
Technologies are evolving and becoming more complex year after year, and along with them, attack methodologies are also improving. Modern realities demand online applications, cloud services, and virtualization platforms, so it's no longer possible to hide behind a corporate firewall and avoid the 'dangerous internet'. All of this, along with the spread of IoT/IIoT, the development of fintech, and the growing popularity of remote work, has dramatically changed the landscape of threats. Let's talk about the cyber dangers that await us in 2020.
Exploitation of 0day vulnerabilities will outpace the release of patches.
The complexity of software systems is increasing, and as a result, they inevitably contain bugs. Developers release fixes, but first, the problem must be identified, which takes time from adjacent teams, including testers who are forced to conduct tests. But many teams are catastrophically short on time. The result is an unacceptably long patch release, or even the appearance of a patch that only works partially.
Released in 2018, that is, it did not resolve the issue completely.
In 2019, Cisco released .
In September 2019, researchers however, they did not fix the error within 90 days.
Blackhat and Whitehat hackers are diligently searching for vulnerabilities, so the likelihood that they will discover a problem first is significantly higher. Some of them aim to receive rewards through Bug Bounty programs, while others pursue specific malicious goals.
More attacks using deepfakes.
Neural networks and artificial intelligence are advancing, creating new opportunities for fraud. Following the fake porn videos featuring celebrities, concrete attacks causing serious financial damage have emerged.
In March 2019, perpetrators stole $243,000 from an energy company with a single phone call."The head of the parent company" instructed the branch manager to transfer money to a contractor from Hungary. The CEO's voice was forged using artificial intelligence.
Given the rapid development of deepfake technology, it is expected that cybercriminals will incorporate the creation of fake audio and video clips into BEC attacks and technical support scams to increase user trust.
Top executives will be the main target for deepfakes, as recordings of their conversations and speeches are publicly accessible.
Attacks on banks through fintech
The adoption of the European payment services directive PSD2 has enabled new types of attacks on banks and their clients. This includes phishing campaigns against users of fintech applications, DDoS attacks on fintech startups, and data theft from banks through open APIs.
Complex attacks through service providers
Companies are increasingly narrowing their specialization, outsourcing non-core activities. Their employees develop trust in outsourcing firms that handle accounting, provide technical support, or ensure security. As a result, compromising just one service provider is sufficient to infiltrate the target infrastructure with malicious code, steal money, or information.
In August 2019, hackers penetrated the infrastructure of two IT companies providing data storage and backup services, and through it
An IT company servicing the New York Police Department temporarily incapacitated the fingerprint database,
As supply chains grow longer, more weak links emerge that can be exploited to attack the largest targets.
Another factor that will facilitate supply chain attacks is the widespread adoption of remote work. Freelancers working via public Wi-Fi or from home are easy targets, as they can interact with several major companies, making their compromised devices a convenient platform for preparing and executing further stages of cyber attacks.
Widespread use of IoT/IIoT for espionage and extortion
The rapid growth of IoT devices, including smart TVs, smart speakers, and various voice assistants, combined with a large number of vulnerabilities found in them, will create many opportunities for unauthorized use.
Compromising smart devices and using AI for speech recognition allows the identification of the surveillance object, turning such devices into tools for extortion or corporate espionage.
Another area where IoT devices will continue to be used is in creating botnets for various malicious cyber services: spam distribution, anonymization, and conducting .
The number of attacks on critical infrastructure objects equipped with components will increase. Their aim could be, for example, ransom extortion under the threat of stopping the operation of the enterprise.
The more clouds, the more dangers
The mass migration of IT infrastructures to the cloud will create new targets for attacks. Deployment and configuration errors in cloud servers are successfully exploited by malicious actors. The number of leaks related to unsafe database configurations in the cloud increases every year.
In October 2019, an ElasticSearch server was discovered in the public domain, containing
At the end of November 2019, , which included full names of subscribers, email addresses, and phone numbers, as well as the texts of SMS messages.
Leaks of data hosted in the cloud will not only damage the reputation of companies but also lead to fines and penalties.
Insufficient access restrictions, improper permission management, and negligence in logging are just some of the mistakes companies will make when setting up their cloud networks. As migration to the cloud increases, third-party service providers with varying security expertise will become more involved in this process, creating additional opportunities for attacks.
Escalation of virtualization issues
Containerization of services simplifies the development, maintenance, and deployment of software; however, it also introduces additional risks. Vulnerabilities in popular container images will continue to be a problem for all who use them.
Companies will also have to face vulnerabilities in various components of the container architecture, from runtime errors to orchestrators and build environments. Malicious actors will seek and exploit any weaknesses to compromise the DevOps process.
Another trend related to virtualization involves serverless computing. According to Gartner's forecast, These platforms allow developers to execute code as a service, eliminating the need to pay for entire servers or containers. However, transitioning to serverless computing does not guarantee immunity from security issues.
Entry points for attacks on serverless applications will be outdated and compromised libraries, as well as improperly configured environments. Attackers will use these to collect sensitive information and infiltrate corporate networks.
How to counter threats in 2020
Given the increasing complexity of cybercriminal activities, companies will need to expand their collaboration with security experts to mitigate risks across all sectors of their infrastructure. This will enable defenders and developers to gain insights and better control network-connected devices and address vulnerabilities.
The constantly evolving threat landscape will require the implementation of multi-layered protection based on security mechanisms such as:
- detecting successful attacks and mitigating their impacts,
- managed detection and attack prevention,
- behavioral monitoring: proactive blocking of new threats and detection of anomalous behavior,
- endpoint protection.
A lack of skills and low quality of knowledge in cybersecurity will determine the overall level of security within organizations, therefore another strategic task for their leadership should be the systematic training of safe employee behavior combined with raising awareness in information security.
Source: habr.com
