The Cisco 2014 Midyear Security Report, released at Black Hat U.S. examines the “weak links” in organizations that contribute to the increasingly dynamic threat landscape. These weak links – which could be outdated software, bad code, abandoned digital properties, or user errors – contribute to the adversary’s ability to exploit vulnerabilities with methods such as DNS queries, exploit kits, amplification attacks, point-of-sale (POS) system compromise, malvertising, ransomware, infiltration of encryption protocols, social engineering and “life event” spam.
The report also shows that focus on only high-profile vulnerabilities rather than on high-impact, common and stealthy threats puts these organizations at greater risk. By proliferating attacks against low-profile legacy applications and infrastructure with known weaknesses, malicious actors are able to escape detection as security teams focus instead on boldface vulnerabilities, such as Heartbleed.