Lavasoft Predicts IT Security Hits on Popular Platforms

Well-known anti-spyware pioneer Lavasoft recently announced its list of security predictions for 2011, anticipating the top threats that Internet users should be aware of this coming year as cyber criminals adapt their tactics, finding new ways to con people while they use the Internet.

Expectations for 2011 include not only an increase in malicious Internet attacks, but the online attackers will bolster their tactics using new twists on traditional methods – as well as focusing on newly emerging platforms – according to Lavasoft Malware Labs.

“We expect that traditionally successful and lucrative modes of attack on PCs, such as rogue threats and exploiting application vulnerabilities for programs people use on a daily basis, will see enhanced attacks using more subtle and sophisticated methods. At the same time, emerging operating systems and popular platforms, like smartphones, will likely attract increasing attacks – the more popular the platform becomes, the greater the incentive to attack,” said Andrew Browne, head of Malware Labs at Lavasoft.

The company's analysts anticipate that the following five threat trends will dominate the security landscape in 2011:

      1. Complex targeted attacks on companies and/or critical infrastructure. Stuxnet made headlines this year due to its complexity, highly precise targeting, and the use of multiple zero-day exploits and stolen digital certificates. While Stuxnet's intention to stay below the radar was not realized, we can expect to see further attempts to evade detection and to compromise fewer but higher value targets.

      2. Zero-day application vulnerability exploits. Users understand the importance of applying operating system patches but are less aware of the need to apply security updates to applications; patches fixing application vulnerabilities are typically slow to appear, and it’s not always apparent to the user that an update is available and that action needs to be taken, making it an easier malware target. Adobe's Flash and Reader applications bore the brunt of exploits in 2010 and were quick to be exploited ─ we can expect malware writers to react more quickly to leverage a wider array of application vulnerabilities.

      3. Scareware and rogue (fake) security products. Rogue security software, also known as scareware, take the form of legitimate-looking anti-virus, anti-spyware and anti-malware products and appear to be beneficial from a security perspective; in reality, they provide little or no protection, generate misleading alerts, or attempt to lure users into fraudulent transactions. The money made from this malware model ensures that cyber criminals will not abandon this profitable endeavor.

      4. Mobile malware. Smartphones are becoming more ubiquitous and as more services involving financial transactions are made available to handsets, exploits that leverage vulnerabilities on smartphone operating systems are sure to be targets for cyber criminals. Recent examples of Android malware and proof of concept examples suggesting iPhones are not immune suggest these non-Windows platforms have already attracted the attention of malware writers.

      5. Blackhat SEO. Cyber scammers will continue to poison search engine results using trending headlines and videos to lead to malicious sites in an attempt to distribute rogue (fake) security software and other types of malware.

    To stay safe in 2011, users should update their computer security software and stay aware and be cautious about the types of threats they may encounter online.

    Founded in 1999, Lavasoft is “the original anti-spyware company.” with more than 400 million downloads worldwide for the flagship Ad-Aware product. A private company headquartered in Gothenburg, Sweden, Lavasoft provides security solutions for individual consumers and enterprise clients alike, including anti-spyware, anti-virus, registry optimization, firewall, digital shredding, and encryption.

Featured

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.