Site navigation

Report: Mitigating the Vulnerability Exploit Surge

Graham Turner

,

Cyber vulnerability risks
Vulnerability exploitation has surged, exposing organisations to financial and operational risks.

One of the most common means cyber-attackers bypass IT security is through their reliance on vulnerabilities (known flaws) to gain access to and potentially manipulate computer systems.

Recently surging vulnerability exploitation has left organisations suffering from financial and operational damages.

In a new report by S&P Global Ratings, Poor Cyber Vulnerability Management Can Be A Governance Issue, they explore the structure & magnitude of cyber-vulnerabilities, its risks and effective remediation planning.

Vulnerability Exploits on the Rise

Cyber-attackers frequently exploit both known vulnerabilities and unsuspecting users to access systems. Methods like phishing and spoofing rely on deception, while more direct approaches focus on exploiting flaws in software.

This approach gained momentum in 2023, with reported vulnerability exploitations almost tripling, driven by an increase in identifiable security flaws. Over 29,000 vulnerabilities were discovered in 2023 alone, according to a report by Qualys, up by roughly 4,000 from the previous year.

Several factors underlie this rise, according to S&P. Improved detection technologies and growing incentives for cybersecurity research have led to more discoveries, while increased software complexity has inadvertently created additional vulnerabilities.

The result is a rapidly expanding attack surface, particularly among internet-exposed systems, which are inherently more accessible to cyber-attackers. This growing risk environment demands heightened awareness, particularly around systems open to public interaction, where rapid patching is essential for minimising exposure.

The case of the MOVEit application breach in 2023 exemplifies the high costs of exploitation.

Attackers leveraged a vulnerability to infiltrate Progressive Software’s MOVEit, a data transfer tool, affecting approximately 2,700 organisations and 95 million individuals globally, at a cost that was estimated at over $15 billion (£11.56 billion), underscoring the financial and reputational risks of poor vulnerability management.

Remediation Strategies and Governance 
According to the report, organisations must approach vulnerability remediation strategically to mitigate these risks. Data analysis from cybersecurity scans of over 7,000 rated entities highlights the common issue of inconsistent remediation practices.

Given the high volume of vulnerabilities, prioritisation is essential, typically guided by the Common Vulnerability Scoring System (CVSS), which rates vulnerabilities by severity on a scale from 1 to 10. However, even “medium-severity” vulnerabilities, with an average CVSS score of 4.87, can pose significant risks if left unaddressed.

The Exploit Prediction Security Score (EPSS) adds a further dimension to prioritisation efforts, offering insight into the likelihood of exploitation. This score can be particularly useful for organisations attempting to distinguish between low-risk vulnerabilities and those with a higher probability of active exploitation.


Recommended reading


Integrating EPSS with CVSS allows security teams to better target critical vulnerabilities that may otherwise be overlooked. For instance, vulnerabilities with lower CVSS scores but high EPSS scores indicate a high likelihood of exploitation, necessitating immediate action.

Despite advancements in remediation scoring, the persistence of older vulnerabilities remains a pressing issue. Almost three-quarters of vulnerabilities discovered were over seven years old, yet continue to expose systems due to insufficient patching or system redundancy.

In terms of mitigating these risks, the report suggests, consistent patching practices, combined with adaptive scoring frameworks like EPSS, are crucial for maintaining cyber-resilience.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data