1 in 15 organizations runs actively exploited version of SolarWinds: report
Summary
Both CiscoWeb VPN and Palo Alto Global Protect joined Citrix NetScaler as VPNs listed in the report with high Temptation Scores. Just 3% of organizations are still running versions of Microsoft Outlook Web Access but this alarmed Randori researchers, who noted the recent Exchange hacks and several known exploits for the tool. Wolpoff suggested security teams always change the default settings so the version number isnt publicly visible, noting that if enterprises are unable to patch or upgrade a tool, they should at least hide it. He urged security teams to find ways to reduce their attack surfaces by taking things offline or disabling functionalities that go unused. It is no longer appropriate for organizations to settle for the configuration the manufacturer sets as default and Wolpoff added that enterprises should segment critical assets as well as appliance and IoT devices.