Connect with us

Technology

IBM Report: Ransomware Persisted Despite Improved Detection in 2022

Published

on

Manufacturing Most Extorted Industry; Email Thread Hijacking Attempts Spike; Time to Ransom Moves from Months to Days

ARMONK, N.Y., Feb. 22, 2023 /PRNewswire/ — IBM (NYSE: IBM) Security today released its annual X-Force Threat Intelligence Index finding that although ransomware’s share of incidents declined only slightly (4 percentage points) from 2021 to 2022, defenders were more successful detecting and preventing ransomware. Despite this, attackers continued to innovate with the report showing the average time to complete a ransomware attack dropped from 2 months down to less than 4 days. 

According to the 2023 report, the deployment of backdoors, which allow remote access to systems, emerged as the top action by attackers last year. About 67% of those backdoor cases related to ransomware attempts, where defenders were able to detect the backdoor before ransomware was deployed. The uptick in backdoor deployments can be partially attributed to their high market value. X-Force observed threat actors selling existing backdoor access for as much as $10,000, compared to stolen credit card data, which can sell for less than $10 today.

“The shift towards detection and response has allowed defenders to disrupt adversaries earlier in the attack chain – tempering ransomware’s progression in the short term,” said Charles Henderson, Head of IBM Security X-Force. “But it’s only a matter of time before today’s backdoor problem becomes tomorrow’s ransomware crisis. Attackers always find new ways to evade detection. Good defense is no longer enough. To break free from the never-ending rat race with attackers, businesses must drive a proactive, threat-driven security strategy.”

The IBM Security X-Force Threat Intelligence Index tracks new and existing trends and attack patterns – pulling from billions of datapoints from network and endpoint devices, incident response engagements and other sources.

Some of the key findings in the 2023 report include:

Extortion: Threat Actors Go-to Method. The most common impact from cyberattacks in 2022 was extortion, which was primarily achieved through ransomware or business email compromise attacks. Europe was the most targeted region for this method, representing 44% of extortion cases observed, as threat actors sought to exploit geopolitical tensions.Cybercriminals Weaponize Email Conversations. Thread hijacking saw a significant rise in 2022, with attackers using compromised email accounts to reply within ongoing conversations posing as the original participant. X-Force observed the rate of monthly attempts increase by 100% compared to 2021 data.Legacy Exploits Still Doing the Job. The proportion of known exploits relative to vulnerabilities declined 10 percentage points from 2018 to 2022, due to the fact that the number of vulnerabilities hit another record high in 2022. The findings indicate that legacy exploits enabled older malware infections such as WannaCry and Conficker to continue to exist and spread.

Extortion Pressure Applied (Unevenly)
Cybercriminals often target the most vulnerable industries, businesses, and regions with extortion schemes, applying high psychological pressure to force victims to pay. Manufacturing was the most extorted industry in 2022, and it was the most attacked industry for the second consecutive year. Manufacturing organizations are an attractive target for extortion, given their extremely low tolerance for down time.

Ransomware is a well-known method of extortion, but threat actors are always exploring new ways to extort victims. One of the latest tactics involves making stolen data more accessible to downstream victims. By bringing customers and business partners into the mix, operators increase pressure on the breached organization. Threat actors will continue experimenting with downstream victim notifications to increase the potential costs and psychological impact of an intrusion – making it critical that businesses have a customized incident response plan that also considers the impact of an attack on downstream victims.

Thread Hijacking on the Rise
Email thread hijacking activity surged last year, with monthly attempts by threat actors doubling compared to 2021 data. Over the year, X-Force found that attackers used this tactic to deliver Emotet, Qakbot, and IcedID, malicious software that often results in ransomware infections.

With phishing being the leading cause of cyberattacks last year, and thread hijacking’s sharp rise, it’s clear that attackers are exploiting the trust placed in email. Businesses should make employees aware of thread hijacking to help reduce the risk of them falling victim.

Mind the Gap: Exploit “R&D” Lagging Vulnerabilities
The ratio of known exploits to vulnerabilities has been declining over the last few years, down 10 percentage points since 2018. Cybercriminals already have access to more than 78,000 known exploits, making it easier to exploit older, unpatched vulnerabilities. Even after 5 years, vulnerabilities leading to WannaCry infections remain a significant threat. X-Force recently reported an 800% increase in WannaCry ransomware traffic within MSS telemetry data since April 2022. The continued use of older exploits highlights the need for organizations to refine and mature vulnerability management programs, including better understanding their attack surface and risk-based prioritization of patches.

Additional findings from the 2023 report include:

Phishers “Give Up” on Credit Card Data. The number of cybercriminals targeting credit card information in phishing kits dropped 52% in one year, indicating that attackers are prioritizing personally identifiable information such as names, emails, and home addresses, which can be sold for a higher price on the dark web or used to conduct further operations.North America Felt Brunt of Energy Attacks. Energy held its spot as the 4th most attacked industry last year, as global forces continue to affect an already tumultuous global energy trade. North American energy organizations accounted for 46% of all energy attacks observed last year, a 25% increase from 2021 levels.Asia Tops the Target List. Accounting for nearly one-third of all attacks that X-Force responded to in 2022, Asia saw more cyberattacks than any other region. Manufacturing accounted for nearly half of all cases observed in Asia last year.

The report features data IBM collected globally in 2022 to deliver insightful information about the global threat landscape and inform the security community about the threats most relevant to their organizations. You can download a copy of the 2023 IBM Security X-Force Threat Intelligence Report here.

Additional sources

Read more about the report’s top findings in this IBM Security Intelligence blog.Sign up for the 2023 IBM Security X-Force Threat Intelligence Index webinar on Thursday, March 2, 2022, at 11:00 a.m. ET here.Schedule a consult with IBM Security X-Force.

About IBM Security
IBM Security helps secure the world’s largest enterprises and governments with an integrated portfolio of security products and services, infused with dynamic AI and automation capabilities. The portfolio, supported by world-renowned IBM Security X-Force® research, enables organizations to predict threats, protect data as it moves, and respond with speed and precision without holding back business innovation. worldwide security experts, IBM is trusted by thousands of organizations as their partner to assess, strategize, implement, and manage security transformations. IBM operates one of the world’s broadest security research, development, and delivery organizations, monitors 150 billion+ security events per day in more than 130 countries, and has been granted more than 10,000 security patents worldwide.

Press Contact:
IBM Security Communications
Michele Brancati
mbrancati@ibm.com

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/ibm-report-ransomware-persisted-despite-improved-detection-in-2022-301752400.html

SOURCE IBM

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Redefining the Standard of Care: Introducing the Aulisa® Monitor Camera for Advanced Patient Monitoring

Published

on

By

PALO ALTO, Calif., Nov. 22, 2024 /PRNewswire/ — Aulisa® Medical USA, Inc., a leader in FDA-cleared, wearable, wireless continuous vital sign monitoring technology, proudly announces the launch of the Aulisa® Monitor Camera, an innovative solution designed to revolutionize patient care in both hospital and home settings. Seamlessly integrating with the Aulisa® Vital Signs Monitoring System, this advanced camera offers caregivers and healthcare professionals enhanced monitoring capabilities and peace of mind.

Redefining the Standard of Care
Hospitals constantly balance delivering exceptional patient care with managing operational costs. The Aulisa® Monitor Camera redefines patient monitoring by providing advanced, centralized solutions that enhance clinical and operational excellence. Designed to optimize patient care, the Aulisa® Monitor Camera integrates with the Centralized Multiple Patient Monitoring (CMPM) System, enabling simultaneous, wireless monitoring of oxygen saturation (SpO2), pulse rate, and body temperature across multiple patients from a centralized nursing station. With a simple app, the Aulisa® Monitor Camera can be integrated into a CMPM. In addition to monitoring a patient’s vital signs, caregivers and family members (such as parents of an infant) can also view the patient’s image and hear their voice. This feature is especially important in specific situations, such as for parents of an infant in the NICU.

This transformative approach eliminates cumbersome wires, streamlines operations, and ensures timely interventions, ultimately improving patient outcomes, enhancing safety standards, and optimizing workflow efficiency while driving significant cost savings and financial performance for healthcare facilities. With a steadfast commitment to compassionate, data-driven care and innovative solutions, Aulisa® Medical is advancing patient health and redefining healthcare excellence, one patient at a time.

Advanced Features for Comprehensive Care
The Aulisa® Monitor Camera offers crystal-clear 2K resolution with night vision, ensuring high-quality visuals day and night. Its two-way audio and human tracking features enable real-time communication and automated movement monitoring, while effortless Wi-Fi integration allows for quick and simple setup via mobile or web devices. With dual functionality as a standalone home surveillance camera, the Aulisa® Monitor Camera delivers unmatched flexibility for various care scenarios.

Engineered for Hospital Excellence
Designed with hospitals and patients in mind, the Aulisa® Monitor Camera addresses the unique demands of modern healthcare settings. From NICUs to patient rooms, it offers caregivers the ability to remotely monitor patients with visual, audio, and motion tracking capabilities. This streamlines workflows, enhances safety, and allows providers to focus on delivering compassionate care while staying equipped with FDA-cleared technology.

Founder’s Vision
“Introducing the Aulisa® Monitor Camera is a natural extension of our mission to enhance patient care and empower healthcare professionals,” said Augustine (Augie) Lien, founder and CEO of Aulisa Medical USA, Inc. “We strive to provide innovative solutions that bring peace of mind to caregivers and families alike. By delivering FDA-cleared technology with seamless functionality, we’re making it easier to ensure safety, connectivity, and exceptional care in every setting.”

Why Choose Aulisa®?
The Aulisa® Monitor Camera enhances efficiency by enabling remote monitoring, reducing physical check-ins, and providing reliable, FDA-cleared technology trusted by healthcare professionals worldwide. It is now available for purchase by healthcare facilities, caregivers, and families.

To learn more about the Aulisa Monitor Camera, the Guardian Angel® CMPM System and other Aulisa Medical products, visit:

www.aulisa.com/products/aulisa-monitor-camerawww.aulisa.com/products/cmpmwww.aulisa.com/collections/guardian-angel-remote-gateway-systems

About Aulisa Medical
Based in Silicon Valley, Aulisa® Medical is a leading medical technology company founded by serial medical technologies entrepreneur, Augustine (Augie) Lien. The company specializes in developing wireless, wearable monitoring systems that provide continuous, cloud-based vital sign data in both clinical and home environments. Through the development of new healthcare innovations, Aulisa® continues to grow the application of digital health technologies that empower both consumers and healthcare providers, incorporating Artificial Intelligence (AI) technologies that can detect adverse events and potentially save lives.

Media Contact:
Kyle Thompson, Vice President of Sales & Marketing
Email: kyle.thompson@aulisa.com
Direct: (650) 387-0001
www.aulisa.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/redefining-the-standard-of-care-introducing-the-aulisa-monitor-camera-for-advanced-patient-monitoring-302314670.html

SOURCE Aulisa Medical USA, Inc.

Continue Reading

Technology

Redefining Financial Frontiers: Nucleus Software Celebrates 30 Years with Synapse 2024 in Singapore

Published

on

By

SINGAPORE, Nov. 23, 2024 /PRNewswire/ — The thriving IndiaSingapore partnership in banking and technology reached a new milestone as Nucleus Software celebrated 30 years of transformative innovation at Synapse 2024, held in Singapore. The event underscored the company’s role in redefining financial services across Southeast Asia (SEA) and the globe, bringing together leaders in finance and technology to explore a shared vision for the future of banking.

Synapse 2024 celebrated 30 years of Nucleus Software’s leadership in driving transformative change across Singapore and Southeast Asia’s financial ecosystem. The event also shone a spotlight on the Global Finance & Technology Network (GFTN), an initiative supported by the Monetary Authority of Singapore (MAS) to champion responsible technology adoption. The event highlighted the deepening synergies between India and Singapore, driven by their shared commitment to innovation, cross-border collaboration, and financial inclusion. As the financial services sector undergoes rapid evolution with advancements in artificial intelligence, blockchain, and digital banking, these partnerships are setting the stage for a more connected, resilient, and inclusive global ecosystem.

Vishnu R. Dusad, Co-founder and Managing Director of Nucleus Software, reflected on the milestone: “For over 30 years, we’ve had the privilege of aligning our journey with Singapore’s ascent as a global financial powerhouse. Back in 1994, when we chose to go East instead of West, it was a bold and emotional decision—guided by our belief in Singapore as a hub for innovation and collaboration. We saw then what remains true today: Singapore is at the heart of the global financial landscape, a place where new ideas take root, and partnerships thrive.”

The event brought together a distinguished array of participants, highlighting the transformative potential of IndiaSingapore collaboration. Mr. Piyush Gupta, CEO of DBS Group and the Guest of Honor, set the tone for the event with his opening remarks, emphasizing the transformative role of big tech in reimagining scalable, customer-centric financial services in the digital age.

Following his address, key speakers enriched the discussions with their insights. Mr. Sopnendu Mohanty, Chief Fintech Officer at the Monetary Authority of Singapore and Group CEO-Designate of The Global Finance & Technology Network (GFTN), underlined the importance of fostering responsible technology adoption and building inclusive financial ecosystems. Mr. Vinod Rai, globally respected public policy expert, Distinguished Visiting Research Fellow at the National University of Singapore, and former Comptroller and Auditor General of India, shared his perspectives on governance and policy frameworks in financial systems. Mr. S.M. Acharya, Chairman of Nucleus Software and former Defence Secretary of India, offered a visionary outlook on leveraging technology to modernize and secure banking frameworks. Finally, Mr. Pieter Franken, Co-founder and Director of GFTN (Japan), a global FinTech pioneer and deep tech innovator, discussed the future of decentralized finance and its implications for the financial sector.

The event showcased the transformative role of technology in global financial systems, emphasizing innovations that set benchmarks for scalability and inclusivity. Panelists discussed the importance of localized solutions, the challenges of cross-border integration, and leveraging dual business models to optimize capital and foster public participation. The dialogue highlighted the need for common standards, unified frameworks like APIs, and collaborative efforts to accelerate financial inclusion and drive global connectivity in the digital age.

For 30 years, Nucleus Software has consistently introduced advanced lending and banking solutions that support financial institutions’ evolving needs in Singapore and South East Asia. Driven by lean development methodologies like Acceptance Test-Driven Development (ATDD) and Continuous Integration/Continuous Delivery (CICD), Nucleus Software continues to push boundaries in efficient, flexible, and secure financial technology.

Photo: https://mma.prnewswire.com/media/2565374/Synapse_2024.jpg
Logo: https://mma.prnewswire.com/media/2565373/Nucleus_Software_Logo.jpg

View original content to download multimedia:https://www.prnewswire.co.uk/news-releases/redefining-financial-frontiers-nucleus-software-celebrates-30-years-with-synapse-2024-in-singapore-302314485.html

Continue Reading

Technology

Sleighing the Digital Divide with Black Friday Tech Deals

Published

on

By

Holiday Mix & Match Deal puts tech and accessories under your tree for $200 or less!

DETROIT, Nov. 22, 2024 /PRNewswire/ — This holiday season, Human-I-T, a nonprofit dedicated to providing equitable access to technology, is making it easier than ever for holiday shoppers to access affordable tech while giving back to their community. The “Mix and Match Deal,” allows individuals to purchase devices and accessories at prices that fit any budget—all while supporting efforts to close the digital divide.

“For the past 12 years, Human-I-T has been laser-focused on three things: making technology accessible and affordable, offering digital navigation support to those who need it most, and saving our planet by keeping e-waste out of landfills,” said Graeme Jackson, Marketing and Content Manager at Human-I-T. “The ‘Holiday Mix & Match Deal’ helps us achieve all three goals, and the best part is that everyone benefits.”

Available from Friday, November 29th, through Monday, December 30th, the deal offers customers the chance to bundle one device—a tablet, Chromebook, or 2-in-1 device—with one accessory of their choice, including JBL speakers, headphones, a protective laptop sleeve, or a wireless keyboard for $200 or less.

For families, students, or job seekers who may struggle to afford essential technology, this initiative is more than a sale—it’s a lifeline. Human-I-T believes that in today’s digital world, access to reliable technology isn’t a luxury; it’s a basic human right.

“This isn’t just about shopping,” added Jackson. “It’s about providing hope, opportunity, and connection to those who need it most. When you shop with us, you’re not only getting a great deal—you’re helping to change lives.”

The Mix & Match Deal is only available for a limited time. By shopping at Human-I-T’s online store customers can brighten their holiday while directly supporting underserved communities.

Don’t wait—login to the Human-I-T store today

and give the gift of technology that gives back!

View original content to download multimedia:https://www.prnewswire.com/news-releases/sleighing-the-digital-divide-with-black-friday-tech-deals-302314632.html

SOURCE Human-I-T

Continue Reading

Trending