Organizations used to be targets of choice — that is, they were specifically identified and hand-picked by attackers.

Now? Every single organization in the world can be a target of opportunity.

Thank automation for allowing threat actors to move at machine speeds. They are expanding their tools beyond single fishing hooks or spears to a “huge fleet of trawlers” that cost mere tens of dollars on the dark web, explained Matt Kraning, CTO of Cortex at Palo Alto Networks.

This rapidly evolving attack paradigm is outlined along with other key trends in the 2023 Unit 42 Attack Surface Threat Report from Palo Alto Networks’ threat intelligence group Unit 42.

The analysis is based on petabytes of information collected by Unit 42 on internet-accessible exposures across 250 organizations in 2022 and 2023.

“It’s the easiest possible time for attackers, in a low-cost and low-risk way, to find and exploit all these systems globally and gain access to the networks of large companies,” Kraning told SDxCentral.

Cloud the dominant attack surface

Per Unit 42, the cloud continues to be the dominant attack surface: The majority (80%) of medium, high or critical exposures were observed on assets hosted in the cloud, compared to those on-premise (19%). Furthermore, more than 75% of publicly accessible software development infrastructure exposures were found in the cloud.

Kraning said that, as companies move to the cloud, more processes are taking place outside of sanctioned environments. This is particularly true of large organizations with divisions on multiple continents.

As such, they likely aren’t going to have all cloud activity going on in a centrally managed way, which makes cloud resources incredibly difficult to track. Today's IT is decentralized by nature, blurring visibility.

“No large org actually knows all of the IT that they have on the internet — at most they might know 60 or 70%,” said Kraning.

It’s a simple fact that once organizations reach a certain size — typically a few thousand people — they lose visibility.

“The root cause tends to be not knowing everything, and you can’t protect anything you don’t know about,” said Kraning, adding that, “the cloud itself is very fast-changing.”

Indeed, Unit 42 found that in a given month, 20% of cloud-based IT infrastructure will be taken offline and replaced with new or updated services. This “cloud dynamism” and the deployment of new services is generally responsible for nearly half of new high or critical cloud exposures every month.

These issues are “not being tracked, they’re not being remediated by security teams,” said Kraning.

Attackers moving at ‘machine speed’

The Unit 42 report also found that attackers are moving at “machine speed.” For instance, they can scan the entire Internet Protocol Version 4 (IPv4) address space for vulnerable targets in just minutes.

The team analyzed 30 common vulnerabilities and exposures (CVEs), finding that three were exploited within hours of public disclosure and 63% within 12 weeks of disclosure.

Furthermore, of 15 remote code execution (RCE) vulnerabilities analyzed, 20% were targeted by ransomware gangs within hours of disclosure and 40% were exploited within eight weeks of publication.

As Kraning noted, attacker automation today is simple and cheap. Once a zero-day vulnerability or other risk is leaked or developed, cheap commodity methods on the dark web — up for grabs for as little as $100 — allow threat actors to use those exploits against “every single connected system on the internet.”

This underscores the fact that no industry or organization is spared. “The biggest takeaway is it’s not just certain industries and not others,” Kraning said. “What this report highlights is how widespread these organizational issues are.”

Remote access exposures on the rise

Not surprisingly with many organizations offering hybrid or fully remote work scenarios, remote access exposures are widespread, accounting for 20% of exposures, according to the report. Microsoft’s Remote Desktop Protocol (RDP) is the most prevalent remote access service in the world and accounts for more than 40% of exposed remote access services.

More than 85% of organizations analyzed by Unit 42 had RDP internet-accessible for at least 25% of the month. This ultimately left them open to ransomware attacks or unauthorized login attempts. Other remote access services include Secure Shell (SSH) or virtual network computing (VNC) that, when compromised, allow attackers to gain unauthorized access to a network or system.

Kraning explained that enterprises often operate these systems with the assumption that they are on a protected network like the intranet. But if they’re exposed to the internet, “it’s like opening up a corporate laptop and leaving it logged in, in Central Park.”

Asset inventory, scenarios and testing critical

How can organizations protect themselves? There’s no one answer.

For starters, Kraning said, it’s important to have an asset inventory system. Enterprise leaders should be able to answer basic inventory questions — and, importantly, have confidence in those answers. For instance: How many routers does the organization run and manage? Why do you have confidence that that number is correct?

Unfortunately, he pointed out, “most organizations are not able to answer that question.”

Furthermore, organizations should have the capability to perform scenarios and map out how they would respond to an attack, he said. It’s critical that they test their ability to remediate vulnerabilities across the entire organization and have quick access to the help they need.

“If you’re doing that sort of exercise for the first time during an emergency, it’s way too late,” said Kraning.

Additional key findings in the Unit 42 report
  • Web framework takeover accounts for 22% of exposures. This is when attackers actively seek out and target websites running vulnerable software, the common being insecure versions of Apache web servers, PHP and jQuery.
  • IT and networking infrastructure exposures make up 17% of exposures. These can include application layer protocols like Simple Network Management Protocol (SNMP), Point-to-Point Tunneling Protocol (PPTP) and internet-accessible administrative login pages.
  • File sharing exposures account for 12%. Examples include publicly accessible file-sharing services, file transfer protocol (FTP) and misconfigured cloud storage. Attackers can access stored data as well future data sent through them.
  • Database exposures and vulnerabilities make up 9% of exposures.

Additional exposures include unpatched, misconfigured and end-of-life (EoL) systems; weak or insecure cryptography; IoT, embedded devices and operational technologies (OT); unencrypted logins and text protocols; development infrastructure; and business operations applications.