Video: Cisco spotlights sophisticated web attacks
It’s a dangerous time for web surfers – care must now be taken to not fall victim to some increasingly savvy internet criminals.
Cisco researchers have warned about the widening threat of profit-driven web criminals, reporting a 90 per cent increase in the growth of threats coming from legitimate domains.
In its Annual Security Threat Report, Cisco also found that exploited websites were now responsible for more than 87 per cent of web-based threats.
It quoted research from security audit provider White Hat Security, which said that 79 per cent of these websites hosting malicious code were legitimate websites that had been compromised.
In 2008, the increase in malicious or infected websites meant that it was much more common for users to fall victim to hosting exploits that were looking for weaknesses in the user's browser or operating system.
Once the exploit found a suitable weakness, it would start to download malware in the background.
Visitors were often falling victim because they tended to trust legitimate websites fully, as they will often have read content or performed transactions with them before.
Popular methods which Cisco talked about were iFrame exploits, SQL injection, cross-site scripting and cross-site request forgery.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Patrick Peterson, Cisco chief security researcher, said: "Every year we see threats evolve as criminals discover new ways to exploit people, networks and the internet.
"This year's trends underscore how important it is to look at all basic policies and technologies."
Cisco and Peterson also released two video blogs in support of the report, which gave brief descriptions of two other key threat trends which gained prominence in 2008.
Botnets
Reputation hijacking
The full report is available here.
-
Broadcom eyes security, performance boosts with vDefend and Avi Load Balancer updatesNews Enhancements to VMware vDefend and VMware Avi Load Balancer use AI-powered automation to help secure private cloud environments
-
How business leaders are using the Dell Pro 7 and Dell Pro 5Sponsored Thanks to flexibility and a range of spec options, the Dell Pro 7 and Pro 5 laptops can suit a variety of business leaders across a mix of workplaces
-
Cisco just launched two cyber-focused small language models: Antares-350M and Antares-1B aim to supercharge codebase analysis – and they run at a “fraction of the compute expense” of popular frontier modelsNews The Antares models unveiled by Cisco aim to cut costs in codebase analysis
-
CISOs are keen on agentic AI, but they’re not going all-in yetNews Many security leaders face acute talent shortages and are looking to upskill workers
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
AI is “forcing a fundamental shift” in data privacy and governanceNews Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up
-
Cisco says Chinese hackers are exploiting an unpatched AsyncOS zero-day flaw – here's what we know so farNews The zero-day vulnerability affects Cisco's Secure Email Gateway and Secure Email and Web Manager appliances – here's what we know so far.
-
Researchers claim Salt Typhoon masterminds learned their trade at Cisco Network AcademyNews The Salt Typhoon hacker group has targeted telecoms operators and US National Guard networks in recent years
-
Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warningsNews Cisco customers are urged to upgrade and secure systems immediately
-
Cisco eyes network security gains for agentic AINews New network security updates aim to secure AI agents across enterprises