Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

It’s time to get ahead of weaponised vulnerabilities

The global crisis revealed a multitude of nascent cyber-security shortcomings

by Dr. Jan-Oliver Wagner
July 19, 2021
in Insight
Author headshot
Share on FacebookShare on Twitter

It comes as no surprise that the Covid-19 pandemic has resulted in an increase in security gaps. The global crisis revealed a multitude of nascent cyber-security shortcomings, including a lack of agility to support homeworking and an overreliance on on-premise security. It also created a whole host of new challenges, from scam Covid-related domains to an increase in phishing attacks.

Indeed, the pandemic has seen cyber-crime flourish. In its Annual Review 2020, the UK’s NCSC revealed that GCHQ handled more than 200 cyber incidents related to the coronavirus during the course of last year – almost a third of the total number of incidents it handled over that period. This included more than 160 instances of high-risk and critical vulnerabilities shared with NHS Trusts. Overall, vulnerabilities have exploded in number over this past year, with HackerOne’s 2021 Hacker Report finding that, as more enterprises moved to the cloud, reports of misconfiguration vulnerabilities rose by 310%.

More opportunities for hackers in new digital landscapes

From Zoom’s security gaps to the SolarWinds attack, vulnerabilities have also been a weapon of choice for hackers over the past year as they take advantage of the new digital landscape. Progress is being made in warding off these vulnerability-based attacks – for example, Kenna Security found a falling number of vulnerabilities being exploited, while HackerOne discovered that the number of white hats reporting vulnerabilities to companies increased by 63% in 2020. But organisations must still be alert to the risks of vulnerabilities and their potential for weaponisation.

The growth of vulnerabilities has meant hackers not only have a larger attack surface, but they have also become less predictable in how they select their targets. Indeed, instead of only focusing on vulnerabilities that are currently being weaponised or those that are likely to be, organisations need to be cognisant of other potential risks. The ‘pandemic’ risk for example, which sees cyber criminals taking advantage of a vulnerability that more and more organisations choose not to manage. The fewer organisations that are ‘vaccinated’, the easier the pandemic spreads.

There’s also automation risk. Increasingly, cyber criminals are using automation tools and techniques to exploit vulnerabilities, as it is not only an attractive low-cost route, but it also significantly reduces the time window in which organisations can deploy countermeasures. Being prepared is therefore essential.

Take a proactive approach

While organisations cannot predict how cyber criminals will attack, they can proactively manage their attack surface through cyber resilience.

This is a continuous process which strengthens an organisation’s ability to resist attacks and enables it to continue functioning during an incident. To achieve this state, organisations need to reduce the size and number of targets that hackers can exploit whilst also establishing and maintaining a stable base to bounce back from in the event of an attack.

Identifying and managing all vulnerabilities will help organisations achieve both these goals. The first step in this process is to create a context for IT security policies, determining which systems, assets and processes need to be protected and to what extent, guiding IT on how best to configure security solutions.

The second step is to scan for all current vulnerabilities, targeting any current infrastructure weaknesses. Keeping a vulnerability database is also a good idea, helping IT to prioritise and mitigate the vulnerabilities that need the most urgent attention. It is also important to assign responsibility and accountability when a vulnerability is detected, ensuring that there is a streamlined process in place that will remediate the issue sooner rather than later.

Once the vulnerability has been mitigated, all the key information pertaining to it – including when it was detected, how long it took to resolve and who is accountable – should be recorded for future analysis and attack prevention.

The wider picture

Vulnerability management is important, yet it is still just one of the many steps to achieving complete sustainable cyber resilience. All hidden risks within digital processes must be taken into consideration and made apparent. Companies must also implement airtight processes across an organisation, from the actions that must be taken to training and educating employees – particularly vital in the age of remote-working.

In these challenging times, where operations have been upended and cyber criminals can use the pandemic to their advantage, protecting against existing and potential weaponised vulnerabilities has never been more important.

Contributed by Dr. Jan-Oliver Wagner, CEO and co-founder, Greenbone Networks

 

 

 

ShareTweet
Previous Post

OneLogin Eases Adoption of Zero Trust Framework with Delegated Administration

Next Post

Preparing for the ever-growing threat of ransomware

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol