ESET reveals top cyber threats of 2024 thus far

ESET has published its Threat Report for the first half of 2024, providing new insights into the cyber threat landscape faced by businesses and individuals worldwide. The report highlights several significant trends and developments in cybersecurity. This includes the increasing use of generative AI tools in cybercrime and the need for vigilance as cybercriminals use more dynamic and sophisticated methods against their targets.

  • Wednesday, 2nd October 2024 Posted 1 year ago in by Phil Alsop

The report reveals a spectrum of sophisticated cyber threats across multiple regions, showcasing the global scale and urgency of today’s cybersecurity challenges.

Among these is the rise of GoldDigger and GoldDiggerPlus malware, which targets Android and iOS devices. Initially emerging in Southeast Asia, these threats have now spread to other regions, including Latin America and South Africa, where they have been found impersonating financial apps to steal facial recognition data for fraudulent transactions.

“The latest developments show the critical need for advanced cybersecurity frameworks that can adapt to the evolving tactics, especially as cybercriminals expand their reach across borders,” says Adrian Standford, Group CTO of ESET Southern Africa. “It is essential for businesses and individuals to implement robust security protocols and continuously monitor their systems to safeguard their digital assets.”

The Ebury botnet, previously examined in ESET's 2014 white paper Operation Windigo, remains dangerous, even years later. Compromising nearly 400,000 Linux and Unix servers worldwide. This botnet poses significant risks to businesses by facilitating cryptocurrency and credit card theft through advanced adversary-in-the-middle attacks. While this threat is particularly concerning for organisations relying on these operating systems, it also serves as a reminder of the importance of comprehensive cybersecurity strategies.

Another critical issue highlighted is the exploitation of vulnerabilities in WordPress plugins by cybercriminal groups like the Balada Injector gang. With over 20,000 websites affected globally, this threat highlights the ongoing risks associated with widely used content management systems.

The growing use of generative AI tools has not gone unnoticed by cybercriminals, who are increasingly leveraging the popularity of AI to distribute malware. The ESET Report The report details how malware disguised as AI assistants and tools are being used to steal social media credentials and cryptowallet information, reflecting a concerning trend where innovation in technology is paralleled by innovation in cybercrime.

Standford says the findings of the H1 Threat Report shows that there is a need for ongoing cybersecurity awareness and education together with proactive security measures, and robust defence strategies. “In an interconnected digital world, South African enterprises should look at prioritising the implementation of advanced security measures, such as AI-driven threat detection and multi-layered defence systems. Whether it's fortifying systems against malware, securing financial transactions, or protecting personal data, it’s imperative that businesses adopt cutting-edge solutions to stay ahead of cyber threats.”

Opus Technology achieves B Corp certification

Posted 6 minutes ago by Sophie Milburn
Opus Technology has earned B Corp status, joining a global community aiming for ethical and sustainable business practices.
CrowdStrike’s Project QuiltWorks brings together industry partners to address AI-discovered vulnerabilities and support efforts to improve...

Scality appoints Greg DiFraia to lead global AI strategy

Posted 3 hours ago by Sophie Milburn
Scality has appointed Greg DiFraia as Senior Vice President of AI Alliances and Partnerships, highlighting its focus on AI and data-driven solutions.
Nebula Global Services has achieved Cyber Essentials Plus certification, confirming independently assessed cyber security controls across its...

Creative ITC and IMSCAD forge joint venture partnership

Posted 4 hours ago by Sophie Milburn
Creative ITC and IMSCAD Services have formed a partnership focused on cloud workstations and digital workspace solutions for design and AEC...
Mhance has appointed Andy Cowdrill to its leadership team, as the company continues to develop its Microsoft-focused strategy.

ISACA launches AAIR certification for AI risk and governance

Posted 23 hours ago by Sophie Milburn
ISACA introduces the AAIR certification, aimed at equipping professionals to govern AI effectively amidst rising adoption and risks.
Cohesity receives Google Cloud Partner of the Year Award for infrastructure modernisation in disaster recovery and backup with Google Cloud