Most Viewed Content:

Cygnus space cargo spacecraft arrives at International Space Station with only half of its solar array

NASA astronaut Nicole Mann, backed up by NASA astronaut...

Google to bring PWA application backup & restore function for Chrome/android

According to thespAndroid reports, GitHub's Chromium repository recently added...

OpenAI Launched Assistants API, Allowing Developers to Customize AI Assistants with One Click

At today's OpenAI's first developer conference, OpenAI launched the...

Microsoft: Most ransomware attacks take advantage of common cybersecurity mistakes

Microsoft Security blog officially released the latest “Cyber Signals” report points out that the vast majority of ransomware attacks begin with cybercriminals taking advantage of common network security mistakes, which, if managed correctly, can prevent most victims from falling victim to attacks.

Microsoft analyzed anonymous data on real threat activity, and according to the report, Microsoft found that more than 80 percent of ransomware attacks can be traced to common configuration errors in software and devices. These errors include: applications being in a default state that allows access to users across the network; security tools being untested or improperly configured; cloud applications being set up in a way that makes it easy for unauthorized intruders to gain access; and organizations not applying Microsoft’s attack surface reduction rules, which allows attackers to use macros and scripts to run malicious code.

Ransomware attackers are looking for exactly these misconfigurations as they seek out vulnerable targets for ransomware attacks and often the threat of double ransom attacks, in which cybercriminals steal sensitive data and threaten to publish it if they don’t pay.

Microsoft warns that the attacks are made more severe by the growth of the ransomware-as-a-service (RaaS) ecosystem, which allows attackers lacking the technical expertise to create and develop their own ransomware to carry out attacks and extort ransoms. RaaS kits are relatively easy to find on underground forums and some include customer support, providing criminals with all the help they need. Some of these ransomware kits are sold through a subscription model, while others are based on an affiliate model in which the developer takes a portion of the profits from each ransom payment for the decryption key.

To prevent cybercriminals from taking advantage of common mistakes and misconfigurations, Microsoft detailed several recommendations for improving cybersecurity. These recommendations include closing security blind spots by verifying that cybersecurity tools and programs are properly configured in a way that protects the system while disabling macros and other scripts commonly utilized by cybercriminals to execute malicious code.

The report also recommends improving the security of people, networks and cloud services through the use of multi-factor authentication, which can prevent cybercriminals from using stolen usernames and passwords to carry out attacks. Organizations should also apply security patches and updates as soon as possible to prevent attackers from being able to exploit known vulnerabilities.

Latest

Starting from 48,900, Geely Panda Karting officially starts pre-sale

Geely Panda Karting officially started pre-sale. The pre-sale price...

Ford: Expand charging network, fuel/ hybrid/ pure electric in parallel

Recently, Ford released the company's comprehensive annual report for...

Chery’s two new cars are exposed, targeting overseas markets

Recently, some media exposed the actual cars of two...

New Trumpchi Shadow Leopard to launch on May 1, upgraded performance rims

Recently, we learned from the official that the 2024...

Newsletter

Don't miss

Starting from 48,900, Geely Panda Karting officially starts pre-sale

Geely Panda Karting officially started pre-sale. The pre-sale price...

Ford: Expand charging network, fuel/ hybrid/ pure electric in parallel

Recently, Ford released the company's comprehensive annual report for...

Chery’s two new cars are exposed, targeting overseas markets

Recently, some media exposed the actual cars of two...

New Trumpchi Shadow Leopard to launch on May 1, upgraded performance rims

Recently, we learned from the official that the 2024...

Samsung Galaxy S25 Ultra expected to feature 5000mAh + 45W Combo

Technology media WccFtech recently reported that Samsung will not...
Threza Gabriel
Threza Gabrielhttps://www.techgoing.com
Threza Gabriel is a news writer at TechGoing. TechGoing is a global tech media to brings you the latest technology stories, including smartphones, electric vehicles, smart home devices, gaming, wearable gadgets, and all tech trending.

Volvo EX90 produced with SPA2 architecture will be launched in October

Recently, we learned from relevant channels that the Volvo EX90 will be officially launched in October 2024, with deliveries starting in November. The car...

Geely Panda Kart edition will start pre-sale on April 30, CLTC has a range of 200km

Geely Panda Kart will start pre-sales on April 30. The design of this model is inspired by go-karts. It uses a rear single motor...

Mercedes-Benz Shifts Focus from Apple CarPlay to Proprietary Car System

Apple announced a new version of CarPlay at WWDC in June 2022, claiming that "CarPlay will no longer be a simple projection of the...