Connect with us

Technology

Critical Risk Severities Across Assets and Industries Are On the Rise According to New 2024 BreachLock Pentesting Intelligence Report

Published

on

NEW YORK, Aug. 1, 2024 /PRNewswire/ — The 2024 BreachLock Pentesting Intelligence Report is out – and there are many new insights that may surprise you. The report analyzed threat intelligence from over 4,000 penetration tests and vulnerability assessments conducted over the past 12 months. Findings were presented across affected assets, associated vulnerability types, prevalence, severity, and the most impacted industries around the globe.

“Today more than ever, CISOs are facing increasing cyber security challenges.  They are facing new and more stringent regulatory guidelines, SEC reporting rules, and an expanding landscape that seeks to hold enterprises more accountable. It leaves CISOs and practitioners unsure of what lies ahead,” states Seemant Sehgal, Founder & CEO of BreachLock. “Security teams are under more scrutiny to reassess risk and quantify the potential financial impact. They need to provide business-oriented programs that drive ROI and reduce risk, and BreachLock aims to provide the offensive security solutions to help enterprises do just this.”

This year’s report includes MITRE ATT&CK adversary tactics and techniques, as well as OWASP Top 10 to see how the report’s findings stack up against real-world observations. Here are some of the report’s top findings:

Industry Findings
The report comprises a healthy representation across enterprise size with small enterprises, or those with less than 50 employees, representing 40% of the report analysis, followed by 35% mid-enterprise (51 to 100 employees) and 25% of large enterprises, or those with 1001 to over 10,000 employees. These enterprises were located across North America, the UK, Europe, and Pan-Asian countries.

It has been a tough year so far in 2024 for the Computer Software & Technology industry, which has been besieged by an escalation in cyber incidents targeting technology infrastructure. Of the Top 5 industries with the highest number of findings, 48% of these were found in the technology sector. 

As researchers began to dig deeper into the data, some surprising industry insights were uncovered. The Banking and Financial Services Institutions (FSI) sector saw a 71.43% increase in Critical and High severities in 2024 in comparison to 2023. This included such vulnerabilities as security misconfiguration, cryptographic failures, and broken access controls, all aligning with OWASP TOP 10.

Healthcare also saw a significant rise in Critical and High severities, revealing an 85.71% increase versus 2023, according to reporting findings. In May 2024, there were 51 data breaches in the U.S. related to healthcare, most notably the United Health-owned Change Healthcare attack resulting in a $220 million paid ransom to a Russian cybercrime group.

Professional Services was a newcomer to the 2024 report. This sector includes such organizations as consumer services, human resources, law practices, legal services, and staffing and recruitment. Due to the sensitive data handled by these types of organizations, in addition to the complexity of attacks and growing regulatory demands, it is not surprising to see this sector in the Top 5 most impacted industries.

Findings Across Assets

Of the 4,000 pentests analyzed for the report, assets included are web applications (49%), external network (17%), internal network (15%), APIs (9%), Cloud (7%), and Mobile apps for both Android and iOS (3%).

The Top 5 most identified vulnerabilities by OWASP aligned with BreachLock’s top 5 findings as follows:

A05:2021 – Security MisconfigurationsA02:2021 – Cryptographic FailuresA01:2021 – Broken Access ControlA04:2021 – Insecure Design InjectionA06:2021 – Vulnerable and Outdated Components

These Top 5 categories, aggregated together, represent 88% of the findings and security weaknesses in the report’s full data set.

In addition, MITRE ATT&CK is another framework BreachLock uses and is also represented in the 2024 report findings. Aligning with MITRE ATT&CK techniques ensures that identified vulnerabilities correspond to real-world attack techniques, validating the relevance and severity of our threat findings. By identifying vulnerabilities associated with the most common and impactful attack techniques, organizations can prioritize their remediation efforts to address the most critical and probable threats first.

In addition, we saw Critical to High severity findings increase across almost every asset but here are a few of the most significant discoveries:

Web Applications: Critical severities are up 150% and High findings increased 60% in 2024 vs. 2023.

Network Infrastructure: Collectively, overall risk severities for both internal and external networks represented 32% of the complete data set with both Critical and High severities increasing 100% and 200%, respectively in 2024 from the previous year.

APIs: Representing almost 10% of the overall risk of all assets tested, the risk distribution shows a 400% increase in Critical severities and a staggering 700% increase in High vs. 2023.

Lastly, the BreachLock Pentesting Intelligence Report outlined some of the new and recent changes to cybersecurity regulations in 2024. Arguably the most impactful change has been the Securities and Exchange Commission (SEC) Disclosure Rules Act. Enacted in July 2023, it was in 2024 that we really began to see the effect that these rules had on major domestic and global companies that experienced significant breaches that were immediately disclosed to the SEC and made public.

In closing, the annual BreachLock Penetration Testing Intelligence Reports have become important to help enterprises and their security teams keep a pulse on the most prevalent vulnerabilities and potential changes to the threat landscape.  It also helps us as a security provider to better understand what is keeping our customers up at night, and to continue to develop innovative solutions to align with their needs and growing attack surface.

For more information, download the 2024 BreachLock Pentesting Intelligence Report or contact us to learn more.

About BreachLock

BreachLock is a global leader in Attack Surface Discovery and Penetration Testing. Continuously discover, prioritize, and mitigate exposures with evidence-backed Attack Surface Management, Penetration Testing, and Red Teaming.

Elevate your defense strategy with an attacker’s view that goes beyond common vulnerabilities and exposures. Each risk we uncover is backed by validated evidence. We test your entire attack surface and help you mitigate your next cyber breach before it occurs.

Know your risk. Contact BreachLock today!

Media Contact:

Megan Charrois

Senior Marketing Executive

Megan.c@breachlock.com

BreachLock.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/critical-risk-severities-across-assets-and-industries-are-on-the-rise-according-to-new-2024-breachlock-pentesting-intelligence-report-302212396.html

SOURCE BreachLock

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Eoptolink Releases OSFP 1.6T DR8 and 2FR4 Series Transceivers for AI/ML Clusters and Cloud Datacenter Networks

Published

on

By

CHENGDU, China, Sept. 20, 2024 /PRNewswire/ — Eoptolink Technology Inc., Ltd. (SZSE: 300502), a leading innovator and provider of advanced optical transceiver solutions, announces the release of its OSFP 1.6T DR8/DR8-2 and 2xFR4 transceivers enabling the next generation high bandwidth networks for AI/ML clusters and cloud datacenters.

Eoptolink 1.6T OSFP transceivers have 8 electrical host interfacing lanes and 8 optical lanes operating at 212.5Gb/s (106GB with PAM4). Equipped with the industry’s latest DSP, these modules support transmission distances of up to 2km without the need to regenerate the FEC. The 1.6T DR8 and DR8-2 modules comes with either one MPO-16 adapter for point-to-point (P2P) connections or two MPO-12 adapters for 2x800G breakout applications. The 1.6T 2xFR4 modules are designed with a dual duplex LC connector running with 2 pairs of fibers only, which could help users to save fiber resources compared to DR8 and DR8-2 versions.

The 1.6T DR8/DR8-2 and 2FR4 Portfolio consists of: – 

EOLO-13T-5H-XMX    OSFP 1.6T DR8, 1×1.6TbE, 500m, MPO-16
EOLO-13T-5H-XDX    OSFP 1.6T DR8, 2x800GbE, 500m, Dual MPO-12
EOLO-13T-02-XMX    OSFP 1.6T DR8-2, 1×1.6TbE, 2km, MPO-16
EOLO-13T-02-XDX     OSFP 1.6T DR8-2, 2x800GbE, 2km, Dual MPO-12
EOLO-16T-02-XXX     OSFP 1.6T 2FR4, 2x800GbE, 2km, Dual Duplex LC

Eoptolink OSFP 1.6T transceivers feature both EML and SiPh-based solutions, and testing has demonstrated excellent performance. “We are very proud of our optical and RF design teams, says Sean Davies, VP Sales, Eoptolink Technology Inc., Ltd. “Our 1.6T OSFP modules do not need an additional FEC on the optical side and this results in lower latency and power consumption of the modules simplifying the complete system and helping our AI and cloud customers in their work.”

About Eoptolink

Eoptolink Technology Inc., Ltd. (SZSE: 300502), a publicly traded company in China, is a leading innovator and provider of advanced optical transceiver solution for data center, enterprise and telecom networks. Eoptolink is dedicated to research, develop, manufacture and markets a diverse portfolio of high-performance optical transceivers for AI, Cloud Data Center, 4G/5G wireless, Transport & Datacom and FTTX applications all over the world.

Contact Us

China(HQ):   

No.510 Wulian Avenue, Chengdu 610200

USA:   

3191 Laurelview Court, Fremont, CA 94538

Thailand:   

390/21 Moo 2, Khao Khan Song, Sriracha, Chonburi 20110

E-mail:  

sales@eoptolink.com 

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/eoptolink-releases-osfp-1-6t-dr8-and-2fr4-series-transceivers-for-aiml-clusters-and-cloud-datacenter-networks-302253858.html

SOURCE Eoptolink Technology Inc., Ltd.

Continue Reading

Technology

Flat Ads Makes Its Mark at DMEXCO 2024: Showcasing Strength in Programmatic Advertising

Published

on

By

COLOGNE, Germany, Sept. 20, 2024 /PRNewswire/ — In September, Flat Ads makes its mark at DMEXCO 2024, the prestigious European event of digital marketing and technology. The highly successful exhibition boasts 650 exhibitors, 850 speakers, and thousands of participants. At the event, Flat Ads showcased the strength of programmatic advertising platform in ad delivery, traffic optimization, and brand safety.

Flat Ads programmatic advertising platform has an exclusive developer traffic of 700 million and an extensive network spanning over 200 countries and regions worldwide. It cooperates with over 200 leading DSP/SSP partners, including FreeWheel, PubMatic and Criteo, leveraging an efficient and complete bidding system, as well as automatic delivery algorithms, to achieve precise marketing and advertising effectiveness maximization.

With its exclusive platform strategy algorithm, Flat Ads programmatic advertising platform can continuously conduct automatic exploration and matching based on the characteristics of DSP and traffic, optimize and adjust the algorithm model in real-time. This not only ensures the sustainability of DSP budgets, but also maximizes traffic utilization and enhances monetization revenue of advertisements.

Moreover, brand protection is among the top priorities of Flat Ads. In addition to accessing to authority agency Pixalate to test the effectiveness of ads, it has also accessed HUMAN, the global cybersecurity authority to safeguard its clients by preventing bot attacks, digital fraud and abuse, ensuring a stable, reliable, and secure programmatic advertising transaction platform.

By participating in DMEXCO 2024, Flat Ads showcased its outstanding strength and fruitful achievements in the programmatic advertising field, attracting the attention of numerous advertisers and developers for cooperation. Flat Ads boasts not only robust technical capabilities and innovative prowess, but also an active and open attitude towards emerging technologies, embracing and exploring them. It remains committed to providing more professional and efficient global marketing services to advertisers and developers worldwide, helping clients stand out in the fiercely competitive market and achieve business growth.

As a globally leading mobile advertising marketing platform, Flat Ads currently operates offices in Singapore, Indonesia, Hong Kong, and Guangzhou, serving over 1000 clients with global marketing solutions. If you’re interested in Flat Ads’ programmatic advertising services, please visit www.flat-ads.com.

View original content:https://www.prnewswire.co.uk/news-releases/flat-ads-makes-its-mark-at-dmexco-2024-showcasing-strength-in-programmatic-advertising-302253872.html

Continue Reading

Technology

Tulufan, Xinjiang: For the first time, a new energy plant and station has achieved “all-green electricity” operation

Published

on

By

TULUFAN, China, Sept. 20, 2024 /PRNewswire/ — On September 19, employees of State Grid Tulufan Electric Power Supply Company came to State Power Investment Zhongli Tenghui Qiquanhu Photovoltaic Power Station to provide comprehensive technical support and guidance for new energy enterprises.

Seven wind power and photovoltaic power generation enterprises, including Xinjiang Jize Power Generation Company in Tulufan, have obtained 6.035 million KWH of grid electricity by purchasing 6,035 “green certificates” to achieve “green electricity – green electricity” and achieve green energy use in the whole link of new energy power generation.

The green power certificate, referred to as “green certificate”, is the only certificate that identifies the production and consumption of renewable energy power. Promoting the all-green operation of new energy power generation is an important measure to promote the green consumption of renewable energy.

“Before, we were just ‘producers’ of green electricity. Now the buyers of green certificates have become green electricity consumers, and the production process is fully green.” Qiquan Lake photovoltaic power station inspection officer Forzati Dilishati said.

Since the launch of the green electricity and green certificate market, State Grid Tulufan Electric Power Supply Company has actively promoted green electricity trading, promoted the supply of green electricity and green certificates in multiple scenarios, promoted the rapid promotion and popularization of related services in Tulufan, and helped build a new power system.

In the first eight months of this year, the cumulative volume of green electricity transactions in Xinjiang reached 1.174 billion KWH, 93.83 times that of the whole year of 2022.

 

View original content:https://www.prnewswire.com/apac/news-releases/tulufan-xinjiang-for-the-first-time-a-new-energy-plant-and-station-has-achieved-all-green-electricity-operation-302253902.html

SOURCE State Grid Tulufan Electric Power Supply Company

Continue Reading

Trending