As per sources, the enterprise attack surface is expanding, becoming both more numerous and specific, according to runZero. CEO HD Moore highlights alarming gaps in infrastructure, including decaying network segmentation, persistent challenges in attack surface management, and an increasing volume of dark matter on modern networks. The convergence of IT and OT amplifies this expansion, necessitating new techniques for asset discovery and management. OT systems, valuable targets for attackers, are consistently exposed to untrusted networks, with over 7% of sampled ICS assets accessible via the public internet, including programmable logic controllers and protocol gateways critical to infrastructure. Security teams often lack visibility into more than half of their network's physical devices. Network "dark matter," comprising unmanaged and rarely updated devices, constitutes 19% of enterprise networks, with an additional 45% offering limited management capabilities. End-of-life hardware and operating systems persistently undermine security postures, with Windows 2012 R2 and Ubuntu 14.04 being common EoL systems. Obsolete VMware ESXi versions and unsupported network devices also pose serious concerns. Printers and network-attached storage devices often breach network segmentation controls by allowing traffic forwarding, with unexpected IP-forwarding behavior detected across various device types. Zero-day attacks at the network edge have surged, challenging suppliers' ability to provide timely patches. Vulnerabilities are exacerbated by insecure authentication methods, such as the 92% of systems running Secure Shell (SSH) service allowing password-based authentication. Additionally, reliance on hardcoded cryptographic keys shared between unrelated environments compromises security benefits. Nearly 16% of Transport Layer Security (TLS) implementations rely on outdated OpenSSL versions, heightening future compromise risks. While Remote Desktop Protocol (RDP) security has improved on Windows with Network Layer Authentication (NLA), Linux-based RDP implementations like xrdp remain vulnerable. Legacy configurations, such as SMB v1 enabled on 13% of Windows systems, perpetuate security risks. These findings underscore the urgent need for robust attack surface management and updated security measures to mitigate evolving threats.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...