OT vulnerabilities jump 88 percent as critical infrastructure continues to be targeted, Skybox reveals

OT vulnerabilities jump 88 percent as critical infrastructure continues to be targeted, Skybox reveals

Threat intelligence firm Skybox Security has disclosed a ‘relentless rise’ in OT vulnerabilities primarily fueled by the accelerating pace of technological change. The critical infrastructure sector was also targeted and attacked, while the average cost of data breaches hit US$4.24 million, up nearly 10 percent from the previous year.

The findings also showed how vulnerabilities, especially in the operational technology (OT) sector, are increasing at an unprecedented rate, while hackers have gotten better and faster at capitalizing on them with new malware and exploits. As a result, cybersecurity teams are defending a larger, more porous perimeter against a growing array of threats while struggling with greater complexity and tighter resource constraints.

In a report released on Tuesday titled ‘Vulnerability and threat trends report 2022,’ Skybox clarifies that a reset is long overdue. “Cybersecurity organizations must move beyond the status quo to a new generation of tools and techniques that flip the script from firefighting to prevention, from manual labor to automated efficiency, and from scattershot, short-term fixes to systematic, comprehensive, and continuous risk reduction,” it added.

“The sheer volume of accumulated risks — hundreds of thousands or even millions of vulnerability instances within organizations — means they can’t possibly patch all of them,” Ran Abramson, threat intelligence analyst at Skybox Security Research Lab, wrote in a media statement. “To prevent cybersecurity incidents, it is critical to prioritize exposed vulnerabilities that could cause the most significant disruption. Then, apply appropriate remediation options including configuration changes or network segmentation to eliminate risk, even before patches are applied or in cases where patches aren’t available,” he added.

Skybox reported that 20,175 new vulnerabilities were published in 2021, up from 18,341 in 2020 –  the most vulnerabilities ever reported in a single year, and the biggest year-over-year increase since 2018. The growth increased in the second half of the year, with 10,723 CVEs published were the most that Skybox has ever seen in six months. The new vulnerabilities add to a huge cumulative total, making it harder for security teams to prioritize and remediate issues.

Skybox said that new vulnerabilities, worrisome as they may be, are just the tip of the iceberg. The total number of vulnerabilities published over the last ten years reached 166,938 in 2021 — a three-fold increase over a decade. These cumulative vulnerabilities, piling up year after year, represent an enormous aggregate risk that has left organizations struggling with a mountain of ‘cybersecurity debt.’

Skybox highlighted that the sheer volume of accumulated risks — hundreds of thousands or even millions of vulnerability instances within some large organizations — means that security teams can’t possibly isolate and patch all of them. Instead, they need to focus on the exposed vulnerabilities that, if exploited, could cause the most significant business impacts.

In addition, OT vulnerabilities jumped 88 percent, from 690 in 2020 to 1,295 in 2021. At the same time, OT assets are increasingly connected to networks, exposing critical infrastructure and other vital systems to potentially devastating breaches. OT systems support energy, water, transportation, environmental control systems, and other essential equipment. Attacks on OT systems have risen precipitously, disrupting operations and even jeopardizing health and safety. The OT vulnerabilities are based on new vulnerabilities shared by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) last year. 

Designed with weak or non-existent security controls, most OT systems are soft targets for cyberattacks, Skybox observed in its report. “The only thing protecting them in the past was that they were inaccessible to external threats because they were air-gapped or connected only to isolated internal networks. That’s changed. Many systems are now connected to larger IT networks and the internet itself, often wirelessly. Much of this networking has taken place without any security oversight or planning; devices have been brought online in ad-hoc fashion,” it added.

“As OT and IT networks converge, threat actors are increasingly exploiting vulnerabilities in one environment to reach assets in the other,” Skybox said in its report. “Many OT attacks begin with an IT breach, followed by lateral movement to access OT equipment. Conversely, intruders may use OT systems as stepping stones to IT networks, where they can deliver malicious payloads, exfiltrate data, launch ransomware attacks, and conduct other exploits. Increasingly, malware is designed to exploit both IT and OT resources,” it added.

While the ​​Colonial Pipeline attack prompted the U.S. federal government to elevate OT to a matter of national security, ​awareness is still lagging in many organizations. Skybox Security’s recent survey of OT security decision-makers revealed that cybersecurity risk is widely underestimated. “For example, 56% of all respondents were highly confident that their organization would not experience an OT breach in the next year, yet 83% said they had at least one OT security breach in the prior 36 months. Forty percent of all respondents said that OT is an afterthought compared to other digital initiatives,” it added.

Skybox said that compounding the problem is the fact that many flaws in OT systems are hidden from security teams, as most OT systems are hard or impossible to scan. At best, companies scan them infrequently (once or twice a year) because they can’t afford to take these mission-critical systems offline or degrade service. Likewise, patching many OT systems is technically impossible or too cumbersome and costly to address OT vulnerabilities. As a result, many OT environments are riddled with security holes, with no effective way to assess weaknesses, much less fix them.

“A different approach is clearly needed: one that eliminates the blind spots by providing a complete view of the OT and IT attack surface and that also facilitates targeted, effective remediation,” the Skybox report observed.

Skybox also threw light on hackers increasingly employing multistage attacks to circumvent defenses and burrow deeper into organizations. “Once restricted to the most sophisticated hackers, these chained attacks can now be carried out even by relative novices, thanks to readily available exploit kits and MaaS that enable inexperienced hackers to execute complicated exploits with no expertise,” the report said.

Typically multistage attacks begin when a hacker takes advantage of a stolen credential or common vulnerability to gain initial access to a system such as a user workstation or network device. “Once they’ve gained a beachhead, they can use a series of local exploits to escalate their privileges to administrator status, conduct reconnaissance, and compromise high-value resources such as directories and hard drives containing sensitive information. This allows them to encrypt or exfiltrate critical data as part of ransomware attacks,” according to Skybox.

The report also disclosed that cryptojacking and ransomware lead new malware production. The malware industry continues to churn out various malicious software, particularly cryptojacking and ransomware programs, which increased by 75 percent and 42 percent, respectively. These programs make it easier for threat actors to mount attacks and turn a quick profit. They demonstrate how nimbly malware developers respond to new market opportunities and economic incentives.

Skybox noted that like cryptojacking, ransomware can yield a high ROI (return on investment) with a low barrier to entry, courtesy the ‘off-the-shelf’ products and services that do the heavy lifting. In the past, such attacks required a degree of sophistication and resources, but no longer.

The report also found that new malware is increasingly targeting more recent vulnerabilities, such as those reported in the last three years. “This indicates that malware developers are moving more swiftly to exploit the latest weaknesses. Often this is accomplished by simply tweaking existing malware to perform new exploits,” it added.

Given the number of new vulnerabilities exploited in the wild rose by 24 percent, Skybox said that is ‘a sign of just how quickly cybercriminals are now moving to capitalize on new weaknesses, shrinking the window that security teams have to detect and address vulnerabilities before an attack,’ it added.

Skybox disclosed that hackers were quick to exploit the Log4Shell vulnerability in December. According to one source, there were more than a million Log4j-related attacks in the first week after the vulnerability was publicly announced, and as documented by Skybox Research Lab, Log4Shell quickly became one of the top targets of new malware.

“Log4Shell highlights the growing danger posed by open-source software and the supply chain,” Skybox said. “Vulnerable or malware-infected components can make their way into widely used software products in ways that are hard to detect and extremely difficult to root out. Such was the case with the Solar Winds hack, and so it is with vulnerable Log4j libraries tucked away in a multitude of enterprise software, with no quick and efficient way to find, much less fix, all of them,” it added.

Following the deteriorating threat landscape, there increasingly is a need to shift away from existing practices. Traditional vulnerability management strategies are wholly out of step with contemporary realities. Approaches centered on scanning and patching are too slow, too scattershot, too laborious, and too costly, as they fail to catch many actual threats while squandering valuable resources on false alarms. As a result, security professionals are fighting a rearguard battle against a growing array of threats and adversaries.

Skybox said in its report that it is time to give the advantage back to the defenders. That means turning the tables and changing the dynamic – from reactive to proactive, from siloed to holistic, from severity-focused to risk-centric, from manual to automated, and from intermittent to continuous. The report proposes the adoption of the vulnerability lifecycle management that offers holistic discovery, precise prioritization, targeted mitigation and remediation, and ongoing oversight

“The lifecycle approach transforms vulnerability management from a sporadic, patchwork process to a continuous and comprehensive one,” Skybox said. “Most importantly, it enables organizations to move from reaction to prevention — no longer stuck responding to threats after the fact but prepared for whatever may come,” it added.

Last September, Skybox reported that increasing threats of vulnerabilities are steadily rising, particularly in sensitive areas such as OT systems and network devices, putting vital infrastructure at risk. The skyrocketing number of OT devices in many organizations, fueled in part by the explosion of IIoT (industrial Internet of Things) products, is adding to the challenge.

Related