follow

help me to improve quality

donate

Pages

Tuesday 18 July 2017

Over 70,000 Memcached Servers Still Vulnerable to Remote Hacking






Results from February Scan:


  • Total servers exposed on the Internet — 107,786
  • Servers still vulnerable — 85,121
  • Servers still vulnerable but require authentication — 23,707


And the top 5 countries with most vulnerable servers are the United States, followed by China, United Kingdom, France and Germany.

Results from July Scan:


  • Total servers exposed on the Internet — 106,001
  • servers still vulnerable — 73,403
  • Servers still vulnerable but require authentication — 18,012


After comparing results from both the Internet scans, researchers learned that only 2,958 servers found vulnerable in February scan had been patched before July scan, while the remaining are still left vulnerable to the remote hack.

Data Breach & Ransom Threats


This ignorance by organisations to apply patches on time is concerning, as Talos researchers warned that these vulnerable Memcached installations could be an easy target of ransomware attacks similar to the one that hit MongoDB databases in late December.


"With the recent spate of worm attacks leveraging vulnerabilities this should be a red flag for administrators around the world," the researchers concluded.

"If left unaddressed the vulnerabilities could be leveraged to impact organisations globally and affect business severely. It is highly recommended that these systems be patched immediately to help mitigate the risk to organisations."

Customers and organisations are advised to apply the patch as soon as possible even to Memcached deployments in "trusted" environments, as attackers with existing access could target vulnerable servers to move laterally within those networks.  

1 comments: