All the latest UK technology news, reviews and analysis

IBM threat report highlights data risks

by Dave Neal

More from this author

26 Feb 2010

Be the first to comment

  • Tweet this
Hacker
Hackers are becoming ever more inventive, IBM has warned

IBM has identified massive rises in phishing and malicious web links in its latest X-Force 2009 Trend and Risk Report.

The company said that more organisations are being targeted by data thieves looking to make monetary gain, and that hackers are using a variety of techniques to bypass defences.

"The number of new malicious web links has skyrocketed globally in the past year. Phishing activity, in which an attacker attempts to acquire sensitive information by masquerading as a legitimate organisation, also increased dramatically in the second half of 2009," said the report.

"Vulnerability disclosures for document readers and editors continued to soar, specifically with PDF documents."

IBM said that vulnerabilities had decreased by 11 per cent year on year, helped mostly by falls in attacks such as SQL injection, in which criminals inject malicious code into legitimate web sites, which it suggested could be a thing of the past.

The report also showed a decline in vulnerabilities in ActiveX, an Internet Explorer plug-in, which may indicate that some of the more easily discovered flaws have been eliminated.

However, web attacks, such as those using malicious code, are increasing, while the number of bad web links rose by 348 per cent last year.

Overall, IBM said that security vendors are making progress in the battle, specifically when it comes to reacting to published flaws.

Vulnerabilities with web browsers, document readers and editors with no available patches have decreased, indicating that software vendors have become more responsive to security issues, according to the report.

"Despite the ever-changing threat landscape, this report indicates that vendors are doing a better job responding to security vulnerabilities," said Tom Cross, manager of IBM X-Force Research.

"However, attackers have clearly not been deterred, as the use of malicious exploit code in web sites is expanding at a dramatic rate."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Information Security Manager

My client is a well established, non profit organisation;...

PHP Web Developer

PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...

HEAD OF DIGITAL - London - £80-95K+

HEAD OF DIGITAL - London - £80-95K + Excellent Bens...

Agile C# Developer - (North London)

Agile C# Developer - (North London) £55,000 - £65,000...

To send to more than one email address, simply separate each address with a comma.