Yes, cyberattacks are frightening, especially the big name hacks, but most assaults end up occurring via simple exploits of known vulnerabilities, publicly exposed devices or just poor hygiene.

Add on top of that, threat actors are using artificial intelligence (AI) to automate all the steps necessary to exploit these vulnerabilities at unprecedented speed. This is why the Cybersecurity and Infrastructure Security Agency (CISA) released the CISA Vulnerability Review for fiscal years 2024 and 2025, offering insights into the root causes of insecure software and practical steps organizations can take to address the flaws threat actors frequently exploit.

In fiscal years 2024 and 2025, most cyber threat activity was not coordinated threat actor groups leveraging Zero Day exploits. Instead, it was opportunistic criminals scanning the Internet for exposed vulnerabilities created by insecure software, according to the report. Unfortunately, the production and use of insecure software is still the norm.

The goal of this review is to establish a baseline understanding of the current vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread.

Security Failures

Indeed, basic security failures enable most compromises. According to the Cyentia Institute’s IRIS Ransomware Report, ransomware alone costs organizations an average financial loss of $3.7 million per incident. The report also estimates that organizations have a 10 percent chance of experiencing a ransomware attack each year.

Schneider Bold

As every security professional is aware, products must be secure by design and this report focuses on that principle.
Instead of users reacting, they should go to a proactive risk management perspective, backed by public-private sector collaboration and leadership support that recognizes cyber risk as a business risk and national security issue.

https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
The review also highlights how organizations can prioritize vulnerabilities for action by using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk, which evaluates exposure status, known exploited vulnerability (KEV) status, potential for exploitation to be automated, and technical impact.

Key findings in the review include:

  • Threat actors scan for and exploit simple, known vulnerabilities rather than relying on advanced techniques.
  • Improper input validation and memory safety vulnerabilities are the most reliable entry points for threat actors and end up frequently targeted.
  • Basic security failures, like poor patching and continued use of end-of-support technology, significantly contribute to compromise.
  • Emerging technology, such as AI, introduces efficiencies threat actors can leverage to automate and scale threat activity.

Click here for view the CISA Vulnerability Review.

ISSSource

Pin It on Pinterest

Share This