Daffodil International University

Faculty of Science and Information Technology => Recent Technologies and Trends in Software Engineering => Software Engineering => Cyber and Software Security => Topic started by: iftekhar.swe on September 05, 2018, 02:20:52 PM

Title: The Top Four Security Vulnerabilities You Might Be Overlooking
Post by: iftekhar.swe on September 05, 2018, 02:20:52 PM
In our day-to-day work with organizations to discover and address security vulnerabilities, we are finding that the top 4 security vulnerabilities that organizations overlook are:

1. Networked printers. From a network security perspective, printers have outdated firmware and are susceptible to multiple attacks. Aside from potential data loss and espionage, more than one proof of concept exists where a printer is used as a springboard to launch other attacks. To resolve this:

2. Internet of Things (IoT). More companies are accepting traditionally isolated devices (e.g., heating, ventilation and air conditioning [HVAC] controllers, IP cameras]. These have firmware that require regular updates. There are proofs of concept in the wild, including data theft, vandalism and remote compromise. To resolve this:


3. Aging infrastructure. Over time, manufacturers such as Cisco end-of-life their products. This means that your network switch’s firmware is often out of date and susceptible to attack and compromise. Purchasing gray market, and/or used devices from auctions increases this risk exponentially. More than one gray market network device has been discovered to have unsigned (compromised) firmware. To resolve this:

4. People. People remain the biggest threat to the organization. People take the easiest path, which is usually not the most secure, constantly creating vulnerabilities in organizations. The latest data1 reveal that 70 percent of US employees lack security and privacy awareness. With an employee clicking on malware every 81 seconds in the US,2 is no surprise that cyberincidents that expose sensitive data are spreading, increasing an organization’s risk. Employees should be trained annually, at a minimum. This training should include social awareness and security awareness.
Title: Re: The Top Four Security Vulnerabilities You Might Be Overlooking
Post by: Fahad Zamal on November 15, 2018, 12:30:31 AM
Yes we did it a lot. Thanks for notify us.