HomeSecurityRansomware: Security vulnerabilities are increasingly being used for initial access

Ransomware: Security vulnerabilities are increasingly being used for initial access

Cybercriminals are frequently changing their tactics to increase the chances of a ransomware, with most attacks now exploiting security vulnerabilities, according to a study by Corvus Insurance.

ransomware vulnerabilities

The cybersecurity insurance company analyzed data from this year to better understand the activity of ransomware gangs.

It claimed that exploiting security vulnerabilities has increased significantly as a method for initial access to systems. In the first half of 2023, one-third of ransomware attacks used vulnerabilities to infiltrate networks.

See also: Apache Struts: Hackers exploit a critical vulnerability

This data may not be representative. The truth is that this year there was a massive exploitation of some vulnerabilities found in MOVEit and GoAnywhere. However, again, there seems to be a relevant evolution in the activity of ransomware gangs.

Corvus also noted that exposed cryptographic keys have become a key way organizations are compromised. It claimed that 7% of the organizations it studied had at least one exposed secret, with the most common being Google API keys, JSON web tokens, Shopify domain keys, and keys for AWS S3 buckets.

See also: Apple fixes zero-day vulnerabilities in older iPhones

However, not all exposed data is equally dangerous for organizations. According to the researchers, the most important ones, and those that require the most attention, “include AWS API keys, keys for cloud storage buckets (AWS S3 and Google Cloud Storage), and API keys from a number of non-cloud services, including LinkedIn, Okta, Slack, MailChimp, Facebook, New Relic, Stripe, and Sauce Labs.”

Ransomware: Security vulnerabilities are increasingly being used for initial access

Protection of organisms

Organizations can identify and protect themselves from cyberthreats and ransomware attacks through a combined security approach. First, they should conduct a security assessment to identify any vulnerabilities in their systems and applications. This can include analyzing network accesses, verifying access rights, and detecting malicious programs. Based on the results of this assessment, organizations can take steps to strengthen their security.

See also: CISA adds two Qlik Sense vulnerabilities to the KEV List

Another way to protect against cyber threats is through user education. Organizations should seek to raise awareness of cyber threats and provide them with appropriate training to identify and avoid risks. This may include training on safe internet browsing, avoiding opening unsolicited emails, and using strong passwords.

Additionally, organizations must keep up-to-date systems their with the latest security patches and monitor reports of new cyber threats. Finally, organizations must implement strong security measures, such as data encryption and the use of multi-factor authentication, to protect their sensitive information.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS