Get the App
SLTechnology News&Howtos  ›  IT Information  › 

700,000 real attack data insights: inadequate cloud protection and 1400% surge in memory-based attacks

Shulou Source: shulou.com Published: 2023-11-24 17:52:49 10月05日 Update

CTOnews.com, July 4, Aqua Security's Nautilus research team collected six months of honeypot data and analyzed 700,000 real-world attack data, covering three key areas: software supply chain, risk posture (including vulnerabilities and misconfigurations), and runtime protection.

One of the most important findings in insight is that threats are investing heavily in resources to avoid detection, thereby establishing a stronger foothold in the compromised system.

Nautilus research found that compared with the 2022 report, non-file (fileless) or memory-based attacks increased by 1400%, mainly taking advantage of vulnerabilities in existing software, applications, or protocols to perform malicious activities in cloud systems, with more than 50% of attacks focused on bypassing defense mechanisms.

Assaf Morag, chief threat intelligence researcher, believes that attackers are increasingly focused on how to successfully evade agentless solutions (agentless solutions).

CTOnews.com attaches an example of Morag-HeadCrab, an extremely complex, covert, Redis-based malware that compromises more than 1200 servers, and only proxy-based scans can detect such attacks.

Original report address: Nautilus

Tags: Attacks software research data malicious vulnerabilities systems agents threats memory protection insight complex powerful important three cloud example supply chain key Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Apple MariaDB NVidia Shulou Information Redmi