New threat intelligence research finds critical infrastructure at heightened risk
News summary
- New vulnerabilities exploited in the wild grew by 30% in H1 2021
- Ransomware grew by nearly 20%
- Cryptomining malware more than doubled
- Cumulative number of known vulnerabilities grew 3x in 10 years
- Download the full report
SAN JOSE, Calif., Sept. 14, 2021 /PRNewswire/ -- Skybox Security, a global leader in security posture management, today released its annual Mid-Year Vulnerability and Threat Trends Report, offering new threat intelligence research on the frequency and scope of global malicious activity. The Skybox Research Lab analysts found that new vulnerabilities in operational technology (OT) devices were up 46% in the first half of 2021, putting vital critical infrastructure at risk.
"Critical infrastructure is the backbone of global enterprises and governments. Operational technology enables revenue creation and business continuity. Yet, despite the criticality, the cybersecurity measures in place are still weak or nonexistent," said Gidi Cohen, CEO and founder, Skybox Security. "Experts warned for years that vital infrastructure is a sitting duck and that it was only a matter of time before they came under widespread assault. Now, those predictions have come true."
To make matters worse, it can be difficult or impossible to identify and remediate OT vulnerabilities through scanning and patching. Nearly all major vendors of OT equipment reported increases in vulnerabilities, especially Siemens. Threat actors are taking advantage of these OT weaknesses in ways that don't just imperil individual companies but also threaten public safety and the global economy.
Skybox Security threat intelligence analyzes exploits in the wild to prioritize vulnerabilities that need remediation. Key findings presented in this mid-year update include:
"The sheer volume of accumulated security debt — hundreds of thousands or even millions of vulnerabilities — means that security teams can't possibly isolate and patch all of them. Malware evolves like viruses, with new variants springing up opportunistically in response to changing environments," said Stav Kaufman, lead analyst, Skybox Research Lab. "As a result, enterprises need precise, exposure-based solutions that cut through the noise, pinpoint the real security threats and enable practical, cost-effective remediation."
For more threat intelligence analysis, download the full report.
Methodology
Skybox Research Lab analysts continuously monitor dozens of security sources, tracking and analyzing hundreds of thousands of vulnerabilities on over ten thousand products, along with the latest data on available exploits and malware taking advantage of these vulnerabilities. The analysts identify the vulnerabilities most likely to impact our customers' unique networks and assets. This threat intelligence powers Skybox's vulnerability and threat management solution and enables our customers to discover, prioritize and remediate risks.
About Skybox Security
Over 500 of the largest and most security-conscious enterprises in the world rely on Skybox for the insights and assurance required to stay ahead of dynamically changing attack surfaces. At Skybox, we don't just serve up data and information. We provide the intelligence and context to make informed decisions, taking the guesswork out of securely enabling enterprises at scale and speed. Our unified security posture management platform delivers complete visibility, analytics, and automation to quickly map, prioritize, and remediate vulnerabilities across your organization. The vendor-agnostic platform intelligently optimizes security policies, actions, and change processes across all corporate and cloud environments. With Skybox, security teams can focus on the most strategic business initiatives while ensuring that enterprises remain protected.
We are Skybox. Secure more, limit less. https://www.skyboxsecurity.com/
Media & analyst contact
Ashley Nakano
Corporate Communications
skyboxglobal@allisonpr.com
© 2021 Skybox Security, Inc. All rights reserved. Skybox Security and the Skybox Security logo are either registered trademarks or trademarks of Skybox Security, Inc., in the United States and/or other countries. All other trademarks are the property of their respective owners. Product specifications subject to change at any time without prior notice.
Photo - https://mma.prnasia.com/media2/1624858/Skybox_Security_midyear_report.jpg?p=medium600
Logo - https://mma.prnasia.com/media2/1011662/Skybox_Security_logo.jpg?p=medium600