
80% of security exposures are caused by misconfigurations
A new study conducted by XM Cyber has delved into over 40 million exposures to gain a comprehensive insight into the current exposure landscape. The research reveals that 80% of exposures are a result of identity and credential misconfigurations, with around one-third of them putting critical assets in danger of a breach.
The majority of exposures are identified within an organization’s active directory, a crucial element for linking users to network resources. Unfortunately, malicious actors often target this component to gain unauthorized access and elevated privileges. The top exposures stem from misconfigurations and credential attacks, leading to blind spots that traditional security tools might overlook. Issues like mishandling login information or managing members contribute to these vulnerabilities. Additionally, many environments lack proper endpoint hygiene, with more than 25% of devices either storing cached credentials or lacking EDR coverage, providing easy initial access points for cyber threats.
Cloud environments are also vulnerable to exposures, as the study reveals that 56% of exposures impacting critical assets occur within cloud platforms. Malicious actors can navigate between on-premises systems and cloud environments effortlessly, jeopardizing crucial cloud assets.