Rising Threats: Navigating the Complex World of Cyber Security Attacks
1. Global Context & Key Statistics
During the World Telecommunication Development Conference held in Kigali, Rwanda (June 2022), global delegates emphasized the necessity of developing a proactive cyber security culture and implementing robust assurance practices.
2. Classification of Malware Threats
Malware (malicious software) manifests in diverse forms designed to compromise system security, spy on users, or disrupt digital workflows:
- Spyware: Infiltrates systems via links and acts as digital espionage tools (e.g., Pegasus) capable of extracting private files and locking data.
- Trojan Horse: Disguises itself as legitimate files; while non-replicating, it hampers performance, leaks data, and spreads when embedded files are transferred.
- Bugs: Design or development flaws in software code that produce unexpected errors or functional failures.
- Viruses: Programs designed to alter device functionality, corrupt storage, or leak confidential data to external actors.
- Adware: Inundates user interfaces and applications with excessive advertisements, severely degrading system processing speeds.
- Worms: Self-replicating malware that spreads autonomously across network connections, disrupting normal operations rapidly.
- Bots: Automated programs that, if compromised, can execute unauthorized tasks, transmit spam, or flood web applications.
- Ransomware: An extended threat vector where malware holds critical data hostage, demanding financial compensation for its restoration.
3. Workplace Vulnerabilities & Attack Vectors
SQL Injection (SQLi)
Occurs when malicious actors insert structured query language code into web application input fields. Successful exploits allow attackers to manipulate backend databases, access sensitive consumer or financial data, alter or delete records, and execute administrative operations. For instance, gaining administrative email access could enable fraudulent fund transfer instructions.
Man-in-the-Middle (MitM) Attacks
Takes place when sensitive transactions or file transmissions occur over unsecured public Wi-Fi networks (e.g., coffee shops). Interceptors eavesdrop on unencrypted data exchanges without the user's consent.
Phishing & Social Engineering
Phishing: Fraudulent emails (e.g., cash prize claims) containing malicious links that silently install data-exfiltrating software upon being clicked.
Social Engineering: Manipulation of human psychology to deceive victims into surrendering access or credentials. Examples include impersonating bank officials to obtain OTPs or impersonating family contacts to request financial transfers.
Occurs when employees, contractors, or business partners intentionally leak confidential data or compromise network operations. Competitors may also use deceptive interview setups (e.g., malicious links in video call chats) to trigger data leaks from company laptops.
4. Infrastructure Attacks & Vulnerabilities
- Denial-of-Service (DoS): Floods a target server with illegitimate request traffic (such as ICMP ping floods or TCP SYN handshake exploits), overloading processing capacity and denying access to legitimate users.
- Distributed Denial-of-Service (DDoS): An amplified DoS attack launched simultaneously from multiple distributed sources, creating long-term business interruption and severe reputational damage.
- Zero-Day Attacks: Exploitation of unknown software vulnerabilities by attackers before developers become aware of the security flaw or issue a corrective patch.
5. Conclusion & Professional Responsibilities
References
1. World Telecommunication Development Conference (Kigali, Rwanda, 2022).
2. CyberArk 2023 Identity Security Threat Landscape Report.
3. Indian Ransomware Report (H1-2022) by CERT-In, Ministry of Electronics & IT, Government of India.
4. Cyber Threat Intelligence Advisory Report (August 2023).