Data Breaches, Hacker Turf Wars, Major Security Threats of 2011 First Half - Security - News & Reviews - eWeek.com

Biggest Threats: Unpatched Software

Biggest Threats: Unpatched Software
Jul 25, 2011
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More


Biggest Threats: Unpatched Software

1

Malware targeting Microsoft, Adobe and Java applications continued to be the biggest threats. Cyber-attackers weren’t going after 0-days, as it was easier and just as lucrative to target unpatched programs using known (and fixed) vulnerabilities.


Facebook Attacks on the Rise

2

Grandparents aren’t the only ones on Facebook. The criminals are, too. The number of Facebook-based scams soared and continue to be a serious threat, tricking users to click on titillating videos or applications. Facebook wasn’t the only social networking site under attack; LinkedIn spam also increased.


Malicious Email on the Rise

3

Attackers are increasingly sending emails in combined attacks, such as spear phishing with HTML or PDF attachments that exploit unpatched software. Other types of malicious spam rely on good old social engineering to get users to hand over sensitive data.


Rare Good News: Less Spam

4

The efforts of Microsoft, the Justice Department and other security companies to shut down Rustock and Coreflood seem to be paying off, as global spam volumes seem to be down. While the amount of malicious spam hasn’t changed, the overall spam volume is much less than it used to be.


Advertisement

Continued Use of Attack Kits

5

While Zeus may be one of the most well-known attack kits, it’s not the most commonly used. That distinction goes to Neosploit, which dominated in the first half of 2011, followed by Phoenix and Blackhole.


Fake AV Becomes More Common

6

Attackers increasingly monetized their scams using fake antivirus software. Users were tricked into downloading malware, usually fake antivirus software, which couldn’t be removed until they handed over their credit card details.


Criminals Use Antivirus, Too

7

Underground antivirus development and testing tools also have proliferated. Now malware developers could, for a small fee, check to see whether current antivirus programs from security vendors would be able to detect their malicious code.


8

More and more Web attacks are relying on malvertisements and other dynamic links to compromise legitimate Websites. Attackers don’t need to hack into major Websites if they can inject malicious code into a URL or into an ad that links to the site.


Attackers Also Cutting Costs

9

Why increase costs when there are so many free or low-cost options available? Cyber-criminals increasingly registered free .co, .cc and similar Internet domains for their attack sites, used free hosting services and relied on free online storage services to host malware files.


U.S. Remains #1 Malware Host

10

While various vendors differed on the exact order, everyone agreed that the U.S. hosted the most malware. The other countries in the top five were China, Germany, the United Kingdom and the Russian Federation.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.