Menlo Security just released their third annual “State of the Web” report and it’s not pretty. The headline finding is that 42% of the top 100,000 sites as ranked by Alexa are more dangerous than you think.
The report defines a risky site as one that meets one of three criteria:
The site, or one of its associated background sites (from which news articles or video is pulled), is running software with a known security vulnerability
The site has been used to launch attacks or distribute malware
The site has suffered a security breach in the past twelve months
This first point is key, and often overlooked by security professionals. Any time your website is pulling content from another source, it creates an opening that a hacker could potentially exploit. Worse, most security professionals lack the tools to properly monitor those connections.
As bad as that sounds, there’s an even worse detail lurking in the pages of the report, and that concerns emails.
Hackers are increasingly moving away from setting up their own domains. Instead, they’re preferring to create a subdomain of a compromised, legitimate domain, which makes it harder to spot. Amir Ben-Efraim, the CEO of Menlo Security, had this to say about the issue:
“It is far easier to set up a subdomain on a legitimate hosting service than use other alternatives – such as trying to hack a popular, well-defended site or to set up a brand-new domain and use it until it is blocked by web security firms. Legitimate domains are often whitelisted by companies and other organizations out of a false sense of security, giving cover to phishing sites.
Also, hosting services typically allow customers to set up multiple subdomains. For example, researchers found 15 phishing sites hosted on the world’s 10 most popular domains.”
The bottom line is: The web and even the most popular sites on it, aren’t nearly as safe as you think.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Do you use any of the following Chrome browser extensions?
One of the greatest challenges among small business owners today is making the decision about IT support and maintenance of the information system; whether to hire an in-house IT tech or to outsource IT support for their business. With the relatively recent availability of Managed Services for small business, the list of choices – and decisions – has grown once again.
Few things are more ubiquitous in an office environment than printers. Of course, these days, most printers are much more than simply that. They can also scan, copy and even send emails. As such, they’ve become an increasingly attractive option to hack, according to the latest data released by Barracuda Networks.
SplashData has released their latest annual report on the most commonly used passwords. Unfortunately, the more things change, the more they stay the same.
Most people agree that the use of USB drives increases efficiency and boosts productivity, which goes a long way toward explaining their popularity, but these handy little drives can also be problematic.
Researchers from the security firm 4iQ have made a disturbing discovery on the dark web. A massive repository has been discovered that contains a staggering 1.4 billion usernames and passwords in plain text.
It has recently come to light that the company was hacked in 2016 in a massive breach that exposed the personal information of more than 57 million Uber users and drivers. A wide range of data was stolen. Where users were concerned, names, email addresses, and phone numbers were compromised.
Facebook has been in hot water with evidence mounting that hordes of fake accounts were used to spread misinformation about the recent presidential election.
You may not have heard of the new strain of ransomware known as BadRabbit. If you haven’t, it’s because the overwhelming percentage of BadRabbit attacks have been occurring in Russia, which accounts for 71 percent of all known infections at present. Unfortunately, there have been a few infections reported in the United States, which may be a harbinger of things to come.