DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Cloud

Dynamic cloud environments contribute 45% of new critical exposures per month: Palo Alto Networks

DigitalCIO Bureau by DigitalCIO Bureau
September 21, 2023
in Cloud, Tech News
0
Dynamic cloud environments contribute 45% of new critical exposures per month: Palo Alto Networks
75
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Rapid digital transformation has led to a sharp rise in organizational network infrastructure, known and unknown, thus greatly increasing the complexity of security environments. Exposures on public facing assets can lead to organizations becoming victims of opportunity rather than targeted attacks. Palo Alto Networks analyzed petabytes of data about internet-accessible exposures across 250 organizations globally between 2022 and 2023. The 2023 Unit 42 Attack Surface Threat Report found that cybercriminals are exploiting new vulnerabilities within hours of public disclosure and that organizations are finding it difficult to manage their attack surfaces at the speed and scale necessary to combat threat actor automation. Other notable findings from the report include:

Cloud Is the Dominant Attack Surface

  • Vast majority of security exposures are present in cloud environments at 80% as compared to on-premise at 19%.
  • Cloud-based IT infrastructure is always in a state of flux, changing by more than 20% across every industry every month.
  • For most organizations, over 45% of high-risk, cloud-hosted exposures each month were a result of the constant change in cloud-hosted new services going online and/or old ones being replaced.
  • Over 75% of publicly accessible software development infrastructure exposures were found in the cloud.

Attackers Move at Machine Speed

  • Today’s attackers have the ability to scan the entire IPv4 address space (containing over 4 billion addresses) for vulnerable targets in minutes.
  • Of the 30 Common Vulnerabilities and Exposures (CVEs) analyzed, three were exploited within hours of public disclosure and 63% were exploited within 12 weeks of the public disclosure.

Remote Access Exposures Are Widespread

  • Over 85% of organizations analyzed had Remote Desktop Protocol (RDP) internet-accessible for at least 25% of the month.
  • Eight of the nine industries that Unit 42 studied had internet-accessible RDP vulnerable to brute-force attacks for at least 25% of the month.
  • Median financial services and state or local government organizations had RDP exposures for the entire month.

Critical Industries Are Exposed

  • IT, security, and networking infrastructure make up the top exposures (48%) for manufacturing, which could lead to loss of production and revenue.
  • Financial institutions most frequently expose file sharing services (38%).
  • For national governments, insecure file sharing and databases are one of the most significant attack surface risks, accounting for over 46% of all the exposures in a typical national government organization.
  • For healthcare organizations, 56% of publicly exposed development environments are often misconfigured and vulnerable.
  • For utilities and energy, Internet-accessible IT infrastructure control panels account for 47% of the exposures.

Recommendations 

  • Gain continuous visibility over all assets: Ensure a comprehensive real-time understanding of all internet-accessible assets, including cloud based systems and services.
  • Prioritize remediation: Focus on remediating the most critical vulnerabilities and exposures based on CVSS (Common Vulnerability Scoring System) and EPSS (Exploit Prediction Scoring System).
  • Secure remote access services: Implement multifactor authentication (MFA), and monitor all remote access services for signs of unauthorized access or brute-force attacks.
  • Address cloud misconfigurations: Regularly review and update inevitable cloud misconfigurations to ensure they align with best security practices.

Tags: Palo Alto Networks
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

TrendAI Becomes Part of Anthropic’s Project Glasswing

by DigitalCIO Bureau
June 5, 2026
0
TrendAI Becomes Part of Anthropic’s Project Glasswing

The collaboration will enhance efforts to detect and address software vulnerabilities through advanced AI capabilities. TrendAI, the enterprise AI security leader of Trend Micro, has announced its participation...

Read moreDetails

Tata Technologies Announces Fourth Edition of InnoVent Hackathon with Emerson and AWS, Spotlighting ‘AI at the Edge’

by DigitalCIO Bureau
June 5, 2026
0
Tata Technologies Announces Fourth Edition of InnoVent Hackathon with Emerson and AWS, Spotlighting ‘AI at the Edge’

Tata Technologies announced the launch of the 4th edition of its flagship engineering innovation hackathon, InnoVent-27. Building on its continued success, this year the initiative has been further...

Read moreDetails

Nokian Tyres accelerates its IT transformation through AI-driven modernization, partnering with TCS

by DigitalCIO Bureau
June 4, 2026
0
Nokian Tyres accelerates its IT transformation through AI-driven modernization, partnering with TCS

Combining advanced AI capabilities with deep manufacturing domain expertise, TCS will support Nokian Tyres in driving innovation and sustainable business outcomes Tata Consultancy Services (TCS) has entered into...

Read moreDetails

TCS broadens its collaboration with Euroclear to upgrade Sweden’s central securities depository system

by DigitalCIO Bureau
June 3, 2026
0
TCS broadens its collaboration with Euroclear to upgrade Sweden’s central securities depository system

TCS BaNCS and Quartz will support Euroclear Sweden’s move toward a unified Nordic securities ecosystem across the Finnish and Swedish financial markets. Tata Consultancy Services (TCS) today announced...

Read moreDetails

Hexaware Enables Enterprises to Confidently Scale AI with New Agentverse Enhancements

by DigitalCIO Bureau
June 3, 2026
0
Hexaware Enables Enterprises to Confidently Scale AI with New Agentverse Enhancements

A next-generation platform for building, deploying, and scaling AI across three core layers Hexaware Technologies has introduced new enhancements to Agentverse, its enterprise AI agent platform, focusing on...

Read moreDetails
Next Post
New Report Highlights Key Elements of Cloud Workload Security Landscape

New Report Highlights Key Elements of Cloud Workload Security Landscape

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Twitter Curbs Access for 143,000 Apps

July 27, 2018
Deloitte And AWS To Deepen Generative AI Driven Innovations For Indian Enterprises

Deloitte And Yotta Data Services to Develop Innovative GenAI Applications

April 18, 2024
83% of Indian Organisations Faced a Cybersecurity Incident in the Past Year

83% of Indian Organisations Faced a Cybersecurity Incident in the Past Year

September 5, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation E-books Fortinet Gartner Generative AI Google Cloud IBM India Infographics Infosys Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Salesforce Sophos Strategic Partnership Tata Consultancy Services TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?