September 26, 2013 By Caleb Barlow < 1 min read

2013 is well on its way to be another record year for cyber intrusions, keeping security as a topic in every corporation’s boardroom and in every government agency.

How many vulnerabilities did your security team find scanning today, last month, or this year? And how many were high risk? In the first six months of 2013, the IBM X-Force Research and Development team analyzed 4,100 new security vulnerabilities and 900 million new web pages and images.

The IBM X-Force team just released their Trend and Risk Report which summarizes their findings on emerging threats and the 2013 attack landscape. If you are a CIO, CEO, CISO or a line of business executive this must read report outlines the new attack opportunities in areas like:

  • Social media: how social media is a valuable tool for business, but is also being used by attackers for reconnaissance and launching attacks
  • Mobile device malware: how the explosive growth of Android devices is attracting malware authors
  • Poisoning the watering hole: how attackers are compromising a central strategic target and launching zero day exploits
  • Distraction and diversion: how attackers are amplifying Distributed-Denial-of-Service (DDoS) attacks as a distraction to allow them to breach other systems
  • Old techniques, new success: how today’s security complexity can enable old gaps to be exploited

Read the latest research from IBM X-Force

More from X-Force

Hive0051 goes all in with a triple threat

13 min read - As of April 2024, IBM X-Force is tracking new waves of Russian state-sponsored Hive0051 (aka UAC-0010, Gamaredon) activity featuring new iterations of Gamma malware first observed in November 2023. These discoveries follow late October 2023 findings, detailing Hive0051's use of a novel multi-channel method of rapidly rotating C2 infrastructure (DNS Fluxing) to deliver new Gamma malware variants, facilitating more than a thousand infections in a single day. An examination of a sample of the lures associated with the ongoing activity reveals…

Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns

13 min read - As of March 2024, X-Force is tracking multiple ongoing ITG05 phishing campaigns featuring lure documents crafted to imitate authentic documents of government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America. The uncovered lures include a mixture of internal and publicly available documents, as well as possible actor-generated documents associated with finance, critical infrastructure, executive engagements, cyber security, maritime security, healthcare, business, and defense industrial production. Beginning in November 2023, X-Force observed ITG05…

Why federal agencies need a mission-centered cyber response

4 min read - Cybersecurity continues to be a top focus for government agencies with new cybersecurity requirements. Threats in recent years have crossed from the digital world to the physical and even involved critical infrastructure, such as the cyberattack on SolarWinds and the Colonial Pipeline ransomware attack. According to the IBM Cost of a Data Breach 2023 Report, a breach in the public sector, which includes government agencies, is up to $2.6 million from $2.07 million in 2022. Government agencies need to move…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today
Press play to continue listening
00:00 00:00