Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

12:00 PM
Connect Directly

The 'Remediation Gap:' A 4-Month Invitation To Attack

Organizations set out the welcome mat for cyberattackers by taking an average of 120 days to patch flaws.

As impactful as targeted attacks can be on organizations when they hit the mark, non-targeted and automated attacks that focus on known vulnerabilities still pose a significant threat to the enterprise. According to a new study out today by Kenna security, the volume of vulnerabilities exploited by untargeted attacks only continues to snowball while organizations continue to fall down in remediating these known vulnerabilities.

“The public has grown plenty familiar with hackers seeking out a specialized target, such as Ashley Madison. But automated, non-targeted attacks still remain the most significant threat to businesses of all sizes,” said Karim Toubba, CEO of Kenna.

Kenna took a deep dive into vulnerability and exploit data from 50,000 organizations over the course of a nearly two-year period from January 2014 to September 2015. It looked at 250 million vulnerabilities and over a billion breach events at these companies and confirmed something most security pros have been warning about for years: organizations taking way too long to remediate their vulnerabilities. The firm found that it takes an average of between 100 to 120 days to patch a flaw once it's found. Meanwhile, the probability of a vulnerability being exploited rises to 90 percent by the time the flaw has been known for between 40 to 60 days.

It's no surprise, then, that the volume of exploits has exploded in 2015. Kenna found that successful exploits rose over four-fold this year. The firm witnessed more than 1.2 billion successful exploits in 2015, compared to just 220 million successful exploits in 2013 and 2014 combined.

In many cases the most successful automated campaigns home in on vulnerabilities left open for far longer than the average 120 day remediation window.

"When we talk about unremediated vulnerabilities that fall prey to attacks at scale, one of the points we need to make is that the vulnerabilities in question are often very old, well-known weaknesses that simply haven’t been fixed yet," the report said. "We’ve seen this over and over again as we evaluate the data."

For example, the report detailed how the positively ancient Slammer vulnerability in SQL Server 2000 still provides fodder for automated attacks. In 2014 Kenna found evidence that it was successfully exploited 156,000 times.

"It’s not new, it’s not hip, it’s not current, so one talks about it – but it’s a significant threat," the report said.

That's, of course, the very long tail of exploitation. More recent, but still well-known vulnerabilities like Heartbleed are proving even more useful to attackers. Based on its data, Kenna predicts that over the next month there will be 5000 successful exploitations of Heartbleed per day

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
10/1/2015 | 7:49:01 AM
Re: home/hone
You have the eyes of a copy editor. Glad you are paying attention!
User Rank: Apprentice
9/30/2015 | 4:16:54 PM
I'd just like to praise you for using "home" instead of the, incorrect, "hone." Nit-picky? Yes, but it's like a little mosquito bite for us OCD types.
What the FedEx Logo Taught Me About Cybersecurity
Matt Shea, Head of Federal @ MixMode,  6/4/2021
A View From Inside a Deception
Sara Peters, Senior Editor at Dark Reading,  6/2/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-06-13
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
PUBLISHED: 2021-06-12
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
PUBLISHED: 2021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.