.
@EdgioApps intel team has pulled together details on over 4,000 URLs publicly announced as being defaced by hacktivists over the last two weeks. Let's take a quick look at what they found...
4,069 URLs > 3,480 Domains > 1,426 IPs > 271 ASNs
Said another way: 4,069 URLs across 3,480 unique domains routed to 1,426 IPs managed by just 271 autonomous systems (network operators).
The URL to ASN ratio is 15:1. What does this tell us about the attacks? It indicates that the hacktivists are using a one-to-many approach, indiscriminately targeting multiple websites in bulk, in the name of their cause. They are not aiming for highly precise strikes; rather, they are using cluster bombs, exploiting weak passwords, lack of MFA, and common vulnerabilities across various websites. Their goal is to cause as much damage as possible with minimum effort.
I have some quick recommendations for you, but more details are in the post.
Multi-factor Authentication
Are you tired of seeing this on the list of recommendations yet? There’s a saying, “when you are tired of saying it, people are starting to hear it.” In that case, make sure you have MFA enforced on all accounts with access to your web resources and admin panels.
User Education
This phrase creates so much nausea, yet we think it’s completely underrated. It wouldn’t surprise us if a majority of these one-to-many compromises started with a phishing attack. Take the time to make sure your team understands why all these security controls are necessary. The key here is to make sure it’s timely, relevant, and engaging. Having trouble making it engaging? Reach out; our team has a ton of ideas to help out.
Web Application and API Protection
As we mentioned before, patching is hard, but when you leverage a good Web Application Firewall (WAF), especially a cloud-delivered one with built-in DDoS protection, API security, and bot management, you’ll be able to breathe easier knowing you can stay protected between the time a vulnerability is discovered and a patch is rolled out, with capabilities like virtual patching.
#threatintelligence #cti #cybersecurity #hacktivists
edg.io/lp/blog/hacktivism-in…