Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

9/24/2019
10:45 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Cloud-Native Breaches Differ Greatly from Malware Attacks of the Past: McAfee Report

Report demonstrates how 99 percent of misconfiguration incidents in public cloud environments go undetected, exposing companies to data loss.

SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee, the device-to-cloud cybersecurity company, today released Cloud-Native: The Infrastructure-as-a-Service Adoption and Risk Report, covering new research on Infrastructure-as-a-Service (IaaS) incidents in the cloud. According to industry analysts, IaaS is now the fastest growing area of the cloud due to the speed, cost and reliability with which organizations can create and deploy applications. The results of the survey demonstrate that 99 percent of IaaS misconfigurations go unnoticed—indicating awareness around the most common entry point to new “Cloud-Native Breaches” (CNB) is extremely low.

 “In the rush toward IaaS adoption, many organizations overlook the shared responsibility model for the cloud and assume that security is taken care of completely by the cloud provider,” said Rajiv Gupta, senior vice president of Cloud Security, McAfee. “However, the security of what customers put in the cloud, most importantly sensitive data, is their responsibility. To defend against the new era of Cloud-Native Breaches, organizations need to use security tools that are cloud-native, purpose-built for cloud security and address their portion of the shared responsibility model.”

IaaS breaches don’t look like your typical malware incident, instead leveraging native features of cloud infrastructure to land the attack, expand to adjacent cloud instances, and exfiltrate sensitive data. In most cases they “land” by exploiting configuration errors in how the cloud environment was set up. This research sheds light on the need for security tools to keep up with IaaS-native issues, especially the ability to continuously audit IaaS deployments for initial misconfiguration and configuration drift over time.

Cloud-Native: The Infrastructure-as-a-Service Adoption and Risk Report also reveals the following:

  • Practitioner-Leadership Disconnect: Results showed that 90 percent of companies have experienced some security issue in IaaS, misconfiguration or otherwise. Yet twice as many practitioners think they’ve never experienced an issue compared to their C-Level leadership. Only 26 percent are equipped to audit for misconfigurations in IaaS, which likely accounts for the lack of visibility. It is possible the speed of cloud adoption is putting some security practitioners behind, lacking the tools they need to stop CNBs, even while their leadership perceives greater risk.
  • Cloud Data Loss in IaaS is on the Rise: Incidents triggered by data loss prevention (DLP) rules in IaaS, such PCI data entering a storage object with public-read access, are up 248 percent year-over-year. Forty-two percent of the storage objects with DLP incidents were misconfigured.
  • IaaS is the New Shadow IT: Keeping track of security incidents in IaaS is increasingly difficult given the ease with which developers can spin up new infrastructure, and this is made worse when organizations operate in multiple cloud service provider environments. Seventy-six percent of respondents said they use multiple IaaS providers, yet data sourced from actual cloud usage shows 92 percent actually do. Incidents will go under the radar if companies aren’t aware of where their infrastructure lives.

For this report, McAfee surveyed 1,000 enterprise organizations worldwide about security issues in IaaS, with a focus on misconfigurations which in some cases have left millions of customer records and intellectual property open to theft. McAfee also analyzed its own customers’ use of IaaS through anonymized, aggregated event data across millions of cloud users and billions of events.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Active Directory Needs an Update: Here's Why
Raz Rafaeli, CEO and Co-Founder at Secret Double Octopus,  1/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
CVE-2020-7222
PUBLISHED: 2020-01-18
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (...