CFOtech Asia logo
Technology news for Asia's CFOs and financial decision-makers
Story image

Latest VMware threat report reveals truth about deepfakes

VMware has released its eighth annual Global Incident Response Threat Report, which takes a deep dive into the challenges faced by security teams amid pandemic disruptions, burnout and geo politically motivated cyber attacks.

The report finds that 65% of defenders state that cyber attacks have increased since Russia invaded Ukraine, according to report findings. The report also shines a light on emerging threats such as deepfakes, attacks on APIs, and cybercriminals targeting incident responders themselves.

Rick McElroy, principal cybersecurity strategist at VMware, says, "Cyber criminals are now incorporating deepfakes into their attack methods to evade security controls. Two out of three respondents in our report saw malicious deepfakes used as part of an attack, a 13% increase from last year, with email as the top delivery method.

"Cyber criminals have evolved beyond using synthetic video and audio simply for influence operations or disinformation campaigns. Their new goal is to use deepfake technology to compromise organisations and gain access to their environment."

Additional key findings from the report include:

Cyber pro burnout remains a critical issue: 47% of incident responders said they experienced burnout or extreme stress in the past 12 months, down slightly from 51% last year. Of this group, 69% (versus 65% in 2021) of respondents have considered leaving their job as a result. Organisations are working to combat this, however, with more than two-thirds of respondents stating their workplaces have implemented wellness programs to address burnout.

Ransomware actors incorporate cyber extortion strategies: The predominance of ransomware attacks, often buttressed by e-crime groups collaborations on the dark web, has yet to let up. 57% of respondents have encountered such attacks in the past 12 months, and two-thirds (66%) have encountered affiliate programs and/or partnerships between ransomware groups as prominent cyber cartels continue to extort organisations through double extortion techniques, data auctions, and blackmail.

APIs are the new endpoint, representing the next frontier for attackers: As workloads and applications proliferate, 23% of attacks now compromise API security. The top types of API attacks include data exposure (encountered by 42% of respondents in the past year), SQL and API injection attacks (37% and 34%, respectively), and distributed Denial-of-Service attacks (33%).

Lateral movement is the new battleground: Lateral movement was seen in 25% of all attacks, with cybercriminals leveraging everything from script hosts (49%) and file storage (46%) to PowerShell (45%), business communications platforms (41%), and .NET (39%) to rummage around inside networks. An analysis of the telemetry within VMware Contexa, a full-fidelity threat intelligence cloud that's built into VMware security products, discovered that in April and May of 2022 alone, nearly half of intrusions contained a lateral movement event.

Chad Skipper, global security technologist at VMware, says, “In order to defend against the broadening attack surface, security teams need an adequate level of visibility across workloads, devices, users and networks to detect, protect, and respond to cyber threats.

"When security teams are making decisions based on incomplete and inaccurate data, it inhibits their ability to implement a granular security strategy, while their efforts to detect and stop lateral movement of attacks are stymied due to the limited context of their systems.

Despite the turbulent threat landscape and rising threats detailed in the report, incident responders are fighting back with 87% saying that they are able to disrupt a cybercriminals activities sometimes (50%) or very often (37%).

They're also using new techniques to do so. Three-quarters of respondents (75%) say they are now deploying virtual patching as an emergency mechanism. In every case, the more visibility defenders have across today's widening attack surface, the better equipped they'll be to weather the storm.

Related stories
Top stories
Story image
Confluent
Confluent reimagines data pipelines with Stream Designer
It will accelerate the shift to real-time with the industry's 1st visual interface for building, testing, and deploying data pipelines natively on Apache Kafka.
Story image
Sustainable IT
WQR: 72% orgs link quality engineering to sustainable IT
The report also highlights that 85% of organisations consider quality engineering pivotal in implementing emerging technologies into real-world use cases.
Story image
IT Automation
Intel hits key milestone in quantum chip production research
Intel demonstrates exceptional yield of quantum dot arrays, showing promise for large-scale qubit production using transistor fabrication technology.
Story image
Digital Transformation
Equinix invests in Indonesia with a $74m data centre
The centre will be strategically located near the largest internet exchanges to meet the country’s growing digital needs.
Story image
Cybersecurity
APAC orgs embracing Zero Trust Security, reveals Okta
Zero Trust Security helps organisations thrive in the era of hybrid work and increasingly sophisticated cyber threats.
Story image
Fintech
New report highlights opportunities and challenges of Super Apps for banking sector
"Staying ahead of the game means predicting where tomorrow will take us, as well as recognising where things currently stand."
Story image
Distributed Denial of Service
Sysdig reveals a loss of $53 for every $1 cryptojackers gain
The 2022 Sysdig Cloud Native Threat Report breaks down supply chain attacks against containers and how geopolitical conflict influences attacker behaviours.
Story image
Sustainable IT
Equinix commits US$50 million to advance digital inclusion
Establishes the Equinix Foundation, an employee-driven charitable organisation, to advance digital inclusion through grants and strategic partnerships.
Story image
Work from home
Jamf showcases new products to simplify and secure work
At the 13th annual Jamf Nation User Conference, the company shared how its continuous product innovation is helping organisations succeed with Apple.
Story image
IT Automation
Tech job moves - Adobe, Ambit, blueAPACHE, Cue & DC Blox
We round up all job appointments from September 26-,30 2022, in one place to keep you updated with the latest from across the tech industries.
Story image
Legacy
Trellix enables greater cyber resiliency with extended XDR platform
"Legacy SIEM technology has failed to modernise security operations. We are confident Trellix XDR fills this critical gap.”
Story image
Microsoft
UiPath and Microsoft partner to empower best-in-class automation
"Together, we are helping customers realise and achieve the business value of automation at scale. We are excited to deliver substantial, integrated cloud offerings.”
Story image
Data analytics
COVID-19 relief innovation takes 2022 SAS Hackathon crown
In COVID-19’s wake, more than 287,000 MSMEs joined JakPreneur, a collaborative government platform that links entrepreneurs and stakeholders
Story image
Digital Transformation
How businesses can stay connected with their clients in a digital environment
Staying connected in a virtual world requires strong communication and collaboration, especially with many workplaces adopting a work-from-anywhere business model.
Story image
Artificial Intelligence
Exclusive: Uniphore shares how Conversational AI can be the key to business success
Conversational AI and Automation are vital tools to help further promote organisational cohesion and communication, and Uniphore is leading the charge.
Story image
eCommerce
New FedEx report reveals biggest trends in eCommerce
The report shows that SMEs and consumers agree that there's room for further growth in the already booming eCommerce sector.
Story image
Artificial Intelligence
Fortinet advances AIOps to aid the hybrid workforce
"We’re continuing our commitment to AI innovation by delivering AIOps capabilities across our robust portfolio of enterprise networking technology."
Story image
Revenue management
BillingPlatform improves offerings to foster customer revenue growth
BillingPlatform has enhanced its platform and products with a focus on helping customers drive revenue growth through improved CPQ functionality, new B2B digital commerce capabilities and expanding its payment integrations to include Stripe, Stax Payments and Adyen.
Story image
Amazon Web Services
Infor named Leader in 2022 Gartner Magic Quadrant for Cloud ERP
For the second consecutive time, Infor has been positioned as a Leader in the 2022 Gartner Magic Quadrant for Cloud ERP for Product-Centric Enterprises.
Story image
Malware
OpenText reveals nastiest malware of 2022, with Emotet at the top
OpenText threat intelligence experts combed through the data, analysed different behaviours, and determined which malicious payloads are the nastiest.
Story image
Subscriptions
Denodo targets mid-market with new subscription models
These new subscriptions will help mid-market companies to streamline data integration and accelerate speed to insights.
Story image
Cloud
IBM releases Transformation Index to assist cloud innovation
IBM has released its Transformation Index: State of Cloud, commissioned by the company and conducted by an independent research firm.
Story image
IT infrastructure
Kyndryl launches open solution, powered by co-creation
Kyndryl Vital is led by global teams of designers who work alongside customers and partners to define and solve complex problems with innovation.
Story image
Cloud
MYOB provides efficiency boost with new inventory solution
Premium Inventory is an integrated solution that helps goods-based businesses improve efficiency, reduce costs and increase cashflow.
Story image
Virtual Private Network
BT enhances global Cardway portfolio with Mako Networks
BT has announced a significant enhancement to its Cardway portfolio of payment solutions following the signing of a global agreement with Mako Networks.
Story image
Workflow Automation
NetSuite announces SuitePeople Workforce Management
Oracle NetSuite has announced NetSuite SuitePeople Workforce Management, a solution created to help organisations manage labour costs and profitability.
Story image
Cloud
Workday expands skills cloud and announces new HCM customer
Workday has expanded its skills cloud service and has also announced that Busy Bees Learning has selected the company's HCM solution as part of an overall HR transformation. 
Story image
Sustainable IT
Adobe surveys sustainability at work in Hong Kong employees
The top three sustainability practices are reducing paper usage (46%), digital document storage and management (43%), and curbing electricity consumption (37%).
Story image
Oracle NetSuite
NetSuite Launches Ship Central to improve warehouse operations
NetSuite WMS and Ship Central offer warehouse operations across SKUs, processes, and locations. NetSuite WMS eliminates manual processes
Story image
Observability
Gigamon named leading vendor in deep observability market
650 Group has published a report, recognising Gigamon as the leading vendor in the deep observability market for 2022.
Story image
Digital Transformation
NEC Corporation and Red Hat expand global collaboration
NEC Corporation and Red Hat have announced an expanded global collaboration to drive IT modernisation and digital transformation on Red Hat OpenShift.
Story image
IT in Manufacturing
Five ways manufacturers can benefit from a purpose-built ERP
As the manufacturing world rapidly evolves to meet new challenges, many organisations are working to define a new roadmap to success.
Story image
Software-as-a-Service
Intel accelerates innovation with software-first approach
Intel introduced new services and tools in AI, security and quantum computing to help developers reduce time-to-market and increase performance and security.
Story image
Cloud
HashiCorp research shows organisations benefit from multi-cloud strategies
The survey highlighted the need for organisations to centralise and automate cloud efforts via platform teams in order to increase operational efficiency.
Story image
Network Management
Data is growing at breakneck speed, but are we optimising its value?
Data lies at the heart of digital transformation, as every digital touchpoint translates to a data point. In this digital-first world, data is being created everywhere today – at breakneck speeds.
Story image
Customer Relationship Management
NetSuite introduces CPQ to help organisations simplify sales process
NetSuite CPQ is the only native configure, price and quote solution built on the NetSuite platform. It works with NetSuite ERP, CRM, and eCommerce solutions
Story image
Cybersecurity
Swift successfully pilots its Securities View capability
The new capability significantly increases transparency in post-trade processing while preventing costly settlement fails; it will be widely available in 2023.
Story image
Tax
BlackLine adds tax hyperautomation capabilities to its solutions
The extension to BlackLine's intercompany solutions comes in response to organisations facing increasing intercompany tax scrutiny globally.
Story image
Cybersecurity
Best practices for industrial cyber resilience
Operational technology (OT) security is gaining more attention than ever before, but sufficient understanding of what it takes to prevent breaches is still lacking amongst many organisations.
Story image
DevOps
Disparate data causing headaches for A/NZ businesses
Gone are the days when developers could get away with merely producing code. Many are now expected to be accountable for their code, which should be ‘clean’, right up to deployment.
Story image
Ransomware
Commonwealth tackling rising cybercrime threat in Asia
Ransomware, identity theft, and virtual security attacks identified as growing threats to security and economic growth.