Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

12:00 PM
Connect Directly

The 'Remediation Gap:' A 4-Month Invitation To Attack

Organizations set out the welcome mat for cyberattackers by taking an average of 120 days to patch flaws.

As impactful as targeted attacks can be on organizations when they hit the mark, non-targeted and automated attacks that focus on known vulnerabilities still pose a significant threat to the enterprise. According to a new study out today by Kenna security, the volume of vulnerabilities exploited by untargeted attacks only continues to snowball while organizations continue to fall down in remediating these known vulnerabilities.

“The public has grown plenty familiar with hackers seeking out a specialized target, such as Ashley Madison. But automated, non-targeted attacks still remain the most significant threat to businesses of all sizes,” said Karim Toubba, CEO of Kenna.

Kenna took a deep dive into vulnerability and exploit data from 50,000 organizations over the course of a nearly two-year period from January 2014 to September 2015. It looked at 250 million vulnerabilities and over a billion breach events at these companies and confirmed something most security pros have been warning about for years: organizations taking way too long to remediate their vulnerabilities. The firm found that it takes an average of between 100 to 120 days to patch a flaw once it's found. Meanwhile, the probability of a vulnerability being exploited rises to 90 percent by the time the flaw has been known for between 40 to 60 days.

It's no surprise, then, that the volume of exploits has exploded in 2015. Kenna found that successful exploits rose over four-fold this year. The firm witnessed more than 1.2 billion successful exploits in 2015, compared to just 220 million successful exploits in 2013 and 2014 combined.

In many cases the most successful automated campaigns home in on vulnerabilities left open for far longer than the average 120 day remediation window.

"When we talk about unremediated vulnerabilities that fall prey to attacks at scale, one of the points we need to make is that the vulnerabilities in question are often very old, well-known weaknesses that simply haven’t been fixed yet," the report said. "We’ve seen this over and over again as we evaluate the data."

For example, the report detailed how the positively ancient Slammer vulnerability in SQL Server 2000 still provides fodder for automated attacks. In 2014 Kenna found evidence that it was successfully exploited 156,000 times.

"It’s not new, it’s not hip, it’s not current, so one talks about it – but it’s a significant threat," the report said.

That's, of course, the very long tail of exploitation. More recent, but still well-known vulnerabilities like Heartbleed are proving even more useful to attackers. Based on its data, Kenna predicts that over the next month there will be 5000 successful exploitations of Heartbleed per day

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
10/1/2015 | 7:49:01 AM
Re: home/hone
You have the eyes of a copy editor. Glad you are paying attention!
User Rank: Apprentice
9/30/2015 | 4:16:54 PM
I'd just like to praise you for using "home" instead of the, incorrect, "hone." Nit-picky? Yes, but it's like a little mosquito bite for us OCD types.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.