HomeSecurityThe real insider threat is security software

The real insider threat is security software

A malicious threat is defined as a security risk that originates within an organization, and with the total cost averaging $11.45 million, it is important for organizations to address this issue. Often, the risk is attributed to malicious or negligent employees, as well as others close to the organization, such as contractors and business partners. But companies and organizations believe that security software will prevent threats. However, this understanding of malicious threats shifts the blame to the human factor, in other words, it exposes them as scapegoats.

While there are people who actively seek to harm an organization, according to the Ponemon Institute report called “The 2020 Cost of Insider Threat Report,” only 23% are insider threats.

Instead of blaming people then, why don't we turn our attention to the root of the problem? Namely, security software.

Whether it's embedded in vulnerabilities, corrupted by governments, or used as a conduit to collect data for profit, the use of security software is currently fraught with problems.

The real insider threat is security software

Double agents in security

One of the largest and most widely used security software providers is the Czech antivirus company Avast, with over 435 million active users in 59 countries using the antivirus. However, as of late January 2020, Avast was collecting user data and selling it to third-party clients through their subsidiary Jumpstart. In this sense, they are working as double agents against the very people who have entrusted them with their online security and, more specifically, their privacy.

In many cases, the software itself is flawed. According to the Veracode SOSS Vol. 10 report published last year, approximately 10 million vulnerabilities were found in 85,000 applications, and 83% of these applications had at least one flaw in the initial scan. Of these vulnerabilities, 20% were rated as “high” or “very high” severity. By exploiting these vulnerabilities, hackers are able to infiltrate an organization and gain access to its data.

Complicating matters further, the sheer scale and complexity of vulnerabilities make it much more difficult to ascertain whether or not a system has been patched. Indeed, the majority of data breaches (60%) occur because software vulnerabilities were left unpatched. The 2017 Equifax data breach and the 2018 Marriott breach are two examples of this type, collectively exposing over 640 million records.

Monkey business in government

In some cases, the government is involved, not in a way that resolves privacy violations or arrests the criminals behind the attacks. Instead, they are the perpetrators. The attacks carried out by APT5, also known as Manganese, on high-tech VPN servers are a clear example.

Since August 2019, it has been revealed that Chinese state-backed hackers have been conducting web scans looking for Fortinet and Pulse Secure VPN servers. They then attempted to exploit two vulnerabilities in these VPN servers to gain access to files without the need for authentication. In doing so, they allowed hackers to gain access to passwords and VPN session data from vulnerable devices. The Iranians are not far behind. A report by cybersecurity firm ClearSky revealed that Iranian government-backed hacking units prioritized exploiting VPN flaws as soon as they were published.

Fortinet and Pulse Secure VPN servers are widely used, with hundreds of thousands of customers. In particular, Pulse Secure is popular among numerous Fortune 500 companies, including some of the largest technology companies and government organizations. The use of a VPN server is, primarily, to protect their internal servers from unauthorized access. However, if they don’t, how can we turn around and blame employees when a breach occurs?

Phishing for a scapegoat

Finally, there’s scareware. As the name suggests, scareware is a form of phishing that preys on your fear and perception of an impending threat. Through a pop-up ad, cybercriminals send warnings suggesting that your computer is infected with malware or is “running slow.” They then exploit your anxiety and panicked reaction to offer a “solution.”

However, the “solution”, which is of course fake, allows the malicious hacker to access your data and install malware on your computer, maybe even ransomware. In this kind of scenario, it’s easy to point the finger at the person who clicked on the ad, but what about the security software providers who would allow this? Isn’t it the responsibility of security software programs to detect malicious ads and prevent them from appearing on your screen?

The real threat

In the end, let’s ask ourselves who the real threat is. Often, people are portrayed as the weakest link and responsible for exposing organizations to malicious threats. However, looking at the evidence, the problems seem to stem from security software and providers . Considering that they are the ones who are supposed to protect us, both as individuals and as organizations, from a cyberattack, it is rather ironic that they are actually the problem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS