Skip to main content
Annual Review

NCSC Annual Review 2022

Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.

Page 11 of 33

Evolving Technical Threat

Last year saw the response to the Log4j vulnerability which showed how widespread some low-level software flaws can be, how hard it is to know what underlying software libraries are in use in users’ applications, and how quickly a vulnerability can be weaponised.

Vulnerabilities: weaknesses in an IT system that can be exploited by an attacker to deliver a successful attack.

The Log4j vulnerability was made public in December and within days it was being exploited. Less than four weeks after it was made public, NHS Digital saw widespread targeting of the specific vulnerability in the VMware Horizon product. The NCSC published alerts and guidance to highlight the risk posed by Log4j and mitigations. However, as the logging utility is widely used, there remains a significant risk where its vulnerabilities remain unpatched.

More generally, technical threat evolved at all levels of sophistication – not only at the “top” end. Activity attributed by Microsoft to NOBELIUM is an example of the evolution of highly technically sophisticated tradecraft.

The NCSC are also seeing changes in less sophisticated attacks – such as the increasing trend to use Multi-Factor Authentication (MFA) Push Exhaustion attacks. This sees attackers trigger a deluge of MFA acceptance prompts on a user's phone until the user clicks 'Allow' to stop the flood of requests. The ongoing attacker tendency of 'Living off the Land' – where the malign actor uses built-in software and functions to perform actions on target systems – means that activity by sophisticated actors can appear very similar to activity by unsophisticated ones.

Another trend observed was the declining use of Remote Desktop Protocol (RDP) practices to gain initial access to target systems. This may be because potential target organisations are protecting themselves better from attacks of this kind or because a large proportion of the vulnerable configurations have already been exploited. As RDP services decline as an initial access route, other ways in such as phishing and access through third parties is increasing as a proportion of all attacks.

Published

Reviewed

Version

1.0

Written for