Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Leadership and ManagementSecurity Education & TrainingCybersecurity News

New Cyberattack Tactics Against Businesses Require Advanced Network Defenses

By Bogdan Botezatu
keys-cyber-enews
November 25, 2019

Threat diversification and sophistication has pushed the limits of IT security professionals in defending organizations of all sizes, across all verticals. The cybersecurity skills shortage has reached an all-time-high, with 53 percent of organizations agreeing they have suffered from this gap.

In the wake of the skills drought, 91 percent of security professionals believe most organizations are vulnerable to a significant cyber-attack, and 94 percent believe cybercriminals have the upper hand on cybersecurity professionals. These concerns keep 49 percent of IT security professionals awake at night, especially since IT and security teams suffer breach burnouts, alert fatigue, inadequate security tools and lack of visibility across the infrastructure.

While some of the biggest threats to organizations include brute force, password stealers, unpatched vulnerabilities and other network-based attacks on endpoints, emails are also a major concern for IT and security teams. Finance, c-level marketing and HR are the main targets of spear-phishing emails, with security rules broken most by senior management (57 percent).

 

Threats Organizations Face

Some of the biggest threats and attacks aimed at organizations – regardless of size and industry vertical – involve internet-exposed services, such as RDP, SSH, SMB, HTTP. Brute force attacks on RDP services account for over 65 percent of all network-based attacks, according to Bitdefender telemetry. Cybercriminals often probe internet-facing services and endpoints for RDP connections that let someone outside the organization dial in remotely. Once inside the targeted machine, they try to take down the security solution and manually deploy threats such as ransomware or lateral movement tools designed to infiltrate and compromise additional machines within the infrastructure.

If not properly configured and secured, RDP can act as a gateway within the organization, effectively enabling threat actors to access sensitive internal resources. Brute forcing passwords is one way to go, as cybercriminals use trial and error to obtain information such as a user password or other credentials or even send multiple distributed requests to a server, seeking a pair of valid credentials. Cybercriminals also try to exploit unpatched vulnerabilities in RDP services to perform remote code execution, and seize control over those gateways. For instance, a recent wormable security flaw in Microsoft RDP service that allows attackers to take remote control of vulnerable systems (BlueKeep - CVE-2019-0708) is one of the most recent such attack vectors used by threat actors to compromise organizations.

These types of attacks are industry-agnostic – the organization merely needs to hold a publicly exposed server. If successful, attackers can move laterally across the infrastructure and compromise other servers or endpoints in an attempt to ensure persistency, access and exfiltrate highly confidential data, or even deploy destructive threats meant to cripple the organization or cover their tracks.

Threat actors also prefer attacks targeting web servers via SQL or command injection, as they could enable remote code execution capabilities on the machine and use it as a gateway or lateral movement pivot within the organization.

SMB exploits have also become a common attack tactic for threat actors, as these SMB servers often sit on Windows domain-based network architectures, allowing all employees to copy documents from these network shares. Consequently, compromising these SMB servers through exploits such as EternlBlue or DoublePulsar lets attackers use them as entry points to breach the organization, move laterally, search for other high-value hosts and even schedule tasks remotely on a computer from the network that has an exposed share.

Active Directory compromise is also a priority for cybercriminals. Recent investigations have even revealed that threat actors can successfully compromise an organization’s AD server in less than two hours. Using a tainted email attachment opened by a financial institution’s employee, the cybercriminal gang successfully managed to compromise select machines in the infrastructure, stealthily moving within the infrastructure and deploying persistency and lateral movement tools. When cybercriminal gangs focus on targeting and compromising particular verticals, they have an intimate understanding of how those infrastructures work, where critical assesses may reside and what cybersecurity defenses the company might have in place.

Most attacks occur using free open-source tools, meaning there is a low barrier-to-entry for cybercriminals. However, threat actors seeking to carry out highly targeted attacks need advanced networking knowledge and custom tools to perform an APT (Advanced Persistent Threat).

Organizations need to focus on deploying and using network attack defense technologies designed to identify and categorize network behaviors that may indicate lateral movement, malware infections, web-service attacks, malicious traffic caused by botnets or TOR/Onion connections and even privacy breaches caused by leaks of passwords or sensitive data.

 

Avoid Breaches With Network Attack Defense

Behavioral technologies, multiple events correlation and network analytics are increasing the chances for organizations to avoid breaches and data theft. Solutions that provide incident response narratives with prescriptive recommendations for addressing threats are the future of IT security, and help address the acute security skills shortage that plagues the industry.

Automated, real-time network traffic inspection and prevention technologies that don’t bog down network traffic can scan the data in streaming mode, blocking threats at the first sign of a malformed data packet. This means the malicious traffic does not even reach the local application or machine, effectively stopping the attack before any payload lands.

Using an event correlation engine fed by proprietary and third-party IoC (Indicators of Compromise) feeds, network attack defense technology can identify and categorize suspicious network behavior. Also, using several machine-learning algorithms to identify specific attack vectors - such as protocols or device specific anomaly detection – while learning the normal behavior of network traffic, can help organizations defend against threats at the network level.

Moreover, having the ability to integrate this network-based threat intelligence with EDR (Endpoint Detection and Response) capabilities can help organizations protect their network as whole, giving them visibility across the entire technology stack, from the network to the operating system. More importantly, a network defense technology that integrates with EDR capabilities can spot complex events while supporting new lateral movement detections from MITRE. This lets organizations paint a complete picture of their overall cybersecurity posture across the entire infrastructure.

Network attack defense technologies can detect and block new types of threats earlier in the attack chain, while correlating multiple attack vectors using both signatures and behavior-based machine learning. Adding network attack defense capabilities to your arsenal can improve your overall security posture by keeping one step ahead of the volume of threats and vectors for attack.

KEYWORDS: cyber security cybersecurity data breaches Information Technology Security ransomware

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Bogdanbotezatu

Bogdan Botezatu is Director of Threat Research and Reporting at Bitdefender. When Bogdan is not documenting sophisticated strains of malware or writing removal tools, he teaches extreme sports such as surfing the Web without protection or how to rodeo with wild Trojan horses. He believes that most things in life can be beat with strong heuristics and that anti-malware research is like working as a secret agent: you need to stay focused at all times, but you get all the glory when you catch the bad guys.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • SEC0421-ProdSpot-Kasada-Slide6-900px

    Protects Against Bots and Evolving Cyberattack Tactics

    See More
  • Axis, Cisco with Advanced Network Video Solutions

    See More
  • Cyber Liability Insurance: Moving from Insurance to Assurance; cyber security news

    How to protect businesses against the threat of ransomware attacks and the role of cyber insurance

    See More

Related Products

See More Products
  • CASP.jpg.jpg

    CASP+ CompTIA Advanced Security Practitioner Certification All-In-One Exam Guide...

  • intelligent.jpg

    Intelligent Network Video: Understanding Modern Video Surveillance Systems, Second Edition

  • Career Network (60 days)

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing