Connect with us

News

Mandiant Unveils M-Trends 2023 Report, Delivering Critical Threat Intelligence Directly from the Frontlines

Published

on

Mandiant, now part of Google Cloud, today released the findings of its M-Trends 2023 report. Now in its 14th year, this annual report provides timely data and expert analysis on the ever-evolving threat landscape based on Mandiant frontline investigations and remediations of high-impact cyber-attacks worldwide. The new report reveals the progress organizations globally have made in strengthening defenses against increasingly sophisticated adversaries.

“M-Trends 2023 makes it clear that, while our industry is getting better at cyber security, we are combating ever-evolving and increasingly sophisticated adversaries. Several trends we saw in 2021 continued in 2022, such as an increasing number of new malware families as well as rising cyber espionage from nation-state-backed actors. As a result, organizations must remain diligent and continue to enhance their cyber security posture with modern cyber defense capabilities. Ongoing validation of cyber resilience against these latest threats and testing of overall response capabilities are equally critical.” – Jurgen Kutscher, VP, Mandiant Consulting at Google Cloud

Global Median Dwell Time Declines to Just Over Two Weeks

According to the M-Trends 2023 report, the global median dwell time – which is calculated as the median number of days an attacker is present in a target’s environment before being detected – continues to drop year-over-year down to 16 days in 2022. This is the shortest median global dwell time from all M-Trends reporting periods, with a median dwell time of 21 days in 2021.

When comparing how threats were detected, Mandiant observed a general increase in the number of organizations that were alerted by an external entity of historic or ongoing compromise. Organizations headquartered in the Americas were notified by an external entity in 55% of incidents, compared to 40% of incidents last year. This is the highest percentage of external notifications the Americas has seen over the past six years. Similarly, organizations in Europe, the Middle East, and Africa (EMEA) were alerted of an intrusion by an external entity in 74% of investigations in 2022 compared to 62% in 2021.

Mandiant experts noted a decrease in the percentage of their global investigations involving ransomware between 2021 and 2022. In 2022, 18% of investigations involved ransomware compared to 23% in 2021. This represents the smallest percentage of Mandiant investigations related to ransomware since prior to 2020.

“While we don’t have data that suggests there is a single cause for the slight drop in ransomware-related attacks that we observed, there have been multiple shifts in the operating environment that have likely contributed to these lower figures. These factors include, but are not limited to ongoing government and law enforcement disruption efforts targeting ransomware services and individuals, which at minimum require actors to retool or develop new partnerships; the conflict in Ukraine; actors needing to adjust their initial access operations to a world where macros may often be disabled by default, as well as organizations potentially getting better at detecting and preventing or recovering from ransomware events at faster rates.” – Sandra Joyce, VP, Mandiant Intelligence at Google Cloud.

Stuart McKenzie, Head of Mandiant Consulting EMEA at Google Cloud, said: “Our latest M-Trends report shows dwell time has decreased for another consecutive year. We look at the median number of days an attacker sits in a target’s environment before being detected – in EMEA this is now less than three weeks, compared to 48 days in the previous year, so an improvement of 58% year-on-year.”

“While this shows clear progress in cyber security capabilities on the part of defenders, we’re also seeing threat actors being increasingly brazen. It’s important that defenses aren’t static and organizations are running continuous testing programs to maintain a strong security posture. As ever, practice makes perfect – one of the best ways to stay prepared is to keep defending against cyber-attacks simulated by a red team. By continuously testing defenses against likely, real-world scenarios, an organization can quickly uncover vulnerabilities and focus on the right things to work on,” concluded Stuart.

Cyber Espionage, Malware Families Increase Globally 

Mandiant identified extensive cyber espionage and information operations leading up to and since Russia’s invasion of Ukraine on February 24, 2022. Most notably, Mandiant saw activity by UNC2589 and APT28 prior to the invasion of Ukraine and observed more destructive cyber-attacks in Ukraine during the first four months of 2022 than in the previous eight years.

In 2022, Mandiant began tracking 588 new malware families, revealing how adversaries are continuing to expand their toolsets. Of the newly tracked malware families, the top five categories consisted of backdoors (34%), downloaders (14%), droppers (11%), ransomware (7%), and launchers (5%). These categories of malware remain consistent over the years and backdoors continue to represent a little over one-third of the newly tracked malware families.

In line with previous years, the most common malware family identified by Mandiant in investigations was BEACON, a multi-function backdoor. In 2022, BEACON was identified in 15% of all intrusions investigated by Mandiant and remains by far the most seen in investigations across regions. It has been used by a wide variety of threat groups tracked by Mandiant including nation-state-backed threat groups attributed to China, Russia, and Iran, as well as financial threat groups and over 700 UNC groups.

“Mandiant has investigated several intrusions carried out by newer adversaries that are becoming increasingly savvy and effective. They leverage data from underground cybercrime markets, conduct convincing social engineering schemes over voice calls and text messages, and even attempt to bribe employees to obtain access to networks. These groups pose a significant risk to organizations, even those with robust security programs, as these techniques are challenging to defend against. As organizations continue to build their security teams, infrastructure, and capabilities, protecting against these threat actors should be part of their design goals.” – Charles Carmakal, CTO, Mandiant Consulting at Google Cloud

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

THIRD EDITION OF BENTLEY’S EXTRAORDINARY WOMEN INITIATIVE WELCOMES STUDENTS FROM THE UK AND QATAR TO CREWE

Published

on

Extraordinary Women

The third edition of Bentley Motors’ Extraordinary Women initiative has concluded with students from universities in the UK and Qatar spending a week at the luxury car brand’s headquarters in Crewe, England. As part of a specially designed schedule, they met with Bentley experts and executives, went behind the scenes of its manufacturing operations, and tackled individual tasks.

Designed to encourage and develop the next generation of young female leaders, the 2024 edition of the Extraordinary Women programme has seen the students receive one-on-one mentorship over the past three months from a selection of inspirational Pioneers from the fields of technology, engineering, design, and business.

The students, who passed through a structured selection process focused around these four specific fields, came from a variety of participating universities: including The University of Doha for Science and Technology in Qatar, and the Universities of Bath, Loughborough, and Manchester Metropolitan in the UK.

Noora Al-Hajri, University of Doha for Science & Technology student, commented, “This experience has been nothing short of life-changing. Through the programme, I have gained invaluable knowledge and skills that will significantly impact my personal and professional growth. The opportunity to learn from inspiring mentors in both Qatar and the UK has been particularly enriching. Their guidance has broadened my horizons, challenged me to think critically, and empowered me to pursue my dreams with renewed confidence. The opportunity to visit the Bentley headquarters at the end of the programme has also been truly awe-inspiring. Thank you, Bentley, for believing in us and for creating such a transformative programme.”

The Pioneers were equally carefully selected. In the UK, entrepreneur Sara Davies MBE, founder and owner of Crafter’s Companion and TV personality from BBC One show Dragons’ Den, provided business mentorship, with Cecilia Harvey, founder of Tech Woman Today, offering the same in the field of technology.

Titi Oliyide CEng MIET, Senior Process Safety Engineer and winner of the 2023 Young Woman Engineer of the Year, mentored the engineering student, and renowned interior designer and Founder of Studioilse, Ilse Crawford provided design support.

The four Qatari Pioneers included Qatar’s UNESCO art ambassador, Muna Al-Bader, in the field of design. Dr Noora Fetais Al Marri, honoured by the Arab Women of the Year 2024 awards for her contributions to cyber security. Education and founding President of the Arab Association for Cyber Security, offered technology mentorship.

Covering the field of engineering was Dr. Hanan Farhat, founder of the Qatar Association for Women Engineers, and Dr. Buthaina Al Ansari in the field of business, who is a senior advisor at the organisation that established Tamkeen Training and Consulting Solutions.

Member of the Board for Human Resources at Bentley Motors, Dr. Karen Lange, commented, “With every year, the Extraordinary Women programme grows stronger, as exemplified by the quality of this year’s Pioneers, all who have generously given their time in the spirit of collaboration as we seek to build a legacy for young women. It has been a great honour to meet and engage with such talented young women during their visit – witnessing their energy and ability fills me with great optimism for the future.”

Launched in the UK and Middle East in 2022, the Extraordinary Women initiative has previously engaged students and Pioneers from the United Arab Emirates, Saudi Arabia, and the United Kingdom. It forms part of Bentley’s wider commitment to diversity, equity, and inclusion under its Beyond100 strategy, and was created to encourage women to explore a variety of career paths in the STEM and automotive sectors.

Continue Reading

Financial

Reem Finance signs with Network International to accelerate digital transformation

Published

on

Network International (Network) has announced the signing of a strategic partnership with Reem Finance, the leading financial services provider in the UAE. The strategic alliance aims to leverage Network’s expertise to provide a fully-fledged payment processing solution to support the digital transition.

The partnership with Network complements Reem Finance’s focus on offering customers with a unique banking experience in tune with the digital age. The scope of services includes a comprehensive range of products and services from transaction processing, card hosting and management, as well as value-added services. As the region’s largest payment solutions company, Network is committed to supporting the UAE financial services sector by providing innovative solutions to customers and enhancing the experience of consumers.

Navneet Dave, Managing Director & Co-Head of Processing – Middle East at Network International, commented, “We are thrilled to partner with Reem Finance as we jointly deliver innovative digital payment solutions that offer an effortless and secure experience for customers. Our collaboration builds on Network’s three decades of experience and expertise in creating world-class digital payments infrastructure and services for clients. It underscores Network’s commitment to empowering our partners with cutting-edge processing services and value-added solutions and driving growth in the UAE financial services industry.”

Mr. Seraj Faidi, CEO of Reem Finance,said: “As part of our ongoing commitment to enhancing the quality of our products and services for our esteemed clients, and in light of our recent collaborations with prominent service providers and partners, we are delighted to partner with Network International to explore innovative paths to accelerate digitizing our services to better serve our customers. This engagement is an important step for Reem Finance in expanding our capabilities to provide top tier, friendly and easy to use services to our customers. We are confident that with Network International, the processing of card transactions related to both consumer and commercial sectors will be state-of-the-art and seamless. We are committed to playing a vital role in elevating the financial system in the UAE, delivering value to our shareholders, and prioritizing the needs of our clients.”

Continue Reading

Financial

Wio Bank Redefines SME Banking with New Embedded Finance

Published

on

Wio Bank PJSC is introducing a new embedded finance service designed especially for the UAE’s small and medium-sized enterprises (SMEs). This initiative includes strategic partnerships with leading accounting software platforms Zoho Books, Fiskl and Wafeq, aiming to embed banking services into daily business operations and simplify financial management.

Wio Business, the bank’s first digital banking application, caters to micro, small, and medium enterprises (MSMEs), as well as freelancers and entrepreneurs. By directly integrating with accounting and financial management systems through APIs, Wio Business facilitates seamless financial workflows, enhancing management and eliminating the need for third-party intermediaries. This integration automates bookkeeping, significantly reducing manual labor and allowing businesses to concentrate on their core activities.

Jayesh Patel, Chief Executive Officer of Wio Bank PJSC, shares his vision for the new service: “By adopting Embedded Finance, we are transforming how businesses manage their finances. Our direct integration initiative simplifies how financial services are delivered and managed, making it easier and more transparent for SMEs.”

With over 94% of UAE businesses categorized as SMEs and significant contributors to employment, Wio Bank’s new service is tailored to meet a vital market need. This initiative, along with its strategic partners, is designed to simplify business operations, allowing them to thrive by focusing on growth rather than administrative financial tasks.

A New Era of Financial Management

Through Wio Business, companies can now link their accounts with selected software platforms such as Zoho Books, Fiskl, and Wafeq, offering a holistic view of their financial health. This integration eliminates the dependency on third-party intermediaries, simplifies financial workflows, ensures real-time financial insights with automatic updates, and streamlines accounting tasks with features like auto-reconciliation of bank statement. Additionally, integrating Wio Business APIs into Corporate ERPs and payment platforms facilitates automated account payables and instant transaction reconciliation, thus reducing manual labor and errors, and enhancing cost efficiency and operational gains.

Wio Bank was established to redefine banking in the UAE for both businesses and consumers. Its second digital offering, Wio Personal, is a day-to-day banking platform that changes how individuals see, manage, and grow their money. It provides users with unprecedented financial visibility and flexibility, serving as a foundation for achieving personal financial goals with an engaging experience that includes smart cards and exciting rewards.

Continue Reading

Trending

Please enable JavaScript in your browser to complete this form.

Copyright © 2023 | The Integrator