Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

5/22/2018
03:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Las Vegas Most Insecure Cyber City in US; St. Louis Least Vulnerable

Forty-three percent chance of users connecting to high or medium-risk networks in Las Vegas - compared to less than 1% risk in least vulnerable areas, Coronet says.

Turns out that what happens in Las Vegas actually happens in at least a couple of other places as well - from a cybersecurity standpoint.

Residents of the Las Vegas, Memphis, and Charlotte metro areas are at substantially higher risk of data theft and other cybersecurity incidents compared to residents in more than four-dozen other areas in the US.

Cloud security vendor Coronet recently analyzed network connectivity and device related data in the 55 most populated areas in the country and found Wi-Fi and cellular networks — and the devices connecting to them — to be the most insecure in these three areas, the new study shows.

The risk level of a user, expressed in the form of a threat index score, was 10 on a scale of 10 in Las Vegas and 9.8 in both Memphis and Charlotte. People logging into websites or accessing cloud data in these designated market areas (DMAs) were most at risk of experiencing security incidents than anywhere else in the country.

"While in Las Vegas there was a 43% probability of users connecting to medium-risk or high-risk networks, in the least vulnerable cities the average probability was less than one percent," says Dror Liwer, Coronet's founder and CISO. "While in Memphis 7% of devices had no malware protection, the national average was 0.2%," he says.

Other risky cities and areas included Houston (9.2), Providence, RI (9.0), Birmingham, AL (9.0), and Jacksonville, FL (8.9). Rounding off the list of the Top 10 most insecure locations were three market areas in Florida — West Palm Beach-Ft. Pierce (8.9), Orlando-Daytona Beach (8.5), and Tampa–St. Petersburg–Sarasota (8.3).

For purposes of the ranking, Coronet considered any region with a threat index of 6.5 or less to be at an acceptable level of risk. By that metric, the least vulnerable metro in America from a cybersecurity standpoint in Coronet's list was the Richmond-Petersburg area in Virginia with a threat index of just 5.8.

Others in the Top 5 least vulnerable market areas were Greensboro-Winston Salem (6.2); Norfolk-Portsmouth-Newport News (6.2); Seattle-Tacoma (6.3) and St. Louis (6.3).

To arrive at the rankings, Coronet analyzed data collected from more than one million PCs, mobile devices, and tablets running its SecureCloud endpoint software. The collected data included device posture information as well as threat, attack, and vulnerability data gathered from the cellular and Wi-Fi networks to which the devices connected.

Scoring Cities

Coronet scored connectivity infrastructure based on factors like vulnerabilities and misconfigurations that were present on them as well on metrics like wrong routing and spoofing. Among the issues the company looked at were risks posed by captive portals, rogue access points, and honeypots. Devices were scored based on things like the presence or absence of active and updated anti-malware tools, active and updated firewalls, password protection, disk and storage encryption, and operating system integrity.

The company then combined and standardized the infrastructure vulnerability score with the device vulnerability score in each region to arrive at the overall Threat Index Score using a risk score range of 1 to 10,  where 10 represented the highest risk and 1 the lowest.

So why are some regions more risky than others from a security standpoint? It has a lot to do with the presence of more threat actors and activity in certain regions than others, Liwer says. "The main issue is not so much the carriers or network providers that are mostly standardized, but rather, the presence of malicious actors," Liwer says. "While the coffee chain network is configured the same way in [most] of its locations, the fact that three of its locations in Las Vegas are under attack has impact on the probability that users will connect to a malicious node." 

Coronet identified several factors as contributing to heightened threat activity in certain regions of the country. For instance, locations in which there are a lot of defense, financial services companies, manufacturing activity and aerospace firms — like the Tampa-St. Petersburg area and Jacksonville – generally tend to see heightened levels of threat activity.

Fast-growing metro regions and tourist destinations like the Orlando-Daytona DMA tend to be risky as well. For instance, more than 60 million people visited the Central Florida region in a 12-month period flooding the area with unsafe devices from around the world and making them a target for attackers, Coronet said.

Regions with aged or aging populations tend to attract a higher than average amount of threat activity as well. The West Palm Beach-Fort Pierce area with its large population of mostly older, wealthy and likely digitally unsophisticated residents makes for an attractive target for criminals as well.

Mixed Signals

The factors that make a region safer than others are less clear. For instance, the Seattle-Tacoma area, which ranked as the fourth safest in the Coronet report, is one of the most high tech regions in the country. But threat activity here is relatively low compared to areas with a similar high-tech profile. One reason could be because the state of Washington operates one of the most efficient cybersecurity agencies in the country. Similarly, the reason why St. Louis ranked as the fifth least vulnerable region in the country could have to do with presence of Missouri Cybersecurity Center.

Related Content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Tor Weaponized to Steal Bitcoin
Dark Reading Staff 10/18/2019
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
State of SMB Insecurity by the Numbers
Ericka Chickowski, Contributing Writer,  10/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18387
PUBLISHED: 2019-10-23
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
CVE-2019-18212
PUBLISHED: 2019-10-23
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal.
CVE-2019-18213
PUBLISHED: 2019-10-23
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response cap...
CVE-2019-18384
PUBLISHED: 2019-10-23
An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as demonstrated by the filename=*public*%25252Fadmin_OnlyRead.txt substring.
CVE-2019-18385
PUBLISHED: 2019-10-23
An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.