CISA: “Most hacks result from basic security failures”

Threat actors don’t necessarily rely on advanced techniques or cutting-edge tools to pull off a cyberattack.
“They exploited simple, known software vulnerabilities that remain widespread and persistent in publicly exposed assets,” the Cybersecurity & Infrastructure Security Agency (CISA) says in its most recent Vulnerability Review report.
According to the cybersecurity agency, most cyberattacks don’t involve leveraging zero-day exploits. Instead, hackers scan the internet for well-known software vulnerabilities to exploit.
“Unfortunately, the production and use of insecure software is still the norm,” the CISA argues, claiming that basic security failures enable most compromises.
Most of the time, threat actors are opportunistic criminals looking for an easy pick. The cybersecurity agency argues that businesses and organizations can reduce their risk of becoming a victim of a cyberattack by addressing underlying weaknesses and prioritizing vulnerabilities.
The agency points to “persistent recurrence” across a wide range of applications, including cross-site scripting, SQL injection, and memory-safety vulnerabilities such as buffer overflows. These problems have been known for decades but still occur, which, according to the agency, indicates “systemic issues” in software development.
The answer to this problem? “Organizations must shift from reacting to threat actors to fixing the fundamental flaws those actors are known to exploit,” the agency says in its Vulnerability Review report.
This begins with using software that’s secure by design and requires prioritization of vulnerabilities and collaboration across industry and government.
Furthermore, improving cybersecurity and cyber defenses demands leadership that understands that cyber risks should be considered as a business risk, a threat to national security, and a risk to operational continuity.
Earlier this week, Igor Sakhnov, corporate vice president and general manager for Azure Networking at Microsoft, warned that hackers are moving faster than security experts can act, thereby shrinking the patch window significantly.
“As the patch window continues to collapse, the industry will need new approaches that complement traditional remediation strategies, reduce exposure quickly, and help defenders regain the one resource that has become increasingly scarce in modern cybersecurity: time,” he explained.
Sakhnov recommended that organizations implement protective network measures rather than validating and deploying software patches.