SonicWall has released its Mid-Year Cyber Threat Report 2024, which unveils yet another rise in overall attacks, after seeing an 11% increase observed in 2023.
SonicWall found that on average, companies were under critical attack – the type of attack most likely to deplete business resources – for 50 hours out of a 40-hour working week, with, according to SonicWall, 12.6% of all revenues exposed to cyber-threats without proper protection. For a £10 million company, that equates to £1.2 million.
The report reveals a 92% increase in encrypted threats, with cybercriminals utilising AI more and more to bypass traditional security measures.
Moreover, the threat to Internet of Things (IoT) devices has intensified, with attacks rising by 107%. On average, compromised IoT devices endured 52.8 hours under attack, underscoring their vulnerability. These devices are often targeted due to their insufficient security measures, providing an easy entry point for attackers.
Malware activity experienced a significant uptick, particularly from March to May, culminating in a 92% increase in May alone. Notably, 15% of all malware now leverages software packing as its primary MITRE tactic, technique, and procedure (TTP), highlighting a trend towards more complex and harder-to-detect malware.
While cryptojacking incidents saw a 60% decline globally after a record-breaking year, India witnessed an alarming 409% increase. This disparity suggests regional variations in threat activity and emphasises the need for localised cybersecurity measures.
Supply chains and business email compromise
Supply chain attacks have become a significant cybersecurity threat, exploiting vulnerabilities in third-party software and services to compromise broader networks. The first half of 2024 saw notable incidents such as the JetBrains TeamCity authentication bypass by manipulating HTTP 404 responses and JSP query parameters, leading to unauthorised access and exploitation by cybercriminals.
Older vulnerabilities, such as Log4j and Heartbleed, continue to pose significant risks, particularly for small businesses with limited resources. The report indicates that over 50% of customers were affected by supply chain vulnerabilities.
Business email compromise (BEC) attacks have also surged, with insurance data showing ten BEC events for every ransomware incident. These attacks often involve social engineering tactics, manipulating individuals into transferring funds or sensitive information. Notably, Microsoft Office 365 misconfigurations have contributed to the rise in BEC incidents.
Phishing tactics have also evolved, with attackers increasingly using HTML files, AI, and QR codes to enhance their campaigns. The report highlights a significant rise in QR code phishing, or “quishing,” which has grown from 0.8% in 2021 to 10.8% of all phishing attacks in 2024.
The rise in IoT attacks has become a major concern, with incidents like the Volt Typhoon botnet attack and coordinated assaults on Denmark’s energy sector illustrating the growing threat. Attackers are exploiting vulnerabilities in IoT devices to form botnets capable of executing large-scale Distributed Denial-of-Service (DDoS) attacks.
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
PowerShell has also become a favoured tool for cybercriminals due to its powerful scripting capabilities and deep integration with Windows. More than 90% of prevalent malware families now leverage PowerShell, with 73% using it to download additional malware or evade detection.
“The threat landscape is completely overwhelming for organisations and the teams who defend them,” said SonicWall partner and Fornida COO Steven Huang.
He concluded: “Most cybersecurity breaches include some degree of human error. Ultimately, there are two ways to battle this; reducing opportunity and educating users. The fewer opportunities there are for an error, the less users will be tested. And the more knowledge they have, the less likely they are to make a mistake even when they face an opportunity to do so.”





