Security tools are good at inspecting websites, domains, URLs, and files, so attackers are moving lower in the stack and communicating directly with IP addresses, where visibility is limited. According to Palo Alto Networks’ report, this creates a visibility gap that allows malicious traffic to blend into normal internet activity and evade detection. At the internet edge, this gap starves security systems of the telemetry needed to identify and block threats. Threat actors hide the … More

The post 52% of direct-to-IP threats are missing from intelligence feeds appeared first on Help Net Security.