Connect with us

Technology

Critical Risk Severities Across Assets and Industries Are On the Rise According to New 2024 BreachLock Pentesting Intelligence Report

Published

on

NEW YORK, Aug. 1, 2024 /PRNewswire/ — The 2024 BreachLock Pentesting Intelligence Report is out – and there are many new insights that may surprise you. The report analyzed threat intelligence from over 4,000 penetration tests and vulnerability assessments conducted over the past 12 months. Findings were presented across affected assets, associated vulnerability types, prevalence, severity, and the most impacted industries around the globe.

“Today more than ever, CISOs are facing increasing cyber security challenges.  They are facing new and more stringent regulatory guidelines, SEC reporting rules, and an expanding landscape that seeks to hold enterprises more accountable. It leaves CISOs and practitioners unsure of what lies ahead,” states Seemant Sehgal, Founder & CEO of BreachLock. “Security teams are under more scrutiny to reassess risk and quantify the potential financial impact. They need to provide business-oriented programs that drive ROI and reduce risk, and BreachLock aims to provide the offensive security solutions to help enterprises do just this.”

This year’s report includes MITRE ATT&CK adversary tactics and techniques, as well as OWASP Top 10 to see how the report’s findings stack up against real-world observations. Here are some of the report’s top findings:

Industry Findings
The report comprises a healthy representation across enterprise size with small enterprises, or those with less than 50 employees, representing 40% of the report analysis, followed by 35% mid-enterprise (51 to 100 employees) and 25% of large enterprises, or those with 1001 to over 10,000 employees. These enterprises were located across North America, the UK, Europe, and Pan-Asian countries.

It has been a tough year so far in 2024 for the Computer Software & Technology industry, which has been besieged by an escalation in cyber incidents targeting technology infrastructure. Of the Top 5 industries with the highest number of findings, 48% of these were found in the technology sector. 

As researchers began to dig deeper into the data, some surprising industry insights were uncovered. The Banking and Financial Services Institutions (FSI) sector saw a 71.43% increase in Critical and High severities in 2024 in comparison to 2023. This included such vulnerabilities as security misconfiguration, cryptographic failures, and broken access controls, all aligning with OWASP TOP 10.

Healthcare also saw a significant rise in Critical and High severities, revealing an 85.71% increase versus 2023, according to reporting findings. In May 2024, there were 51 data breaches in the U.S. related to healthcare, most notably the United Health-owned Change Healthcare attack resulting in a $220 million paid ransom to a Russian cybercrime group.

Professional Services was a newcomer to the 2024 report. This sector includes such organizations as consumer services, human resources, law practices, legal services, and staffing and recruitment. Due to the sensitive data handled by these types of organizations, in addition to the complexity of attacks and growing regulatory demands, it is not surprising to see this sector in the Top 5 most impacted industries.

Findings Across Assets

Of the 4,000 pentests analyzed for the report, assets included are web applications (49%), external network (17%), internal network (15%), APIs (9%), Cloud (7%), and Mobile apps for both Android and iOS (3%).

The Top 5 most identified vulnerabilities by OWASP aligned with BreachLock’s top 5 findings as follows:

A05:2021 – Security MisconfigurationsA02:2021 – Cryptographic FailuresA01:2021 – Broken Access ControlA04:2021 – Insecure Design InjectionA06:2021 – Vulnerable and Outdated Components

These Top 5 categories, aggregated together, represent 88% of the findings and security weaknesses in the report’s full data set.

In addition, MITRE ATT&CK is another framework BreachLock uses and is also represented in the 2024 report findings. Aligning with MITRE ATT&CK techniques ensures that identified vulnerabilities correspond to real-world attack techniques, validating the relevance and severity of our threat findings. By identifying vulnerabilities associated with the most common and impactful attack techniques, organizations can prioritize their remediation efforts to address the most critical and probable threats first.

In addition, we saw Critical to High severity findings increase across almost every asset but here are a few of the most significant discoveries:

Web Applications: Critical severities are up 150% and High findings increased 60% in 2024 vs. 2023.

Network Infrastructure: Collectively, overall risk severities for both internal and external networks represented 32% of the complete data set with both Critical and High severities increasing 100% and 200%, respectively in 2024 from the previous year.

APIs: Representing almost 10% of the overall risk of all assets tested, the risk distribution shows a 400% increase in Critical severities and a staggering 700% increase in High vs. 2023.

Lastly, the BreachLock Pentesting Intelligence Report outlined some of the new and recent changes to cybersecurity regulations in 2024. Arguably the most impactful change has been the Securities and Exchange Commission (SEC) Disclosure Rules Act. Enacted in July 2023, it was in 2024 that we really began to see the effect that these rules had on major domestic and global companies that experienced significant breaches that were immediately disclosed to the SEC and made public.

In closing, the annual BreachLock Penetration Testing Intelligence Reports have become important to help enterprises and their security teams keep a pulse on the most prevalent vulnerabilities and potential changes to the threat landscape.  It also helps us as a security provider to better understand what is keeping our customers up at night, and to continue to develop innovative solutions to align with their needs and growing attack surface.

For more information, download the 2024 BreachLock Pentesting Intelligence Report or contact us to learn more.

About BreachLock

BreachLock is a global leader in Attack Surface Discovery and Penetration Testing. Continuously discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing, and Red Teaming.

Elevate your defense strategy with an attacker’s view that goes beyond common vulnerabilities and exposures. Each risk we uncover is backed by validated evidence. We test your entire attack surface and help you mitigate your next cyber breach before it occurs.

Know your risk. Contact BreachLock today!

Media Contact:

Megan Charrois

Senior Marketing Executive

Megan.c@breachlock.com

BreachLock.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/critical-risk-severities-across-assets-and-industries-are-on-the-rise-according-to-new-2024-breachlock-pentesting-intelligence-report-302212396.html

SOURCE BreachLock

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

On World Cleanup Day 2024, VIAIM’s Newly Launched Service Upgrade Provides Added Multilingual Support and Commitment to Environmental Goals, Helping to Shape a More Sustainable Future

Published

on

By

SINGAPORE, Sept. 20, 2024 /PRNewswire/ — VIAIM,  an AI technology hardware company deeply rooted in the smart office sector, is marking the inaugural World Cleanup Day 2024, which falls on September 20, with the official launch of a service package upgrade, reinforcing its dedication to both innovation and environmental responsibility.

This upgrade introduces Malay and Thai language support, expanding the total number of supported languages from 11 to 13. With these additions, VIAIM is taking another step towards making seamless cross-cultural communication more accessible, especially for users across Southeast Asia. At the same time, the Company continues to align its operations with sustainability efforts, lowering the usage threshold for customers and offering environmentally friendly solutions that contribute to a greener planet.

As part of VIAIM’s latest service package upgrade, users enjoy enhanced features designed to make their work and daily lives more efficient. These include free transcription and translation time, along with increased access to To-do List and Summary functions, providing customers with more comprehensive functionality at no additional cost.

These upgrades not only reflect the brand’s core philosophy of “user-first”, but also emphasize VIAIM’s commitment to continuously enhancing user experiences. Now, users can manage tasks more effectively, saving time and reducing the need for additional services, making their workflow more streamlined and productive.

Beyond product and service innovations, VIAIM remains committed to its environmental goals, aligning with global best practices in environmental, social, and governance (ESG) initiatives. VIAIM believes that, just as its users seek to improve their daily lives through technology, the company must contribute to a better world for future generations.

VIAIM is fully committed to environmental protection and sustainable development through its use of molded pulp, an environmentally friendly material for packaging while maintaining a laser focus on technology upgrades that reflect its customer-centric philosophy. The company utilizes molded pulp, an eco-friendly packaging material, to minimize environmental impact, while its smart office solutions contributes to a paperless workplace, further reducing waste. This dual focus on customer convenience and sustainability enhances the overall value that VIAIM delivers to its global customer base.

“Innovation serves as a breakthrough in technology and is also a cornerstone of environmental and social responsibility,” said TOM, Product Manager of VIAIM. “With our latest service upgrades, we not only improve the user experience but also make it easier for our customers to participate in sustainable practices. By embracing these advancements, users can contribute to environmental preservation, while enjoying the benefits of advanced cross-language support and smarter office tools. VIAIM’s mission is to bridge technological innovation with social responsibility, inviting our customers to join us in creating a brighter, more sustainable future.”

About VIAIM

VIAIM is an innovative technology company in the consumer-goods sector. With a focus on versatile, multimodal interactions, we strive to provide effective solutions that meet users’ specific needs. By harnessing state-of-the-art technology, we bring our visionary ideals to life, helping people embrace the incredible possibilities the Company offers.

CONTACT:
Qian Wang
wangqian@vision-intelligence.tech

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/on-world-cleanup-day-2024-viaims-newly-launched-service-upgrade-provides-added-multilingual-support-and-commitment-to-environmental-goals-helping-to-shape-a-more-sustainable-future-302253841.html

SOURCE VIAIM

Continue Reading

Technology

G42 Collaborates with NVIDIA to Deliver Next-Generation Climate Solutions Using Earth-2

Published

on

By

ABU DHABI, UAE, Sept. 20, 2024 /PRNewswire/ — G42, a leader in AI and cloud computing, today announced that it is partnering with NVIDIA to advance climate technology with a focus on developing AI solutions aimed at dramatically enhancing the accuracy of weather forecasting globally.

The collaboration builds on NVIDIA’s Earth-2, an open platform that accelerates climate and weather predictions with interactive, AI-augmented, high-resolution simulation. G42 and NVIDIA will initially focus on a square-kilometer resolution weather forecasting model that improves the accuracy of meteorological predictions.

Key to this initiative is the establishment of a new operational base and Climate Tech Lab in Abu Dhabi. This state-of-the-art facility will serve as a hub for research and development, driving forward both companies’ commitment to environmental sustainability. This facility will also mobilize the creation of tailored climate and weather solutions that leverage over 100 petabytes of geophysical data assets.

Peng Xiao, Group CEO of G42, said, “This initiative with NVIDIA is a testament to our commitment to applying AI in ways that not only innovate but also solve critical global challenges. Establishing the Earth-2 Climate Tech Lab in Abu Dhabi allows us to leverage our unique capabilities and insights to foster a sustainable future for the world.”

In addition to fostering innovation in climate technology, the initiative will focus on building a robust framework for integrating enhanced weather prediction capabilities with comprehensive data metrics and visualization. This will assist organizations worldwide in achieving their sustainability goals through well-informed, data-driven environmental strategies.

“Our collaboration with G42 marks a pivotal step toward harnessing AI to understand and predict climate phenomena with unprecedented accuracy,” said Jensen Huang, founder and CEO of NVIDIA. “The Earth-2 Climate Tech Lab will propel environmental solutions using the most advanced accelerated computing and AI technology to benefit millions of people around the world.”

By uniting G42’s AI expertise with NVIDIA’s computational acumen, this partnership aims to deliver transformative climate solutions that combine scientific accuracy with real-world applicability, driving impactful change across industries and ecosystems.

About G42

G42 is a technology holding group, a global leader in creating visionary artificial intelligence for a better tomorrow. Born in Abu Dhabi and operating worldwide, G42 champions AI as a powerful force for good across industries. From molecular biology to space exploration and everything in between, G42 realizes exponential possibilities, today.
To know more visit www.g42.ai.

Media contacts
Media and PR Team, G42
media@g42.ai

View original content:https://www.prnewswire.co.uk/news-releases/g42-collaborates-with-nvidia-to-deliver-next-generation-climate-solutions-using-earth-2-302253818.html

Continue Reading

Technology

Kawasaki and CB&I Sign Strategic Collaborative Agreement for Promoting Commercial-Use Liquefied Hydrogen Supply Chain

Published

on

By

HOUSTON, Sept. 19, 2024 /PRNewswire/ — Kawasaki Heavy Industries, Ltd. (Kawasaki) and CB&I, a wholly owned unrestricted subsidiary of McDermott, announced today their signing of a strategic agreement for promoting a commercial-use liquefied hydrogen (LH2) supply chain and realizing a zero-carbon-emission society. The signing ceremony took place at Gastech Exhibition & Conference in Houston on September 18, 2024.

“We are very pleased for this opportunity to build and launch a commercial liquefied hydrogen supply chain in cooperation with CB&I,” said Motohiko Nishimura, President, Energy Solutions & Marine Engineering Company, Kawasaki Heavy Industries, Ltd. “By taking advantage of both companies’ strengths and specialized know-how, we aim to cost down hydrogen, strengthen hydrogen supply chain competitiveness, and accelerate the transition to a zero-carbon society.”

Both companies will use their specialized know-how to provide infrastructure that will enable commercial-scale international LH2 supply chains in order to help achieve carbon-neutrality. By leveraging our combined expertise to deliver large-scale LH2 infrastructure solutions, CB&I and Kawasaki are removing barriers, driving down costs and enhancing scalability across the entire supply chain.

“This strategic partnership represents a significant advancement in liquid hydrogen storage capabilities,” said Mark Butts, Senior Vice President of CB&I. “Our technical expertise and extensive experience in liquid hydrogen storage position us at the forefront of the energy transition, delivering reliable storage solutions and executing projects worldwide with proven success.”

Under this agreement, the companies will provide infrastructure to advance the global realization of a sustainable energy economy and meet decarbonization targets. This collaboration will reduce LH2 infrastructure costs and contribute to more widespread use of this clean and efficient energy source.

About CB&I
CB&I is the world’s leading designer and builder of storage facilities, tanks, and terminals. With more than 60,000 structures completed throughout its 130-year history, CB&I has the global expertise and strategically located operations to provide its customers world-class storage solutions for even the most complex energy infrastructure projects. CB&I is a wholly owned unrestricted subsidiary of McDermott. To learn more, visit www.cbi.com.

About McDermott
McDermott is a premier, fully-integrated provider of engineering and construction solutions to the energy industry. Our customers trust our technology-driven approach engineered to responsibly harness and transform global energy resources into the products the world needs. From concept to commissioning, McDermott’s innovative expertise and capabilities advance the next generation of global energy infrastructure—empowering a brighter, more sustainable future for us all. Operating in over 54 countries, McDermott’s locally-focused and globally-integrated resources include more than 30,000 employees, a diversified fleet of specialty marine construction vessels and fabrication facilities around the world. To learn more, visit www.mcdermott.com.

About Kawasaki Heavy Industries, Ltd.
Kawasaki Heavy Industries, Ltd. is general engineering manufacturer with over 125 years of experience manufacturing products spanning land, sea and air. Kawasaki established the Kawasaki Group’s new vision statement, “Group Vision 2030: Trustworthy Solutions for the Future,” and is focusing on three fields, “A Safe and Secure Remotely-Connected Society,” “Near-Future Mobility,” and “Energy and Environmental Solutions” in order to provide solutions for social issues. For “Energy and Environmental Solutions” in particular, by securing the technology necessary for the entire supply chain (for production, transportation, storage and utilization) ahead of the rest of the world, Kawasaki aims to bring about a society that utilizes hydrogen, the ultimate clean energy that emits no carbon dioxide when used. To learn more, visit https://global.kawasaki.com/en.

Forward-Looking Statements
McDermott cautions that statements in this communication which are forward-looking, and provide other than historical information, involve risks, contingencies and uncertainties. These forward-looking statements include, among other things, statements about the expected benefits from the collaboration agreement discussed in this press release.  Although we believe that the expectations reflected in those forward-looking statements are reasonable, we can give no assurance that those expectations will prove to have been correct. Those statements are made by using various underlying assumptions and are subject to numerous risks, contingencies and uncertainties, including, among others: adverse changes in the markets in which we operate or credit or capital markets; our inability to successfully execute on contracts in backlog; changes in project design or schedules; the availability of qualified personnel; changes in the terms, scope or timing of contracts, contract cancellations, change orders and other modifications and actions by our customers and other business counterparties; changes in industry norms; actions by lenders, other creditors, customers and other business counterparties of McDermott and adverse outcomes in legal or other dispute resolution proceedings. If one or more of these risks materialize, or if underlying assumptions prove incorrect, actual results may vary materially from those expected. You should not place undue reliance on forward-looking statements. This communication reflects the views of McDermott’s management as of the date hereof. Except to the extent required by applicable law, McDermott undertakes no obligation to update or revise any forward-looking statement.

For media inquiries, please use the contact information below:

Reba Reid
Global Media Relations
+1 281 588 5636
RReid@McDermott.com

Kristi Krupala-Grove
CB&I Media Relations
+1 346 313 9636
KKrupala2@mcdermott.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/kawasaki-and-cbi-sign-strategic-collaborative-agreement-for-promoting-commercial-use-liquefied-hydrogen-supply-chain-302253698.html

SOURCE McDermott International, Ltd

Continue Reading

Trending