“Hackers don’t break in, they log in,” WatchGuard’s CSO said last week at the Channel Company’s Midsized Enterprise Summit, explaining why multi-factor authentication is critical and how every employee within a company should be required to use it. He also highlighted how ransomware groups are going big game hunting now, with larger payouts and double and triple extortion. And in a report from Positive Technologies, 69% of all malware attacks include ransomware.
There’s no honor among thieves, however. Turns out REvil added a back door to hijack ransomware negotiation from their affiliates to cut them out from payments. Security researchers have confirmed previous rumors.
CISA has released an advisory on Conti ransomware, noticing an increase in attacks. And Microsoft has uncovered a Phishing as a Service operations. An entire phishing operation, including collections of pages and templates combined with hosting and email sending service. Register for $800, and new templates for attack run from $80 to $100 within a full ecommerce store.
Let’s Encrypt, will stop using an older root certificate next week. Users running older versions of macOS from 2016 and Windows XP (with Service Pack 3) are likely to face issues, along with clients dependent on OpenSSL 1.0.2 or earlier, and older PlayStations that haven’t been upgraded to newer firmware.
Also on older tech – Apple has depreciated Transport Layer Security 1.0 and 1.1, and plans to remove support entirely in future releases. Mind you, that’s 20 year old tech.
According to a report by cybersecurity researchers at Netscout, there were 5.4 million recorded DDoS attacks during the first half of 2021 – a figure that represents an 11% rise compared with the same period last year.
And, Microsoft is investigating a new Exchange bug. Found in Autodiscover, it can be leveraged to grab Windows user’s credentials. The researchers released the flaw before notifying Microsoft.
All this security stuff is stressing people out. Kaspersky’s research says that 70% of consumers are stressed about breaches – although this is a decrease since 2019 and 2018. That all said… it has not led to action.
I want to highlight that ecommerce option for criminals here. That’s how easy it is to get into the field. There is certainly no loyalty there, but with the criminals – better knowns as a businesses’ competition – finding it so easy to make money, it’s no wonder we’re seeing this.
Of course, on the defender’s side, we’re still looking at supporting 20 year old tech. The fact that those two technical issues are stories speaks to the problem… but also the opportunity. If security threats ARE viewed as competition, then the framing of the investment to eliminate those older problems is entirely one of besting the competition. It’s a framing I’m growing increasingly fond of.

