https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • Analytics
    • Artificial Intelligence
    • Cloud
    • Data Centers
    • Desktop
    • IoT
    • Mobility
    • Networking
    • Open Source
    • RMM/PSA
    • Security
    • Virtualization
    • Voice/Connectivity
  • Strategy
    • Back
    • Best Practices
    • Business Models
    • Channel 101
    • Channel Programs
    • Channel Research
    • Digital Transformation
    • Diversity & Inclusion
    • Leadership
    • Mergers and Acquisitions
    • Sales & Marketing
    • Specialty Practices
  • MSSP Insider
    • Back
    • Business of Security
    • Cloud and Edge
    • Endpoint
    • Network
    • People and Careers
    • Training and Policies
  • MSP 501
    • Back
    • 2020 MSP 501 Rankings
    • 2020 Hot 101 Rankings
    • 2020 MSP 501 Report
  • Intelligence
    • Back
    • Our Sponsors
    • From the Industry
    • Content Resources
    • COVID-19 Partner Help
    • Galleries
    • Podcasts
    • Reports
    • Videos
    • Webinars
    • White Papers
  • EMEA
  • Awards
    • Back
    • Excellence in Digital Services
    • 2020 MSP 501
    • Top Gun 51
  • Events
    • Back
    • CP Conference & Expo
    • Channel Partners Evolution
    • Channel Evolution Europe
    • Channel Partners Event Coverage
    • Webinars
  • Channel Mentor
    • Back
    • Channel Market Intelligence
    • Channel Educational Series
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • Analytics
    • Artificial Intelligence
    • Cloud
    • Data Centers
    • Desktop
    • IoT
    • Mobility
    • Networking
    • Open Source
    • RMM/PSA
    • Security
    • Virtualization
    • Voice/Connectivity
  • Strategy
    • Back
    • Best Practices
    • Business Models
    • Channel 101
    • Channel Programs
    • Channel Research
    • Digital Transformation
    • Diversity & Inclusion
    • Leadership
    • Mergers and Acquisitions
    • Sales & Marketing
    • Specialty Practices
  • MSSP Insider
    • Back
    • Business of Security
    • Cloud and Edge
    • Endpoint
    • Network
    • People and Careers
    • Training and Policies
  • MSP 501
    • Back
    • 2020 MSP 501 Rankings
    • 2020 Hot 101 Rankings
    • 2020 MSP 501 Report
  • Intelligence
    • Back
    • Our Sponsors
    • From the Industry
    • Content Resources
    • COVID-19 Partner Help
    • Galleries
    • Podcasts
    • Reports
    • Videos
    • Webinars
    • White Papers
  • EMEA
  • Awards
    • Back
    • Excellence in Digital Services
    • 2020 MSP 501
    • Top Gun 51
  • Events
    • Back
    • CP Conference & Expo
    • Channel Partners Evolution
    • Channel Evolution Europe
    • Channel Partners Event Coverage
    • Webinars
  • Channel Mentor
    • Back
    • Channel Market Intelligence
    • Channel Educational Series
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Digital Service Providers
  • Cloud Service Providers
  • CHANNEL PARTNERS ONLINE
 Channel Futures

MSSP Insider


Shutterstock

PC Endpoint Security

Endpoint Security: Could CMSs Pose Problems?

  • Written by Derek Handova
  • June 5, 2019
Cross-site scripting, unverified plug-ins and adware are potential CMS endpoint problems.

… take over the entire WCMS account with just a list of compromised credentials. Hackers use this type of credential stuffing attack to guess the admin account password. They can then use the site as part of malware distribution campaigns.”

To defend against credential stuffing attacks, Wilson recommends deploying two-factor authentication and checking password strength as passwords are being created. Other security measures can also help protect endpoint security, but they can entail asking hard questions of CMS vendors, design agencies, hosting companies and MSSPs themselves.

Hosted CMS Applications and Endpoint Security

And when companies use outside providers like design agencies, hosting companies or MSSPs to host their CMS-powered websites, the CMS could pose endpoint security problems for their end-user customers if not properly protected against adware, say digital marketing experts.

BrandLock's Vanhishikha Bhargava

BrandLock’s Vanhishikha Bhargava

“Common belief says that a CMS can actually protect a site from adware,” said Vanhishikha Bhargava, head of marketing at BrandLock, a provider of conversion optimization suites. “But the truth is that it only protects the site from hacks. So while the CMS will keep a retail site’s customer data safe, adware injected by browser extensions and web apps almost appear similar to an overlay.”

Even worse, the CMS has absolutely no way of identifying what kind of ad an adware strain will inject into the consumer’s browser while on the site. Bhargava says her company has identified that brands like Cartier, Jabra, and Puma have been threatened by adware on the consumer endpoint but that its machine learning-powered solution strengthens CMSs and keeps adware at bay.

Browser Security and Endpoint Security

When it comes to browser security, it should be strict by default — locked down to prevent unannounced automatic installation of hidden plug-ins and block unsigned and untrusted content.

“Browser security should include testing and validation with warnings if untrusted code, content or communications are initiated,” said Scott Mongeau, principal cybersecurity solutions manager at SAS. “A protocol should be in place to alert security stewards when suspicious content shows up in the supply chain. There should be a clear disaster recovery plan concerning how to quickly remediate an incident.”

The Large Attack Surface of CMSs

With at least half of websites built with a CMS, statistics show that the number of installations of some publicly available and vulnerable CMSs is making things worse, due to the large surface of potential attacks, according to security researchers.

“Often, enterprises have decent systems with a good amount of protection mechanisms in place, but they can still be compromised,” said Leigh-Anne Galloway, cybersecurity resilience lead at Positive Technologies, a security specialist. “It’s inevitable because of the low level of security awareness for the majority of companies in the retail industry. Vulnerabilities such as default credentials, database abuse, publicly available backups and configuration files, and using outdated versions of software were all used in successful intrusion scenarios.”

Then if a CMS is combined with e-commerce features, not only is your business infrastructure vulnerable to attack, but your customers’ financial information also is vulnerable to theft, such as in recent attacks on British Airways and Magento, Galloway says.

  • Page 1
  • Page 2
Tags: MSPs Endpoint MSSP Insider MSSP Insider

Related


  • Cybersecurity Roundup
    Democrats to Take Charge of Federal Cybersecurity in Election Aftermath
    Democrats will have their hands full when dealing with federal cybersecurity.
  • DC Capitol Riot
    US Capitol Rioters Pose Cybersecurity Threat Due to Device Access, Theft
    It's not yet known what all the rioters got their hands on or saw.
  • 2021 - The Year of Extortion
    Expect 2021 to Be Fraught with Cybersecurity Threats
    Ransomware, insider threats, VPNs, weak APIs. Here's what MSPs/MSSPs need to know for 2021.
  • Cybersecurity Roundup
    Beyond SolarWinds, Russian Hackers Target Austin, Texas
    All cities with critical infrastructure should be worried about cyberattacks.

One comment

  1. Avatar dave.eversden@forever-group.co.uk November 25, 2020 @ 4:46 am
    Reply

    Dave at Forever Group here. I found this article very interesting. Of course, locally served or sideloaded content is not going to traverse traditional web gateway or security technologies such as Cisco Umbrella.

    For me, this really cements the importance of peripheral cyber security strategies such as patch management to ensure that known browser vulnerabilities are closed down ASAP. Likewise, endpoints should really have zero-day-capable security solutions in place – and ideally intrusion prevention and web security to thwart the inevitable ‘dial-home’ if a foothold is gained.

    Thank you for highlighting a non-obvious avenue where website-based threats could circumvent perimeter defences.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • IBM: Cybercriminals Could Disrupt COVID-19 Vaccine Supply Chain
  • FASTCHAT: How Old, Unpatched Technologies Are Creating New Security Threats for MSPs and Their Customers
  • Acronis Cyber Threats Report: 2021 Will Be 'Year of Extortion'
  • 8 Ways Fraud Email Can Compromise Your Back Office

Galleries

View all

New, Changing Partner Programs: AWS, Tech Data, Avaya, Verizon

January 11, 2021

Industry Perspectives

View all

Help Your Customers Mitigate Malware: Viruses, Worms, and Trojans…Oh My!

January 15, 2021

SMBs’ Cybersecurity Risk Awareness Is Rising

January 13, 2021

Your Cloud Data Is Protected, But Is It Portable?

January 12, 2021

Webinars

View all

Blueprint for a Scalable MSSP Practice in 2021

January 21, 2021

Who’s Behind the Mask? Hacker Personas Explained

January 26, 2021

How Managed Hosting Providers Thrive with the Alternative Cloud

February 24, 2021

White Papers

View all

Why Subscription Business Model

January 15, 2021

The Ultimate MSP Guide to Sales Efficiency

January 14, 2021

Eight Reasons Why MSPs Need IT Industry-Specific Sales Tools

January 14, 2021

Upcoming Events

View all

Channel Partners Virtual

March 2, 2021 - March 4, 2021

Channel Partners Conference & Expo

November 1, 2021 - November 4, 2021

Videos and Fastchats

View all

FASTCHAT: How SOAR Eliminates Security Challenges and Elevates Service Provider Revenues

January 6, 2021

Happy Holidays from Channel Partners & Channel Futures!

December 21, 2020

FASTCHAT: How Old, Unpatched Technologies Are Creating New Security Threats for MSPs and Their Customers

December 3, 2020

Twitter

ChannelFutures

.@IBMServices snaps up #MSP Taos for #hybridcloud expertise. dlvr.it/RqggQR https://t.co/Fy3uPDtLNw

January 16, 2021
ChannelFutures

.@LenovoBusiness launches its thinnest #ThinkPad to date @CES, revamped ThinkBooks and #ThinkReality glasses.… twitter.com/i/web/status/1…

January 16, 2021
ChannelFutures

Help your customers mitigate #malware @Tech_Data #cryptolocker #antivirus #ransomware #cybersecurity… twitter.com/i/web/status/1…

January 15, 2021
ChannelFutures

Advantages of the Subscription business model for MSPs and IT Resellers @kaspersky dlvr.it/RqgDJn https://t.co/ay694fudp3

January 15, 2021
ChannelFutures

Cloud #distributor @Pax8 launches in UK with leadership team in place. dlvr.it/RqfJWx https://t.co/RsKDCowM5V

January 15, 2021
ChannelFutures

bit.ly/3oO2vFY twitter.com/Craig_Galbrait…

January 15, 2021
ChannelFutures

The Ultimate MSP Guide to Sales Efficiency @zomentum dlvr.it/Rqc63q https://t.co/rHIVLkR01K

January 15, 2021
ChannelFutures

Eight Reasons Why MSPs Need IT Industry-Specific Sales Tools dlvr.it/Rqc62k https://t.co/MQDcIYc7G9

January 15, 2021

MSSP Insider

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Channel Partners Online

Want more? Find more channel news and analysis on our sister site, Channel Partners.

Media Kit And Advertising

Want to reach our audience? Access our media kit

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Online
  • Channel Partners Events
  • MSP 501
  • MSSP Insider
  • IoT World Today
  • Webhostingtalk

WORKING WITH US

  • Contact
  • About us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2021 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X