Sign in
  • Latest News
  • Physical Security
    • Access Control & Identification
    • Critical Infrastructure
    • Dealers & Integrators
    • Integration
    • Perimeter Protection
    • Video Surveillance
  • IT Security
    • Communications
    • Corporate Facilities
    • Cyber Security
    • Data Storage
    • Encryption
    • Networking Security
  • Government Security
    • Education
    • Federal
    • Law Enforcement
    • Military
    • Municipal
    • Security Services
    • State
  • Ports of Entry
    • Aerospace
    • Airports/Aviation
    • Border
    • CBRNE Detection
    • Maritime
  • Crisis Responders
    • Campus Security
    • Disaster Prevention
    • Emergency Response
    • First Responders
  • AST Awards
Sign in
Welcome!Log into your account
Forgot your password?
Password recovery
Recover your password
Monday, March 20, 2023
  • Sign in / Join
  • Events
  • About
  • Blog
  • Advertise
  • Contact
  • Sign Up
  • Sitemap
  • Privacy Policy
  • Cart
Sign in
Welcome! Log into your account
Forgot your password? Get help
Password recovery
Recover your password
A password will be e-mailed to you.
American Security Today
 
American Security Today American Security Today
  • Latest News
    • “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.
      Corporate Facilities

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      Sylvia Zachary, Cybersecurity & Software Director - Secure Communications (SCOM), for Cubic Mission & Performance Solutions, shares her thoughts and experiences in Embracing Your Strengths, and Celebrating Diversity During Women’s History Month and Beyond.
      Cyber Security

      Embracing Your Strengths During Women’s History Month and Beyond

      Temple University Police Officer Christopher Fitzgerald (Courtesy of Temple University and Social Media)
      Campus Security

      Hero Down: Accused Cop Killer Tried to Rob Fallen Temple Officer

      The Niagara Falls School District added Evolv Express® AI weapons detection systems to its schools through a partnership with STANLEY Security
      Access Control & Identification

      Niagara Falls City Schools Prioritize Learning with New Security by Evolv

      HALO Smart Sensor 3C is an all-in-one safety device that now includes a Panic Button, 2-way Audio Communi-cations, Indoor Health Index, Emergency Escape and Alert Lighting, Motion Detection, and options for People Counting and customized sensors such as ozone, sulfur dioxide, water leaks, and more.
      Access Control & Identification

      IPVideo Offerings Backed by Decades of Security & Technology Innovation

  • Physical Security
    • AllAccess Control & IdentificationCritical InfrastructureDealers & IntegratorsIntegrationPerimeter ProtectionVideo Surveillance
      “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.
      Corporate Facilities

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      The Niagara Falls School District added Evolv Express® AI weapons detection systems to its schools through a partnership with STANLEY Security
      Access Control & Identification

      Niagara Falls City Schools Prioritize Learning with New Security by Evolv

      HALO Smart Sensor 3C is an all-in-one safety device that now includes a Panic Button, 2-way Audio Communi-cations, Indoor Health Index, Emergency Escape and Alert Lighting, Motion Detection, and options for People Counting and customized sensors such as ozone, sulfur dioxide, water leaks, and more.
      Access Control & Identification

      IPVideo Offerings Backed by Decades of Security & Technology Innovation

      With its ongoing leadership throughout the biometric solutions industry, NEC's robust biometric authentication solution emphasizes how NEC's ability to meet existing and new customer demands, empower end users to take control over their biometric data and steer the biometric industry into the next phase of growth. (Courtesy of NEC)
      Access Control & Identification

      NEC Named Leader in the Frost Radar Biometrics Authentication Solutions

  • IT Security
    • AllCommunicationsCorporate FacilitiesCyber SecurityData StorageEncryptionNetworking Security
      “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.
      Corporate Facilities

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      Sylvia Zachary, Cybersecurity & Software Director - Secure Communications (SCOM), for Cubic Mission & Performance Solutions, shares her thoughts and experiences in Embracing Your Strengths, and Celebrating Diversity During Women’s History Month and Beyond.
      Cyber Security

      Embracing Your Strengths During Women’s History Month and Beyond

      FirstNet must operate in accordance with its Congressional mandate, and without undue influence from commercial interests, explains Commissioner Bratton, Former NYPD and LAPD Police Commissioner, Vice Chairman of the Secretary of Homeland Security’s Advisory Council. Commissioner Bratton shown here addressing attendees at the 2022 'ASTORS' Homeland Security Awards Ceremony and Banquet Luncheon in New York City.
      Communications

      Legendary 9/11 Public Servants Raise Concerns Over FirstNet IG Report

      One of the most popular types of phygital attacks is “warshipping,” in which the attacker sends a digital device small enough to fit in a modestly sized cardboard package, through the mail.
      Campus Security

      Phygital Attacks: Protecting Critical Infrastructure from Cyber Threats

  • Government Security
    • AllEducationFederalLaw EnforcementMilitaryMunicipalSecurity ServicesState
      “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.
      Corporate Facilities

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      Sylvia Zachary, Cybersecurity & Software Director - Secure Communications (SCOM), for Cubic Mission & Performance Solutions, shares her thoughts and experiences in Embracing Your Strengths, and Celebrating Diversity During Women’s History Month and Beyond.
      Cyber Security

      Embracing Your Strengths During Women’s History Month and Beyond

      Temple University Police Officer Christopher Fitzgerald (Courtesy of Temple University and Social Media)
      Campus Security

      Hero Down: Accused Cop Killer Tried to Rob Fallen Temple Officer

      The Niagara Falls School District added Evolv Express® AI weapons detection systems to its schools through a partnership with STANLEY Security
      Access Control & Identification

      Niagara Falls City Schools Prioritize Learning with New Security by Evolv

  • Ports of Entry
    • AllAerospaceAirports/AviationBorderCBRNE DetectionMaritime
      “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.
      Corporate Facilities

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      Sylvia Zachary, Cybersecurity & Software Director - Secure Communications (SCOM), for Cubic Mission & Performance Solutions, shares her thoughts and experiences in Embracing Your Strengths, and Celebrating Diversity During Women’s History Month and Beyond.
      Cyber Security

      Embracing Your Strengths During Women’s History Month and Beyond

      With its ongoing leadership throughout the biometric solutions industry, NEC's robust biometric authentication solution emphasizes how NEC's ability to meet existing and new customer demands, empower end users to take control over their biometric data and steer the biometric industry into the next phase of growth. (Courtesy of NEC)
      Access Control & Identification

      NEC Named Leader in the Frost Radar Biometrics Authentication Solutions

      Keith Terreri, Executive Vice President of Enterprise Services and Business Operations, NEC Corporation of America, explains why NEC supports the Annual 'ASTORS' Homeland Security Awards Program, and American Security Today’s Mission
      Access Control & Identification

      Why NEC Supports AST’s Mission & ‘ASTORS’ Homeland Security Awards

  • Crisis Responders
    • AllCampus SecurityDisaster PreventionEmergency ResponseFirst Responders
      Temple University Police Officer Christopher Fitzgerald (Courtesy of Temple University and Social Media)
      Campus Security

      Hero Down: Accused Cop Killer Tried to Rob Fallen Temple Officer

      The Niagara Falls School District added Evolv Express® AI weapons detection systems to its schools through a partnership with STANLEY Security
      Access Control & Identification

      Niagara Falls City Schools Prioritize Learning with New Security by Evolv

      HALO Smart Sensor 3C is an all-in-one safety device that now includes a Panic Button, 2-way Audio Communi-cations, Indoor Health Index, Emergency Escape and Alert Lighting, Motion Detection, and options for People Counting and customized sensors such as ozone, sulfur dioxide, water leaks, and more.
      Access Control & Identification

      IPVideo Offerings Backed by Decades of Security & Technology Innovation

      With its ongoing leadership throughout the biometric solutions industry, NEC's robust biometric authentication solution emphasizes how NEC's ability to meet existing and new customer demands, empower end users to take control over their biometric data and steer the biometric industry into the next phase of growth. (Courtesy of NEC)
      Access Control & Identification

      NEC Named Leader in the Frost Radar Biometrics Authentication Solutions

  • AST Awards
Home IT Security Cyber Security Passwords a Top Threat, Multi-Factor Authentication Needed, Study Says
  • IT Security
  • Cyber Security
  • Crisis Responders
  • Disaster Prevention
  • Government Security
  • State

Passwords a Top Threat, Multi-Factor Authentication Needed, Study Says

By
Tammy Waitt
-
September 12, 2018
Facebook
Twitter
Google+
Pinterest
WhatsApp
    Courtesy of WatchGuard Technologies
    WatchGuard’s Q2 2018 Internet Security Report uncovers cybercriminals’ heightened use of credential-focused attacks, the continued prevalence of malicious Office documents, and more

    WatchGuard® Technologies, has released the findings of its new Internet Security Report for Q2 2018, which explores the latest security threats affecting small to midsize businesses (SMBs) and distributed enterprises.

    This new research from WatchGuard Threat Labs revealed that 50% of government and military employee ‘LinkedIn’ passwords were weak enough to be cracked in less than two days.

    This finding, along with the emergence of the Mimikatz credential-stealing malware as a top threat and the popularity of brute force login attacks against web applications, underscores the reality that passwords alone can’t offer sufficient protection, and emphasizes the need for multi-factor authentication (MFA) solutions, in every organization.

    Corey Nachreiner, CTO at WatchGuard Technologies
    Corey Nachreiner, CTO at WatchGuard Technologies

    “Authentication is the cornerstone of security, and we’re seeing overwhelming evidence of its critical importance in the common trend of password- and credential-focused threats throughout Q2 2018,” explains Corey Nachreiner, chief technology officer at WatchGuard Technologies.

    “Whether it’s an evasive credential-stealing malware variant or a brute force login attack, cyber criminals are laser-focused on hacking passwords for easy access to restricted networks and sensitive data.”

    “At WatchGuard, these trends are driving new innovative defenses within our product portfolio, including AuthPoint, our Cloud-based multi-factor authentication solution and our IntelligentAV service, which leverages three malware detection engines to prevent malware strains that evade traditional signature-based antivirus products.”

    “Every organization should seek out vendor and solution provider partners that offer layered protection against these ever-evolving attack techniques.”

    (Learn More about Multi-Factor Authentication. Courtesy of WatchGuard Technologies and YouTube. Posted on May 2, 2018.)

    The insights, research and security best practices included in WatchGuard’s quarterly Internet Security Report are designed to help organizations of all sizes understand the current cyber security landscape and better protect themselves, their partners and customers from emerging security threats.

    Roughly half of government and military employee passwords are weak.

    • After conducting a thorough analysis of the 2012 LinkedIn data dump to identify trends in user password strength, WatchGuard’s Threat Lab team found that half of all passwords associated with “.mil” and “.gov” email address domains within the database were objectively weak.

    • Of the 355,023 government and military account passwords within the database, 178,580 were cracked in under two days.

    • The most common passwords used by these accounts included “123456,” “password,” “linkedin,” “sunshine,” and “111111.”

    • Conversely, the team found that just over 50% of civilian passwords were weak.

    • These findings further illustrate the need for stronger passwords for everyone, and a higher standard for security among public service employees that handle potentially sensitive information.

    • In addition to better password training and processes, every organization should deploy multi-factor authentication solutions to reduce the risk of a data breach.

    Key Takeaways from the Q2 2018 Report Include:

    Mimikatz was the most prevalent malware variant in Q2.

    • Representing 27.2% of the top 10 malware variants listed last quarter, Mimikatz is a well-known password and credential stealer that has been popular in past quarters, but has never been the top strain.

    • This surge in Mimikatz’s dominance suggests that authentication attacks and credential theft are still major priorities for cyber criminals – another indicator that passwords alone are inadequate as a security control, and should be fortified with MFA services that make hackers’ lives harder by requiring additional authentication factors in order to successfully login and access the network.

    More than 75% of malware attacks are delivered over the web.

    • A total of 76% of threats from Q2 were web-based, suggested that organizations need an HTTP and HTTPS inspection mechanism to prevent the vast majority of attacks.

    • Ranked as the fourth most prevalent web attack in particular, “WEB Brute Force Login -1.1021” enables attackers to execute a massive deluge of login attempts against web applications, leveraging an endless series of random combinations to crack user passwords in a short period of time.

    • This attack in particular is another example of cyber criminals’ heightened focus on credential theft, and shows the importance of not only password security and complexity, but the need for MFA solutions as a more effective preventative measure.

    (Learn More about WatchGuard Technologies. Courtesy of WatchGuard Technologies and YouTube. Posted on Jul 2, 2018.)

    • Cryptocurrency miners earn spot as a top malware variant.

    • As anticipated, malicious cryptominers are continuing to grow in popularity as a hacking tactic, making their way into WatchGuard’s top 10 malware list for the first time in Q2.
    • Last quarter, WatchGuard uncovered its first named cryptominer, Cryptominer.AY, which matches a JavaScript cryptominer called “Coinhive” and uses its victims’ computer resources to mine the popular privacy-focused cryptocurrency, Monero (XRM).
    • The data shows that victims in the United States were the top geographical target for this cryptominer, receiving approximately 75% of the total volume of attacks.

    Cyber criminals continue to rely on malicious Office documents.

    • Threat actors continue to booby-trap Office documents, exploiting old vulnerabilities in the popular Microsoft product to fool unsuspecting victims.
    • Interestingly, three new Office malware exploits made WatchGuard’s top 10 list, and 75% of attacks from these attacks targeted EMEA victims, with a heavy focus on users in Germany specifically.

    The complete Internet Security Report features an in-depth analysis of the EFail encryption vulnerability, and insights into the top attacks in Q2 and defensive strategies SMBs can use to improve their security posture.

    These finding are based on anonymized Firebox Feed data from nearly 40,000 active WatchGuard UTM appliances worldwide, which blocked nearly 14 million malware variants (449 per device) and more than 1 million network attacks (26 per device) in Q2 2018.

    For more information, download the full report here.

    WatchGuard logoWatchGuard’s mission is to make enterprise-grade security accessible to companies of all types and sizes through simplicity, making WatchGuard an ideal solution for distributed enterprises and SMBs.

    • TAGS
    • 'LinkedIn' passwords
    • AuthPoint
    • brute force login attacks
    • Corey Nachreiner
    • Cryptocurrency miners
    • cyber criminals
    • defensive strategies
    • EFail encryption vulnerability
    • Internet Security Report for Q2 2018
    • malicious Office documents
    • mall to midsize businesses (SMBs)
    • Mimikatz credential-stealing malware
    • need for multi-factor authentication (MFA)
    • WatchGuard Technologies
    • WatchGuard Threat Labs
    Facebook
    Twitter
    Google+
    Pinterest
    WhatsApp
      Previous articleTrump Signs US Election Security Executive Order (Multi-Video)
      Next articleTSA Screens Record-Breaking Travel Numbers in Busiest Summer Ever
      Tammy Waitt

      RELATED ARTICLESMORE FROM AUTHOR

      “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.
      Corporate Facilities

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      Sylvia Zachary, Cybersecurity & Software Director - Secure Communications (SCOM), for Cubic Mission & Performance Solutions, shares her thoughts and experiences in Embracing Your Strengths, and Celebrating Diversity During Women’s History Month and Beyond.
      Cyber Security

      Embracing Your Strengths During Women’s History Month and Beyond

      Temple University Police Officer Christopher Fitzgerald (Courtesy of Temple University and Social Media)
      Campus Security

      Hero Down: Accused Cop Killer Tried to Rob Fallen Temple Officer

      The Niagara Falls School District added Evolv Express® AI weapons detection systems to its schools through a partnership with STANLEY Security
      Access Control & Identification

      Niagara Falls City Schools Prioritize Learning with New Security by Evolv

      HALO Smart Sensor 3C is an all-in-one safety device that now includes a Panic Button, 2-way Audio Communi-cations, Indoor Health Index, Emergency Escape and Alert Lighting, Motion Detection, and options for People Counting and customized sensors such as ozone, sulfur dioxide, water leaks, and more.
      Access Control & Identification

      IPVideo Offerings Backed by Decades of Security & Technology Innovation

      With its ongoing leadership throughout the biometric solutions industry, NEC's robust biometric authentication solution emphasizes how NEC's ability to meet existing and new customer demands, empower end users to take control over their biometric data and steer the biometric industry into the next phase of growth. (Courtesy of NEC)
      Access Control & Identification

      NEC Named Leader in the Frost Radar Biometrics Authentication Solutions

      EDITOR PICKS

      “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      March 10, 2023
      Sylvia Zachary, Cybersecurity & Software Director - Secure Communications (SCOM), for Cubic Mission & Performance Solutions, shares her thoughts and experiences in Embracing Your Strengths, and Celebrating Diversity During Women’s History Month and Beyond.

      Embracing Your Strengths During Women’s History Month and Beyond

      March 10, 2023
      Temple University Police Officer Christopher Fitzgerald (Courtesy of Temple University and Social Media)

      Hero Down: Accused Cop Killer Tried to Rob Fallen Temple Officer

      February 21, 2023

      POPULAR POSTS

      “It is an honor to join you today and to stand with the incredible men and women of law enforcement,” said President Donald J. Trump at the 270th session of the FBI National Academy.

      Trump Congratulates FBI National Academy’s 270th Class (Learn More)

      December 16, 2017

      Gulfstream G600 Takes Flight Ahead of Schedule (See in Action)

      December 18, 2016
      “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      March 10, 2023

      POPULAR CATEGORY

      • Government Security5205
      • Law Enforcement4041
      • Federal3931
      • Disaster Prevention3285
      • Municipal3052
      • Security Services2996
      • State2960
      • Crisis Responders2446
      • Emergency Response2320
      American Security Today
      ABOUT US
      Security as it is today – bringing security issues from protecting our communities, ports and cities to evolving threats to you in realtime – today’s real threats
      Online Payments
      Contact us: twaitt@americansecuritytoday.com
      FOLLOW US
      © Copyright 2017 - AST
      MORE STORIES
      “By building on our core solutions through ongoing innovation, we will continue to alleviate customers’ pain points while adding new value through advanced vision solutions,” explains Soon-hong Ahn, President and CEO of Hanwha Vision.

      Hanwha’s New Rebrand Reflects Focus on Global Vision for the Future

      March 10, 2023
      Sylvia Zachary, Cybersecurity & Software Director - Secure Communications (SCOM), for Cubic Mission & Performance Solutions, shares her thoughts and experiences in Embracing Your Strengths, and Celebrating Diversity During Women’s History Month and Beyond.

      Embracing Your Strengths During Women’s History Month and Beyond

      March 10, 2023
      Temple University Police Officer Christopher Fitzgerald (Courtesy of Temple University and Social Media)

      Hero Down: Accused Cop Killer Tried to Rob Fallen Temple Officer

      February 21, 2023