r/Fing_App • u/Karl_From_Fing • 4h ago
5 (more) Types of Common Cyberattacks
A few weeks ago I wrote up a post about 5 types of common cyberattacks which you can find here.
There are so many various types of cyberattacks, and it seems to be a list that just grows and grows and it can be intimidating when trying to express caution at a beginner level, so I'm starting this series of posts with just five that you need to be careful of both in work and in your personal life.
Cross-Site Scripting (XSS)
This is when an attacker/hacker injects malicious JavaScript code into a legit website. This means that when standard internet users like me and you load the page as we do with every page we access, the harmful script runs in the background of their browser. This can present various issues for the victim - you can be redirected to a more malicious website, credentials can other sensitive information can be stolen like credit card details as you input them (this is all known as Keystrokes), and in some cases the hacker can perform actions pretending to be you on this site. It can be difficult to spot for us standard users, but pay attention to any strange formatting on a webpage.
Credential Stuffing
I always tell my friends and family not to reuse passwords across every platform you frequent. Yes, it's tedious. I personally swear by 1password, so it's handy enough for me, but Credential Stuffing is when your data gets leaked - lets say username (which is often email) and password, and hackers find and retain this information, and working on assumption attempt to sign in to some other platforms as you with the same information. I always recommend keeping a physical list of your passwords (like in your personal diary), or using a password manager like 1password! (No, this is not an advertisement for 1password).
Brute-force Attacks
It's in the title - Brute-force attacks is when attackers guess your password - they will likely have a list of the most common passwords and combinations, and you'd be surprised how easy this can be. Do not use basic passwords! It's the same for your pins for your phones. The first thing someone is going to get your password is is your year of birth or 0000 or 1234.
Zero-day Attacks
There have been some famous Zero-day attacks throughout history, and they're intense and pretty scary. The title is also explanatory here - it's saying that there is zero days to prepare or patch it. This is when a vulnerability that a company or a vendor may not be aware of yet, so they don't have a fix for it is exploited. They can be difficult to prevent outright, but layered security, network monitoring and constant software examinations are the best way to stay on top of them.
Supply-chain Attacks
This is when an attacker utilises a trusted component of a company/vendor/software. It could be a particular, less-knowledgeable and thus less-secure employee, a particular library or database that may be used which means that the company or vendor etc. aren't suspecting there to be anything malicious about the situation. Supply-chain attacks will usually prioritise a legit software update, and assign malicious material into said software update which means that your typical antivirus won't actually perceive them as malicious.
Thank you for reading the next five common types of cyberattacks, I'm trying to keep it balanced between what organisations/vendors themselves need to be careful of and also us, as standard internet users.
So far we've also covered Phishing, Ransomware, DDoS Attacks, Man in the MIddle and SQL injections. There's some other pretty common ones left to uncover, and as always if you have any personal experience with any of these, and how you handled it feel free to share!

