DXC Security Threat Intelligence Report

Stay up to date on the latest threats, vulnerabilities and nation-state activities.

Mark Hughes, president of Security, DXC

Cyber warfare heats up

Hackers are fighting in Ukraine and elsewhere, and national cyber security agencies are warning of potential consequences close to home. Be cyber aware during these times.

VULNERABILITY

Log4j exploits VMware Horizon servers

Malicious actors are now exploiting the Log4J vulnerability in VMware Horizon to gain system control.

THREAT UPDATE

Sabbath emerges on dark web

The unorthodox Sabbath ransomware group steals large amounts of data and then extorts ransom, sometimes through public data leaks.

By the numbers

50%
year-over-year increase in cyberattacks in 2021, with 925 weekly attacks per organization in Q4 (Check Point Research)
38%
of IT leaders surveyed experienced a security breach in 2021 (Salesforce)
83%
of organizations say their inventory and documentation may not reflect all existing API functions (Salt Security)

VULNERABILITY

Samba patches dangerous bug

Samba developers have patched a critical vulnerability that allows remote attackers to execute arbitrary code as root.

THREAT UPDATE

Magniber posing as Windows Installer

Magniber ransomware is now extending its influence by disguising itself as Windows MSI files.

NATION STATE

Threat hunting tips for Log4J vulnerability

A critical RCE vulnerability in Apache’s Log4J 2, a widely used open source logging utility, gives bad actors full system control.

Subscribe for the latest threat updates.

What’s next for enterprise security? Look to public cloud

The latest integrated security tools from leading cloud providers could be a catalyst to simplify and modernize IT environments. DXC's cloud and security experts share insights on how to simplify complex environments, increase speed and flexibility, and control costs.

Other news

TeaBot Trojan again in Google Play Store

TeaBot banking malware posing as a QR code scanning utility is infecting U.S. users and eyeing global victims. 

Phishing campaign targets Ukrainian refugee aid

An attack likely by a state-backed threat actor is using Ukrainian armed service members’ accounts to deliver phishing messages to European government personnel supporting refugees.

Log4shell exploits still threaten vulnerable systems

Threat actors are still exploiting Log4j software in unpatched systems to deploy DDoS botnets and cryptominers.

Sharp rise in API attacks

Attacks abusing programming APIs grew 681% in 2021, yet most companies still take the wrong security approach.

New malware families target Ukraine

HermeticWiper and a worm attacked Ukrainian organizations hours before Russian land invasion.

Hackers hit Russian Nuclear Institute

Anonymous hacking groups leaked 40,000+ nuclear safety-related documents and attacked Belarus bank websites.

 

 

DXC Security Threat Intelligence Report

Get the latest threat updates

Protect your enterprise. Subscribe to DXC's monthly report on the latest threats, breaches, cybercrimes and nation-state activities.