Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Age-related cognitive decline can be slowed by eating healthy and exercising your body and brain

July 28, 2025

Crème fraîche creates a creamy broth in a briny-sweet steamed clams recipe

July 28, 2025

South Korean beauty products could be subject to steep tariffs

July 28, 2025
Facebook X (Twitter) Instagram
Trending
  • Age-related cognitive decline can be slowed by eating healthy and exercising your body and brain
  • Crème fraîche creates a creamy broth in a briny-sweet steamed clams recipe
  • South Korean beauty products could be subject to steep tariffs
  • What to Stream: Reneé Rapp, Anthony Mackie and Jason Momoa
  • Trump calls for DC to restore old NFL name as experts say Native mascots cause harm
  • The Founder Of Shake Shack Is Now A Billionaire
  • What to know about the dating app Tea and its hacked data
  • If you don’t have diabetes, do you really need a continuous glucose monitor?
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Monday, July 28
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Verizon DBIR Flags Major Patch Delays on VPNs, Edge Appliances 
Cybersecurity

Verizon DBIR Flags Major Patch Delays on VPNs, Edge Appliances 

adminBy adminApril 24, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 46


The latest Verizon Data Breach Investigations Report (DBIR) landed this week with a startling statistic about the security posture of perimeter gear: barely half of the zero‑days exploited last year in VPNs and internet‑facing appliances were fully patched, and it took a median 32 days to get there. 

Those weak spots, abundant in devices from Ivanti, Fortinet, SonicWall and Citrix, pushed vulnerability exploitation up 34 percent year‑over‑year, making it the second‑most common way professional hackers broke in, behind only stolen credentials.

“The percentage of edge devices and VPNs as a target on our exploitation of vulnerabilities action was 22%, and it grew almost eight-fold from the 3% found in last year’s report,” according to the DBIR. 

“Organizations worked very hard to patch those edge device vulnerabilities, but our analysis showed only about 54% of those were fully remediated throughout the year.”

The findings match public reporting on waves of malware campaigns by nation-state APTs and ransomware gangs against VPN appliances, edge routers and firewalls.

Verizon’s researchers say credential abuse accounted for 22 percent of initial access (flat from last year), while exploitation of unpatched vulnerabilities climbed to 20 percent. 

Data-extortion ransomware hacks appeared in 44 percent of the breaches studied, a big 37 percent jump, and the DBIR found that the median payment fell to $115,000 from $150,000. 

The report noted that 64% of corporate ransomware victims refused to pay at all, up from 50 percent two years ago. The numbers diverge sharply by company size: while ransomware factored into 39 percent of breaches at large enterprises, it hit small and mid‑sized businesses in 88 percent of cases, Verizon said.

Advertisement. Scroll to continue reading.

The report also called attention to data breaches that hinged on a hack of a third party software supplier, MSP or partner portal.  These supply chain breaches doubled to 30 percent and Verizon investigators found a 94‑day median lag between discovery of leaked secrets in public code‑repos and remediation.

The DBIR, which compiles raw forensics data from law‑enforcement agencies, insurers, MSSPs and CERTs worldwide, found that nation state-backed APT activity accounted for 17% of breaches, with vulnerability exploitation providing the beachhead 70 percent of the time. 

While cyberespionage remains the main motive, the DBIR noted that 28 percent of nation state‑linked cases aimed directly at financial gain, confirming public reports that some government hackers are moonlighting for cash.

The report also warns that a significant number of breaches (60%) still involve email phishing, mis-sent data or password reuse as humans continue to fall for cybercriminal tricks.

The report found that infostealer logs show 30 percent of compromised endpoints belonged to licensed enterprise devices, but almost half were unmanaged machines storing both personal and corporate credentials, a sign that bring‑your‑own‑device policies continue to complicate corporate defenses.

Published annually since 2008, the DBIR is treated as a barometer for how attacks unfold in practice and Verizon said this edition parsed data from more than 22,000 security incidents, including 12,195 confirmed breaches. 

Related: Chinese APT Tools Found in Ransomware, Blurring Attribution Lines

Related: FBI Uses Malware ‘Self-Delete’ Trick to Erase PlugX From US Computers

Related: Chinese Cyberspy Possibly Launching Ransomware Attacks as Side Job

Related: Rapid7 Reveals RCE Path in Ivanti VPN Appliance After Silent Patch Debacle

Related: Chinese APT Pounces on Misdiagnosed RCE in Ivanti VPN Appliances  



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

The Founder Of Shake Shack Is Now A Billionaire

July 26, 2025

Todd Williamson/Getty Images for Airbnb Danny Meyer made his name opening up a string of…

‘South Park’ Creators Trey Parker and Matt Stone Are Now Billionaires

July 25, 2025

How Jeffrey Epstein Got So Rich

July 25, 2025

Vanta Raises Funds At $4 Billion Valuation—Despite Not Needing Cash

July 23, 2025
Our Picks

Age-related cognitive decline can be slowed by eating healthy and exercising your body and brain

July 28, 2025

Crème fraîche creates a creamy broth in a briny-sweet steamed clams recipe

July 28, 2025

South Korean beauty products could be subject to steep tariffs

July 28, 2025

What to Stream: Reneé Rapp, Anthony Mackie and Jason Momoa

July 28, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.