Site navigation

Menlo Security Report Highlights Dangerous Lack of Web Security

Ross Kelly

,

Dark Web

Menlo Security’s State of the Web report has highlighted a concerning lack of security on millions of websites around the world. 

According to a report by Menlo Security, nearly half of the world’s most popular websites are ‘risky’ in regards to cybersecurity.

The State of the Web report, published this month, analysed the Alexa Top 100,000 websites for the first half of 2018 and found that 42% of websites were risky to web users. Despite this, the UK was identified as one of the least dangerous places to browse the web.

UK Analysis

As part of the report, websites were deemed a risk to users if they were built on – or connected to – sites that used vulnerable server software. Websites that have previously suffered security breaches or those that had been exploited to launch attacks in the previous 12-months were also deemed a risk to users.

Although the report highlights the dangers of web browsing, the UK was found to be among the safest countries on earth for web users. As one of six nations analysed in detail, researchers examined the nation’s top 50 websites; analysing how much code was fetched and executed by the sites, as well as the type of code and its origin.

The report said: “People in different countries prefer different websites, and the risks associated with using the most popular sites in those countries varies accordingly,”

The UK had the second joint-lowest number of scripts executed per website (41) and also the sole website with the highest amount of scripts executed from background domains (156). According to the report, scripts can enhance a user’s browsing experience, however, they can also be hijacked and manipulated by malicious actors to deploy malware or launch attacks.

Just over half of UK websites (52%) downloaded more than 1MB of code onto a user’s device, ranking it third for the average amount of code downloaded (1.55MB). The US placed first in this category, with user’s downloading around 1.8MB of code.

Although the UK ranked well in regard to web security, Menlo Security said: “the web remains a dangerous place for users to work and play.”

Vulnerabilities

A particular weakness identified by the Menlo Security report was web software, with many of the world’s most popular sites running on back-end servers that are antiquated and may not have been updated for several years. These websites, the report said, are highly vulnerable to malware and could expose visitors to infections or breaches are a far higher rate.

Analysis showed that 7.6% of web domains that delivered malware are being hosted on vulnerable servers; which include sites running on outdated versions of Apache, nginx, Microsoft IIS, Drupal and a host of others. In the US, the oldest software being used was PHP version 5.2.3.

This software was released more than a decade ago in 2007, and could leave web users at great risk of attack.

According to the report, “active content downloads and scripts running in the background will continue to be essential to providing a great, dynamic web experience, but there is no excuse for popular websites to use vulnerable server software”

The report added: “Doing so creates a clear and present danger to the sites’ visitors and to the websites to which it serves background content.”

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data