Intelligent CISO Issue 66 | Page 31

In an industry where guest satisfaction and reputation are paramount , staying secure while offering cutting-edge technology is a delicate balancing act .
infographic

In an industry where guest satisfaction and reputation are paramount , staying secure while offering cutting-edge technology is a delicate balancing act .

team , along with specific mitigation strategies to bolster defences .”
The report analyses threat groups and their methods throughout the attack cycle , from initial foothold through to exfiltration . A few key findings from the report include :
• MOVEit RCE ( CVE-2023-34362 ) vulnerability is one of the top exploits threat actors use to target hospitality clients . Analysis of 150 + victims within the hospitality sector shows a significant surge in Clop ransomware attacks due to this MOVEit zero-day vulnerability .
• HTML attachments make up 50 % of the file types being used for emailborne malware attachments . HTML file attachments are being used in phishing as a redirector to facilitate credential theft and for delivering malware through HTML Smuggling .
• Obtaining credential access , primarily by using brute force attacks , was behind 26 % of all reported incidents . This tactic has threat actors leveraging valid accounts to compromise systems by simply logging in using weak passwords that are vulnerable to password guessing .
Trustwave SpiderLabs ’ research serves as a resource for hospitality organisations to understand and combat the multitude of attack groups , malware variants and techniques deployed against them . u www . intelligentciso . com
31