Many Canadian, U.S. SMB websites vulnerable to spoofing, clickjacking and sniffing, says vendor

Websites of Canadian and American small and medium businesses continue to be vulnerable to spoofing, clickjacking and sniffing, according to a report from a new cybersecurity company offering cloud-based protection for SMBs.

The report from CyberCatch, headquartered in San Diego with an office in Vancouver, B.C., is aimed at trumpeting the capabilities of its CyberXRay tool. It scanned 20,000 randomly selected SMB websites in the U.S. and 1,850 in Canada.

Among Canadian sites it found

  • 84.3 per cent were vulnerable to being spoofed, which the report defines as a website, software or web application that didn’t sufficiently verify the origin or authenticity of data and could accept invalid data. This would allow an attacker to send carefully crafted scripts to force the web server to produce information such as usernames, passwords, content of a shopping cart, or in some cases, the entire customer database.;
  • 73.3 per cent were vulnerable to clickjacking, which allows an attacker to insert stylesheets, iframes, text boxes or layers in a website;
  • and 26.8 per cent were vulnerable to sniffing attacks, which allow an attacker to view the transmission of sensitive data in cleartext because it isn’t encrypted. If a website had simple single-factor authentication with just a user name and password, and was using a deprecated version of Secure Sockets Layer (SSL) or Transport Layer Security (TLS), the
    password could be easily detected and discoverable using simple network sniffing, the report says.

Among U.S. sites it found

  • 32.7 per cent were vulnerable to being spoofed;
  • 27.9 per cent were vulnerable to clickjacking;
  • and 10.5 per cent were vulnerable to sniffing.

The report also breaks down vulnerable sites by industry.

“SMBs across U.S. and Canada should scan their websites, software and web applications facing the Internet to make sure there are no vulnerabilities,” the report says. IT security managers should also implement a cybersecurity control to regularly scan all IT assets
for hardware and software vulnerabilities and set a policy to fix the weaknesses within a reasonable time.

“SMBs have limited resources, lack cybersecurity knowledge and the how-to. They rely on their IT provider, but IT is not cybersecurity,” said company founder and CEO Sai Huda. The report “reveals how vulnerable SMBs are to cyberattacks today and this is the reason why CyberCatch was founded. Our mission is to protect SMBs by focusing on the root cause for data breaches and ransomware: security holes.”

The company, whose advisory board includes former RCMP assistant commissioner Kevin Hackett and former U.S. Secretary of Homeland Security Tom Ridge, offers a software-as-a service network monitoring and cybersecurity controls testing service that starts at US$250 a month for firms with up to 50 employees, rising to US$1,000 a month for up to 499 employees. There are discounts for paying annually. There’s also a similarly-priced continuous compliance assessment service that gives instant benchmarking, a cyber hygiene score, a system security plan, a security awareness module for employees and a virtual CISO to offer advice.

It also offers a separately-priced cyber incident simulator for table-top exercises for US$95 a year.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
ASX defies weak commodities to eke out a small gain thumbnail

ASX defies weak commodities to eke out a small gain

The S&P/ASX 200 Index added 20.9 points to 6800.1; the All Ordinaries rose 0.3 per cent to 6999.8.Gold producer St Barbara failed to recover from Tuesday’s weak reception to its production downgrade that it blamed on skills and equipment shortages; the shares fell a further 4.8 per cent to 50¢ after the previous session’s 22
Read More
Investors in Collapsed South African Crypto Platform Reimbursed a Portion of Invested Funds thumbnail

Investors in Collapsed South African Crypto Platform Reimbursed a Portion of Invested Funds

Investors in Africrypt, the now-defunct South African crypto platform, were recently reimbursed a portion of their invested funds. The payments were made by Pennython Project Management LLC as part of a settlement offer that potentially ends claims against Africrypt’s runaway directors. White Knight Investor Identity Revealed Investors in Africrypt, a collapsed South African cryptocurrency investment…
Read More
MRiT: Marek Niedużak leaves the Ministry of Development and Technology thumbnail

MRiT: Marek Niedużak leaves the Ministry of Development and Technology

2021-12-30 18:16publikacja2021-12-30 18:16fot. Piotr Guzik / / FORUMWiceminister rozwoju i technologii Marek Niedużak ze skutkiem na dzień 31 grudnia 2021 r. złożył rezygnację ze sprawowanej przez siebie funkcji - poinformował w czwartek resort. Niedużak w ministerstwie odpowiadał za obszar regulacji prawnych dla przedsiębiorców. "Bardzo dziękuję Panu ministrowi za lata pracy w Ministerstwie Rozwoju i Technologii na…
Read More
Microsoft'tan dev satın alma! thumbnail

Microsoft’tan dev satın alma!

YASAL UYARI: Piyasa verileri Foreks Bilgi İletişim Hizmetleri A.Ş. tarafından sağlanmaktadır. Üye girişi yapılan Canlı Borsa sayfaları haricinde Hisse senedi verileri 15 dk gecikmelidir. Tahvil-Bono-Repo özet verileri her durumda 15 dk gecikmelidir. Burada yer alan yatırım bilgi, yorum ve tavsiyeleri yatırım danışmanlığı kapsamında değildir. Yatırım danışmanlığı hizmeti; aracı kurumlar, portföy yönetim şirketleri, mevduat kabul etmeyen…
Read More
Bitdeer Group Develops Systems for Safer Digital Asset Services thumbnail

Bitdeer Group Develops Systems for Safer Digital Asset Services

Bitdeer Group’s leadership in pioneering compliance and upholding rigorous standards keeps digital asset business sustainable for the long term. With continually practicing the global compliance strategy and prospective planning, Bitdeer Group has established strict know-your-customer (KYC) and updating know-your-transaction (KYT) procedures for all individual and enterprise clients who utilize Bitdeer. This move reflects Bitdeer Group’s…
Read More
Crypto in 2024 – Bullish or Bearish? thumbnail

Crypto in 2024 – Bullish or Bearish?

By Mark Hunter2 weeks agoFri Dec 22 2023 07:23:05 Reading Time: 2 minutes Crypto has recovered splendidly in 2023, buoyed by the Bitcoin ETF narrative There are a number of reasons why 2024 should be a good year, but in crypto nothing is certain What are our thoughts for 2024? The crypto space has seen
Read More
Index Of News
Total
0
Share