In July 2017, Gartner Distinguished Analyst Neil McDonald predicted that financially motivated attackers would shift to the application layer, with business applications such as ERP, CRM, and HR becoming more attractive targets. “In many organizations, ERP applications are maintained by a separate team and security is not a high priority. As a result, patches often go unpatched for years to ensure operational availability,” he said.
are actively exploiting known vulnerabilities in ERP applications and targeting high-value assets such as SAP HANA. The number of publicly available exploits for SAP and Oracle ERP applications malta whatsapp data increased by 100% over the past three years, and interest in and activity in their vulnerabilities increased by 160% in 2017 compared to 2016 .
Well-known hacktivist and cybercriminal groups are expanding their arsenal of tactics, methods, and procedures, specifically targeting ERP applications. Hacktivist groups, particularly those associated with Anonymous, are expanding their operations. More than nine operations involve hacking and disabling critical ERP platforms.
Known malware such as Dridex has been used to steal credentials and data from firewall-protected ERP applications. Hackers with ties to certain governments have been recruited to hack into ERP applications to obtain sensitive information and/or disrupt critical business processes.
Outsiders and company employees are revealing information that could be very valuable to sophisticated people. Researchers have found 545 SAP files that were made publicly available as a result of misconfiguration of systems, allowing attackers to determine the location of secret files on organizations' networks.
The study shows that cybercriminals
-
- Posts: 537
- Joined: Mon Dec 23, 2024 3:13 am