Attacks/Breaches
12/24/2009
12:06 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Top 10 Security Challenges For 2010

Cloud-hosted malware, bot blasts, compromised smartphones, and privacy-busting malvertising are a few of the security pitfalls we can expect this year.

6. Bots, Bots, And More Bots

Why bother with cloud-hosted malware when botnets offer the same service for less? Even better for cybercriminals, botnets offer a source of income. For security vendors, that suggests bots will continue to become more sophisticated. Botnets have become the foundation of cybercrime, Symantec claims.

Dan Hubbard, CTO of Websense, said that there has been some good news about bots -- better communication in the security community and with law enforcement, resulting in more arrests and botnet takedowns than in the past.

But because botnets generate cash for criminals, he expects more criminal gangs will choose a path to wealth that's easier than building a botnet: hijacking a botnet operated by a different gang.

That kind of conflict could actually limit botnet growth or at least attract the attention of security experts and law enforcement. Contrarian view: Botnets not only have to defend against security researchers, but against other botnet operators. Websense sees botnet gangs fighting turf wars, similar to the way that the Bredolab botnet shut down the Zeus/Zbot on infected computers.

7. Piracy Gets Riskier

In early December, Microsoft launched a broad effort to reduce software piracy, noting that it has received a rising number of complaints from users who purchased or otherwise obtained pirated versions of Windows.

It seems that counterfeit software is increasingly infected software. IBM Internet Security Systems' X-Force researchers expect that use of pirated software will increasingly lead to malware infection and that users of such software will become the "Typhoid Marys" of the global computing community.

Contrarian view: Will the last user of desktop software please turn out the lights? We're all moving into the cloud where we don't have to worry about a counterfeit, infectious version of Google Apps, at least until someone alters our DNS host file.

8. Mobile Security Becomes Real Issue

"Smartphones such as the iPhone and Android-based handsets, which are used increasingly for business purposes, are essentially miniature personal computers, and in 2010 will face the same types of attacks that target traditional computing," predicts Websense. And the company is not alone in that belief. Practically every security vendor has or is developing a mobile security product or service. As with Macs, the security industry would welcome a new market.

Websense's Hubbard says it will be interesting to see how Apple's closed App Store and Google's more open Android Market compare in terms of mobile malware in 2010.

Contrarian view: The researchers at IBM ISS X-Force believe that attacks on mobile phones will remain scarce. But while network-based attacks on mobile phones may remain relatively rare, physical attacks will rise: Snatch-and-grab attacks are considerably easier than cyberattacks and produce both data and a physical item that can be sold. With unemployment over 10%, unsolicited phone collection could become a growth industry.

Previous
3 of 4
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.