Skybox Security: Financial Service Organisations Must Change
By FF Newsroom · 4 May 2017

Threat-Centric Vulnerability Management identifies the true risk of vulnerabilities, focuses action where it’s needed most and prioritizes imminent threats.
Skybox Security today announced the availability of threat-centric vulnerability management (TCVM) for the Skybox Security Suite, signaling a fundamental shift in the approach to managing and prioritizing vulnerabilities.
TCVM changes vulnerability management from an exercise of trying to patch “everything all the time” to focused, intelligent action that considers real-world threats.
At the launch of TCVM, Skybox updated on the major trending event categories impacting organizations including banks, insurers and other financial institutions today: the use of a specific, commercialized set of exploit kits, the rise of targeted client-side vulnerabilities and the continued popularity of Internet of Things (IoT) botnets.
- A small, targeted number of exploit kits are dominating the dark web. In the first part of this year, five major exploits kits dominated chatter on the dark web, targeting nearly 70 vulnerabilities in Firefox, Adobe Flash, Microsoft Internet Explorer and Edge, Java, Microsoft XML Services and more. These vulnerabilities are known to distribute different malware as payload — for example, popular ransomware and banking Trojans.
- Threat actors continue to target specific vulnerabilities included in exploit dumps by hacker groups such as The Shadow Brokers. The group, notorious for allegedly leaking the National Security Agency (NSA)'s hacking tools, continues to pepper the dark web with exploit dumps like the major one on April 14 that contained many OS and server-side exploits. These dumps and targeted vulnerabilities impact web apps built with Apache Struts plus VMware, Cisco, Oracle and Microsoft products, to name just a few.
- Poor IoT security is still vulnerable. Botnets are exploiting vulnerabilities in network devices, gateways, cameras and other internet-connected devices, delivering distributed denial of service (DDoS) attacks through things like the ‘HTTP Port 81 Botnet’ and the Amnesia botnet which is the next generation of Mirai malware after source code was published and shared online.
- Exist and are exposed in the network
- Be actively exploited in the wild; or known to be attacked within a specific industry or geography
- Have an exploit available, but are not known to be part of an active exploit campaign
- Exist but are not exposed in the network