ESET reveals top cyber threats of 2024 thus far

ESET has published its Threat Report for the first half of 2024, providing new insights into the cyber threat landscape faced by businesses and individuals worldwide. The report highlights several significant trends and developments in cybersecurity. This includes the increasing use of generative AI tools in cybercrime and the need for vigilance as cybercriminals use more dynamic and sophisticated methods against their targets.

  • Wednesday, 2nd October 2024 Posted 5 months ago in by Phil Alsop

The report reveals a spectrum of sophisticated cyber threats across multiple regions, showcasing the global scale and urgency of today’s cybersecurity challenges.

Among these is the rise of GoldDigger and GoldDiggerPlus malware, which targets Android and iOS devices. Initially emerging in Southeast Asia, these threats have now spread to other regions, including Latin America and South Africa, where they have been found impersonating financial apps to steal facial recognition data for fraudulent transactions.

“The latest developments show the critical need for advanced cybersecurity frameworks that can adapt to the evolving tactics, especially as cybercriminals expand their reach across borders,” says Adrian Standford, Group CTO of ESET Southern Africa. “It is essential for businesses and individuals to implement robust security protocols and continuously monitor their systems to safeguard their digital assets.”

The Ebury botnet, previously examined in ESET's 2014 white paper Operation Windigo, remains dangerous, even years later. Compromising nearly 400,000 Linux and Unix servers worldwide. This botnet poses significant risks to businesses by facilitating cryptocurrency and credit card theft through advanced adversary-in-the-middle attacks. While this threat is particularly concerning for organisations relying on these operating systems, it also serves as a reminder of the importance of comprehensive cybersecurity strategies.

Another critical issue highlighted is the exploitation of vulnerabilities in WordPress plugins by cybercriminal groups like the Balada Injector gang. With over 20,000 websites affected globally, this threat highlights the ongoing risks associated with widely used content management systems.

The growing use of generative AI tools has not gone unnoticed by cybercriminals, who are increasingly leveraging the popularity of AI to distribute malware. The ESET Report The report details how malware disguised as AI assistants and tools are being used to steal social media credentials and cryptowallet information, reflecting a concerning trend where innovation in technology is paralleled by innovation in cybercrime.

Standford says the findings of the H1 Threat Report shows that there is a need for ongoing cybersecurity awareness and education together with proactive security measures, and robust defence strategies. “In an interconnected digital world, South African enterprises should look at prioritising the implementation of advanced security measures, such as AI-driven threat detection and multi-layered defence systems. Whether it's fortifying systems against malware, securing financial transactions, or protecting personal data, it’s imperative that businesses adopt cutting-edge solutions to stay ahead of cyber threats.”

Endava has launched its latest research report “AI and the Digital Shift: Reinventing the Business Landscape”.

3,000% surge in enterprise use of AI/ML tools

Posted 2 days ago by Phil Alsop
Zscaler has released the ThreatLabz 2025 AI Security Report, based on insights from more than 536 billion AI transactions processed between February...
Over one in four (28%) British small business owners have used AI tools to help run their business.

Tech fragmentation cited as biggest cyber challenge

Posted 3 days ago by Phil Alsop
New Palo Alto Networks data shows 82% of UK organisations confident in their use of AI, despite AI being identified as biggest cyber risk for 2025.
MIT researchers crafted a new approach that could allow anyone to run operations on encrypted data without decrypting it first.
CyberArk has released its 2025 State of Machine Identity Security Report, revealing that machine identity-related security incidents are on the rise,...
Asana Work Innovation Lab findings reveal AI adoption in many companies is happening in a ‘leadership bubble’—executives are early adopters but...

Global trust in Digital Services declines

Posted 6 days ago by Phil Alsop
Thales 2025 Digital Trust Index reveals most industries experienced a decline in consumer trust compared to last year.