Enterprises are now confronting more cybersecurity threats as attackers more often attack network devices, specifically routers. Routers have become the main target of cyberattacks, surpassing conventional endpoints, says the 2025 report of Forescout Research's Vedere Labs. Their visibility at network borders and the fact that they contain high-severity vulnerabilities make them perfect entry points for hackers. More than 50% of the highly vulnerable devices are routers today, and they are often used in massive, targeted campaigns that breach larger enterprise networks. The report this year also shows the biggest change in device vulnerability trends, with 12 new types of devices added to the most vulnerable devices list. Included among them are Application Delivery Controllers (ADCs), firewalls, and IPMI devices, which are critical to server management but are infested with vulnerabilities, some of which already have publicly available exploits. The retail industry was found to have the riskiest devices, followed by financial services, government, healthcare, and manufacturing. What is particularly interesting is that the gap in risk between industries is decreasing, indicating a broadening threat to all industries. One of the biggest challenges is the widespread use of outdated systems and insecure protocols. Legacy Windows versions are still prevalent in government and healthcare environments, and unencrypted Telnet use has exploded, displacing more secure alternatives like SSH—particularly in government networks. These old technologies make it an open door for cyber attackers. The report calls for a comprehensive, automated security solution that spans IT, IoT, OT, and IoMT devices. The use of standalone endpoint security is no longer sufficient. Enterprises need to harden security at the network level and deploy adaptive frameworks to match changing threats. Real-time monitoring and active risk management are now critical to defend against such advanced threats.
The U.S. Cybersecurity and Infrastructure Security Agency warned about a critical vulnerability in Motex Lanscope Endpoint Manager that is currently being exploited in active attac...
Cybersecurity firm Sansec has issued an urgent warning about an active exploitation campaign targeting a newly exposed flaw in Adobe Commerce and Magento Open-Source platforms. The...
The state-backed Iranian hacker group MuddyWater has targeted over 100 government organizations using version 4 of the Phoenix backdoor in their attacks. Also known as Static Kitte...