Known Vulnerabilities Caused Most Attacks
During the first quarter, 82% of incidents responded to by Tetra Defense were caused by the external exposure of a known vulnerability on the victim’s network or a RDP.
Tetra Defense classifies external exposures in two ways:
- External vulnerabilities, which could have been mitigated through publicly available security patches and software updates. In these instances, a threat actor utilized a known vulnerability to gain access to the network before the internal organization was able to patch the system. In the first quarter, 57% of total incidents were caused by the exploitation of external vulnerabilities.
- Risky external exposures, which are IT practices such as leaving an RDP port open to the public internet. These behaviors are considered risky because the mitigation relies on an organization’s continued security vigilance and willingness to enforce consistent standards over long periods of time. In the first quarter, 25% of total incidents Tetra Defense handled were caused by risky external exposures.
Tags: