Latest news

The report is based on research from 888 companies worldwide, and gives insight into the network security events that actually occurred within organizations during 2012, and the security risks that companies are exposed to.
Hidden security threats
The research revealed that 63% of organizations globally were infected with bots, and 53% were infected with new malware at least once a day as a result of existing infections on their networks. 70% of the bots detected communicated with their external command centres at least every 2 hours. 58% of command centers are based in the USA, with just 4% in China.
It also highlighted that 75% of organizations are not using the latest software versions in popular software (Acrobat Reader, Flash, Internet Explorer, Java), which can lead to security vulnerabilities. Also, 44% were not using the latest Microsoft Windows Service Packs, which include the latest Microsoft security updates.
Risky Web 2.0 applications
91% of organizations used applications with potential security risks, giving hackers an unprecedented range of options for penetrating corporate networks. 61% of organizations were found to be using P2P file-sharing, and 43% using anonymizer applications: in the majority of cases, this usage conflicted with the organization’s web usage and security policies, and can potentially open a backdoor to networks. 69% of organizations were found to be using Dropbox for cloud storage.
Data loss incidents
54% of organizations had at least one potential data loss incident as a result of emails being sent in error to an external recipient, or information being incorrectly posted online. Credit card information was the most common type of sensitive information sent outside organizations (29%), and public sector bodies and financial companies were the most likely to do this.
“Our research uncovered many alarming vulnerabilities and security threats on networks that most organizations were not aware of,” said Amnon Bar-Lev, president of Check Point. “With clearer visibility of these, IT professionals can now better define a security blueprint to protect their organizations from the constant stream of evolving security threats, ranging from botnets, to employees using risky web applications like anonymizers, to data loss.”
The complete report is available here.


Spotlight

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






