Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
PR Newswire
SAN JOSE, Calif., Feb. 18, 2022
SAN JOSE, Calif., Feb. 18, 2022 /PRNewswire/ -- The Application Security Division of NTT Ltd., a world leader in application security, today released AppSec Stats Flash: 2021Year in Review, an analysis of the data generated from more than 15 million application security scans performed by organizations throughout 2021. The report focuses on changes within Window-of-Exposure and Time-to-Fix data across industry verticals, such as Healthcare, Manufacturing, Utilities and Retail, and aims to arm organizations with actionable key takeaways for securing their web applications in the modern threat landscape.
Within the report, NTT Application Security researchers found that half (50 percent) of all sites tested were vulnerable to at least one serious exploitable vulnerability throughout 2021, while only 27 percent were vulnerable less than thirty days. Additionally, the report uncovers a concerning downward trend in organizations' remediation rates of critical vulnerabilities, which fell from 54 percent to 47 percent throughout the course of the year.
Key findings from the report include:
"Marred by the Colonial Pipeline attack and the ongoing Log4j fallout, the events of 2021 brought application security to the forefront of the wider media and public conversation," said Craig Hinkley, chief executive officer at NTT Application Security. "Despite the elevated push to remediate critical vulnerabilities in both public and private sector applications, there's evidence that suggests this inadvertently led to an overall negative result, as these initiatives seem to have occurred as a tradeoff with—rather than an addition to—existing remediation efforts. Moving forward, it is critical for application security programs to evolve toward a more comprehensive approach that brings together robust security testing, strategic remediation efforts and contextual education of developers, development operations and security operations personnel."
The report also examines the most common types of security vulnerabilities discovered in application security tests throughout 2021. Information Leakage, Insufficient Session Expiration, Insufficient Transport Layer Protection, Cross-Site Scripting and Content Spoofing were found to be the five most likely vulnerability classes identified throughout the year.
Those interested in learning more about the findings can download the report today, or visit here to find previous AppSec Stats Flash reports examining the state of application security on a month-by-month basis.
For more information about NTT's Application Security Division and its recently launched WhiteHat Vantage platform, please visit whitehatsec.com.
About NTT
NTT Ltd. is a leading global technology services company. Working with organizations around the world, we achieve business outcomes through intelligent technology solutions. For us, intelligent means data driven, connected, digital and secure. Our global assets and integrated ICT stack capabilities provide unique offerings in cloud-enabling networking, hybrid cloud, data centers, digital transformation, client experience, workplace and cybersecurity. As a global ICT provider, we employ more than 40,000 people in a diverse and dynamic workplace that spans 57 countries, trading in 73 countries and delivering services in over 200 countries and regions. Together we enable the connected future. Visit us at hello.global.ntt
Media Contact
Chris Marsh
Senior Manager, Analyst Relations & Communications
NTT Application Security
chris.marsh@global.ntt
Allison Arvanitis
Lumina Communications for NTT Application Security
NTTAppSec@luminapr.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/new-report-shows-half-of-websites-were-vulnerable-to-exploitation-throughout-2021-301485539.html
SOURCE NTT Ltd.
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs