2024-11-03-KROLL-CTI聚光灯趋势报告(英)_21页_499kb
报告摘要
Summary of Kroll CTI Spotlight Trends Report: September 2024
Methodology and Data Scope
- The report is based on Kroll's cybersecurity incident response engagements, drawing intelligence from over 3,000 annual engagements.
- Data is collected during initial scoping and engagement lifecycle, with monthly and quarterly reports.
Key Findings for September 2024
- Top Initial Access Methods: Phishing (links) accounted for 32%, followed by Valid Accounts (insider, 24%) and External Remote Services (21%).
- Most Impacted Sectors: Professional Services (25%) and Manufacturing (20%) were primary targets.
- Top Threat Incident Types: Email Compromise (37%) and Ransomware (21%) dominated incidents.
- Ransomware Variants: LOCKBIT (17%), PLAY (17%), and AKIRA (17%) were most common.
- Geographical Trends: North America was a top region for ransomware victim postings.
Sector-Specific Analysis
- Professional Services: High incidence of Email Compromise and Phishing as initial access.
- Manufacturing: Top threats included Ransomware, with initial access via Valid Accounts and External Remote Services.
- Other Sectors: Tech & Telecom (9%) and Retail/Restaurant (8%) also showed significant impacts.
Ransomware Insights
- Initial Access: VPN usage was prevalent for variants like AKIRA, LOCKBIT, and others.
- Victim Trends: Manufacturing (31%) was most targeted; consumer/industrial and North America were top for shaming site postings.
Threat Event Trends
- Incident Types: Email Compromise (37%), Ransomware (21%), and Unauthorized Access (17%) were dominant.
- Comparative Analysis: Over the past six months, Email Compromise remained steady, while Ransomware fluctuated.
Vulnerabilities and Methodology
- Key vulnerabilities included CVEs like Microsoft and Apache Seata issues.
- Initial access vectors emphasize phishing and remote services.
Context and Additions
- Professional Services and Manufacturing remain high-risk sectors.
- Recommendations focus on mitigation through enhanced security measures against phishing and unauthorized access.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载