5 things to know about ransomware threats in 2025

5 things to know about ransomware threats in 2025 5 things to know about ransomware threats in 2025

Naturally, generative AI threats exist; however, the focus on new technologies risk overshadowing the importance of cybersecurity hygiene practices, especially in resource-constrained sectors like public healthcare, says Aaron Bugal, Sophos field CTO, APJ. “It can come at the expense of addressing more fundamental cybersecurity basics, which contribute to ransomware vulnerabilities.”

Ransomware attack data in the Sophos State of Ransomware 2024 report shows that vulnerability management, compromised credentials, malicious email, and phishing are the most common starting points. It’s these risk factors that need to be managed through routine processes. “A lot of the attacks we’re seeing today, attackers are getting in using deficiencies in what constitutes a poorly managed or mismanaged environment and it’s just giving them the green light,” Bugal tells CSO.

Not protecting credentials, lack of multi-factor authentication, not patching well-known vulnerabilities, not keeping up with aging devices and user accounts, and overlooked configurations can get put off or forgotten about if too much focus is turned to generative AI. “Some things can be trivial to discover and mitigate, but if they’re overlooked by organizations, it leaves them vulnerable to attacks,” he says.

Add a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use