Intelligent CISO Issue 27 | Page 19

cyber trends It is essential for us to take our digital health as seriously as we take our physical health. Stay strong and secured. From supporting channels that carry a small fraction of network activity, these services have become the mainstream channels that provide most of the access to on-premises resources. Since these services used to be accessed only occasionally, many enterprises have not patched the services’ security vulnerabilities. Here lies a huge opportunity for the attackers. The remote code execution vulnerabilities on Remote Desktop Protocol (RDP) are highly wormable. For instance, the BlueKeep vulnerability, which is extremely wormable, is still out there and attackers are trying to develop an exploit for this. Considering the seriousness of this security loophole, Microsoft even released patches for operating systems such as Windows XP and Vista, which were declared EOL. BlueKeep is just one such vulnerability. There are numerous known and unknown RDP and VPNbased vulnerabilities out there, providing www.intelligentciso.com | Issue 27 19