DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Cloud

Dynamic cloud environments contribute 45% of new critical exposures per month: Palo Alto Networks

DigitalCIO Bureau by DigitalCIO Bureau
September 21, 2023
in Cloud, Tech News
0
Dynamic cloud environments contribute 45% of new critical exposures per month: Palo Alto Networks
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Rapid digital transformation has led to a sharp rise in organizational network infrastructure, known and unknown, thus greatly increasing the complexity of security environments. Exposures on public facing assets can lead to organizations becoming victims of opportunity rather than targeted attacks. Palo Alto Networks analyzed petabytes of data about internet-accessible exposures across 250 organizations globally between 2022 and 2023. The 2023 Unit 42 Attack Surface Threat Report found that cybercriminals are exploiting new vulnerabilities within hours of public disclosure and that organizations are finding it difficult to manage their attack surfaces at the speed and scale necessary to combat threat actor automation. Other notable findings from the report include:

Cloud Is the Dominant Attack Surface

  • Vast majority of security exposures are present in cloud environments at 80% as compared to on-premise at 19%.
  • Cloud-based IT infrastructure is always in a state of flux, changing by more than 20% across every industry every month.
  • For most organizations, over 45% of high-risk, cloud-hosted exposures each month were a result of the constant change in cloud-hosted new services going online and/or old ones being replaced.
  • Over 75% of publicly accessible software development infrastructure exposures were found in the cloud.

Attackers Move at Machine Speed

  • Today’s attackers have the ability to scan the entire IPv4 address space (containing over 4 billion addresses) for vulnerable targets in minutes.
  • Of the 30 Common Vulnerabilities and Exposures (CVEs) analyzed, three were exploited within hours of public disclosure and 63% were exploited within 12 weeks of the public disclosure.

Remote Access Exposures Are Widespread

  • Over 85% of organizations analyzed had Remote Desktop Protocol (RDP) internet-accessible for at least 25% of the month.
  • Eight of the nine industries that Unit 42 studied had internet-accessible RDP vulnerable to brute-force attacks for at least 25% of the month.
  • Median financial services and state or local government organizations had RDP exposures for the entire month.

Critical Industries Are Exposed

  • IT, security, and networking infrastructure make up the top exposures (48%) for manufacturing, which could lead to loss of production and revenue.
  • Financial institutions most frequently expose file sharing services (38%).
  • For national governments, insecure file sharing and databases are one of the most significant attack surface risks, accounting for over 46% of all the exposures in a typical national government organization.
  • For healthcare organizations, 56% of publicly exposed development environments are often misconfigured and vulnerable.
  • For utilities and energy, Internet-accessible IT infrastructure control panels account for 47% of the exposures.

Recommendations 

  • Gain continuous visibility over all assets: Ensure a comprehensive real-time understanding of all internet-accessible assets, including cloud based systems and services.
  • Prioritize remediation: Focus on remediating the most critical vulnerabilities and exposures based on CVSS (Common Vulnerability Scoring System) and EPSS (Exploit Prediction Scoring System).
  • Secure remote access services: Implement multifactor authentication (MFA), and monitor all remote access services for signs of unauthorized access or brute-force attacks.
  • Address cloud misconfigurations: Regularly review and update inevitable cloud misconfigurations to ensure they align with best security practices.

Tags: Palo Alto Networks
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Google completes acquisition of Wiz

by DigitalCIO Bureau
March 12, 2026
0
Google completes acquisition of Wiz

Google announced the completion of its acquisition of Wiz, a leading cloud and AI security platform headquartered in New York. Wiz will join Google Cloud and maintain its...

Read moreDetails

NTT DATA Named a ‘Best in Class’ Provider in Four PAC RADAR SAP Services 2026 Reports

by DigitalCIO Bureau
March 12, 2026
0
NTT DATA Named a ‘Best in Class’ Provider in Four PAC RADAR SAP Services 2026 Reports

NTT DATA today announced it has been named a Best in Class provider by PAC across four reports in the PAC RADAR SAP Services 2026 assessment. The recognitions span SAP-Related...

Read moreDetails

Fractal unveils intelligent sales agents to accelerate B2B growth

by DigitalCIO Bureau
March 11, 2026
0
Fractal unveils intelligent sales agents to accelerate B2B growth

Flyfish.ai now deploys 35+ coordinated AI agents across the sales lifecycle, helping early enterprise adopters close deals up to 30% faster and improve sales productivity by 42%. Fractal...

Read moreDetails

TCS Named a Leader in Artificial Intelligence and Generative AI Services by Everest Group

by DigitalCIO Bureau
March 11, 2026
0
TCS Named a Leader in Artificial Intelligence and Generative AI Services by Everest Group

Cited as key strengths are Tata Consultancy Services platform-led AI transformation strategy, proprietary industry assets, and strong co-innovation with partners Tata Consultancy Services (TCS), has been positioned as...

Read moreDetails

SEI Engages IBM to Accelerate Enterprise Transformation Through Agentic AI

by DigitalCIO Bureau
March 10, 2026
0
SEI Engages IBM to Accelerate Enterprise Transformation Through Agentic AI

SEI announced it has joined forces with IBM IBM to accelerate enterprise transformation through agentic AI and automation and modernize how it operates, innovates, and delivers value to clients—reinforcing...

Read moreDetails
Next Post
New Report Highlights Key Elements of Cloud Workload Security Landscape

New Report Highlights Key Elements of Cloud Workload Security Landscape

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Fortinet Threat Predictions for 2025: Get Ready for Bigger, Bolder Attacks

Fortinet Threat Predictions for 2025: Get Ready for Bigger, Bolder Attacks

November 26, 2024
CRISIL To Acquire Bridge To India Energy

Arctic Wolf Snaps up UpSight Security

November 6, 2025

NTT: 80% of Healthcare Organizations have a well-defined GenAl strategy

July 24, 2025

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?