ESET reveals top cyber threats of 2024 thus far

ESET has published its Threat Report for the first half of 2024, providing new insights into the cyber threat landscape faced by businesses and individuals worldwide. The report highlights several significant trends and developments in cybersecurity. This includes the increasing use of generative AI tools in cybercrime and the need for vigilance as cybercriminals use more dynamic and sophisticated methods against their targets.

  • Wednesday, 2nd October 2024 Posted 1 year ago in by Phil Alsop

The report reveals a spectrum of sophisticated cyber threats across multiple regions, showcasing the global scale and urgency of today’s cybersecurity challenges.

Among these is the rise of GoldDigger and GoldDiggerPlus malware, which targets Android and iOS devices. Initially emerging in Southeast Asia, these threats have now spread to other regions, including Latin America and South Africa, where they have been found impersonating financial apps to steal facial recognition data for fraudulent transactions.

“The latest developments show the critical need for advanced cybersecurity frameworks that can adapt to the evolving tactics, especially as cybercriminals expand their reach across borders,” says Adrian Standford, Group CTO of ESET Southern Africa. “It is essential for businesses and individuals to implement robust security protocols and continuously monitor their systems to safeguard their digital assets.”

The Ebury botnet, previously examined in ESET's 2014 white paper Operation Windigo, remains dangerous, even years later. Compromising nearly 400,000 Linux and Unix servers worldwide. This botnet poses significant risks to businesses by facilitating cryptocurrency and credit card theft through advanced adversary-in-the-middle attacks. While this threat is particularly concerning for organisations relying on these operating systems, it also serves as a reminder of the importance of comprehensive cybersecurity strategies.

Another critical issue highlighted is the exploitation of vulnerabilities in WordPress plugins by cybercriminal groups like the Balada Injector gang. With over 20,000 websites affected globally, this threat highlights the ongoing risks associated with widely used content management systems.

The growing use of generative AI tools has not gone unnoticed by cybercriminals, who are increasingly leveraging the popularity of AI to distribute malware. The ESET Report The report details how malware disguised as AI assistants and tools are being used to steal social media credentials and cryptowallet information, reflecting a concerning trend where innovation in technology is paralleled by innovation in cybercrime.

Standford says the findings of the H1 Threat Report shows that there is a need for ongoing cybersecurity awareness and education together with proactive security measures, and robust defence strategies. “In an interconnected digital world, South African enterprises should look at prioritising the implementation of advanced security measures, such as AI-driven threat detection and multi-layered defence systems. Whether it's fortifying systems against malware, securing financial transactions, or protecting personal data, it’s imperative that businesses adopt cutting-edge solutions to stay ahead of cyber threats.”

Commvault partners with Delinea and Pinecone to enhance security and resilience for enterprises, centralising credential management and safeguarding...
New research highlights executive priorities amidst evolving pressures, showcasing the pivotal role of AI and automation within contemporary business...

Accelerating the next wave of AI-driven cybersecurity

Posted 1 day ago by Sophie Milburn
CrowdStrike, AWS, and NVIDIA join forces to fuel innovation in AI-driven cloud security.

Identity security meets real-time threat response

Posted 2 weeks ago by Sophie Milburn
SailPoint announces new integrations with CrowdStrike to bolster identity-based threat response, advancing security operations and decision-making...

Small businesses face rising cybersecurity attacks

Posted 2 weeks ago by Sophie Milburn
Nearly half of US SMBs faced cyberattacks, yet many remain underprepared and reliant on untrained staff for security, Guardz study finds.
TCS strengthens its alliance with Aviva by expanding its policy administration services, embracing advanced digital solutions for customer-focused...
Hammer teams up with Nexsan to offer storage solutions across EMEA, enhancing modern data management capabilities.

Nordic security expertise expands in Europe

Posted 2 weeks ago by Sophie Milburn
MetaCompliance expands its foothold in Europe by acquiring Nordic leader Junglemap, enhancing its capacity to offer advanced security and compliance...