Listen to the spooks and stop ignoring known vulnerabilities!

In 2023, threat actors exploited more zero-day vulnerabilities than they did in 2022. Given the number of reported zero-days already this year, I strongly expect that pattern will be repeated for 2024.

But it isn’t just the number of zero-days that worries me: it’s the way in which they were exploited to gain access to enterprises large and small.

In 2022, less than half of the “most frequently exploited” vulnerabilities list, published annually and jointly by the five-eyes intelligence agencies, began their journey as zero-days. In 2023, that became the majority.

โ€œMalicious cyber actors continue to have the most success exploiting vulnerabilities within two years after public disclosure of the vulnerability,โ€ the newly published five-eyes joint cybersecurity advisory said. This isn’t history. This is the here and present. You need to pay attention to the 2023 list in 2024 and into next year.

Now consider who’s warning you about these vulnerabilities. It’s the US Cybersecurity and Infrastructure Security Agency (CISA). It’s the FBI and the National Security Agency (NSA) . How about adding the National Cyber Security Centre (NCSC-UK) into the mix?

If that still isnโ€™t enough, I doubt that little old me is going to make much difference to your security posture, but Iโ€™ll sure as heck give it a go…

What you need to do about known vulnerabilities

First, let’s try some name recognition. Do Apache, Atlassian, Barracuda Networks, Cisco, Fortinet, JetBrains, Microsoft, Progress or Zoho ring any bells? Those vendors were all victims of the top 15 most frequently exploited vulnerabilities across 2023.

The impacted products included Confluence Data Center and Server, FortiOS, Log4j2, ManageEngine, MOVEit Transfer and Microsoft Office.

The names are important. They represent some of the most commonly used products from the biggest vendors, which is why they are such a target for threat actors looking for ways into your networks and ultimately your data.

Iโ€™m not going to list all the CVEs here, because that would be more boring than a Texan with a sniff of oil. Instead, Iโ€™m going to implore you to go and read the document itself, if you take security in any way seriously for your organisation.

Hereโ€™s another link. It isnโ€™t a PDF like the first one; see how easy Iโ€™m making this for you.

Most importantly, you need to focus your attention on the litigations offered by these intelligence agencies. I know that there will be a subset of readers who distrust anything the three-letter acronym agencies have to say, but take a deep breath, swallow hard, and do it for once. Please.

  • Update your systems and software.
  • Routinely perform automated asset discovery.
  • Implement a robust patch management process.
  • Perform regular secure system backups.
  • Maintain an updated cybersecurity incident response plan.
  • Enforce phishing-resistant multifactor authentication for all users.
  • Regularly review, validate, remove unprivileged accounts.
  • Configure access controls using the principle of least privilege.
  • Configure and secure internet-facing network devices.
  • Continuously monitor the attack surface.

Look, I didnโ€™t say it was going to be easy. There is nothing in life thatโ€™s worth having that is easy. That includes a strong security posture, but, as in life, itโ€™s worth working hard for.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.