F5 Labs Publishes Digital Privacy and Security Threat Trends
F5 Labs Publishes Digital Privacy and Security Threat Trends
  • Jung So-yeon
  • 승인 2024.01.09 12:09
  • 댓글 0
이 기사를 공유합니다

- Credential stuffing accounts for 19.4% of all protected traffic
- Reverse Phishing Proxies Becoming a Standard Approach, Neutralizing Most Multi-Factor Authentication (MFA)
- Malware, phishing and social engineering techniques popularize methods to bypass multi-factor authentication

Seoul, South Korea-based F5 today announced that its recently released "2023 Privacy Threat Report" reveals that threats to digital identity are persistent and evolving at a rapid pace. The report focuses on three threats that have the greatest impact on digital privacy: credential stuffing, phishing, and multi-factor authentication (MFA) bypass. 

Across all sectors, the report found that credential stuffing accounted for an average of 19.4 percent of protected traffic in the sampled organizations, with credential stuffing dropping to 6 percent after mitigations were implemented. Mobile endpoints are generally more likely to be proactively mitigated through automation than web endpoints, with organizations in the travel, telecom, and technology sectors experiencing higher rates of credential stuffing than other sectors. 

As the phishing industry has matured with the proliferation of phishing tools and services, the technical sophistication and cost of phishing has decreased. In particular, phishing attacks target financial organizations and organizations that support large-scale single sign-on, such as Microsoft, Facebook, Google, and Apple.  Reverse phishing proxies, also known as real-time phishing proxies or man-in-the-middle (MITM) phishing, are now a standard approach and can bypass most multi-factor authentication by harvesting session cookies.

Multifactor bypass techniques are now more common as malware, phishing, and other social engineering vector-based strategies gain traction. Technologies based on public key cryptography, such as the FIDO2 suite, are showing greater resistance to multi-factor bypass techniques. 

The F5Labs 2023 Privacy Threat Report provides neutral recommendations for the average organization to mitigate digital privacy threats based on an analysis of 320 billion data transactions from 159 companies and organizations from March 2022 to April 2023. 


댓글삭제
삭제한 댓글은 다시 복구할 수 없습니다.
그래도 삭제하시겠습니까?
댓글 0
댓글쓰기
계정을 선택하시면 로그인·계정인증을 통해
댓글을 남기실 수 있습니다.

  • ABOUT
  • CONTACT US
  • SIGN UP MEMBERSHIP
  • RSS
  • 2-D 678, National Assembly-daero, 36-gil, Yeongdeungpo-gu, Seoul, Korea (Postal code: 07257)
  • URL: www.koreaittimes.com | Editorial Div: 82-2-578- 0434 / 82-10-2442-9446 | North America Dept: 070-7008-0005 | Email: info@koreaittimes.com
  • Publisher and Editor in Chief: Monica Younsoo Chung | Chief Editorial Writer: Hyoung Joong Kim | Editor: Yeon Jin Jung
  • Juvenile Protection Manager: Choul Woong Yeon
  • Masthead: Korea IT Times. Copyright(C) Korea IT Times, All rights reserved.
ND소프트