Security Teams Face Burnout Amid Fight Against Geopolitically Motivated Attacks

By

Security teams today are facing endless waves of cyberattacks. They continue to reel from pandemic disruptions and burnout while bracing for a barrage of cyberattacks. Many of those attacks are geopolitically motivated – specifically, tied to Russia’s invasion of Ukraine. In fact, according to VMware’s eighth annual Global Incident Response Threat Report, 65% of defenders state that cyberattacks have increased since Russia invaded Ukraine of February 24.

Many of the cyber attacks are directly related to Russia’s Ukraine campaign.  Leading up to the invasion, Russian cyberattacks hit Ukraine’s largest gas retailer, their defense ministry’s website and at least 21 companies involved in the liquefied natural gas industry. This included Chevron, Cheniere Energy and Kinder Morgan. New malware and exploits targeting Ukrainian government networks, domestic telecom companies and other critical infrastructure continued after the invasion.

Zero-day exploits also are showing no signs of abatement after record levels last year. A little less than two-thirds of respondents said they experienced such attacks in the past 12 months, up from 51% in 2021. This surge is also attributed to largely to geopolitical conflict.

The report shined a light on emerging threats such as deepfakes. Deepfake attacks rose by 13% with 66% of respondents saying they witnessed them in the past 12 months. Email was the top delivery method at more than three-fourths, for such attacks, which corresponds with the rise in BECs. From 2016 to 2021, BEC incidents cost organizations an estimated $43.3 billion, according to the FBI.

“Cybercriminals have evolved beyond using synthetic video and audio,” said Rick McElroy, principal cybersecurity strategist at VMware. “Their new goal is to use deepfake technology to compromise organizations and gain access to their environment.”

APIs are also increasingly under threat – 23% of all attacks seen by respondents in the past 12 months compromised API security. Breached systems can be used to distribute attacks, known as progressive API attacks.

With rising threats, incident responders are fighting back and 87% saying that they are able to disrupt a cybercriminal’s activities sometimes or very often. However, they need to be able to perform even better if they hope to continue to repel threats. Security teams need more visibility across today’s widening attack surfaces to be better equipped to weather the storm.

To do this, security teams should:

  • Focus on workloads holistically. Companies must understand the inner workings of their entire workload.
  • Inspect in-band traffic. Many modern attacks succeed by disguising themselves as legitimate IT practices.
  • Integrate network detection and response with endpoint detection and response.
  • Embrace Zero Trust principles. This broad approach to security assumes every digital transaction could be dangerous.
  • Conduct continuous threat hunting. Security teams should assume attackers have multiple avenues into their organization.

Just as security teams were feeling a calm from pandemic disruptions, an endless wave of threats came in full force, and have not slowed down. As long as security teams have more visibility of the widening attack surface, they will be better equipped to defeat the bad actors and prevent successful attacks.




Edited by Erik Linask
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

TechZone360 Editor

SHARE THIS ARTICLE
Related Articles

ChatGPT Isn't Really AI: Here's Why

By: Contributing Writer    4/17/2024

ChatGPT is the biggest talking point in the world of AI, but is it actually artificial intelligence? Click here to find out the truth behind ChatGPT.

Read More

Revolutionizing Home Energy Management: The Partnership of Hub Controls and Four Square/TRE

By: Reece Loftus    4/16/2024

Through a recently announced partnership with manufacturer Four Square/TRE, Hub Controls is set to redefine the landscape of home energy management in…

Read More

4 Benefits of Time Tracking Software for Small Businesses

By: Contributing Writer    4/16/2024

Time tracking is invaluable for every business's success. It ensures teams and time are well managed. While you can do manual time tracking, it's time…

Read More

How the Terraform Registry Helps DevOps Teams Increase Efficiency

By: Contributing Writer    4/16/2024

A key component to HashiCorp's Terraform infrastructure-as-code (IaC) ecosystem, the Terraform Registry made it to the news in late 2023 when changes …

Read More

Nightmares, No More: New CanineAlert Device for Service Dogs Helps Reduce PTSD for Owners, Particularly Veterans

By: Alex Passett    4/11/2024

Canine Companions, a nonprofit organization that transforms the lives of veterans (and others) suffering PTSD with vigilant service dogs, has debuted …

Read More