Tag Archive for: Insights

Researchers Share New Insights Into RIG Exploit Kit Malware’s Operations


RIG Exploit Kit

The RIG exploit kit (EK) touched an all-time high successful exploitation rate of nearly 30% in 2022, new findings reveal.

“RIG EK is a financially-motivated program that has been active since 2014,” Swiss cybersecurity company PRODAFT said in an exhaustive report shared with The Hacker News.

“Although it has yet to substantially change its exploits in its more recent activity, the type and version of the malware they distribute constantly change. The frequency of updating samples ranges from weekly to daily updates.”

Exploit kits are programs used to distribute malware to large numbers of victims by taking advantage of known security flaws in commonly-used software such as web browsers.

The fact that RIG EK runs as a service model means threat actors can financially compensate the RIG EK administrator for installing malware of their choice on victim machines. The RIG EK operators primarily employ malvertising to ensure a high infection rate and large-scale coverage.

As a result, visitors using a vulnerable version of a browser to access an actor-controlled web page or a compromised-but-legitimate website are redirected using malicious JavaScript code to a proxy server, which, in turn, communicates with an exploit server to deliver the appropriate browser exploit.

The exploit server, for its part, detects the user’s browser by parsing the User-Agent string and returns the exploit that “matches the pre-defined vulnerable browser versions.”

“The artful design of the Exploit Kit allows it to infect devices with little to no interaction from the end user,” the researchers said. “Meanwhile, its use of proxy servers makes infections harder to detect.”

Since arriving on the scene in 2014, RIG EK has been observed delivering a wide range of financial trojans, stealers, and ransomware such as AZORult, CryptoBit, Dridex, Raccoon Stealer, and WastedLoader. The operation was dealt a huge blow in 2017 following a coordinated action that dismantled its infrastructure.

RIG Exploit Kit

Recent RIG EK campaigns have targeted a memory corruption vulnerability impacting Internet Explorer (CVE-2021-26411, CVSS score: 8.8) to deploy RedLine Stealer.

Other browser flaws weaponized by the malware include

Source…

Cyber security training: Insights for future professionals


In this era of digitalisation, the world is witnessing exponential growth in incidents that compromise the security of information owned by businesses or governments. Recently the Royal Mail’s overseas deliveries suffered severe disruption due to a ransomware attack linked to Russian criminals. In 2022, around 50 Indian government websites were hacked and eight data breaches were reported. These included a ransomware attack on some servers at the All India Institute of Medical Science (AIIMS) that paralysed operations of the premier medical institute in India for many weeks.

The tremendous increase in such incidents has fuelled the demand for qualified IT professionals who could prevent cyber attacks on critical government and business IT assets. But there exists a considerable mismatch in the supply-demand situation of qualified cyber security professionals. To complicate this further, professionals entering this field face difficulty in deciding what skills they should acquire. This article explores what paths are available in cyber security training by analysing reports released by two eminent associations in the field of information security.

The first report discussed is the latest edition of the annual report on the cyber security workforce released by (ISC)2 titled 2022 Cyber Security Workforce Study. This report presents insights into the challenges and opportunities faced by cyber security professionals around the world. The report was prepared after conducting a survey among 11,779 cyber security professionals. The study estimates that the size of the global cyber security workforce in 2022 was 4.7 million people and the gap in the global cyber security workforce stood at 3.4 million people, which is an increase of 26.6% at the year-over-year (YoY) level.

Clearly, there exists a wide gap between the supply and demand of cyber security professionals, and the shortage is more evident in the EMEA and APAC regions where the YoY increase is greater than 50%. Half of the cyber security professionals under age 30 who participated in the survey started their careers in IT and then moved to cyber security. Both vendor-neutral certifications (e.g., (ISC)2, ISACA or CompTIA)…

Source…

Computer Security for Consumer Market Size 2023 Comprehensive Insights and Capacity Growth Analysis 2026


The MarketWatch News Department was not involved in the creation of this content.

Feb 20, 2023 (The Expresswire) —
Pre and Post Covid Report Is Covered | Final Report Will Add the Analysis of the Impact of Russia-Ukraine War and COVID-19 on This Industry.

[98 Pages Report]Computer Security for Consumer Market” size is projected to reach Multimillion USD by 2026, In comparison to 2023, at unexpected CAGR during 2023-2026 and generated magnificent revenue. This study provides all the most recent market facts and trends for your business analytics and strategic decision-making. This Computer Security for Consumer Market research report is meant to be helpful to all business owners, investors, and stakeholders in the industry. It provides significant insights into the factors affecting the global Computer Security for Consumer market and the industry’s yearly growth.

The market is segmented on the basis of End-user Industry (Below 20 Years Old, 20-50 Years Old, Above 50 Years Old), By Type (Network Security, Identity Theft, Endpoint Security, Antivirus Software, Others), and Geography (Asia-Pacific, North America, Europe, South America, and Middle-East and Africa).

“Computer Security for Consumer market revenue was Million USD in 2016, grew to Million USD in 2020, and will reach Million USD in 2026, with a CAGR of during 2020-2026.”Ask for Sample Report

GlobalComputer Security for Consumer MarketReport 2023 is spread across98 pagesand provides exclusive vital statistics, data, information, trends and competitive landscape insights in this niche sector.

Who are some of the key players operating in the Computer Security for Consumer market and how high is the competition 2023?

Company Information: List by Country Top Manufacturers/ Key Players In Computer Security for Consumer Market Insights Report Are:

● Trend Micro ● F-Secure ● Bitdefender ● McAfee ● Avast ● Comodo ● NortonLifeLock ● Kaspersky Lab ● AHNLAB ● ESET ● Fortinet

Get a sample copy of the Computer Security for Consumer Market report 2023

Attractive Opportunities In the Computer Security for Consumer Market:

The Global Computer Security for Consumer market…

Source…

Cybersecurity Insights with Contrast CISO David Lindner | 12/23


David Lindner, Chief Information Security Officer

David is an experienced application security professional with over 20 years in cybersecurity. In addition to serving as the chief information security officer, David leads the Contrast Labs team that is focused on analyzing threat intelligence to help enterprise clients develop more proactive approaches to their application security programs. Throughout his career, David has worked within multiple disciplines in the security field—from application development, to network architecture design and support, to IT security and consulting, to security training, to application security. Over the past decade, David has specialized in all things related to mobile applications and securing them. He has worked with many clients across industry sectors, including financial, government, automobile, healthcare, and retail. David is an active participant in numerous bug bounty programs.

Source…