Big Banks Vulnerable to Web, Mobile Attacks

Mohammad.Poorya

Bardzo aktywny
Ekspert
Dołączył
19 Wrzesień 2018
Posty
3453
Reakcje/Polubienia
13975
Miasto
On a Bike!
Nearly all of the largest 100 banks are vulnerable to web and mobile attacks, which give hackers access to sensitive data, according to
Zaloguj lub Zarejestruj się aby zobaczyć!
.

“We leveraged an enhanced methodology from our
Zaloguj lub Zarejestruj się aby zobaczyć!
that covered web and mobile application security of the world largest companies from the FT 500 list,” the
Zaloguj lub Zarejestruj się aby zobaczyć!
said. “For the purpose of this research, we carefully studied external web applications, APIs and mobile apps of the
Zaloguj lub Zarejestruj się aby zobaczyć!
that contains the world's largest financial organizations from 22 countries.”

According to the findings, 85 e-banking web applications failed a GDPR compliance test and 49 failed a PCI DSS test. “Only three main websites (
Zaloguj lub Zarejestruj się aby zobaczyć!
,
Zaloguj lub Zarejestruj się aby zobaczyć!
and
Zaloguj lub Zarejestruj się aby zobaczyć!
) out of 100 had the highest grades 'A+' both for SSL encryption and website security,” the report said.

“Given the non-intrusive nature of the research and formidable resources available to the top banks studied in the research, the findings urge financial institutions to revise their existing approaches to application security,” said Ilia Kolochenko, CEO and founder of ImmuniWeb.

“Most of the data breaches involve or start with
Zaloguj lub Zarejestruj się aby zobaczyć!
that are too frequently under prioritized by future victims. Unfortunately, most cybersecurity teams today carry a burdensome duty to meet compliance and regulatory requirements as the first priority and simply lack available resources to tackle other essential tasks. Eventually, they become low-hanging fruits for cybercriminals.”

Researchers detected 29 active phishing campaigns targeting customers of the financial institutions. “Phishing websites either spread banking malware aimed to steal e-banking credentials or provide fraudulent login forms aimed to steal victim’s credentials. Most of the malicious websites were hosted in the US,” the report said.

Zaloguj lub Zarejestruj się aby zobaczyć!
 
Do góry