Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

1/20/2011
01:49 PM
50%
50%

Malware, Mobile Lead SMB Security Threats

Online marketing and blogs are another key attack vector that small and midsize businesses need to guard, says Blue Coat Security researcher.

Top 10 Security Stories Of 2010
(click image for larger view)
Slideshow: Top 10 Security Stories Of 2010

The fact that attacks on SMB systems don't often generate headlines -- as with recent government or larger enterprise hacks -- might actually make them more vulnerable. Awareness is key, especially in organizations where IT resources are spread thin, as when all tech things fall on the shoulders of one manager or employee.

"For the SMBs who don't have the level of budget and security people that a larger organization might have, the problem's magnified," Larsen said.

He encourages systems administrators and other IT pros at SMBs to think about what kinds of attacks their company might attract and what the attacker might be after -- financial and customer information are two common targets -- and then adds some unsettling advice: "You have to start from the premise that whatever defenses you have put in place won't work."

That's not intended to cause hopelessness, but rather to keep SMBs alert and better able to identify unusual activity on their networks. That remains true, Larsen said, even when a smaller firm has enlisted the help of a vendor like Blue Coat.

Staying current with patches -- and not necessarily just waiting for automatic updates -- is also critical: "It's a necessary nuisance that you have to keep up with," Larsen said. Education, too, is important: Larsen recommends blogs such as Threatpost, Krebs on Security, and, of course, Blue Coat's own security blog as good ways to keep tabs on what's out there. Staying in the loop is especially important as newer technologies, such as HTML5, emerge and evolve.

Larsen said the rapid rise of online marketing channels such as social media and turnkey blogging platforms has likewise increased exposure to security risks. "It's become really easy for someone who sets up a Web site now to add all kinds of cool stuff to it just by clicking a check box," Larsen said. "By checking that box, I've now introduced another security hole."

A marketing manager with virtually no Web development chops, for example, can launch a company blog within a matter of minutes today. But if no consideration is given to the blog as a potential entry point for an attack and monitoring it accordingly, it could easily become vulnerable. Larsen said he encounters countless instances of malware that can be traced back to dead blogs and wikis, particularly those that are still running on older versions of the software platform.

In 2011, staying offline likely isn't a feasible sales and marketing approach for most SMBs. But doing business online requires a certain amount of vigilance.

"You now have a moral responsibility to keep an eye on how the bad guys might try to use your Web site as a way as a way to get into your customer database," Larsen said. "If you're not willing to do that, you need to find somebody who will, or have the discussion that maybe this isn't worth the hassle, it's not worth the risk."

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-20288
PUBLISHED: 2021-04-15
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associa...
CVE-2021-31229
PUBLISHED: 2021-04-15
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant.
CVE-2021-28548
PUBLISHED: 2021-04-15
Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted JSX file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploi...
CVE-2021-28549
PUBLISHED: 2021-04-15
Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted JSX file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploi...
CVE-2021-30209
PUBLISHED: 2021-04-15
Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may lead to obtaining system permissions.