Site navigation

Misconfigurations and Basic Errors Behind 9.5M Cyber-Attacks

Tom Quinn

,

cybersecurity misconfigurations
“While the cybersecurity industry often focuses on zero-day exploits and advanced persistent threats, attackers are still finding success through simple missteps,” said Doug McKee, SonicWall.

Misconfigurations fuelled more than 9.5 million cyber-attacks over the first half of this year, according to new research from SonicWall, with basic errors like accidental data exposure and authentication failures leaving organisations dangerously exposed to sophisticated threats.

The cyber firm’s latest Threat Brief found that nearly 70% of firms faced at least one authentication bypass attempt between January and June, with many incidents linked to long-standing vulnerabilities like Fortra GoAnywhere MFT, which attackers continue to exploit years after its initial discovery. 

These misconfigurations – essentially errors or incorrect settings in hardware, software, or network systems that create security vulnerabilities, operational problems, or system outages – are easily overlooked, but can create significant issues for even global firms.

In 2023, Toyota issued an apology to more than a quarter of a million customers after some of their data was potentially exposed due to misconfigured cloud settings, resulting in an investigation for all of the company’s cloud environments.

In the US, Wired reported last week that a misconfigured platform used by the Department of Homeland Security accidentally exposed sensitive intelligence regarding thousands of government and private sector workers – simply because its access settings were left at ‘everyone’.

However, the SonicWall data shows that this year, consulting services firms have been disproportionately impacted, accounting for 46% of all misconfiguration-related detections, followed by information services (32%), which the cyber firm said was likely due to these industries having more complex IT environments coupled with rapid deployment cycles.

According to the report threat, around 88% of misconfigurations fall into three main categories, namely directory access misconfigurations (45%), accidental data exposure (24%), and authentication failures (19%). In contrast, bypassing security features accounts for just 4%.

Research firm Gartner alluded to the seriousness of this problem in an earlier study, which predicted that by the end of 2025, 99% of cloud security failures will be customer-side misconfigurations, which are already leaving the door open for threat actors to conduct more nefarious attacks.

A recent report from Infoblox, for instance, found that the threat group dubbed ‘Hazy Hawk’ has been exploiting misconfigured DNS settings, leveraging these to gain control and leverage trusted domains to host malicious content, while another, ‘Vacant Viper’, is reportedly hijacking domains left vulnerable due to misconfigured DNS name servers.


Recommended reading


Even SonicWall isn’t immune. Last month, the firm disclosed that an Akira ransomware campaign targeting SonicWall devices was due to users not resetting their passwords, a crucial and recommended step, following an earlier vulnerability being discovered.  

“Misconfigurations are not obscure technical flaws; they are operational challenges that persist because they are difficult to manage at scale,” said Doug McKee, executive director of threat research at SonicWall.

“While the cybersecurity industry often focuses on zero-day exploits and advanced persistent threats, attackers are still finding success through simple missteps. 

“The fact that misconfigurations remain one of the leading causes of breaches shows that organisations need better visibility, consistent processes and operational support to avoid repeating the same mistakes.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data