<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyber attacks Archives - ProtectionWeb</title>
	<atom:link href="https://www.protectionweb.co.za/tag/cyber-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.protectionweb.co.za/tag/cyber-attacks/</link>
	<description>First with Security News</description>
	<lastBuildDate>Tue, 20 May 2025 07:28:57 +0000</lastBuildDate>
	<language>en-ZA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>

<image>
	<url>https://www.protectionweb.co.za/wp-content/uploads/2024/04/cropped-ProtectionWebLogo-512x512-1-32x32.png</url>
	<title>cyber attacks Archives - ProtectionWeb</title>
	<link>https://www.protectionweb.co.za/tag/cyber-attacks/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The evolution of AI in phishing attacks: Why even the most experienced can fall victim</title>
		<link>https://www.protectionweb.co.za/cyber-security/the-evolution-of-ai-in-phishing-attacks-why-even-the-most-experienced-can-fall-victim/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Tue, 20 May 2025 07:28:57 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Kapersky]]></category>
		<category><![CDATA[phishing]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97857</guid>

					<description><![CDATA[<p>The evolution of AI is not only affecting various industries, but it has also transformed cybercriminals’ tactics. One alarming trend is the use of AI to enhance phishing scams, refining them, targeting specific individuals, and making these attacks almost impossible to recognise. Kaspersky reviews how AI is changing phishing techniques and why even the most [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/the-evolution-of-ai-in-phishing-attacks-why-even-the-most-experienced-can-fall-victim/">The evolution of AI in phishing attacks: Why even the most experienced can fall victim</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span lang="en-US" data-ogsc="black" data-olk-copy-source="MessageBody">The evolution of AI is not only affecting various industries, but it has also transformed cybercriminals’ tactics. One alarming trend is the use of AI to enhance phishing scams, refining them, targeting specific individuals, and making these attacks almost impossible to recognise. Kaspersky reviews how AI is changing phishing techniques and why even the most cyber-aware employees may fall for these scams.</span></p>
<p><span lang="en-US" data-ogsc="black">According to a recent Kaspersky </span><a title="https://www.kaspersky.com/blog/cyber-defense-and-ai-kaspersky-report-2024/" href="https://www.kaspersky.com/blog/cyber-defense-and-ai-kaspersky-report-2024/" data-auth="NotApplicable" data-linkindex="2" data-ogsc=""><span lang="en-US" data-ogsc="rgb(17, 85, 204)">study</span></a><span lang="en-US" data-ogsc="black">, the number of cyberattacks experienced by organisations in the last 12-months is reported to have increased by 29% in South Africa. The most ubiquitous threat came from phishing attacks, with 67% of those questioned in South Africa reporting this type of incident. With AI becoming a more prevalent enabler for cybercriminals, over half of the respondents in South Africa (53%) anticipate significant growth in the number of phishing attacks. In this text, Kaspersky examine how AI is used in phishing and why experience alone is sometimes not enough to avoid becoming a victim.</span></p>
<p data-ogsb="white"><b><span lang="en-US" data-ogsc="black">Personalisation through AI</span></b></p>
<p data-ogsb="white"><span lang="en-US" data-ogsc="black">Previously, phishing attacks relied on a generic mass message sent to thousands, hoping some of the recipients would fall for the bait. AI has changed this into scripting highly personalised phishing emails in large numbers. Using publicly available information like that on social media, job boards, and companies&#8217; websites, these AI-powered tools can generate emails tailored to an individual&#8217;s role, interests, and communication style. For example, a CFO might receive a fraudulent email that mirrors the tone and formatting of their CEO’s messages, including accurate references to recent company events. This level of customisation makes it exceptionally challenging for employees to distinguish between legitimate and malicious communications.</span><span data-ogsc="black"> </span></p>
<p><b><span lang="en-US" data-ogsc="black">Deepfake technology</span></b></p>
<p><span lang="en-US" data-ogsc="black">AI has also introduced deepfakes into the phishing arsenal. These are increasingly being leveraged by cybercriminals to create fake but highly accurate audio and video messages, crafted to reflect the voice and appearance of the executives they seek to impersonate. For example, in one reported case, attackers used a deepfake to impersonate multiple members of staff during a video conference, convincing the employee to transfer </span><a title="https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk/index.html" href="https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk/index.html" data-auth="NotApplicable" data-linkindex="3" data-ogsc=""><span lang="en-US" data-ogsc="rgb(17, 85, 204)">approximately $25.6 million</span></a><span lang="en-US" data-ogsc="black">. As deepfake technology continues to advance, it is expected that such attacks will become more frequent and harder to detect. </span></p>
<p><b><span lang="en-US" data-ogsc="black">Bypassing traditional defenses</span></b></p>
<p><span lang="en-US" data-ogsc="black">Cybercriminals can manipulate the script of traditional e-mail filtering systems with the use of AI. By analysing and mimicking legitimate email patterns, AI-generated phishing emails can bypass security software detection. Machine learning algorithms can test and refine phishing campaigns in real time, enhancing their success rates and making them increasingly sophisticated.</span></p>
<p><b><span lang="en-US" data-ogsc="black">Why experience is not enough</span></b></p>
<p><span lang="en-US" data-ogsc="black">Even experienced employees are falling victim to these advanced phishing attacks. The level of realism and personalisation that AI can achieve may override the skepticism that keeps experienced professionals cautious. Moreover, AI-generated attacks often exploit human psychology, such as urgency, fear, or authority, pressuring employees into acting without double-checking the authenticity of the request.</span></p>
<p><b><span lang="en-US" data-ogsc="black">Combatting AI-hyped phishing</span></b></p>
<p><span lang="en-US" data-ogsc="black">To defend against AI-driven phishing attacks, organisations must adopt a proactive and multi-layered approach that emphasises comprehensive cybersecurity. Regular, up-to-date AI-focused cybersecurity awareness training is critical for employees, helping them identify the subtle signs of phishing and other malicious tactics. </span><a title="https://www.kaspersky.co.za/small-to-medium-business-security/security-awareness-platform" href="https://www.kaspersky.co.za/small-to-medium-business-security/security-awareness-platform" data-auth="NotApplicable" data-linkindex="4" data-ogsc=""><span lang="en-US" data-ogsc="">Kaspersky Automated Security Awareness Platform</span></a><span data-ogsc="black"> <span lang="en-US" data-ogsc="">can help with such training. Alongside this, businesses should implement robust security tools, such as Kaspersky Next and Kaspersky Security for Mail Server, capable of detecting anomalies in emails, such as unusual writing patterns or suspicious metadata.K</span></span></p>
<p><span lang="en-US" data-ogsc="black">A zero-trust security model also plays a vital role in minimising the potential damage of a successful attack. By restricting access to sensitive data and systems, this approach ensures that even if attackers breach one layer of security, they cannot compromise the entire network. Together, these measures create a comprehensive defense strategy, combining advanced technology with vigilant human oversight.</span></p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/the-evolution-of-ai-in-phishing-attacks-why-even-the-most-experienced-can-fall-victim/">The evolution of AI in phishing attacks: Why even the most experienced can fall victim</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Latest NETSCOUT Threat Intelligence Report Reveals Diverse DDoS Threats Across Southern Africa </title>
		<link>https://www.protectionweb.co.za/cyber-security/latest-netscout-threat-intelligence-report-reveals-diverse-ddos-threats-across-southern-africa/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Thu, 17 Apr 2025 06:54:29 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[DDoS]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97634</guid>

					<description><![CDATA[<p>The newly released NETSCOUT Threat Intelligence Report for July to December 2024 reveals a complex and contrasting distributed denial of service (DDoS) attack landscape across southern Africa. According to the report, South Africa, Mauritius and Angola were among the most heavily targeted nations over the second half of last year, while countries like Zambia, Eswatini and Zimbabwe experienced [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/latest-netscout-threat-intelligence-report-reveals-diverse-ddos-threats-across-southern-africa/">Latest NETSCOUT Threat Intelligence Report Reveals Diverse DDoS Threats Across Southern Africa </a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span lang="en-GB" data-ogsc="black" data-olk-copy-source="MessageBody">The newly released </span><span lang="en-GB" data-ogsc="black"><a title="https://www.netscout.com/threatreport" href="https://www.netscout.com/threatreport" data-auth="NotApplicable" data-linkindex="2" data-ogsc=""><span data-ogsc="rgb(150, 96, 125)">NETSCOUT Threat Intelligence Report for July to December 2024</span></a></span><span lang="en-GB" data-ogsc="black"> reveals a complex and contrasting distributed denial of service (DDoS) attack landscape across southern Africa. According to the report, South Africa, Mauritius and Angola were among the most heavily targeted nations over the second half of last year, while countries like Zambia, Eswatini and Zimbabwe experienced lower attack volumes but faced evolving and increasingly complex threats.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">Highest number of attacks and vectors reported in South Africa</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">South Africa once again recorded the highest number of DDoS attacks in the region by a considerable margin with 130,931 events, although this has dropped significantly compared to the more than 230,000 incidents seen over the first half of 2024. </span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">The largest attack peaked at 210.65 Gbps and 20.38 Mpps, with a maximum of 23 attack vectors used in a single incident — the highest in southern Africa – led by TCP ACK, DNS Amplification and TCP SYN/ACK amplification. </span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Top targeted industries included computer-related services businesses, insurance agencies and brokerages as well as computing infrastructure providers, reflecting South Africa&#8217;s digital maturity and central role in Africa’s online ecosystem. Interestingly, both wired and wireless telecommunications providers, portfolio management companies and commercial banking organisations also rated amongst the 10 most attacked sectors in South Africa.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">Mauritius under siege, as DDoS attacks jump by 37 percent</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Mauritius continues to be a key local hotspot, registering over 41,800 attacks, a marked increase over the </span><span lang="en-GB" data-ogsc="rgb(34, 34, 34)">30,446 incidents in the first half of last year.</span><span lang="en-GB" data-ogsc="black"> The wireless telecommunications carriers sector alone accounted for nearly 40,000 incidents, making it one of the most targeted verticals across the region, followed to a lesser degree by wired telecommunications and full-service restaurants. </span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Peak throughput reached 35 Mpps and peak bandwidth reached 224 Gbps, confirming the nation’s growing vulnerability due to its increasing digital infrastructure.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">Namibia sees fewer attacks but remains regional hotspot</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Despite a relatively small population size when compared to other southern African countries, Namibia reported 45,283 attacks, placing it among the top five in the region.  However, this was a noteworthy decrease after the 76,337 experienced in the former half of 2024.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">The most used vector was DNS amplification (34,508 incidents), followed by TCP ACK and TCP SYN/ACK amplification. The largest recorded attack reached 30.11 Gbps and 2.88 Mpps. Notably, restaurants were flagged as the number one targeted sector, followed by computer services businesses and wireless telecommunications organisations.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">More attacks, greater complexity: Angola’s growing DDoS challenge</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">With an increased 19,046 DDoS attacks over the 14,281 incidents in the first half of 2024, Angola faced up to 18 distinct vectors in a single event. The DNS amplification vector was dominant (4,753 attacks), with significant use of TCP ACK and TCP SYN as well. </span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Wired telecommunications and computing infrastructure providers were the primary victims, with the largest attack hitting 85.94 Gbps and an average duration of 76.13 minutes.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">Botswanan tele</span></b><b><span lang="en-GB" data-ogsc="black">communications in the crosshairs</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Botswana recorded 981 attacks, which almost exclusively affected wireless telecommunications organisations, with a maximum bandwidth of 2.49 Gbps and average duration of 29 minutes. The dominant vector was TCP SYN/ACK amplification.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">Eswatini suffers specific targeting</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Eswatini saw 619 incidents over the last six months of 2024; up from 209 for the first half of the year and representing an increase of effectively 200 percent. A number of these attacks were specifically directed toward the real estate sector, suggesting focused rather than opportunistic activity. The average attack duration was shorter than for other southern African countries, at 7.3 minutes, with bandwidth below 1 Gbps.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">High intensity strikes in Zimbabwe</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Zimbabwe experienced<span data-ogsc=""> </span>476 DDoS attacks<span data-ogsc=""> </span>over the period, with the<span data-ogsc=""> </span>largest recorded attack<span data-ogsc=""> </span>reaching a<span data-ogsc=""> </span>bandwidth of 1.07 Gbps<span data-ogsc=""> </span>and a<span data-ogsc=""> </span>throughput of 2.51 Mpps.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Where the country had previously recorded only 189 attacks over the first six months of 2024, telecommunications bore the brunt of high-impact attacks over the second part of the year, experiencing the maximum bandwidth and throughput. This was followed by supermarkets and grocery retailers, as well as one attack on a local sporting goods retail business, which was the longest specific DDoS duration in the country at 37 minutes.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">Tech and telecoms under fire in Mozambique</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Mozambican organisations were subjected to a total of 425 DDoS attacks, most commonly of the TCP ACK and TCP SYN/ACK amplification variety, a serious reduction in attack frequency after the 3,145 incidents over the first half of the year.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">With a peak attack rate of 1.83 Gbps, computer-related services and satellite telecommunications were the two main verticals under attack noted in the 2h 2024 report.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">DDoS attacks drop in Zambia</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">Zambia experienced the lowest number of DDoS events in the region, at 153, down from 428 from January to June 2024, with the largest attack measured at 9.63 Gbps and 0.95 Mpps. </span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">While relatively low in volume, the attacks were technically diverse, with up to eight vectors used in a single incident. Top vectors included TCP SYN/ACK, TCP ACK and DNS amplification, and almost all attacks were directed at the computer services field. </span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p>&nbsp;</p>
<p><b><span lang="en-GB" data-ogsc="black">Shared vectors and regional trends</span></b><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">“The NETSCOUT data revealed in the second Threat Intelligence Report for 2024 underlines a rapidly evolving DDoS threat landscape across southern Africa, with countries like South Africa, Mauritius and Angola facing high volumes of increasingly sophisticated attacks,” explains Bryan Hamman, regional director for Africa at NETSCOUT. </span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">“Across the board, TCP ACK, DNS amplification, TCP SYN/ACK amplification and ICMP remain the most used attack vectors within the region, and the practice of multivector attacks in many of the countries shows a shift toward more sophisticated, layered methods designed to bypass standard mitigation measures.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">“And even while other countries, such as Zambia and Mozambique, reported fewer incidents, the technical diversity and targeted nature of the attacks reveal a concerning trend toward more calculated and industry-specific campaigns.</span><u data-ogsc=""></u><u data-ogsc=""></u></p>
<p><span lang="en-GB" data-ogsc="black">&#8220;As digital ecosystems across southern Africa expand, so too does the attack surface,&#8221; adds Hamman. &#8220;Organisations must remain vigilant, investing in proactive threat intelligence and robust, multi-layered cybersecurity strategies to stay ahead of threat actors targeting the region.&#8221;</span></p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/latest-netscout-threat-intelligence-report-reveals-diverse-ddos-threats-across-southern-africa/">Latest NETSCOUT Threat Intelligence Report Reveals Diverse DDoS Threats Across Southern Africa </a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Tactical Typing: The Rise of Cyber Security in Modern Warfare</title>
		<link>https://www.protectionweb.co.za/cyber-security/97533/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Thu, 03 Apr 2025 09:15:47 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[MWR CyberSec]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97533</guid>

					<description><![CDATA[<p>As was highlighted at the Public-Private Partnerships (PPP) for Defence &#38; Security conference on 07 March 2025, there is a large emphasis on boosting South Africa’s defensive capabilities going forward; however, one key area that — in our view — did not get the necessary attention was cyber. Who are we? MWR CyberSec is a [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/97533/">Tactical Typing: The Rise of Cyber Security in Modern Warfare</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As was highlighted at the Public-Private Partnerships (PPP) for Defence &amp; Security conference on 07 March 2025, there is a large emphasis on boosting South Africa’s defensive capabilities going forward; however, one key area that — in our view — did not get the necessary attention was cyber.</p>
<p>Who are we? MWR CyberSec is a South African cyber security consultancy with research and bespoke consultancy at the core of what we do. Solving our clients’ unique cyber security challenges and ensuring they are more resilient to cyber-attacks is why we exist and continue to exist.</p>
<p>Some foundational concepts are useful for fully understanding cyber-attacks, so we’ll speed run them. The Lockheed Martin Cyber Kill Chain is a model for identification and prevention of cyber intrusions activity. The model identifies what the adversaries must complete in order to achieve their objective and, at a high-level, details the seven steps that Advanced Persistent Threat (APT) groups often follow during their attacks.</p>
<p>An APT group is a highly skilled and organised team of cyber attackers that conduct prolonged and targeted campaigns to infiltrate specific organisations or nations, aiming to achieve various goals such as: data theft, financial gain, disruption of operations, intelligence gathering, espionage, amongst others.</p>
<p>For APTs, so-called zero-day exploits are the holy-grail because they enable these attackers to infiltrate systems undetected, maintain prolonged access, and extract valuable information without triggering security defences and in a way that bypasses protection mechanisms wholesale. A zero-day exploit is a vulnerability that is unknown to developers and has no available fix, making it a prime target for cyber attackers to exploit before it is patched. As a side-note, to quantify their value, depending on the software systems targeted, zero-day exploits can easily sell for $10 million on exploit development markets.</p>
<p>Cyber-attacks to further a nation states goals have for a long while been the ideas of movies and fiction. However, in the near past (the last decade) this has rapidly moved from an ephemeral idea into real-world actions and scenarios that could play out in pursuit of a nation’s geopolitical goals. We have taken some time in our introductory article to unpack some of these below.</p>
<p>Around 2010, one of the most prevalent examples of cyber warfare and the weaponisation was in full effect, namely the Stuxnet worm. Stuxnet was a powerful computer worm, designed by U.S. and Israeli intelligence, that was used to derail a key part of the Iranian nuclear program by destroying the centrifuges that Iran was using to enrich their uranium. When Stuxnet infected a computer, it would check if it was connected to specific types of Programmable Logic Controllers (PLCs) manufactured by Siemens. PLCs are a fundamental element of many industrial control systems, in this case uranium centrifuges. If no PLCs were detected, the worm did nothing. However, if PLCs were detected, Stuxnet then manipulated the PLCs, which would result in the centrifuges being spun irregularly, and thus damaging or destroying them. After deploying Stuxnet, it was successful and ultimately set the Iranian nuclear program back approximately 2 years.</p>
<p>The only reason Stuxnet was discovered, was because it accidentally spread beyond the Iranian nuclear facility. One of the more notable bits related to Stuxnet is that PLCs are commonly air gapped (i.e. disconnected from external networks, especially the internet) as a hard defensive mechanism. Stuxnet was coded to spread via USB and it would spread to the computers controlling the PLCs via this mechanism. The fundamental take-away from this attack is that even highly secured areas, against an adversary that is dedicated and committed to the cause, are hard to detect and defend successfully 100% of the time.</p>
<p>In a similar manner, could a relatively innocuous piece of tech be used in ways unexpected. A simple question jumps to mind, is it possible to hack a Jeep Cherokee wirelessly from a number of kilometres away? The answer is yes. It was done by two researchers in 2015 who put a journalist behind the wheel and demonstrated their control over the vehicle from a distance. The journalist recounted the experience vividly: “I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold”. The researchers were able to fully take control of the vehicle using only a laptop and an internet connection, leading to them toying with the likes of the air-conditioning, radio, and windshield wipers. But it goes beyond this, the researchers were able to cut all power to the drive train rendering the car useless on the highway and no means to move. They were still able to take this a step further by cutting the Jeep’s brakes, leaving the journalist frantically pumping the pedal as the SUV slid uncontrollably into a ditch.</p>
<p>Furthermore, the control of the vehicle enables surveillance too, providing the capability of tracking a targeted Jeep’s GPS coordinates, measuring its speed, as well as dropping pins on a map to trace its route. If you want to see more, the full video of this endeavour was uploaded to WIRED’s <a href="https://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/">blog</a>. This is an interesting attack avenue as it explores hacking cars, which just about everyone uses in some shape or form on a daily basis and are incorporating more of this sort of technology into them, but regardless back to the more military focused incidents.</p>
<p>A huge step-up in the cyber warfare area has been playing out as part of the Russia Ukraine conflict. The best example of this is the suspected Russian attack on the Viasat KA-SAT network that shut down communications that Kyiv, Ukraine heavily relied upon. The Russian operation resulted in an immediate and significant loss of communication in the earliest days of the war for the Ukrainian military, which relied on Viasat’s services for command and control of the country’s armed forces. The interesting part, this attack was initially launched 1 hour before Russians invaded Ukraine in February 2022. The attack was executed with a new strain of wiper malware called “AcidRain” that was designed to remotely erase vulnerable modems and routers. In the cross-fire of this targeted attack, remote control of 5800 wind turbines belonging to Enercon in Central Europe was also affected. This scenario demonstrated a real example of how cyber-attacks can be targeted and timed to amplify military forces on the ground by disrupting and even destroying the technology used by enemy forces. The Danish defence minister stated that, “The cyber threat is constant and evolving.</p>
<p>Cyber-attacks can do great damage to our critical infrastructure, with fatal consequences”, further highlighting the importance of cyber defence and incident response capabilities. These capabilities don’t explicitly end at the terrestrial. There are companies who can be incredibly technically advanced in the solutions they provide; however, they are not immune to cyber breaches. Cyber security is often neglected until the inevitable happens, they are breached. Russia has attempted attacks against the Starlink systems in order to jam the internet service in Ukraine.</p>
<p>A Belgian cyber security researcher was able to breach Elon Musk’s Starlink satellite system using a simple Raspberry Pi device in conjunction to other electronic components costing the equivalent of 500 ZAR. This is a prime example of the fact that hacking does not always follow the “traditional” path of compromising an individual’s computer or an organisations server, but can instead begin with targeting embedded electronic systems in hardware-based attacks.</p>
<p>A notable ATP group to mention is that of the “Volt Typhoon” group, which has been linked to the Chinese government and active since 2021. The existence of this particular APT group surfaced publicly in May 2023, when Microsoft reported that the group, had targeted US critical infrastructure in espionage operations, and lay dormant within their infrastructure for as long as 5 years. Specifically, this APT group was targeting Operation Technology (OT) systems using zero-day exploits, to pre-position themselves for future attacks of sabotage. This group even demonstrating critical capabilities in compromising Microsoft to see the level of detail that the organisation had on them, during the course of Microsoft raising these events publicly.</p>
<p>In early 2024 the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory that raised concerns about the potential for these threat actors to use their network access for highly disruptive effects in the event of potential geopolitical tensions and/or military conflicts. It is critical to note that no impact from this attack was witnessed in any of the systems they were found to have compromised. This largely indicates a co-ordinated effort, from a highly sophisticated state sponsored actor pre-positioning for maximum damage to enhance geopolitical outcomes. It was noted through the investigation that activity related to this threat actor had gone back, in some cases, in excess of 10 years. Once again highlighting why cyber defensive capabilities are so important. Can you imagine the fallout had this ATP group been able to disrupt critical infrastructure, power stations, water supplies and government infrastructure, within the United States.</p>
<p>MWR has long spoken of the need for organisations to assume that at some point they will be breached, and prepare as such. The reality is an organisation can only prepare for compromise, by having a robust, encompassing and sound cyber security strategy and a capable suite of armaments to deal with this unfortunate scenario. The three pillars of people, process and technology need to be soundly practiced, complementary in all they do and have the ability to rapidly work to contain, eradicate and recover from a cyber security compromise. Unfortunately, in our experience, often the hardest phase for an attacker to complete is the initial phase to gain access. Once in a target environment it is far too common that organisations have minimal controls and restrictions within their internal network. We therefore advise our clients to work backward. Understand what you have that an attacker would want access to, and structure controls, defences and barriers from this point outward towards the external perimeter. Performing this exercise will give you a view you never had of your internal network and how an attacker is likely to target you. This ultimately makes you more robust against their attacks.</p>
<p>From MWR’s experience, what we can say is that you do not want to end up in a position where you have to perform incident response activities to eradicate the threat actor. However, you want to prepare as if you will end up there someday. It can prove to be a very challenging endeavour whilst potentially incurring financial and reputational damage as a result of such a breach. As an example, IBM’s 2024 <em>Cost of a Data Breach</em> report shows data breaches in South Africa cost 53.10 million ZAR per incident, on average. The main driving factors of these costs are business disruption, post-breach customer support as well as remediation. In addition to this non-compliance with regulations also contributes to this number. It is substantially easier to be proactive when it comes to security rather than being forced to become reactive to such events.</p>
<p>Companies developing new technology face near constant attempts to breach their security. Unfortunately, those companies without mature cyber security environments may never realise a breach has occurred, let alone actually respond in an appropriate manner until it is too late. Real-world attackers essentially have “unlimited” time, and if advanced and persistent enough, they will find a way in. Would you be able to respond and eliminate the threat before substantial amounts of damage can be caused, or would you rather take the proactive approach and diminish the chances of ever having to be in such a position?</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/97533/">Tactical Typing: The Rise of Cyber Security in Modern Warfare</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>South Africa Faces Increased Cyberattacks Against Government Agencies</title>
		<link>https://www.protectionweb.co.za/cyber-security/south-africa-faces-increased-cyberattacks-against-government-agencies/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Thu, 13 Mar 2025 09:43:32 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[South Africa]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97386</guid>

					<description><![CDATA[<p>In late January, South Africans discovered their national weather service had been taken offline by a cyberattack from an unknown source. The attack that took down the weather service on January 26 followed a failed attempt the day before, according to South African officials. The breach did not block the service from using its weather [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/south-africa-faces-increased-cyberattacks-against-government-agencies/">South Africa Faces Increased Cyberattacks Against Government Agencies</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In late January, South Africans discovered their national weather service had been taken offline by a cyberattack from an unknown source.</p>
<p>The attack that took down the weather service on January 26 followed a failed attempt the day before, according to South African officials. The breach did not block the service from using its weather forecasting technology, but it did block the service’s ability to report aviation and marine forecasts and shut down its email system and website. The cyberattack also affected Mozambique, Zambia and other countries that rely on South Africa for weather forecasts.</p>
<p>The attack against the South African Weather Service is part of a broader pattern of cyberattacks across the continent. Attacks rose by 37% in 2024 compared to 2023. Worldwide, attacks rose about 30%, according to cybersecurity company Check Point Software Technologies.</p>
<p>As one of the continent’s countries with the highest internet connectivity, South Africa has become a major target for cybercriminals.</p>
<p>“The attack surface has increased, while the attacks by cybercriminals have grown in frequency, strength and severity,” Adius Ncube, a senior advisor with South Africa’s Oliver Wyman risk management company, wrote for the Daily Maverick.</p>
<p>Cyberattacks are also increasingly targeting the nation’s critical infrastructure, including health care systems, utilities and ports, he noted. In 2024, South African organizations and government agencies, on average, each experienced 1,450 cyberattacks a week.</p>
<p>Among the attacks on government institutions, cyberattacks:</p>
<ul>
<li>Shut down blood testing at the National Health Laboratory Service, which screens for tuberculosis, HIV/AIDS, mpox, among other things.</li>
<li>Breached the Companies and Intellectual Property Commission, which handles registration of businesses and intellectual property rights.</li>
<li>Hacked the Government Employees Pension Fund, Africa’s largest pension fund, worth more than $85 billion.</li>
</ul>
<p>Even the State Security Agency, which tracks foreign and domestic threats, was not immune from attacks The agency was hacked just days before the 2023 BRICS economic summit.</p>
<p>In a presentation to South Africa’s Parliament last July, Minister in the Presidency Khumbudzo Ntshavheni acknowledged the “exponential increase” in cyberattacks on government institutions and the impact they can have on the economy.</p>
<p>“In our efforts to strengthen cybersecurity, we are hard at work building and strengthening our capabilities and capacity to proactively combat emerging cyberthreats and potential cyberattacks on our communications environment,” Ntshavheni said.</p>
<p>The government will speed up the implementation of its decade-old National Cyber Security Framework to improve the response to attacks, she said</p>
<p>Critics of South Africa’s cybersecurity say that even though the government has made some strides in cyber readiness, including creating a military Cyber Command, more must be done.</p>
<p>“The reality, however, is that other issues have been consistently ranked above cybersecurity,” analysts Joe Devanny and Russell Buchan wrote in 2024 for the Carnegie Endowment.</p>
<p>Ncube is among those calling for the government to invest more in cybersecurity and to take a more strategic approach to protect its online resources.</p>
<p>“While South Africa has yet to experience a truly devastating attack, it’s certainly not immune to one,” Ncube wrote. “Experts agree that in the case of South Africa, as with most countries, it is only a matter of time before the country experiences a highly disruptive attack.”</p>
<p>Even as the government pledges to step up high-level cybersecurity efforts, the true defense against malicious hackers starts with individual users, Ncube noted. For that reason, the government and businesses must educate internet users about the risks they face from cyberattacks. The majority of cyberattacks begin by tricking an individual internet user into opening an innocent-looking email or message.</p>
<p>“While an integrated approach won’t stop every attack, it will prevent many more than allowing organizations in charge of critical infrastructure to each take care of their own cybersecurity needs,” Ncube wrote. “Moreover, such an approach can also help mitigate the impact of any such attack.”</p>
<p>&nbsp;</p>
<p><em>This article was republished with permission from African Defence Review, the original article can be found <a href="https://adf-magazine.com/2025/02/south-africa-faces-increased-cyberattacks-against-government-agencies/">here.</a></em></p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/south-africa-faces-increased-cyberattacks-against-government-agencies/">South Africa Faces Increased Cyberattacks Against Government Agencies</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Is AI a game-changer for cyberthreats in Africa?</title>
		<link>https://www.protectionweb.co.za/featured/is-ai-a-game-changer-for-cyberthreats-in-africa/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Mon, 17 Feb 2025 10:54:03 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Generative AI]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97265</guid>

					<description><![CDATA[<p>As the African continent continues its digital transformation, cybercriminals are becoming increasingly sophisticated, with AI emerging as a tool for more strategic and effective attacks &#8211; including distributed denial-of-service (DDoS) strikes. Bryan Hamman, regional director for Africa at NETSCOUT, explains: “We&#8217;re witnessing AI not just as a defence mechanism but also as a potential threat amplifier. The [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/featured/is-ai-a-game-changer-for-cyberthreats-in-africa/">Is AI a game-changer for cyberthreats in Africa?</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span lang="en-GB" data-ogsc="black" data-olk-copy-source="MessageBody">As the African continent continues its digital transformation, cybercriminals are becoming increasingly sophisticated, with AI emerging as a tool for more strategic and effective attacks &#8211; </span><span data-ogsc="rgb(40, 45, 52)">including distributed denial-of-service (DDoS) </span><span lang="en-US" data-ogsc="rgb(40, 45, 52)">strikes</span><span lang="en-GB" data-ogsc="black">.</span></p>
<p><span lang="en-GB" data-ogsc="black">Bryan Hamman, regional director for Africa at NETSCOUT, explains: “We&#8217;re witnessing AI not just as a defence mechanism but also as a potential threat amplifier. The adoption of machine learning allows adversaries to automate reconnaissance and tailor attacks at extraordinary scale.”</span></p>
<p><span lang="en-GB" data-ogsc="black">In many African countries, digital adoption is outpacing cybersecurity measures, placing businesses, governments and individuals in a precarious position. According to Hamman, without the right proactive measures in place, local organisations risk falling victim to AI-powered threat scenarios, where malware can evade traditional defences, phishing attacks become hyper-personalised and response times shrink dangerously.</span></p>
<p><span lang="en-GB" data-ogsc="black">&#8220;AI can be a double-edged sword, and African businesses must ensure they leverage its benefits for better protection, while steering clear of the darker side of AI by staying a step ahead of attackers,&#8221; he advises.</span></p>
<p><span lang="en-US" data-ogsc="black">Generative AI (GenAI) can take many facets of cyberthreats to new levels. These could include:</span></p>
<ul type="disc">
<li data-ogsc="black"><span data-ogsc="">Enhancements to social engineering, such as:</span>
<ul type="circle">
<li data-ogsc="black"><span data-ogsc="">Crafting more convincing and unique phishing emails.</span></li>
<li data-ogsc="black"><span data-ogsc="">Mimicking voices in audio messages.</span></li>
</ul>
</li>
</ul>
<ul type="disc">
<li data-ogsc="black"><span data-ogsc="">Image or video generation:</span>
<ul type="circle">
<li data-ogsc="black"><span data-ogsc="">Deepfake images have been shown to trick biometric facial recognition if executed correctly.</span></li>
</ul>
</li>
</ul>
<ul type="disc">
<li data-ogsc="black"><span data-ogsc="">Attack scale:</span>
<ul type="circle">
<li data-ogsc="black"><span data-ogsc="">Scaling an attack to be bigger and better is easier than ever due to the automation AI can empower.</span></li>
<li data-ogsc="black"><span data-ogsc="">Automating rudimentary processes, such as sending phishing emails, can allow cyber criminals target more individuals within an organisation to increase their chances of gaining access.</span></li>
</ul>
</li>
</ul>
<p><span lang="en-GB" data-ogsc="black">Furthermore, the integration of AI into denial-of-service (DDoS) attacks is becoming a reality, allowing threat actors to optimise botnet behaviour and target selection, making these disruptions more destructive and difficult to mitigate.</span></p>
<p><span lang="en-GB" data-ogsc="black">NETSCOUT urges organisations to stay vigilant by investing in AI-driven security solutions and fostering a culture of cybersecurity awareness through consistent training. &#8220;The key lies in not just reacting to threats, but pre-empting them,&#8221; Hamman concludes. “As African markets grow, robust, AI-driven cybersecurity strategies will become increasingly crucial to ensuring that digital innovation is secure and sustainable.”</span></p>
<p><em><span lang="en-GB" data-ogsc="black">NETSCOUT&#8217;s Arbor DDoS protection assures the world’s largest networks and service providers against DDoS attacks of all shapes and sizes. For more information, click <a href="https://www.netscout.com/">here.</a> </span></em></p>
<p>The post <a href="https://www.protectionweb.co.za/featured/is-ai-a-game-changer-for-cyberthreats-in-africa/">Is AI a game-changer for cyberthreats in Africa?</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>South Africa Faces Escalating Cybersecurity Threats to Critical Infrastructure</title>
		<link>https://www.protectionweb.co.za/state-security/south-africa-faces-escalating-cybersecurity-threats-to-critical-infrastructure/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Fri, 17 Jan 2025 08:33:10 +0000</pubDate>
				<category><![CDATA[State Security]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[South Africa]]></category>
		<category><![CDATA[SSA]]></category>
		<category><![CDATA[State Security Agency]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97088</guid>

					<description><![CDATA[<p>As cybercrime incidents rise globally, South Africa is grappling with an increasing frequency of cyber-attacks targeting critical infrastructure across various sectors. The State Security Agency (SSA) has acknowledged that the nation faces significant threats, with ransomware attacks emerging as a predominant concern over the past year. Critical sectors such as telecommunications, finance, transportation, energy, education, [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/state-security/south-africa-faces-escalating-cybersecurity-threats-to-critical-infrastructure/">South Africa Faces Escalating Cybersecurity Threats to Critical Infrastructure</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As cybercrime incidents rise globally, South Africa is grappling with an increasing frequency of cyber-attacks targeting critical infrastructure across various sectors. The State Security Agency (SSA) has acknowledged that the nation faces significant threats, with ransomware attacks emerging as a predominant concern over the past year.</p>
<p>Critical sectors such as telecommunications, finance, transportation, energy, education, and healthcare have been affected, highlighting vulnerabilities in systems essential to the economy. Among the notable incidents in the public sector were attacks on the National Health Laboratory Service and Denel, showcasing the growing sophistication and reach of cybercriminals.</p>
<p>The SSA warns that threats to South Africa’s critical information infrastructure are likely to escalate, driven by the nation’s advanced communications systems, its position in the global community, and evolving geopolitical dynamics. These factors make the country an attractive target for malicious actors seeking to exploit vulnerabilities for financial or strategic gain.</p>
<p>To combat these risks, the SSA has intensified collaboration with public and private sector entities. This coordinated approach aims to monitor, detect, and respond to cyber threats, safeguarding the integrity of critical information infrastructure and maintaining national security.</p>
<p>While these efforts are ongoing, the SSA emphasises that the challenges posed by cybercrime will require continued vigilance and adaptation as the digital landscape evolves.</p>
<p>The post <a href="https://www.protectionweb.co.za/state-security/south-africa-faces-escalating-cybersecurity-threats-to-critical-infrastructure/">South Africa Faces Escalating Cybersecurity Threats to Critical Infrastructure</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
