Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

11/12/2013
02:39 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Report: Social Media Gets Abused

New data culled from real-world branded social media accounts shows cybercriminals' obsession with going social

Social media postings between 1 a.m. and 3 a.m. mostly come from rogue accounts, and social spam is growing 100 percent faster than legitimate posts and comments, according to new data gleaned from corporate social media content.

And in case you think Facebook and Twitter get hit with the most malicious content, think again: YouTube has five times more bad content than those two social networks, Google+, and other social networks, according to new data gathered by Nexgate, a cloud provider of brand protection and compliance for enterprise social media accounts.

The data was culled from Nexgate's scan of more than 100 million pieces of social media content, mostly from what it monitors for its global financial services, pharmaceutical, Internet security, manufacturing, media, and retailer customers. The data came from some 10,000 branded social media accounts supporting 25 million users.

About 12 percent of all questionable social media content includes malware, spam, and criminal activity, and 80 percent of social media postings in the wee hours of 1 a.m. to 3 a.m. are from rogue accounts.

"Roughly 90 percent of the bad stuff on branded social media accounts is content that violates acceptable use policy -- things like adult content, hate speech, pornography, as well as controversial topics like politics and religion," says Harold Nguyen, lead data scientist at Nexgate.

Nexgate also found a nearly 400 percent increase in the volume of security and compliance risks in brands' social media accounts. "This increase isn’t just from everyday consumers. Increasingly, it’s from automated bots and fake accounts, which the bad guys have created as an efficient source for getting revenue from unprotected organizations and their unsuspecting consumers," he says.

Corporate brands have an average of six apps connected to their social media accounts, and they have an average of more than 300 social media accounts.

Spam is a big problem in social media: About 5 percent of social apps are spam-related, according to Nexgate's data, and one in 200 social media messages contain spam. During the period of January through July 2013, social media spam jumped by a whopping 355 percent, the data shows.

Another fun fact: Spammers typically send spam to a minimum of 23 different social media accounts.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Deliver a Deadly Counterpunch to Ransomware Attacks: 4 Steps
Mathew Newfield, Chief Information Security Officer at Unisys,  12/10/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19604
PUBLISHED: 2019-12-11
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
CVE-2019-14861
PUBLISHED: 2019-12-10
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permiss...
CVE-2019-14870
PUBLISHED: 2019-12-10
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authent...
CVE-2019-14889
PUBLISHED: 2019-12-10
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence...
CVE-2019-1484
PUBLISHED: 2019-12-10
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.