Media and entertainment firms are being hit with more cyberattacks than ever
Attack surface is increasing every month, report warns
Adding new services to the corporate infrastructure substantially increases the attack surface, and thus the chance of being successfully hit with a cyberattack. Despite this, enterprises across the majority of industries are adding many new services every month, risking devastating breaches, experts have warned.
A new report from Palo Alto Networks’ cybersecurity arm, Unit 42 has claimed the typical organization adds, or updates, more than 300 services every month.
Unit 42 found that organizations in the Media and Entertainment vertical were adding a significant number of services each month - 7,469. Telecommunications were placed second with 2,892 (roughly a third of what the Media and Entertainment firms are adding), followed by Insurance with 2,271,
Wide range of targets
”These new and updated services are responsible for nearly 32% of organizations’ new high or critical cloud exposures,” the researchers said in the report.
Quickly adding new services, without central oversight, “inevitably” leads to misconfigurations and exposures, Unit 42 concluded, adding that these mean a higher chance of a breach.
“It’s challenging to strengthen your defenses appropriately without complete knowledge of your entire attack.”
Misconfigured databases, for example, are one of the most common causes of data leaks. Many organizations are collecting huge amounts of personally identifiable information (PII) about their customers, partners, and employees, and are often storing this information in an unprotected cloud-based database.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
As a result, crooks who know where to look can easily obtain this data, and either sell it on the dark web, or use it to engage in phishing and social engineering attacks.
In fact, Palo Alto says that attackers can scan the entire IPv4 address space (which counts 4.3 billion IPv4 addresses) in minutes, noting, “once attackers are in, they move faster to steal data, according to Unit 42 research, sometimes getting in and out in less than one day.”
More from TechRadar Pro
- Hundreds of Google Firebase websites might have leaked data online
- Here's a list of the best malware removal tools around today
- These are the best endpoint security tools right now
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.