Skip to content

24.3.6 Voyager released

Changes compared to 24.3.5

Enhancements

  • Added the ability to configure SQL timeouts for MSSQL restores
  • Improved error message output for when a Hyper-V backup fails due to Hyper-V not being installed on the endpoint
  • Added additional threading to single file downloads from Microsoft 365, and added retry logic for when the download URL has expired. Expired URLs can cause 401 errors.

Bug Fixes

  • Fixed an issue causing a crash when data from multiple disks is selected for restore during granular restore workflows
  • Fixed an issue causing logins requiring 2FA to fail on the Comet Server web interface
  • Fixed an issue with the Comet Server web interface settings page to crash when a tenant has been deleted

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

Juggling security: How many passwords does the average person have in 2024?

For nearly four years, the magic number in every cybersecurity expert’s mind was 100 – the average number of passwords a person handles. During the pandemic and following a boost in hybrid work and digital communication, our usage of digital spaces has only expanded. It’s time to look at the newest numbers: How many passwords does the average person have in 2024?

A survey conducted by NordPass in 2024 revealed a rapid growth in password usage for personal purposes, with an increase of nearly 70% in just over three years. According to the latest data, the number is now 168. For the first time, the survey also recorded the average number of passwords used for business-related accounts: 87. Let’s take a closer look at the research and learn what this increased number of passwords means for our online safety.

The upward-pointing trend

NordPass has been tracking password usage statistics since 2020. The first survey was conducted in February of that year, just a month before the start of the COVID-19 pandemic. It was reported that an average user handled around 80 passwords at that time.

The follow-up survey was conducted in October of the same year. Eight months into the pandemic, the uptick in password handling was already evident. The average number of passwords handled by a person went up 25% to the number cited since – 100.

As stated by Tomas Smalakys, CTO at NordPass, COVID was perceived as the main cause at the time, as people were staying indoors and handling all processes – from shopping to medical appointments – online.

However, a lot has changed in four years, and the rapid increase in digital accounts we handle now goes beyond the life rhythm of lockdowns. According to Smalakys, “the amount of accounts that people hold gets higher every year. Multiple factors come into play – new services get launched, new shops are opened.”

As the scope of digital services increases, so does the number of accounts users handle. Naturally, the latest password statistics reflect this. It’s important to note that the numbers don’t just consider active or frequently used accounts. In fact, many accounts remain dormant as users forget about them and don’t delete them even if the accounts are no longer needed.

First insights into business password handling

For the first time, the 2024 NordPass password survey also researched work-related password usage. It was revealed that the average number of passwords per person in the workplace is 87.

While this is a new index for the NordPass survey, we can assume that the number of accounts required for work has seen a similar upward trend in recent years as remote and hybrid work opportunities have become increasingly popular.

Adding the number of personal and business passwords together brings the total to 255. Juggling that many passwords can be problematic in terms of both security and convenience.

Methodology: The new quantitative research by NordPass was conducted on March 4-15, 2024, and surveyed 1,509 NordPass users.

What happens when you have too many passwords to remember?

The problem with handling so many accounts on average is that they aren’t equally important to a person. In fact, many accounts are abandoned or forgotten after a handful of visits. This can pose a serious security risk, as users may overlook data breaches and not realize their accounts have been compromised.

Managing hundreds of accounts can be a tedious job that not all users are willing or able to do. The trend points toward people hoarding their online accounts and forgetting to review and close accounts they don’t use as frequently or no longer require. In many cases, breaches are overlooked, as the users simply forget they have accounts on breached platforms.

Another issue concerns the reuse of passwords. With nearly 200 accounts to manage, creating and then remembering a unique password for each one can seem impossible. This leads to people reusing the same or similar passwords for different accounts to simplify logging in. For example, they may reuse the same word or phrase, adding a single number, capital letter, or special symbol if required for security purposes.

This opens up multiple accounts to vulnerabilities. For example, if one account is breached, all accounts using the same password and owned by that user are at risk. Abandoned accounts on rarely visited platforms with weaker security measures can become the prime target for cybercriminals.

The threat increases if people reuse the same credentials for both personal and work accounts. A breach of a personal account could potentially affect the company’s security as well. According to the 2023 Data Breach Investigations Report, stolen credentials were among the top three main methods of accessing an organization, followed by phishing and vulnerability exploitation. Password mismanagement and vulnerabilities pose risks ranging from loss of access to financial damages or identity theft.

What can you do to handle passwords easier?

You might be thinking about how many accounts you currently have and how many may use insecure passwords. To make your credentials management less overwhelming, here are some best practices you can follow to reduce the number of passwords used in your daily life:

  • Deactivate unused accounts. Considering how many passwords the average person has, tracking down every unused account you’ve created may be difficult. However, if you know for certain that you no longer need an account, deactivate it to reduce your password load.

  • Set up a password manager. As you work to reduce the number of accounts you own, you will encounter many that remain necessary. NordPass helps individuals and businesses manage their passwords with ease and security in mind. Its built-in features support generating unique and secure passwords, simplifying logging in with autofill, and accessing all sensitive data on desktop and mobile devices as well as major browsers.

  • Regularly update your credentials. The longer you use a password, the higher the chances of it being breached. If you regularly change your passwords, you keep your accounts safer. Password Health lets you see which of your login credentials are weak, old, or reused.

  • Make sure all passwords are strong. We recommend passwords be at least 20 characters long and contain a combination of letters, numbers, and special symbols. A password generator helps quickly create passwords that meet this criteria. For more tips on creating strong passwords, visit our dedicated blog post.

  • Stay ahead of breaches. Use the Data Breach Scanner to get real-time alerts if your passwords, email addresses, or credit card details have appeared on the dark web.

  • Enable multi-factor authentication (MFA). Add an extra layer of protection to your accounts and ensure that even if your password is compromised, cybercriminals cannot access the affected account.

  • Switch to a passwordless solution where possible. Passkeys are a new, more secure way of logging in to your accounts. They use a combination of biometric verification with cryptographic keys, offering a safer and more convenient alternative to passwords. NordPass lets you easily store and manage passkeys on different devices.

Whether you have 18 or 168 passwords, NordPass makes password management simple and convenient. Your passwords, passkeys, credit card details, and other sensitive information are protected in the xChaCha20-encrypted vault, which only you can access.

NordPass offers a range of features tailored for personal and business use, including Email Masking, passkey support, secure item sharing, centralized policies for companies, and an Activity Log. You can try NordPass Free and Premium for your personal use or sign up for one of the Business plans based on your organization’s needs.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

Prevention-first security begins with data-enhanced insight: Meet ESET Threat Intelligence

Supporting threat hunters and incident response teams with hands-on data is crucial, as it not only safeguards organizations but provides the basis for a proactive prevention-first security strategy.

In recent years, a significant number of cyberattacks have been ransomware related and, despite fluctuations in frequency and intensity, they remain one of the most prevalent and feared security threats.

Ransomware attacks are highly orchestrated, but what makes them particularly insidious is that they are not merely automated programs running rampant through systems without direction but are often controlled minute-by-minute by human attackers. Once attackers utilize various Trojans to deploy the necessary tools, they meticulously navigate dozens of steps in search of valuable information within the compromised network. From there the options left open to defenders narrow, then increasingly become measures focused on mitigation — or worse, remediation.

The selection of “measures” is very much based on a keen understanding of the threats faced and any associated peculiarities, whether they be unique processes around privilege escalation or credential access techniques that enable cybercriminals to retrieve sensitive information until they can exfiltrate what they deem valuable. Every day, ESET Threat Intelligence (ETI) processes hundreds of millions of indicators of compromise (IOCs), akin to a database of clues left by cyber-intruders while they crawl through a victim’s network.

Preventing these chains of attacks is crucial since they can have long-lasting consequences, going beyond mere financial loss or data breach. They can provide leverage for future attacks and can sap the capacity and impact of defenders’ work across an organization’s entire threat surface. Working to avoid the narrowing of options means taking a prevention-first approach, putting in place preventive measures that stop ransomware payloads from reaching the endpoints. This process starts with insight and intelligence.

Putting threat intelligence to work

Researchers, SOC teams, threat hunters, and even curious prevention-minded admins can benefit from the types of threat intelligence that inform everything from replicated attack scenarios that aid red and blue team network defenders to security strategies, prevention measures, and detection and response incident triage.

ESET Threat Intelligence comes to users in highly accurate, curated, and actionable formats that amount to an up-to-date technical manual that enables customers to logically pursue a prevention-first approach to security.  Specifically, both (wider) industry and ESET Threat Intelligence data are compiled and ready to be paired with observations made via other tools, including XDR, SIEM, and/or SOAR, to prevent damages from (for example) ransomware and any subsequent extortion from taking place.

Users employing data/intel gathered in ETI for their inspection and/or monitoring of security incidents is just one way to create better-informed operators. In this use case, operators, increasingly supported by automation, can more consciously interact with incidents from an XDR’s triage system, for example, executables, malicious processes, computers, and threat indicators. From there, various forms of mitigation can be conducted in an informed, systematic, and prioritized manner. Specifically, an ESET user might employ ETI to cross-reference relevant data to better understand the actions necessary to perform in ESET INSPECT* (the XDR-enabling module of the ESET PROTECT platform).

The ransomware case here puts into focus why ESET Threat Intelligence, with its APT reports, unique data feeds, dashboard, and portal, has grown in popularity.

*ESET Threat Intelligence and ESET INSPECT (detection & response module) are not currently integrated via the ESET PROTECT platform.

Threat Intelligence – the tricks & trade of ransomware

In late 2023, ESET observed the SmokeLoader malware family, a generic backdoor with a range of capabilities that depend on the modules included in any given build of the malware, being utilized as one of the multiple variants packed by AceCryptor, a crypto service used worldwide by cybercriminals to obfuscate malware. SmokeLoader is deployed to download and execute the final payload of an attack discreetly, to evade security measures, making it crucial to rely on robust cyber defense mechanisms.

Defenders can specifically utilize ETI’s backend tracking systems to support an improved understanding of threats and apply their learnings to both prevention and proactive defense processes. ETI assembles all the clues needed to deploy prevention mechanisms and, when necessary, effectively mitigate against malware like SmokeLoader. Importantly, ETI’s benefits are vendor agnostic, so businesses already running alternate SIEM/SOAR products, including Microsoft Azure Sentinel, OpenCTI, IBM QRadar, Anomali and ThreatQuotient (outside of the ESET PROTECT ecosystem) can also gain from ETI’s unique data stream via our API.

This means that a wider spectrum of curious, prevention-minded admins can now turn to the main ESET research findings and other relevant data. These are published in regular reports on the ETI platform and portal and are accessible in specific territories, with ESET continuously working to expand their availability.

Delivering data to stop an attack before it happens

As with the SmokeLoader data, ETI clusters data on a wide spectrum of malware, finds similarities or particularities, highlights what stands out, and monitors attack chains and any changes in TTPs. This automation occurs in real time, continuously updating all feeds to provide end customers with the most important and immediately actionable intel on threats targeting them. These outputs are also synthesized into specific APT reports, which ensures customers receive pertinent information without being overwhelmed by excessive data.

ESET Threat Intelligence provides its data feeds to customers through the TAXII server, integrating it directly into their current systems, for example, Microsoft Sentinel or the OpenCTI Threat Intelligence Platform. The feeds cover various aspects of cybersecurity, including tracking malicious files, botnets, and APTs; identifying potentially harmful domains or URLs and IPs considered malicious; and tracking the associated data. To ensure compatibility and easy integration, the feeds are provided in widely used formats, such as JSON and STIX 2.1.

Fighting malicious activity

Preventing multifaceted threats from impacting your network, business continuity, and/or reputation requires a comprehensive and always up-to-date knowledge base. Thus, moving beyond the technical defenses against ransomware and other malware, security operators at organizations must adopt a knowledge-based security culture that puts learning on level with action.

The cornerstones of security are particularly essential at public and private institutions that depend on well-developed SOC teams, threat hunters, and security operators that have both technical skills and access to the ever-growing body of work on threat actors, system configuration, and an understanding of what is and isn’t working.

These cornerstones are where ESET Research employs its long history of collaboration with law enforcement agencies, the Joint Cyber Defense Collaborative, and even its work with “No More Ransom” to communicate our views on ransomware, fight threats at large, and inform how and why we’ve built our threat intelligence platform, ETI.

Explore your use case for ETI via ESET API, ESET APT reports, the ETI data feed, or a comprehensive toolset for an ESET-powered prevention-first approach.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Should the cybersecurity world prepare for AI-based critical infrastructure attacks?

Imagining a future, in which anyone could be attacked by an intelligence beyond the means of  humans is rather scary. Perhaps that’s why AI is better imagined as another tool to support people’s work. Again, however, the combined capability of such a human actor is also of concern, especially if said actor does not have their community’s best interests in mind.

With AI becoming increasingly important, just like companies, people race to figure out how it could be used to serve their own purposes, supporting their endeavors. Specifically in the field of cybersecurity, AI can serve both a constructive, but also a destructive role, with the former meaning the support of better cyber defense, and the latter attempting to cripple said cyber defenses.

Of specific concern is the potential for cyberattacks on critical infrastructure to become more widespread. Critical infrastructure, usually considered to include power generation and electrical grid, hospitals and healthcare systems, and the global supply chain, could also include digital supply chains and the internet itself. Depending on the specific needs, resources, and development level of a nation, critical infrastructure represents all the systems, networks, and assets that are essential, with their continued operation required to ensure the security of a given state, its economy, and the public’s health or safety. As the idea behind the attacks is to weaken adversaries by crippling their day-to-day business, an effective AI tool could, hypothetically, help bad actors commit attacks, or even increase the pool of potential attackers, by making malware coding easier. However, not everyone shares the same opinion.

The role of AI – can hacking become easier?

According to an interview with ESET security researcher Cameron Camp, we are not really close to “full AI-generated malware,” though ChatGPT is quite good at code suggestion, he says, generating code examples and snippets, debugging, and optimizing code, and even automating documentation.

He agreed that ChatGPT could be used as a handy tool to assist programmers, one that could serve as a first step toward building malware, but not yet, as it is currently rather shallow, makes errors, creates bogus answers and is not very reliable for anything serious.

Nonetheless, Mr. Camp highlighted three areas, which might be interesting from the perspective of language models: 

More convincing phishing – From probing more data sources and combining them seamlessly to create specifically crafted emails where clues to their malicious intentions would be very difficult to detect, readers will be hard-pressed not to fall for social engineering. Nor will people be able to spot phishing attempts simply due to sloppy language mistakes, as they could have convincing grammar.

More specifically, spear-phishing could become even more convincing, as tailor-made emails or messages, even including personalized emotional triggers, could become easier to construct thanks to AI help. These abilities will be further supported by with multilingual text-generating options, such methods might work on a wider, global scale, which in case the targeting of critical infrastructure of several states at once would serve a useful purpose.

Ransom negotiation automation – Smooth-talking ransomware operators are rare, but adding a little ChatGPT shine to the communications could lower the workload of attackers seeming legit during negotiations. This will also mean fewer mistakes that might enable defenders to home in on the true identities and locations of the operators.

Furthermore, thanks to easier video and voice generation with AI (see example here), malicious actors could become anyone, hiding their identities more efficiently. In fact, concerns about AI have become so widespread in this area that many professionals want to stipulate in their contracts a ban on the use of their work for AI purposes.

And if you don’t believe this, check out this video of President Biden, Trump and Obama discussing a videogame, all AI-generated, of course. Imagine how, during a ransomware attack, an online intruder could imitate a highly placed official to ask for access to a network or a system remotely…

Better phone scams – With natural language generation getting more natural, scammers will sound like they are from your area and have your best interests in mind. This is one of the first onboarding steps in a confidence scam: sounding more confident by sounding like they’re one of your people.

As long as scammers generate the right natural cadence to a person’s voice, they can easily fool their victims, but the problem with any AI-generated content today is that there is an inherent, let’s say, ‘artificiality’ to it, meaning that despite these voices, videos or text looking legit, they still harbor some specific mistakes or issues that are easy to spot, like how ChatGPT makes false statements or how its responses might seem like it is just regurgitating a Wikipedia page.

However, all of this does not mean that generative AI cannot be used for brainstorming, to create a base for some work, however, the correctness of the information one is provided should still be checked. The legal ramifications of using AI-generated content (sourced from the net) might also be something to consider.

Critical Infrastructure vs. AI – emerging legislation

As AI starts to play an increasingly important role in cybersecurity, businesses and governments will need to accommodate and use AI to their own advantage – as crooks will definitely try to do the same. From a July 2022 report by Acumen Research and Consulting, the global AI market was $14.9 billion in 2021 and is estimated to reach $133.8 billion by 2030.

Thanks to the growing use of the Internet of Things and other connected devices, cloud-based security services could provide new opportunities for the use of AI. Antivirus, data loss prevention, fraud detection, identity and access management, intrusion detection/prevention systems, and risk and compliance management services already use tools like Machine learning to create more resilient protection.

On the flip side, bad actors could also use AI to their advantage. With a large enough market of smart AI, crooks could easily use it to identify patterns in computer systems to reveal weaknesses in software or security programs, enabling them to exploit those newly discovered weaknesses.

So, critical infrastructure could become one of the targets. With AI attacking and defending it, going for a tit-for-tat, security actors and governments will have to remain smart. The European Union is already trying to assess the risks by proposing the EU AI Act, to govern its use in Europe, classifying different AI tools according to their perceived level of risk, from low to unacceptable. Governments and companies using these tools will have different obligations, depending on the risk level.

Some of these AI tools may be considered high risk, such as those used in critical infrastructure. Those using high-risk AIs will likely be obliged to complete rigorous risk assessments, log their activities, and make data available to authorities to scrutinize to increase compliance costs for companies.  In case a company breaks the rules, the fine would likely be around 30 million euros or up to 6% of their global profits.

Similar rules and ideas are included within the recently proposed EU Cyber Solidarity Act, as government officials try to stay ahead of critical infrastructure attacks.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.