Our report on the threats seen in 3Q 2014 shows us that once again, software vulnerabilities are the most favored cybercriminal targets. Following the second quarter’s infamous Heartbleed vulnerability came another serious vulnerability in open-source software: Shellshock. Having gone unnoticed for years, the Shellshock incident suggests that there might be more vulnerabilities in Bash or in applications previously thought safe. Below is a timeline of events that Shellshock unraveled.
Figure 1. A timeline of events that illustrate the Shellshock exploitation that took place last quarter.
Apart from threatening to wreak havoc on over half a billion servers and Linux and UNIX systems worldwide, Shellshock also proves that cybercriminals and attackers still target systems that users may tend to overlook. Case in point, the third quarter also exposed several loopholes in point-of-sale (PoS) systems, whose threats appear to be growing as evidenced by last quarter’s Home Depot data breach.
Vulnerabilities were also seen in Android-based devices with over 75% of Android users affected by both FakeID vulnerability and Android browser flaws. Here’s a breakdown of the Android OSes affected by these vulnerabilities that we’ve also included in our report:
Figure 2. Android Operating Systems Affected by FakeID and Android Browser Vulnerabilities.
Apart from targeting the mobile platform, threat actors also utilized vulnerabilities to launch attacks, which signaled a dire need for network administrators to be able to spot indicators of compromise (IOCs) and implement effective network monitoring.
For more details about these and other security threats in the third quarter, check our security roundup titled Vulnerabilities Under Attack: Shedding Light on the Growing Attack Surface.
'Security_News > 해외보안소식' 카테고리의 다른 글
윈도우 커버로스(Kerberos) 취약점 발생 (0) | 2014.12.04 |
---|---|
日本 IPA, 2014년 3분기 소프트웨어 취약점 신고 현황 발표 (0) | 2014.12.04 |
美날씨채널 웹사이트 XSS 취약점 패치 (0) | 2014.12.04 |
월스트리트 기업 내부정보 절도 (0) | 2014.12.03 |
소니 픽쳐스 공격자, 미발표 영화 유출 (0) | 2014.12.03 |