Connect with us

Hi, what are you looking for?

HEADLINES

Cybercriminals attack cloud server honeypots within 52 seconds

Credit: The Digital Artist | Pixabay

Sophos has announced the findings of its report, Exposed: Cyberattacks on Cloud Honeypots, which reveals that cybercriminals attacked one of the cloud server honeypots in the study within 52 seconds of the honeypot going live in Sao Paulo, Brazil. On average, the cloud servers were hit by 13 attempted attacks per minute, per honeypot.

A honeypot is a system intended to mimic likely targets of cyberattackers, so that security researchers can monitor cybercriminal behaviours. The honeypots were set up in 10 of the most popular Amazon Web Services (AWS) data centers in the world, including California, Frankfurt, Ireland, London, Mumbai, Ohio, Paris, Sao Paulo, Singapore, and Sydney over a 30-day period.

 

In the study, more than 5 million attacks were attempted on the global network of honeypots in the 30-day period, demonstrating how cybercriminals are automatically scanning for weak open cloud buckets. If attackers are successful at gaining entry, organisations could be vulnerable to data breaches. Cybercriminals also use breached cloud servers as pivot points to gain access onto other servers or networks.

Advertisement. Scroll to continue reading.

 

“The Sophos report, Exposed: Cyberattacks on Cloud Honeypots, identifies the threats organisations migrating to hybrid and all-cloud platforms face. The aggressive speed and scale of attacks on the honeypots shows how relentlessly persistent cybercriminals are and indicates they are using botnets to target an organisation’s cloud platforms. In some instances, it may be a human attacker, but regardless, companies need a security strategy to protect what they are putting into the cloud,” said Matthew Boddy, security specialist, Sophos. “The issue of visibility and security in cloud platforms is a big business challenge, and with increased migration to the cloud, we see this continuing.”

 

Visibility into Weaknesses

 

Advertisement. Scroll to continue reading.

Continuous visibility of public cloud infrastructure is vital for businesses to ensure compliance and to know what to protect. However, multiple development teams within an organisation and an ever-changing, auto-scaling environment make this difficult for IT security.

 

Sophos is addressing security weaknesses in public clouds with the launch of Sophos Cloud Optix, which leverages artificial intelligence (AI) to highlight and mitigate threat exposure in cloud infrastructures. Sophos Cloud Optix is an agentless solution that provides intelligent cloud visibility, automatic compliance regulation detection and threat response across multiple cloud environments.

 

“Instead of inundating security teams with a massive number of undifferentiated alerts, Sophos Cloud Optix significantly minimises alert fatigue by identifying what is truly meaningful and actionable,” said Ross McKerchar, CISO, Sophos. “In addition, with visibility into cloud assets and workloads, IT security can have a far more accurate picture of their security posture that allows them to prioritise and proactively remediate the issues flagged in Sophos Cloud Optix.”

Advertisement. Scroll to continue reading.

 

Key features in Sophos Cloud Optix include:

 

Smart Visibility – Provides automatic discovery of an organisation’s assets across AWS, Microsoft Azure and Google Cloud Platform (GCP) environments, via a single console, allowing security teams complete visibility into everything they have in the cloud and to respond and remediate security risks in minutes

 

Advertisement. Scroll to continue reading.

Continuous Cloud Compliance – Keeps up with continually changing compliance regulations and best practices policies by automatically detecting changes to cloud environments in near-time

 

AI-Based Monitoring and Analytics – Shrinks incident response and resolution times from days or weeks to just minutes. The powerful artificial intelligence detects risky resource configurations and suspicious network behavior with smart alerts and optional automatic risk remediation

 

“Migrating several petabytes of data and many applications to AWS and Azure made it necessary to transition from a manual to automated process for security monitoring. Sophos Cloud Optix’s multi-cloud security and compliance platform capabilities provided real-time cloud workload protection status in seconds. The AI-powered monitoring and alerts helped reduce the noise and allowed our teams to focus on delivering value to the business,” said Aaron Peck, vice president and CISO, Shutterfly, Inc., a Sophos customer, based in Redwood City, Calif.

Advertisement. Scroll to continue reading.

 

“Our goal is to provide the most comprehensive and highly-effective cyber security services to all of our clients. Whether in technology, manufacturing or utilities, our customers want to maximise their investments and protect their data in the cloud. The partnership with Sophos and the ability to offer Sophos Cloud Optix is important to us because it allows us to provide continuous compliance coupled with intelligent cloud visibility and immediate threat response. With Cloud Optix, our growing customer-base will have the opportunity to solve the toughest challenges in cloud security,” said Rajeev Khanolkar, president and CEO, SecurView Inc., a Sophos partner based in Edison, New Jersey.

 

Sophos Cloud Optix leverages AI-powered technology from Avid Secure, which Sophos acquired in January 2019. Founded in 2017 by a team of highly distinguished leaders in IT security, Avid Secure revolutionised the security of public cloud environments by providing effective end-to-end protection in cloud services, such as AWS, Azure and Google.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

The cybersecurity landscape is fast changing, and businesses across all industries as well as consumers are facing evolving threats to their data and privacy....

HEADLINES

Pondering on the significant events and trends that shaped the financial threats’ sector in 2021, Kaspersky researchers have forecasted several important tendencies expected to...

HEADLINES

As organizations worldwide slow down for the holidays as well as find themselves in work environment transitions - with many returning to pre-pandemic in-office...

HEADLINES

Deep learning models have reached the point where they can train themselves to enable security systems to predict threats before they happen.

SOFTWARE

MicroWorld's latest offering aims to reinvent cybersecurity in the face of an ever-evolving threat landscape, especially in light of the ongoing pandemic. The cyber...

HEADLINES

When you compare the immense financial losses that a breached company suffers with the much smaller-scale financial transactions taking place on these criminal forums,...

HEADLINES

The vast majority (70%) of all IT teams said the number of phishing emails hitting their employees increased during 2020. This rose to 82%...

HEADLINES

According to WorldRemit, there are four industry-wide scams that Filipinos should be aware of this 2021: “email scams, online dating scams, shopping scams and...

Advertisement