Cisco: new exploit kits, Java vulnerabilities, PoS attacks are most serious threats in 2014
Exploit kit variety, point-of-sale attacks reign in 2014: Cisco — Summary: Cisco's security team says that exploit variety is gaining steam, and both the Internet of Things and point …
Context & Ripple Effects
This is Cisco's mid-year refresh of a story it started in January, when its Security Report found 91% of 2013 attacks were Java exploits. The August update widens the frame: beyond Java, Cisco's security team now ranks exploit kit variety and point-of-sale attacks among the most serious threats of 2014, with the Internet of Things flagged as an emerging concern.
The pickup was unusually broad for a vendor threat report — eight outlets including eWeek, Network World, PC Advisor, FedScoop and National Defense Magazine ran it on or about the same day, suggesting the findings landed with both enterprise IT and government/defense readers. It also sits awkwardly beside Cisco's own commercial push: the company has spent 2014 promoting an IoT effort tied to a predicted $19 trillion in value over ten years while simultaneously warning that connected devices are becoming an attack surface.
First-order effects
- Enterprises still running Java in production environments are directly warned that the platform remains their highest-frequency exposure, six months after Cisco quantified it at 91% of observed attacks.
- Retailers and anyone operating point-of-sale infrastructure become a named target class in Cisco's threat model, putting PoS hardening on the immediate agenda for merchants.
Second-order effects
- Competing security vendors are pushed to match Cisco's semiannual reporting cadence and breadth, since a report syndicated across eight outlets doubles as market positioning for Cisco's security portfolio.
- The IoT warning pressures the same connected-device ecosystem Cisco is courting with its $19 trillion value pitch — device makers face buyers who now ask how threats like these apply to their products.
Third-order effects
- If exploit kits keep proliferating and attacks keep migrating from desktops to payment terminals and embedded devices, enterprise defense budgets shift from perimeter and PC endpoints toward transaction and machine-to-machine infrastructure.
- Vendor-published threat intelligence is consolidating into a de facto industry forecasting layer, with companies like Cisco shaping which risks enterprises prioritize — a role that carries obvious conflicts when the reporter also sells the remediation.
The trend: Threat activity documented by major vendors is migrating from desktop software exploitation toward payment systems and connected devices, with semiannual vendor reports increasingly setting the enterprise security agenda.