Select your language

Three types of vulnerabilities commonly exploited in cybersecurity

Tres tipos de vulnerabilidades comúnmente explotadas en ciberseguridad

International. Certain types of known vulnerabilities that are usually being exploited in computer systems were shared by the specialist, Fluid Attacks, a company that emphasizes the need to check daily that the systems that allow users to perform their work are updated and free of vulnerabilities.

Felipe Gómez, LATAM Manager of Fluid Attacks, states that "there are a lot of known vulnerabilities that cybercriminals are routinely taking advantage of. That is why it is very important for organizations to ensure that they have a solution to continuously check if the software they use, especially the components that can be accessed from the Internet or by visitors or intruders in their corporate network, is free of already known vulnerabilities."

Companies are often more exposed than they realize by having outdated software. Many of them do not address this problem quickly enough and become victims of cyberattacks. Below, Fluid Attacks provides details of three types of vulnerabilities that are now commonly exploited by attackers:

Path traversal: A software component can be hacked if it allows access to files that are not supposed to be accessible. Attackers can then bypass the boundaries of the software and gain access to functionality or sensitive information.

Remote Code Execution (RCE): This vulnerability allows remote execution of commands on the computing device of another person or organization. If a software component has this type of vulnerability, an internal or external attacker can trigger unexpected actions on systems.

- Publicidad -

Elevation of privilege: Typically, misconfiguration allows users to assign themselves, in some way, rights that they shouldn't have. For example, a sales representative in a company could exploit this vulnerability to give more resources or authorizations than they should in their role.

"Closing these 'invisible doors' could contribute significantly to risk management, saving effort and money, and preserving good reputation in organizations. Being aware of these security issues can help them avoid falling victim to the already frequent ransomware-type attacks, which have increased globally by 93% and have a fairly high international impact," adds Gómez.

Something that organizations must be clear about is that cybersecurity is not simply focused on a couple of things that are solved once and for all. Cybersecurity has a fairly broad spectrum. That is why, although, as in this case, obsolete computer programs must be taken into consideration due to the risk they represent, other components of computer and business environments must also be addressed by organizations as potential attack surfaces.

"Continuous controls are essential, as threats evolve steadily and rapidly, in an increasingly digital and software-mediated world. Through ethical hacking or continuous penetration testing, any organization can benefit, since among many other security problems, they are pointed out where those 'invisible doors' are and provided with the necessary information to close them effectively, "concludes the executive.

Duván Chaverra Agudelo
Duván Chaverra AgudeloEmail: [email protected]
Editor Jefe
Jefe Editorial en Latin Press, Inc,. Comunicador Social y Periodista con experiencia de más de 13 años en medios de comunicación. Apasionado por la tecnología.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The growing convergence between physical and digital threats is forcing organizations to rethink their security strategies. Faced with this scenario, there is a need for comprehensive approaches...

AI applied to medical security

AI applied to medical security

The Directorate of the Medical Emergency System (SEM), attached to the Ministry of Health of El Salvador, strengthened its technological infrastructure with the modernization of its video...

Eight Red Dot Awards Highlight Innovation in Technology Design

Eight Red Dot Awards Highlight Innovation in Technology Design

International. The technology company Ajax Systems announced that it has won eight awards in the Red Dot Design Award, one of the most prestigious global awards in the field of industrial design....

Villa María del Triunfo reinforces its security with intelligent video surveillance

Villa María del Triunfo reinforces its security with intelligent video surveillance

Peru. The district of Villa María del Triunfo has launched an intelligent video surveillance system that already shows results in terms of citizen security and that will be expanded in a second...

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Denmark. The company reported net income of $340 million in 2025, representing a 10% growth from the previous year. The company spent about a third of this revenue on innovation, with an emphasis on...

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

United States. In response to the growth in demand for monitoring and management software solutions in the security industry, Micro Key Solutions announced the expansion of its operations in Latin...

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Mexico. Grupo Multisistemas de Seguridad Industrial (GMSI) advances in its national growth strategy with the inauguration of new offices in Morelia, Michoacán, with the aim of expanding its coverage...

Case study: Security system modernization with artificial intelligence and centralized monitoring

Case study: Security system modernization with artificial intelligence and centralized monitoring

Mexico City. The Superior Audit Office of the Federation (ASF) implemented an ambitious technological renovation project in its five headquarters located in Mexico City, with the aim of...

Automated key and equipment management strengthens security in mining operations

Automated key and equipment management strengthens security in mining operations

International. Access and equipment management in the mining industry is evolving towards increasingly automated models, in response to operational complexity and occupational safety demands.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter