Trending Topics

The speed of malware growth: 26.5 new variants an hour
What if I were to tell you that the threat landscape is changing faster than ever before? According to newly published research from SonicWall, a rather mind-boggling 26.5 new malware variants are being created every hour.
Or, to put it another way, that’s 637 new, never before seen, malware variants every single day.
That’s probably got your attention, but I’m sorry to report there’s more to come. Like the fact that 61% of attacks analysed by the SonicWall researchers saw new vulnerabilities being exploited within just two days. And encrypted attacks against businesses, created to make detection efforts as difficult as possible, have grown by 80% across 2024.
SMBs are at the sharp end of these attacks, with SonicWall stating that identity, cloud, and credential compromise account for 85% of all actionable alerts.
That’s the bad news, but here’s the worst: While threat actors are moving at an unprecedented pace, as that two-day window mentioned earlier shows, “we’re observing that it takes some organisations 120 to 150 days to apply a critical patch,” SonicWall CEO Bob VanKirk said. “In 2024,” VanKirk continued, “we witnessed alarming trends that underscore the urgent need for proactive defense strategies.”

AI driving malware growth
Part of the problem is, as I’ve mentioned here at TechFinitive before, the advances in AI-driven attack methodologies. These are now available to threat actors at a cost that makes them profitable when targeting not just large enterprises but the smaller end of the business market as well.
“SMBs are facing a storm of cyber threats, as attackers leverage automation, AI, and advanced evasion techniques to evade traditional defenses,” the report stated, “as attack surfaces expand and the time to exploit vulnerabilities shrinks, SMBs must prioritise proactive security measures.”
Given that the SonicWall intelligence found, on average, organisations were under critical attack for 68 days, the time to get proactive is long since overdue.
What that means for your business is that simply reacting to incidents after they have occurred really isn’t an option any longer. Instead, you need to be actively identifying threats and mitigating them before they can cause you harm.
That means scanning for vulnerabilities and patching systems in a timely fashion, employing a hunter mentality rather than a prey one.
Unless you do that, I’m afraid you’re doomed to be part of the shocking statistic list next year.
More articles by Davey
- Safer Internet Day Should Be Every Single Day
- As ransoms plummet, is this the end of ransomware? Hint: nope
- Davey’s security lessons to learn from 2024
