Most Popular Stories
- Chrome 17's new features enhance speed, security
- Bug in Trendnet webcams exposes them to public viewing
- Spotlight: Intel launches 520 Series solid-state drive
- Apple's iPad 3 will be unveiled first week of March, says report
- Microsoft: How Windows 8 on ARM will be different
- There's no escaping the app economy
Events
- MDSL Telecom Expense Management Roadshow
Feb 21–23, 2012 — New York, Houston, Chicago - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> Tech world's top flops and fiascos of 2011 | Windows 8 slideshow | Cybersecurity | Caron's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
FierceCIO provides CIOs with IT best practices, business intelligence, and forward-looking IT strategies. Join 32,000+ industry insiders who get FierceCIO twice a week via email and save time.
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
- Durable Smart Devices for Mobile Field Forces: Selection and Evaluation Criteria
- Security Intelligence: Changing the Way You See Your SAP Landscape
- Whitepaper: 10 Reasons You Absolutely Need AD Reporting
- The Shortcut Guide to Secure, Managed File Transfer
Study: Old security flaws cause some breaches
A new study finds that many companies still have old security vulnerabilities lurking in their systems, leaving a back door open for hackers to get in and attack. The report from Trustwave is based on an analysis of more than 1,900 penetration tests and more than 200 data breach investigations conducted for clients including American Express, MasterCard and several large retailers.
Until now, many companies have been relying on finding the latest vulnerabilities, not reaching back to old and supposedly well-understood ones. But the finding sets the stage for companies to do another inventory of their systems, looking for cracks that may have been left in place for years.
Are you one of these companies? And would it be worth your while to patch your system to prevent an opening?
The most common vulnerability discovered during Tustwave's penetration tests involved the management interfaces for web application engines such as WebSphere and ColdFusion. Amazingly, in many cases, the management interfaces were accessible directly from the Internet and had little or no password protection.
There is some good news out of this survey. It means that companies will not have to provide expensive fixes to a problem easily and more cheaply solved.
For more on old vulnerabilities:
- see this CIO.com article
Related Articles:
The 10 most terrifying IT breaches of 2009
11 hidden security threats
Cost of data breaches gets higher
Related Stories
- Is your VoIP network secure?
- Security woes dog Microsoft
- Lotus Notes catches a bug
- Identy theft is not cheap
- Hacker exposes eBay users' personal info
- CSI: IT security
- UCLA making databases less sensitive, more secure
- Agriculture agency latest victim of data theft
- Survey: Many CIOs getting stricter about social networking
- Hacking is top cause of data breaches
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




