<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>risk scenarios Archives - ProtectionWeb</title>
	<atom:link href="https://www.protectionweb.co.za/tag/risk-scenarios/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.protectionweb.co.za/tag/risk-scenarios/</link>
	<description>First with Security News</description>
	<lastBuildDate>Thu, 09 Jan 2025 09:53:36 +0000</lastBuildDate>
	<language>en-ZA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>

<image>
	<url>https://www.protectionweb.co.za/wp-content/uploads/2024/04/cropped-ProtectionWebLogo-512x512-1-32x32.png</url>
	<title>risk scenarios Archives - ProtectionWeb</title>
	<link>https://www.protectionweb.co.za/tag/risk-scenarios/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Kaspersky explores 2025 potential IT outage and supply chain risk scenarios</title>
		<link>https://www.protectionweb.co.za/cyber-security/kaspersky-explores-2025-potential-it-outage-and-supply-chain-risk-scenarios/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Thu, 09 Jan 2025 09:53:36 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[2025]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[Kapersky]]></category>
		<category><![CDATA[Kaspersky Security Bulletin]]></category>
		<category><![CDATA[risk scenarios]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=97037</guid>

					<description><![CDATA[<p>As part of its annual Kaspersky Security Bulletin, the company’s experts have analysed significant supply chain attacks and IT outages from the past year and explored potential future risk scenarios, providing insights aimed at helping businesses of all sizes enhance cybersecurity, build resilience, and prepare for possible emerging threats in 2025. In 2024, supply chain [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/kaspersky-explores-2025-potential-it-outage-and-supply-chain-risk-scenarios/">Kaspersky explores 2025 potential IT outage and supply chain risk scenarios</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span lang="en-US" data-ogsc="black" data-olk-copy-source="MessageBody">As part of its annual Kaspersky Security Bulletin, the company’s experts have analysed significant supply chain attacks and IT outages from the past year and explored potential future risk scenarios, providing insights aimed at helping businesses of all sizes enhance cybersecurity, build resilience, and prepare for possible emerging threats in 2025.</span><u></u><u></u></p>
<p><span lang="en-US" data-ogsc="black" data-ogsb="white">In 2024, supply chain attacks and IT outages emerged as dominant cybersecurity concerns, </span><span lang="en-US" data-ogsc="black">demonstrating that virtually no infrastructure is immune to risk<span data-ogsc="" data-ogsb="white">. A faulty CrowdStrike update affected millions of systems, and sophisticated incidents, such as the XZ backdoor and the Polyfill.io supply chain attack exposed the risks inherent in widely used tools. These and other high-profile cases highlight the need for rigorous security measures, robust patch and update management, and proactive defenses to safeguard global supply chains and infrastructure.</span></span><u></u><u></u></p>
<p><span lang="en-US" data-ogsc="black" data-ogsb="white">In its “Story of the Year”, the Kaspersky Security Bulletin reflects on 2024’s past incidents, while contemplating hypothetical future scenarios, and considering their potential consequences, as follows:</span><u></u><u></u></p>
<p><b><span lang="en-US">What if a major AI provider faced an outage or a data breach? </span></b><span lang="en-US">Businesses are increasingly relying on various models such as those from OpenAI, Meta, Anthropic and others. <span data-ogsc="black">However, </span>despite the excellent user experience these integrations offer, they introduce significant cyber risks. Reliance on a single or limited number of AI service providers creates concentrated points of failure. If a major AI company experiences a critical disruption, it could significantly impact dozens or even thousands of services that depend on them.</span><u></u><u></u></p>
<p><span lang="en-US">Furthermore, an incident at any major AI provider could result in one of the most severe data leaks, as these systems may store vast amounts of sensitive information.</span><u></u><u></u></p>
<p><b><span lang="en-US">What if on-device AI tools were exploited? </span></b><span lang="en-US">As AI becomes more integrated into everyday devices, the risk of it becoming an attack vector grows significantly. For instance, the </span><span lang="ru"><a title="https://securelist.com/trng-2023/" href="https://securelist.com/trng-2023/" data-auth="NotApplicable" data-linkindex="2" data-ogsc=""><span lang="en-US" data-ogsc="">Operation Triangulation</span></a></span><span lang="en-US"> campaign, uncovered by Kaspersky in 2023, demonstrated how attackers could compromise device integrity by exploiting zero-day vulnerabilities in the system software and hardware to deploy advanced spyware. Similar potential software or hardware-assisted vulnerabilities in the neural processing units powering AI – both broadly and in specific platforms like Apple Intelligence – could, if discovered, extend or present an even greater threat. Exploiting such weaknesses could harness AI capabilities to significantly amplify the scope and impact of such attacks.</span><u></u><u></u></p>
<p><span lang="en-US">Kaspersky’s research into Operation Triangulation also revealed the first of its kind case reported by the company: the misuse of on-device machine learning for data extraction, highlighting that the features designed to enhance user experience are already being weaponised by sophisticated threat actors.</span><u></u><u></u></p>
<p><b><span lang="en-US">What if threat actors disrupted satellite connectivity? </span></b><span lang="en-US">While the space industry in general has been encountering various cyberattacks for a while, the new target for threat actors may be satellite Internet providers as important elements of the global connectivity chain. Satellite Internet can provide temporary communication links when other systems are down; airlines, ships, and other platforms may rely on it to provide </span><span lang="ru"><a title="https://www.scmp.com/tech/big-tech/article/3183749/us-approves-spacexs-starlink-satellite-internet-use-planes-and-ships" href="https://www.scmp.com/tech/big-tech/article/3183749/us-approves-spacexs-starlink-satellite-internet-use-planes-and-ships" data-auth="NotApplicable" data-linkindex="3" data-ogsc=""><span data-ogsc=""><span lang="en-US" data-ogsc="rgb(17, 85, 204)">onboard connectivity</span></span></a></span><span lang="en-US" data-ogsc="rgb(17, 85, 204)">; </span><span lang="en-US">it may also be used to enable secure communication services.</span><u></u><u></u></p>
<p><span lang="en-US">This presents cyber risks: a targeted cyberattack or a faulty update from a leading or dominant satellite provider could cause Internet outages and potential communication breakdowns, impacting individuals and organisations.</span><u></u><u></u></p>
<p><b><span lang="en-US" data-ogsc="black" data-ogsb="white">What if major physical threats to the Internet occurred?</span></b><span lang="en-US"> </span><span lang="en-US" data-ogsc="black" data-ogsb="white">Continuing the topic of connectivity, the Internet is also vulnerable to physical threats. 95% of global data is </span><span lang="ru"><a title="https://csis-website-prod.s3.amazonaws.com/s3fs-public/publication/210309_Hillman_Subsea_Network_1.pdf?VersionId=1c7RFgLM3w3apMi0eAPl2rPmqrNNzvwJ" href="https://csis-website-prod.s3.amazonaws.com/s3fs-public/publication/210309_Hillman_Subsea_Network_1.pdf?VersionId=1c7RFgLM3w3apMi0eAPl2rPmqrNNzvwJ" data-auth="NotApplicable" data-linkindex="4" data-ogsc=""><span lang="en-US" data-ogsc="">transmitted</span></a> </span><span lang="en-US" data-ogsc="black" data-ogsb="white">through subsea cables, and there are </span><span lang="ru"><a title="https://pulse.internetsociety.org/en/ixp-tracker/" href="https://pulse.internetsociety.org/en/ixp-tracker/" data-auth="NotApplicable" data-linkindex="5" data-ogsc=""><span lang="en-US" data-ogsc="">nearly</span></a><span data-ogsc="black" data-ogsb="white"> </span></span><span lang="en-US" data-ogsc="black" data-ogsb="white">1,500 Internet Exchange Points (IXPs) – physical locations, sometimes within data centers, where different networks exchange traffic.</span><span lang="en-US"> </span><u></u><u></u></p>
<p><span lang="en-US" data-ogsc="black" data-ogsb="white">A disruption to just a few critical components of this chain – such as key cables or IXPs – could overload the remaining infrastructure, potentially causing widespread outages and significantly impacting global connectivity.</span><u></u><u></u></p>
<p><b><span lang="en-US" data-ogsc="black" data-ogsb="white">What if severe vulnerabilities in Windows and Linux kernel were exploited? </span></b><span lang="en-US" data-ogsc="black" data-ogsb="white">These operating systems power many of the world’s critical assets, including servers, manufacturing equipment, logistics systems, IoT devices, and others. A remotely exploitable kernel vulnerability in these systems could expose countless devices and networks worldwide to potential attacks, creating a high-risk situation in which global supply chains could face significant disruption.</span><u></u><u></u></p>
<p><span lang="en-US" data-ogsc="black" data-ogsb="white">“Supply chain risks may seem overwhelming, but awareness is the first step toward prevention,” said Igor Kuznetsov, Director of Global Research and Analysis Team (GReAT) at Kaspersky. “By testing updates rigorously, leveraging AI-driven anomaly detection, and diversifying providers to reduce single points of failure, we can reduce weak elements and build resilience. A culture of responsibility among personnel is equally vital, as human vigilance remains the cornerstone of security. Together, these measures can safeguard supply chains and ensure a more secure future”.</span><u></u><u></u></p>
<p><span lang="ru"> </span></p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/kaspersky-explores-2025-potential-it-outage-and-supply-chain-risk-scenarios/">Kaspersky explores 2025 potential IT outage and supply chain risk scenarios</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
