Picus Security: Major Cyber Breaches and Attack Campaigns of 2024
Picus Security's analysis highlights the most significant cyberattacks of 2024, noting the exploitation of known vulnerabilities and advanced tactics by state-sponsored actors.
Cybersecurity firm Picus Security has released an analysis detailing the major cyber breaches and attack campaigns observed in 2024. The report highlights the increasing sophistication of state-sponsored threat actors who utilized advanced tactics, including zero-day exploits and stealthy malware, to target critical infrastructure globally.
The analysis points to nation-state actors from China, Russia, and Iran as being responsible for highly sophisticated campaigns. One prominent incident involved the Chinese group Salt Typhoon, which breached nine major U.S. telecommunications companies, including AT&T and Verizon, exfiltrating sensitive data by exploiting well-documented, yet unpatched, vulnerabilities.
Another significant event was the cyberattack on the U.S. Treasury Department, attributed to Salt Typhoon. Attackers gained unauthorized access through vulnerabilities in BeyondTrust's remote support software, underscoring the importance of securing third-party solutions and maintaining robust security practices.
Further incidents examined include the large-scale breach of Change Healthcare by the ALPHV/BlackCat ransomware group. This attack, facilitated by a lack of multi-factor authentication on a Citrix remote access portal, resulted in the exposure of personal data for over 100 million individuals and caused widespread disruption to U.S. healthcare services.
Picus Security's findings suggest that the prevalent exploitation of known vulnerabilities in 2024 demonstrates that failure to patch systems can lead to severe consequences. Organizations are urged to prioritize proactive measures, continuous vulnerability monitoring, and strong security frameworks to mitigate evolving cyber threats.