Web 2.0 Tops 'Emerging Cyber Threats'

The ever-nebulous "Web 2.0" is emerging as one of the five top security risks to watch for both consumers and the enterprise--this according to the inaugural edition of the "GTISC Emerging Cyber Threats Report for 2008" out of Georgia Tech's Information Security Center. The report, released at the GTISC Security Summit on Emerging Cyber Security Threats and Countermeasures, identifies the key data security threats that are likely to expand and evolve in the coming year.

According to the report, the chief motivator for all of the top emerging threats will continue to be financial gain, taking advantage of holes in continually advancing applications whose development has been, to date, outpacing the development of countermeasures.

Commenting on the report, GTISC Director Mustaque Ahamad said, “As newer and more powerful applications enabled by technologies like Web 2.0 continue to grow, and converged communications applications increasingly rely on IP-based platforms, new challenges will arise in safegaurding these applications and the services they rely on. The GTISC Emerging Cyber Threats Report for 2008 highlights those areas of greatest risk and concern, particularly as continued convergence of enterprise and consumer technologies is expected over the coming year."

The report listed five broad categories of data security risk, cited below:
  • Web 2.0 and client-side attacks on social networking technologies, aimed at "stealing private data, hijacking Web transactions, executing phishing scams, and perpetrating corporate espionage;"
  • Targeted messaging attacks, aimed at individual users, largely for the purpose of stealing authentications and private data;
  • Botnets expanding the scope of their activities to the theft of information and increasing abuse of DMS servers;
  • Mobile convergence threats, including "vishing," "smishing," and voice spam, plus denial of service attacks targeting voice infrastructure; and
  • RFID attacks, including automated exploitation tools for tracking users via RFID devices, cloning, RF blocking, and even a form of tunneling in which commands, such as SQL queries, might be submitted to an RFID reader.
The predictions, however, are not all dire. The GTISC suggests that in the coming year the gap between application development and security and countermeasure development will begin to narrow as coordination between the "security industry, carriers, Internet Service Providers, application developers, and the user community" increases.

More information, including the complete report, can be found at the links below.

Read More:

About the Author

David Nagel is the former editorial director of 1105 Media's Education Group and editor-in-chief of THE Journal, STEAM Universe, and Spaces4Learning. A 30-year publishing veteran, Nagel has led or contributed to dozens of technology, art, marketing, media, and business publications.

He can be reached at [email protected]. You can also connect with him on LinkedIn at https://www.linkedin.com/in/davidrnagel/ .


Featured

  • CIS Sandbox Tutor Eli Blouin at Bentley University imagines a future technology learning partner that supports curiosity, critical thinking, feedback, and personalized learning.

    Student Voices: Technology as a Future Learning Partner

    A data analytics and marketing major at Bentley University and a distinguished lecturer at the university explore the future of "technology learning partners" — technologies that participate in the learning process by asking questions and giving feedback, not just information search results.

  • lock symbol with quantum bits in dynamic motion

    Microsoft Accelerates Focus on Quantum-Safe Security

    Microsoft is speeding up its quantum-safe security timeline, saying advances in quantum computing and new federal requirements have pushed post-quantum cryptography from a future planning issue into an immediate engineering priority.

  • interconnected nodes with currency symbols

    Gartner: Half of Gen AI Projects Could Exceed Budget by 2028

    Organizations may be underestimating the actual cost of generative AI as they move from experimentation to production, according to Gartner's "10 Best Practices for Optimizing Generative and Agentic AI Costs" report.

  • robot hand holding stacks of coins

    Designing AI Systems for Financial Aid

    Financial aid offices have been slow to adopt AI, risking technological stagnation at a critical early student touchpoint. Systematic AI integration can improve student experiences and strengthen institutional positioning.