Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 2018 Predictions – From Cryptocurrency Mining To ‘Fileless’ Attacks
Articles

2018 Predictions – From Cryptocurrency Mining To ‘Fileless’ Attacks

ISBuzz TeamBy ISBuzz TeamDecember 13, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Wide spread cryptocurrency mining

Cryptocurrency mining will become one of the major monetisation avenues for attackers as more and more attacks and malware include mining functionality to generate revenue. In particular a focus will be on in-browser mining that will be the result of website attacks. A simple few lines of Javascript can cause visiting browsers to ‘mine’ cryptocurrency while on the affected sites. This is occurring now, but isn’t as widespread as it likely will be next year.

An increase in DDoS attacks

The return of mega DDoS attacks via IoT powered botnets is likely in 2018. These have been pretty silent compared to last year’s attack against Dyn that took down many commonly used services but could come back in a more nefarious way. The next wave could potentially affect large swathes of Internet services either by design or as collateral damage from another entity being hit due to the sheer size of the attack. The wide attack surface of IoT devices makes them particularly attractive for botnets and this will only get bigger with the amount of home automation products sold over Christmas.

This malicious activity will be for political advantage as well as monetary gain. While ransomware and DDoS attacks are likely to get more targeted in the way that phishing evolved into spear phishing attacks.

Encouraging young talent into the industry

The skills gap is definitely still holding the industry back. As cyber warfare increases, governments need to upskill the next generation of defenders. Figures around the cyber skills shortage make for sobering reading. A report from Frost & Sullivan and (ISC)² found that the global cybersecurity workforce will have more than 1.5 million unfilled positions by 2020.

Both private and state schools need strong cyber programs and academies should look to develop cyber skills in children from disadvantaged backgrounds. This will hopefully prevent talented teenagers being sucked into the dark side.

Although at the same time that industry struggles to recruit talent, university graduates are finding it hard to start their careers in cyber security. We need to improve opportunities for entry level positions including internships, apprenticeships, more cyber classes in schools, and formal cyber programs. This also requires a look beyond STEM as careers in threat intelligence can better suit analytical degrees, due to the need to be able to research, analyse and draw conclusions, which can give them the edge over those with a scientific mind-set.

There are some bright new leaders in the industry that are focusing on education and engaging young talent in the industry and this has to continue.

Stealthy ‘fileless’ attacks will increase

There is likely to be a move towards more sophisticated ‘fileless’ attacks (malicious scripts that hijack legitimate software, without installing themselves). There has already been a sharp rise. Such attacks are very difficult to stop with existing endpoint security and organisations will need to move to next generation of defences.

The focus will likely be on other industries outside of Financial Services. As the banks become more resilient in their ability to profile and learn from actors, less well-protected organisations could be targeted, as we have seen that with Forever 21 and the recent Jewson attacks in the UK.

More integrated collaboration is required

The likes of NSC and GCHQ are being effective in their limited remits and are busy disrupting many adversary groups. But they need to move faster and cannot be limited to cyber crime. There must also be a focus on state sponsored, hacktivism and other sophisticated attacks, and levels of awareness and associated education should be increased concurrently.

Such government groups cannot defend alone, and should collaborate more with organisations themselves, as well as private groups such as the Cyber Defence Alliance and FS-ISAC, and continue to drive closed and industry collaboration.

Europe needs to catch up

The US market is incredibly mature when it comes to intelligence strategies. Their understanding of intelligence, how it can be leveraged and operationalised is 18 months ahead of the UK and other European countries. Defence is critical, but it should be well understood that black boxes no matter how complex will not stop attacks. The UK and Europe need to focus less on doing ‘just enough’ for compliance. If you are implementing privilege account management protections, you need to cover everything, not just the devices that get you a tick in the box. Intelligence lead strategies are critical to identifying compromise and exposing ‘indicators of attack’. As any Red Team person will tell you, intelligence-driven incident response starts by learning from the adversaries.

[su_box title=”About Travis Farral” style=”noise” box_color=”#336588″][short_info id=’104004′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The next phase of endpoint security starts with simplicity

June 24, 20266 Mins Read

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}