Poor router security makes SMBs vulnerable to attack

Issue 4 2022 Information Security

Prevailing wisdom is to make sure that your computer and any linked cloud services are protected to the hilt with software and support services to detect and prevent malicious ransomware and other cybercriminal attacks. However, another vulnerable frontier is every user’s gateway to the internet: the router.


Carlo Bolzonello.

While major malware and ransomware incidents frequently make headlines in the media, router vulnerabilities are not as frequently publicised, but the outcomes of these violations could be immensely damaging to the businesses they affect.

For example, if a router was used at a business at which access control was managed over the internet, the compromised router would give cybercriminals access to the internal network. Leveraging past insecure firmware updates, criminals could make surveillance cameras ‘loop’ on empty footage, making it possible to gain access without detection, and tamper with or steal items and documents.

A compromised router also makes it possible for cybercriminals to snoop on non-encrypted internet traffic, redirecting DNS requests to attacker-controlled servers, making it possible for external parties to access unprotected internal resources and unprotected devices, particularly those with weak passwords. This in turn leads to credentials theft, and the theft of intellectual property and competitive information.

This type of criminal access also leads to third parties being compromised, such as clients, suppliers, or even other entities in a shared supply chain.

“Attacks via compromised routers are most frequently targeted at companies with small or medium-sized digital infrastructure, such as independent law firms, private clinics and other healthcare facilities, agencies, and even news organisations,” says Carlo Bolzonello, country lead for Trellix in South Africa.

“These organisations may feel a false sense of security because they don’t think they’re as big or important to cybercriminals as big corporates or government, but they still hold a treasure trove of personal data, and are linked to ‘bigger fish’, making them ideal targets for malicious actors wanting to harvest information for illegal use, or for ransom.

“While the ransomware hits that make the news are usually about big companies, cybercriminals know that these organisations typically have a security solution with extended detection and response protocols (XDR) in place. That’s why they’re content to turn their attention to small environments that are easier to access, and more likely to pay a ransom because they don’t want to attract any negative attention from clients.”

Small- and medium sized businesses can access XDR solutions, which integrate multiple security products into cohesive security systems, providing a holistic but simple view of threats across a business’s entire technology stack – including its routers.

“The growing shift to work from home, which means that privately owned routers are linking into businesses’ networks, means that it’s more imperative than ever for enterprises of all sizes to have a unified and proactive approach to cybersecurity,” Bolzonello says. “Every business – no matter its size – needs to protect its entire landscape of technology assets, including all endpoints, mobile, network, and cloud workloads.”

Find out more at https://trellix.com




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

New ransomware using BitLocker to encrypt data
Technews Publishing Information Security Residential Estate (Industry)
Kaspersky has identified ransomware attacks using Microsoft’s BitLocker to attempt encryption of corporate files. It can detect specific Windows versions and enable BitLocker according to those versions.

Read more...
Create order from chaos
Information Security
The task of managing and interpreting vast amounts of data is akin to finding a needle in a haystack. Cyberthreats are growing in complexity and frequency, demanding sophisticated solutions that not only detect, but also prevent, malicious activities effectively.

Read more...
Trend Micro launches first security solutions for consumer AI PCs
Information Security News & Events
Trend Micro unveiled its first consumer security solutions tailored to safeguard against emerging threats in the era of AI PCs. Trend will bring these advanced capabilities to consumers in late 2024.

Read more...
Kaspersky finds 24 vulnerabilities in biometric access systems
Technews Publishing Information Security
Customers urged to update firmware. Kaspersky has identified numerous flaws in the hybrid biometric terminal produced by international manufacturer ZKTeco, allowing a nefarious actor to bypass the verification process and gain unauthorised access.

Read more...
Responsible AI boosts software security
Information Security
While the prevalence of high-severity security flaws in applications has dropped slightly in recent years, the risks posed by software vulnerabilities remain high, and remediating these vulnerabilities could hinder new application development.

Read more...
AI and ransomware: cutting through the hype
AI & Data Analytics Information Security
It might be the great paradox of 2024: artificial intelligence (AI). Everyone is bored of hearing it, but we cannot stop talking about it. It is not going away, so we had better get used to it.

Read more...
NEC XON shares lessons learned from ransomware attacks
NEC XON Editor's Choice Information Security
NEC XON has handled many ransomware attacks. We've distilled key insights and listed them in this article to better equip companies and individuals for scenarios like this, which many will say are an inevitable reality in today’s environment.

Read more...
iOCO collaboration protection secures Office 365
Information Security Infrastructure
The cloud, in general, and Office 365, in particular, have played a significant role in enabling collaboration, but it has also created a security headache as organisations store valuable information on the platform.

Read more...
Cybercriminals embracing AI
Information Security Security Services & Risk Management
Organisations of all sizes are exploring how artificial intelligence (AI) and generative AI, in particular, can benefit their businesses. While they are still figuring out how best to use AI, cybercriminals have fully embraced it.

Read more...
A strong cybersecurity foundation
Milestone Systems Information Security
The data collected by cameras, connected sensors, and video management software can make a VMS an attractive target for malicious actors; therefore, being aware of the risks of an insecure video surveillance system and how to mitigate these are critical skills.

Read more...