International. Certain types of known vulnerabilities that are usually being exploited in computer systems were shared by the specialist, Fluid Attacks, a company that emphasizes the need to check daily that the systems that allow users to perform their work are updated and free of vulnerabilities.
Felipe Gómez, LATAM Manager of Fluid Attacks, states that "there are a lot of known vulnerabilities that cybercriminals are routinely taking advantage of. That is why it is very important for organizations to ensure that they have a solution to continuously check if the software they use, especially the components that can be accessed from the Internet or by visitors or intruders in their corporate network, is free of already known vulnerabilities."
Companies are often more exposed than they realize by having outdated software. Many of them do not address this problem quickly enough and become victims of cyberattacks. Below, Fluid Attacks provides details of three types of vulnerabilities that are now commonly exploited by attackers:
Path traversal: A software component can be hacked if it allows access to files that are not supposed to be accessible. Attackers can then bypass the boundaries of the software and gain access to functionality or sensitive information.
Remote Code Execution (RCE): This vulnerability allows remote execution of commands on the computing device of another person or organization. If a software component has this type of vulnerability, an internal or external attacker can trigger unexpected actions on systems.
Elevation of privilege: Typically, misconfiguration allows users to assign themselves, in some way, rights that they shouldn't have. For example, a sales representative in a company could exploit this vulnerability to give more resources or authorizations than they should in their role.
"Closing these 'invisible doors' could contribute significantly to risk management, saving effort and money, and preserving good reputation in organizations. Being aware of these security issues can help them avoid falling victim to the already frequent ransomware-type attacks, which have increased globally by 93% and have a fairly high international impact," adds Gómez.
Something that organizations must be clear about is that cybersecurity is not simply focused on a couple of things that are solved once and for all. Cybersecurity has a fairly broad spectrum. That is why, although, as in this case, obsolete computer programs must be taken into consideration due to the risk they represent, other components of computer and business environments must also be addressed by organizations as potential attack surfaces.
"Continuous controls are essential, as threats evolve steadily and rapidly, in an increasingly digital and software-mediated world. Through ethical hacking or continuous penetration testing, any organization can benefit, since among many other security problems, they are pointed out where those 'invisible doors' are and provided with the necessary information to close them effectively, "concludes the executive.


