":66367,"date":"2021-11-09T12:09:38","date_gmt":"2021-11-09T12:09:38","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=66367"},"modified":"2023-06-14T09:47:42","modified_gmt":"2023-06-14T08:47:42","slug":"mcafee-enterprise-and-fireeye-predict-top-2022-cyberthreats","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2021\/11\/09\/mcafee-enterprise-and-fireeye-predict-top-2022-cyberthreats\/","title":{"rendered":"McAfee Enterprise and FireEye predict top 2022 cyberthreats"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p><strong><em>McAfee Enterprise and FireEye have released its 2022 Threat Predictions, examining the top cybersecurity threats they predict enterprises will face in 2022.<\/em><\/strong><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Bad actors have taken note of successful tactics from 2021, including those making headlines tied to ransomware, nation states, social media and the shifting reliance on a remote workforce.<\/p>\n\n\n\n<p>McAfee Enterprise and FireEye expect them to pivot those into next years\u2019 campaigns and grow in sophistication, wielding the potential to wreak more havoc across the globe. Skilled engineers and security architects from the recently combined entity offer a preview of how the threat landscape might look in 2022 and how these new or evolving threats could potentially impact enterprises, countries and civilians.<\/p>\n\n\n\n<p>\u201cOver this past year, we have seen cybercriminals get smarter and quicker at retooling their tactics to follow new bad actor schemes \u2013 from ransomware to nation states \u2013 and we don\u2019t anticipate that changing in 2022,\u201d said Raj Samani, Fellow and Chief Scientist of the combined company. \u201cWith the evolving threat landscape and continued impact of the global pandemic, it is crucial that enterprises stay aware of the cybersecurity trends so that they can be proactive and actionable in protecting their information.\u201d<\/p>\n\n\n\n<p><strong>McAfee Enterprise and FireEye 2022 Predictions:<\/strong><\/p>\n\n\n\n<p><strong>Use of social media for targeted attacks. <\/strong>While this approach is not new, it is relatively uncommon. After all, it does demand a level of research to \u2018hook\u2019 the target into interactions and establishing fake profiles are more work than simply finding an open relay somewhere on the Internet. That being said, the targeting of individuals has proven a very successful channel, and we predict the use of this vector could grow not only through espionage groups, but other threat actors looking to infiltrate organizations for their own criminal gain.<\/p>\n\n\n\n<p><strong>Nation states turn to hackers for hire. <\/strong>In 2022, we will see an increase in the blending of cybercrime and nation-state operations. In many cases, a start-up company is formed, and a web of front companies or existing \u2018technology\u2019 companies are involved in operations that are directed and controlled by the countries\u2019 intelligence ministries.The initial breach with tactics and tools could be similar as \u2018regular\u2019 cybercrime operations, however it is important to monitor what is happening next and act fast &#8211; companies should audit their visibility and learn from tactics and operations conducted by actors targeting their sector.<\/p>\n\n\n\n<p><strong>Rise of smaller affiliates. <\/strong>The Ransomware-As-a-Service (RaaS) eco system has evolved with the use of affiliates, the middlemen and women that work with the developers for a share of the profits. However, for a long time, RaaS admins and developers were prioritized as the top targets, often neglecting the affiliates since they were perceived as less skilled. This, combined with the lack of disruptions in the RaaS ecosystem, will create an atmosphere where those lesser-skilled affiliates can thrive and grow into very competent cybercriminals, eventually with a mind of their own<strong>.<\/strong><\/p>\n\n\n\n<p><strong>Game of ransomware thrones<\/strong>. In 2022, theseself-reliant cybercrime groups will shift the balance of power within the RaaS eco-kingdom from those who control the ransomware to those who control the victim\u2019s networks. Ransomware has generated billions of dollars in recent years and it\u2019s only a matter of time before some individuals who believe they aren\u2019t getting their fair share become unhappy.<\/p>\n\n\n\n<p><strong>Keep a close eye on API. <\/strong>Recent statistics suggest that more than 80% of all Internet traffic belongs to API-based services. 5G and IoT traffic between API services and apps will make them increasingly lucrative targets, causing unwanted exposure of information. The connected nature of APIs potentially also introduces additional risks to businesses as they become an entry vector for wider supply chain attacks. In most cases, attacks targeting APIs go undetected as they are generally considered as trusted paths and lack the same level of governance and security controls.<\/p>\n\n\n\n<p><strong>Hijackers will target your application containers<\/strong>. Containers have become the de facto platform of modern cloud applications. In a recent IBM survey, 64% of adopters expected to containerize over 50% of existing and new business applications over the next two years. However, the accelerated use of containers increases the attack surface for an organization. And while attacks against containers are not new, in 2022, we anticipate expanded exploitation on the orchestration layers, increasing use of malicious or backdoored images through insufficient vulnerability checks and increasing attacks targeting vulnerable applications.<\/p>\n\n\n\n<p><strong>Zero cares about Zero-Days<\/strong>. 2021 is already being touted as one of the worst years on record with respect to the volume of zero-day vulnerabilities exploited in the wild. The scope of these exploitations, the diversity of targeted applications and ultimately the consequences to organizations were all notable. As we look to 2022, we expect these factors to drive an increase in the speed at which organizations respond. As a consequence, we can also expect renewed diligence around asset and patch management. From identifying public facing assets to quickly deploying patches despite potential business disruption, companies will have a renewed focus on reducing their \u2018time to patch\u2019.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>McAfee Enterprise and FireEye have released its 2022 Threat Predictions, examining the top cybersecurity threats they predict enterprises will face in 2022. Bad actors have taken note of successful tactics from 2021, including those making headlines tied to ransomware, nation states, social media and the shifting reliance on a remote workforce. McAfee Enterprise and FireEye [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":66368,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5307,3624,14804,5,6,13,79],"tags":[14242,2997,2604,1530,706,2761,3282,1043],"class_list":["post-66367","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-case-study-newsletter","category-cybersecurity","category-enterprise-security","category-insights","category-top-stories","category-used","tag-14242","tag-api","tag-containers","tag-cybersecurity","tag-fireeye","tag-mcafee","tag-raj-samani","tag-ransomware"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/66367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=66367"}],"version-history":[{"count":6,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/66367\/revisions"}],"predecessor-version":[{"id":66404,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/66367\/revisions\/66404"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/66368"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=66367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=66367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=66367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}