https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Shutterstock

Chapter 11 filing

Zero-Day Malware Attacks Spike in Q2

  • Written by Edward Gately
  • September 24, 2020
While malware volume fell, network attacks actually rose.

Despite a decrease in number, evasive zero-day malware attacks circumventing antivirus protections jumped in the second quarter.

That’s according to WatchGuard Technologies’ Internet Security Report for Q2 2020. Seventy percent of all attacks involved zero-day malware. That’s a 12% increase over the previous quarter.

WatchGuard’s quarterly research reports are based on anonymized Firebox Feed data from active WatchGuard appliances.

Attacks sent over encrypted HTTPS connections accounted for 34% of attacks. Organizations that aren’t able to inspect encrypted traffic will miss one-third of incoming threats.

Even though the percentage of threats using encryption decreased from 64% in the first quarter, the volume of HTTPS-encrypted malware increased dramatically.

It appears more administrators are taking the necessary steps to enable HTTPS inspection on Firebox security appliances. But there’s still more work to be done.

Surprising Increase in Network Attacks

Corey Nachreiner is WatchGuard‘s CTO.

WatchGuard's Corey Nachreiner

WatchGuard’s Corey Nachreiner

“One of the things we found slightly surprising in our [second quarter] results was that network attacks increased despite the general shift to working from home for many employees,” he said. “As the pandemic accelerated the adoption of remote work, we had expected to see some of our threat volume numbers drop. Note, this isn’t because cybercriminals are attacking less, but more because they are now attacking users at home — which employers’ corporate perimeter security devices may not detect.”

While malware volume fell, network attacks actually rose, Nachreiner said.

“In hindsight, this makes sense, as companies’ network services still remain in the cloud and at the office, even when employees access them from home,” he said. “Our takeaway is that businesses do need to reinforce their endpoint protection to keep workers at home safe. But network security is still necessary to protect the services within their organization’s physical and cloud perimeter.”

This is a great time for MSSPs to focus on technologies and services that can protect these users no matter where they work, Nachreiner said.

Other findings include:

  • JavaScript-based attacks are on the rise.
  • Attackers increasingly use encrypted Excel files to hide malware.
  • A six-year-old denial of service (DoS) vulnerability affecting WordPress and Drupal made a comeback in the second quarter. It affects every unpatched Drupal and WordPress installation. Bad actors can cause CPU and memory exhaustion on underlying hardware.
  • Malware domains leverage command and control servers to wreak havoc.

What Organizations Should Do

“There are three primary things we think organizations should be doing better to protect themselves,” Nachreiner said. “First, scanning HTTPS traffic for malware and network threats. In both our second quarter and previous first quarter report, we found a significant portion of malware arrives via encrypted, HTTPS traffic. Previously, we found about two-thirds of malware arrived via HTTPS, and during the second quarter that dropped to about one-third. Despite the drop, one-third is a lot of malware to miss for an organization, especially when the average WatchGuard Firebox sees at least 670 variants of malware a quarter.”

Second, organizations should use advanced or proactive malware detection, he said.

“Every quarter, our zero-day malware statistic shows a big portion of malware evades traditional, signature-based protections,” Nachreiner said. “If you don’t have behavioral or ML-based anti-malware services, you could miss two-thirds of the threats out there.

 And finally, multifactor authentication (MFA) is necessary for every employee, he said.

“Our report consistently shows signs that cybercriminals focus on credential theft and leaks as one of the easiest ways to compromise a network,” Nachreiner said. “MFA is the best way to protect your users’ credential and secure your authentication process. While some SMBs have deployed MFA to privileged users for certain workloads, we find few deploy it throughout their organization for every user — but doing so is one of the best ways to secure your company.”

Tags: Agents Cloud Security

Most Recent


  • Baseball swing
    VMware Partner Connect Now in Full Swing Worldwide
    "This is the complete end state” of VMware’s channel program, per Tracy-Ann Palmer, and will hold for years.
  • Doubling down
    The Gately Report: Huntress to Double Down on MSP Partner Investment
    A massive health care industry data breach remained under wraps for nearly a year.
  • Layoffs
    Latest Amazon Layoffs Impacting 9,000 Workers, Including AWS
    This likely isn't the end of layoffs at Amazon.
  • HPE Greenlake depiction
    HPE to Expand GreenLake Into ITOM Market with OpsRamp Acquisition
    OpsRamp was part of Hewlett Packard Pathfinder’s venture capital investment in 2020.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • USB drive
    A Coup and a Theft: Why MSPs Can’t Let Clients Get Lax About USB Security
  • Ransomware skull and crossbones
    JBS Did What it 'Needed to Do' with $11 Million Ransom Payment
  • hybrid clouds
    Nutanix, HPE Team on Hybrid, Multicloud via GreenLake
  • lone Arctic wolf
    Arctic Wolf Enhances Partner Program with 2 New Tiers

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

VMware Partner Connect Now in Full Swing Worldwide

March 20, 2023

The Gately Report: Huntress to Double Down on MSP Partner Investment

March 20, 2023

8 Channel People Making Waves This Week at T-Mobile, Kaseya, Google Cloud, Atlassian, More

March 17, 2023

Industry Perspectives

View all

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

How Hybrid Work Poses Major Cybersecurity Risks

March 1, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Real-Life M&A: Advice for a Successful Channel Deal

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

XDR Technology: Latest Breakthroughs, How to Talk to Customers

March 1, 2023

Coffee with Craig and James Episode 119: Alliance of Channel Women

February 22, 2023

Twitter

ChannelFutures

.@HPE acquiring @OpsRamp to add capabilities to @HPE_GreenLake. #cloud dlvr.it/SlCFz9

March 20, 2023
ChannelFutures

The relationship between technology advisor (agent) firms, technology service distributors (TSDs) and suppliers is… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

.@citrix channel marketing exec Tricia Atkinson is joining @Equinix to lead global partner #marketing.… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

.@bizITsolutions announced a partnership with New Charter Technologies. dlvr.it/SlBh09 https://t.co/xpqbQcKC6y

March 20, 2023
ChannelFutures

.@VMware has finalized #PartnerConnect and plans to keep it as-is (minus simplification changes) for years to come.… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

Our latest #GatelyReport includes a Q&A with @HuntressLabs, massive ILS #databreach, new @SECGov cyber proposal,… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

Channel people making waves include: @MikeSievert, @TheFredVoccola, @Ichhpurani, @mcannonbrookes, @scottfarkas… twitter.com/i/web/status/1…

March 17, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X