Websense Security Labs has published a security survey it conducted in 2015. According to the Websense 2015 Threat Report, the volume of malware threats has decreased, despite an increase in breaches.
But the bad news comes later. Websense Security Labs reports that it recorded 3.96 billion online security threats in 2014, which is 5.1% fewer than the threats in 2013. Despite this, the number of high-profile breaches has increased.
Hackers seem to have changed tactics and from the massive, blatant breaches of past years, they prefer more "quiet, targeted and unique attacks" which, according to Websense, are much more effective.
The Websense 2015 Threat Report was published on Wednesday, April 8, and reports that malware authors continue to reuse the same delivery techniques and infrastructure.
99.3% of malware uses command and control infrastructures that have been used by other malware developers.
About one in three (30%) of end users click on malicious URLs that come in an email, even if they have been warned about the risk.
“End users appear to be becoming increasingly desensitized to warnings, do not feel responsible, and continue to lack training from the businesses they work for,” according to Websense.
Hackers, meanwhile, according to the company, gain skills through the adoption of tools available online, not because they have knowledge. This practically means that any restless 13-year-old can take down your website.
Script kiddies, according to the company, can now carry out successful attacks thanks to exploit kits for rent, Malware-as-a-Service, and other malicious services that they can freely purchase online.
In 2014, 81% of all emails scanned by Websense were classified as malicious. Websense Security Labs detected more than 3 million malicious files attached to emails in the last 30 days of 2014 alone.
The Websense 2015 Threat Report is available here, but registration is required.
