Login

Register

Login

Register


Organizations in the UK and Netherlands are more exposed to high-risk vulnerabilities than any others in Europe, with misconfiguration a major challenge, according to new data from Outpost24.

The security provider analyzed vulnerability data collected from over two million assets across 10 markets, over a 12-month period to November 2019. It looked at various parameters across this data including OWASP Top 10 and CWE weakness information.

It found that in the Netherlands, 50% of the vulnerabilities discovered were classified as high-risk, versus 43% in the UK. These were significantly higher than most other countries, aside from Brazil (47%).

Japan had the lowest number of high-risk vulnerabilities at less than 10%.

Unfortunately, organizations are giving attackers a helping hand by failing to mitigate these risks swiftly. The average time to patch is 105 days, while the average time for a bug to be identified and exploited has dropped to just 15 days.

“This leaves a window of almost three months for hackers to exploit vulnerabilities when they are left unpatched,” warned vulnerability research manager, Srinivasan Jayaraman.

According to the research, a whopping 82% of vulnerabilities analyzed were due to misconfiguration in areas like firewalls and passwords; categorized as CWE-16.

“CWE-16 weaknesses can be introduced due to weak/default passwords, deprecated protocols, open public database instance or if the file system is exposed and not encrypted,” explained Jayaraman.

“This highlights the importance of having fundamental security configurations in place to cover your networks, applications and cloud. If this is ignored by security teams you leave yourself open to hackers and its critical to prioritize checking for misconfiguration and implementing continuous monitoring.”

In addition, misconfiguration was reported in 86% of web applications assessed in the report against the OWASP Top 10.

____________________________________________________________________________________________________________________

#infosec #itsecurity #hacking #hacker #computerhacker #blackhat #ceh #ransomeware #maleware #ncs #nationalcybersecurityuniversity #defcon #ceh #cissp #computers #cybercrime #cybercrimes #technology #jobs #itjobs #gregorydevans #ncs #ncsv #certifiedcybercrimeconsultant #privateinvestigators #hackerspace #nationalcybersecurityawarenessmonth #hak5 #nsa #computersecurity #deepweb #nsa #cia #internationalcybersecurity #internationalcybersecurityconference #iossecurity #androidsecurity #macsecurity #windowssecurity
____________________________________________________________________________________________________________________

Source link

Leave a Reply

Shqip Shqip አማርኛ አማርኛ العربية العربية English English Français Français Deutsch Deutsch Português Português Русский Русский Español Español

National Cyber Security Consulting App

 https://apps.apple.com/us/app/id1521390354

https://play.google.com/store/apps/details?id=nationalcybersecuritycom.wpapp


NATIONAL CYBER SECURITY RADIO
[spreaker type=player resource="show_id=4560538" width="100%" height="550px" theme="light" playlist="show" playlist-continuous="true" autoplay="false" live-autoplay="false" chapters-image="true" episode-image-position="left" hide-logo="false" hide-likes="false" hide-comments="false" hide-sharing="false" hide-download="true"]
HACKER FOR HIRE MURDERS
 [spreaker type=player resource="show_id=4569966" width="100%" height="350px" theme="light" playlist="show" playlist-continuous="true" autoplay="false" live-autoplay="false" chapters-image="true" episode-image-position="left" hide-logo="false" hide-likes="false" hide-comments="false" hide-sharing="false" hide-download="true"]

ALEXA “OPEN NATIONAL CYBER SECURITY RADIO”

National Cyber Security Radio (Podcast) is now available for Alexa.  If you don't have an Alexa device, you can download the Alexa App for free for Google and Apple devices.   

nationalcybersecurity.com

FREE
VIEW