• Latest
  • Trending
The True Danger for Organizations: Unpatched Vulnerabilities

The True Danger for Organizations: Unpatched Vulnerabilities

June 13, 2022
Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

July 29, 2025
French Telco Orange Hit by Cyber-Attack

French Telco Orange Hit by Cyber-Attack

July 29, 2025
ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023
Vice President Dr. Bawumia inaugurates  ICT Hub

Vice President Dr. Bawumia inaugurates ICT Hub

April 2, 2023
Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023
Data Leak Hits Thousands of NHS Workers

Data Leak Hits Thousands of NHS Workers

February 20, 2023
EU Cybersecurity Agency Warns Against Chinese APTs

EU Cybersecurity Agency Warns Against Chinese APTs

February 20, 2023
How Your Storage System Will Still Be Viable in 5 Years’ Time?

How Your Storage System Will Still Be Viable in 5 Years’ Time?

February 20, 2023
The Broken Promises From Cybersecurity Vendors

Cloud Infrastructure Used By WIP26 For Espionage Attacks on Telcos

February 20, 2023
Instagram and Facebook to get paid-for verification

Instagram and Facebook to get paid-for verification

February 20, 2023
YouTube CEO Susan Wojcicki steps down after nine years

YouTube CEO Susan Wojcicki steps down after nine years

February 20, 2023
Inaugural AfCFTA Conference on Women and Youth in Trade

Inaugural AfCFTA Conference on Women and Youth in Trade

September 6, 2022
  • Consumer Watch
  • Kids Page
  • Directory
  • Events
  • Reviews
Monday, 31 August, 2026
  • Login
itechnewsonline.com
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion
Subscription
Advertise
No Result
View All Result
itechnewsonline.com
No Result
View All Result

The True Danger for Organizations: Unpatched Vulnerabilities

by ITECHNEWS
June 13, 2022
in Leading Stories, Opinion
0 0
0
The True Danger for Organizations: Unpatched Vulnerabilities

It is no secret that 2021 saw an increase in cyberattacks all around the globe; specifically in critical infrastructure organizations. In October of that year, The U.S. Cybersecurity and Infrastructure Security Agency issued Alert AA21-287 in response to cyberattacks targeting the financial, gas, food and transportation sectors. The advisory was released to draw attention to infrastructure vulnerability and the facilities being targeted by hostile cyber activity. It seems that every year, new software comes out that should limit the number of ransomware attacks, but every year attacks seem to increase. Why is that? 

Cyberattack groups succeed when they are one step ahead, and they know they have to evolve their tactics going into a new year. In fact, Check Point Research reported that cyberattacks have recently increased 50% year-over-year. In 2022, ransomware methods and cyberattack techniques, in general, continue to change, demonstrating actors’ growing technological sophistication and the growing threat to enterprises around the world. But there is one way, in particular, they keep getting in—by exploiting system vulnerabilities. 

YOU MAY ALSO LIKE

French Telco Orange Hit by Cyber-Attack

ATC Ghana supports Girls-In-ICT Program

How Attackers Exploit Vulnerabilities 

A study from Ponemon Institute showed 60% of cyberattack victims were breached due to an unpatched vulnerability. The study showed that in a time where known security flaws are the primary cause of data breaches, most businesses are dealing with technologies and practices that aren’t up to par. Organizations must keep those weaknesses hidden from the public eye or measuring control hazards will become impossible as a result.

While updating systems can take a few hours, previous breaches have proven that failing to patch systems with the most recent security upgrades can be more costly. 

Learning From the News

In February 2022, the Cybersecurity and Infrastructure Security Agency (CISA) released two alerts that had enterprises and government infrastructures reevaluating their cybersecurity protocols. One alert stated that, from January 2020 through February 2022, the FBI, the National Security Agency (NSA) and CISA all saw Russian state-sponsored cyberattacks on U.S.-cleared defense contractors. Simple passwords, unpatched systems and unwitting personnel were all taken advantage of by the attackers to obtain initial access before advancing across the CDC network to establish persistence and exfiltrate data. The information obtained provided valuable insight into the development and deployment schedules for U.S. weapons platforms, vehicle specs and plans for communications infrastructure and information technology. 

The other CISA alert reported that cybersecurity authorities in the United States, Australia and the United Kingdom observed a surge in high-impact ransomware attacks on critical infrastructure firms around the world in 2021. Additionally, the FBI, CISA and NSA discovered ransomware incidents across 14 of the 16 key infrastructure sectors in the United States, including the defense industrial base, emergency services, food and agriculture, government facilities and information technology.

The CISA alerts showed that spear phishing, credential harvesting, brute force/password spray techniques and known vulnerability exploitation against accounts and networks with weak security have all been employed by Russian state-sponsored cyberattackers in the past to obtain access to target networks. Simple passwords, unpatched systems, and unsuspecting personnel are used by these actors to obtain initial access before moving laterally through the network to create persistence and exfiltrate data. The current situation also indicated that Russian state-sponsored attacks will rise due to the ongoing Ukraine conflict. 

Assessing Vulnerabilities Based on Weaponization; Prioritizing Based on Risk Levels 

To become aware of vulnerabilities, organizations need to invest in discovering and maintaining their attack surface. An attack surface is the summation of all points of entry that an attacker could breach. Tools such as vulnerability scanners, application and event monitoring systems and patch management systems, among others, are helpful ways to manage your attack surface. Once your organization is aware of its vulnerabilities, where do you start patching? For an effective patching strategy, vulnerabilities should be prioritized. That can be done through risk scoring.

The Importance of Risk Scoring

By calculating the risk for each group inside your business, your team will be able to create a workflow engine that allows collaboration between your security and IT operations teams, expediting remediation processes and drastically reducing time-to-remediation.

It’s important to understand that shifting away from traditional approaches will take time, resources and cooperation across information systems and the business. However, scenarios from the past two years and ongoing attacks during the Ukraine/Russia conflict have shown us that doing so, in the end, will provide a significant return on investment. 

Source: Aaron Sandeen
Via: Security Boulevard
ShareTweet

Get real time update about this post categories directly on your device, subscribe now.

Unsubscribe

Search

No Result
View All Result

Recent News

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

July 29, 2025
French Telco Orange Hit by Cyber-Attack

French Telco Orange Hit by Cyber-Attack

July 29, 2025
ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023

About What We Do

itechnewsonline.com

We bring you the best Premium Tech News.

Recent News With Image

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

July 29, 2025
French Telco Orange Hit by Cyber-Attack

French Telco Orange Hit by Cyber-Attack

July 29, 2025

Recent News

  • Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa July 29, 2025
  • French Telco Orange Hit by Cyber-Attack July 29, 2025
  • ATC Ghana supports Girls-In-ICT Program April 25, 2023
  • Vice President Dr. Bawumia inaugurates ICT Hub April 2, 2023
  • Home
  • InfoSec
  • Opinion
  • Africa Tech
  • Data Storage

© Copyright 2026, All Rights Reserved | iTechNewsOnline.Com - Powered by BackUPDataSystems

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion

© Copyright 2026, All Rights Reserved | iTechNewsOnline.Com - Powered by BackUPDataSystems

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
Go to mobile version