The report offers an overview of the web-based attacks, provides a compendium of trends and identifies attack vectors. A series of proposed actions for mitigation is provided.
Web-based attacks are an attractive method by which threat actors can delude victims using web systems and services as the threat vector. This covers a vast attack surface, for instance facilitating malicious URLs or malicious scripts to direct the user or victim to the desired website or downloading malicious content (watering hole attacks1, drive-by attacks2) and injecting malicious code into a legitimate but compromised website to steal information (i.e formjacking3) for financial gain, information stealing or even extortion via ransomware.
Para leer más ingrese a:
https://www.enisa.europa.eu/publications/web-based-attacks
https://www.enisa.europa.eu/publications/web-based-attacks/at_download/fullReport