Vulnerabilities / Threats
12/27/2012
12:47 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Sophos Unveils Thirteen IT Security Trends For 2013

Report provides baseline of what all organizations should be prepared for in coming year

BOSTON, MA – December 21, 2012 – Sophos has released its Thirteen Trends for 2013 report, developed by James Lyne, director of technology strategy. Lyne anticipates the IT security industry will experience a continuation of trends present in 2012, and this report provides a baseline of what all organizations should be prepared for in the coming year.

Trends for 2013:

1. Attack toolkits will continue to proliferate

2. The modernization and hardening of operating systems

3. Cloud-based malware testing will change the threat protection model

4. An increased focus on layered security

5. One step forward, two steps back in technology adoption

6. Mobile attacks will become more advanced

7. Web servers will be back in the crosshairs

8. Further integration of devices, applications and networks

9. Increasingly diverse business models and irreversible malware

10. Skills problem will become more apparent

11. Cyber criminal anti-forensics will become more prevalent

12. More advanced hacktivism and political debate

13. Arguments will continue over big data vs. analytics and confusion

For more information about each trend, please see the full report on the Sophos website here.

Sophos recently released its Security Threat Report 2013, a comprehensive assessment of IT security happenings in 2012, including a look ahead at what's expected in 2013 including trends from bring your own device (BYOD) to the increasing adoption of and uncertainty around the cloud to countless other security challenges faced by organizations of all sizes. The full report is available for download here.

About Sophos

More than 100 million users in 150 countries rely on Sophos' complete security solutions as the best protection against complex threats and data loss. Simple to deploy, manage, and use, Sophos' award-winning encryption, endpoint security, web, email, mobile and network security solutions are backed by SophosLabs - a global network of threat intelligence centers.

Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-4801
Published: 2014-12-18
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before 4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.