{"id":30908,"date":"2023-08-02T15:44:40","date_gmt":"2023-08-02T14:44:40","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=30908"},"modified":"2023-08-16T10:54:51","modified_gmt":"2023-08-16T09:54:51","slug":"nozomi-labs-report-shows-surge-in-ot-iot-security-threats","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2023\/08\/02\/nozomi-labs-report-shows-surge-in-ot-iot-security-threats\/","title":{"rendered":"Nozomi Labs report shows surge in OT &amp; IoT security threats"},"content":{"rendered":"\n<p><strong><em>Report reveals malware activity in OT and IoT environments worldwide jumped 10x the first half of 2023.<\/em><\/strong><\/p>\n\n\n\n<p>The latest Nozomi Networks Labs OT and IoT Security Report: <em>Unpacking the Threat Landscape with Unique Telemetry Data<\/em>, shows malware activity and alerts on unwanted applications&nbsp;increasing dramatically in OT and IoT environments.<\/p>\n\n\n\n<p>Unique telemetry from Nozomi Networks Labs \u2013 collected from OT and IoT environments covering a variety of use cases and industries worldwide \u2013 found malware-related security threats spiked 10x over the last six months.&nbsp;<\/p>\n\n\n\n<p>In the broad category of malware and potentially unwanted applications, activity increased 96%.<\/p>\n\n\n\n<p>Threat activity related to access controls more than doubled.<\/p>\n\n\n\n<p>Poor authentication and password hygiene topped the list of critical alerts for a second consecutive reporting period \u2013 though activity in that category declined 22% over the previous reporting period.<\/p>\n\n\n\n<p>Chris Grove, Director of Cybersecurity Strategy, Nozomi Networks, said: \u201cA significant decrease in activity per customer in categories such as authentication and password issues and suspicious or unexpected network behaviour suggests that efforts to secure systems in these areas may be paying off.&nbsp;<\/p>\n\n\n\n<p>\u201cOn the other hand, malware activity increased dramatically, reflecting an escalating threat landscape.<\/p>\n\n\n\n<p>\u201cIt\u2019s time to \u2018put the pedal to the metal\u2019 in shoring up our defences.\u201d<\/p>\n\n\n\n<p>Top critical threat activity in real world environments over the last six months were:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\">\n<li>Authentication and Password Issue \u2013 down 22%<\/li>\n\n\n\n<li>Network Anomalies and Attacks \u2013 up 15%<\/li>\n\n\n\n<li>Operational Technology (OT) Specific Threats \u2013 down 20%<\/li>\n\n\n\n<li>Suspicious or Unexpected Network Behaviour \u2013 down 45%<\/li>\n\n\n\n<li>Access Control and Authorisation \u2013 up 128%<\/li>\n\n\n\n<li>Malware and Potentially Unwanted Applications \u2013 up 96%<\/li>\n<\/ol>\n\n\n\n<p>Specific to malware, denial-of-service (DOS) activity remains one of the most prevalent attacks against OT systems, followed by the remote access trojan (RAT) category commonly used by attackers to establish control over compromised machines.&nbsp;<\/p>\n\n\n\n<p>Distributed denial of service (DDoS) threats are the top threat In IoT network domains.<\/p>\n\n\n\n<p>Malicious IoT botnets remain active this year. Nozomi uncovered growing security concerns as botnets continue to use default credentials in attempts to access IoT devices.<\/p>\n\n\n\n<p>Findings from January- June 2023 were:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>An average of 813 unique attacks daily \u2013 the highest attack day hit 1,342 on May 1<\/li>\n\n\n\n<li>Top attacker IP addresses were associated with China, the United States, South Korea, Taiwan and India<\/li>\n\n\n\n<li>Brute-force attempts remain a popular technique to gain system access \u2013 default credentials are one of the main ways threat actors gain access to IoT<\/li>\n<\/ul>\n\n\n\n<p>On the vulnerability front, Manufacturing and Energy and Water\/Wastewaterremain the most vulnerable industries.<\/p>\n\n\n\n<p>Food and Agriculture and Chemicals move into the top five replacing Transportation and Healthcare which were among the top five most vulnerable sectors in the previous six-month reporting period.<\/p>\n\n\n\n<p>In the first half of 2023:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CISA released 641 Common Vulnerabilities and Exposures (CVEs)<\/li>\n\n\n\n<li>62 vendors were impacted<\/li>\n\n\n\n<li>Out-of-Bounds Read and Out-of-Bounds Write vulnerabilities remained in the top CWEs &#8211; both are susceptible to several different attacks including buffer overflow attacks.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Report reveals malware activity in OT and IoT environments worldwide jumped 10x the first half of 2023. The latest Nozomi Networks Labs OT and IoT Security Report: Unpacking the Threat Landscape with Unique Telemetry Data, shows malware activity and alerts on unwanted applications&nbsp;increasing dramatically in OT and IoT environments. Unique telemetry from Nozomi Networks Labs [&hellip;]<\/p>\n","protected":false},"author":58,"featured_media":30909,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[510,3488,37,43,514],"tags":[626,4740,97,1820,4608,4741],"class_list":["post-30908","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-study-newsletter","category-cybersecurity","category-research","category-top-stories","category-used","tag-malware","tag-nozomi-labs","tag-ot","tag-report","tag-security-threats","tag-telemetry"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/30908","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/58"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=30908"}],"version-history":[{"count":6,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/30908\/revisions"}],"predecessor-version":[{"id":31105,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/30908\/revisions\/31105"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/30909"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=30908"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=30908"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=30908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}