Site navigation

Report: Cyber-Crime Adapts and Overcomes

Elizabeth Greenberg

,

cyber-crime
Cyber-crime is thriving in the new threat landscape, with external dangers expanding as adversaries harness old techniques and master new tech. 

External threats to IT systems continue to expand with the advent of AI for phishing, the use of online advertisements as an attack vector, and continued quicker exploitation of new vulnerabilities.

This is according to new research from BlueVoyant, a cybersecurity company, which analysed the trends in external cyber-defence, highlighting some new risks organisations face from outside the traditional IT perimeters.

“Organisations’ attack surfaces are ever expanding, and cyber-threat actors are adapting their strategies to exploit new avenues of vulnerabilities,” said Joel Molinoff, BlueVoyant’s global head of supply chain defense. “BlueVoyant undertook this research to shine a light on the attack vectors organisations need to be aware of and recommended actions to help prevent the latest threats.”

AI continues to transform how enterprises do business with the ability to generate content efficiently. Cyber-criminals are also capitalising on AI to create more effective phishing campaigns.

While AI may not fundamentally change the way threat actors levy attacks, security teams should be aware of how their adversaries are using it to streamline their workflow and make brand abuse easier.

“The biggest cybersecurity risk from the increasing use of AI tools is an escalated volume of attacks,” said Ron Feler, BlueVoyant’s global head of threat intelligence. “While the essentials of the attacks don’t change, the increased number and diversity of attacks make defenders’ jobs more challenging.”

More advanced uses of AI, including AI-powered malware, are still in their infancy, according to the report, and do not post a severe threat – yet.

Further, attackers are now using online advertisements as attack vectors. Threat actors are using search engine ads as phishing distribution vectors to lure unsuspecting victims to malicious websites impersonating large financial institutions in the UK, US, and Eastern Europe.

Threat actors are able to use the customisation settings available for targeted advertisements to evade detection, as well as to display the ads only to specific users meeting their criteria.

The report also found that many organisations are not enabling all key components that secure the authenticity and integrity of the messages, which could leave them susceptible to email-based threats.


Recommended reading


Email authentication should be enabled all together, and organisations need to pay closer attention to services which connect their internal networks to external environments.

In previous reports, BlueVoyant found that organisations were often slow to patch systems even as attackers were exploiting new vulnerabilities faster. Now, the exploitation of vulnerabilities is happening even faster, prompting a high-stakes race between threat actors and defenders after a disclose.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data