惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
Y
Y Combinator Blog
M
MIT News - Artificial intelligence
The Cloudflare Blog
WordPress大学
WordPress大学
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 司徒正美
小众软件
小众软件
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
J
Java Code Geeks
云风的 BLOG
云风的 BLOG
C
Check Point Blog
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
V
V2EX
F
Fortinet All Blogs
B
Blog
大猫的无限游戏
大猫的无限游戏
N
Netflix TechBlog - Medium
B
Blog RSS Feed
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Enterprise Cybersecurity Software Fails 20% of the Time, ...
Danny Palmer · 2026-03-24 · via www.infosecurity-magazine.com

Endpoint cybersecurity software fails to protect one in five enterprise devices, leaving organizations vulnerable to cyber threats, research by Absolute Security has warned.

This protection gap means that organizations face the equivalent of 76 days a year in which they’re providing cybercriminals which increased access to their network, potentially leading to data breaches and downtime.

The findings come from Absolute Security’s 2026 Resilience Risk Index. The report, published on March 23, is based on analysis of device-level telemetry across tens of millions of enterprise endpoints, which have been validated as using endpoint management and cybersecurity software

Christy Wyatt, president and CEO of Absolute Security, commented, “Cyber-attacks are inevitable, downtime is optional.”

“The cybersecurity industry has rushed to provide innovations that detect and prevent threats, unfortunately it’s lagging when it comes to ensuring that tools can remain operational when they are needed most,” she added.

Slow Patch Management Leaves Systems Vulnerable

No single issue is the reason for this, but rather it is because of the growing complexity of enterprise IT environments.

The report noted that delays in applying security patches and software updates remain common, with almost a quarter (24%) of endpoint vulnerability management platforms classed as operating outside of compliance, up from 20% in the previous year.

This means that a growing share of enterprise endpoints are operating with software which is known to be vulnerable to potential security issues and exploitation but has not been remediated. These vulnerabilities expand the exploitation window which attackers can use to their advantage.

This issue also persists at an operating system level. According to analysis by Absolute, the application of critical updates for Microsoft Windows were delayed by an average of 127 days, leaving devices vulnerable to downtime caused by zero-day vulnerabilities and other cyber-attacks.

Meanwhile, nearly 10% of enterprise endpoints are now permanently unpatched — creating vulnerabilities that organizations may never be able to remediate. This is particularly the case if organizations continue to use Windows 10, which has been out of support since October 2025.

Overall, some organizations are struggling to manage their cybersecurity posture. This  ultimately results in the enterprise being vulnerable to cyber-attacks as well as at a disadvantage because of downtime and remediation.

However, enforcing policies around patch management, especially for enterprise security solutions and operating systems can go a long way to ensuring that networks are protected from cyber threats.

“In modern enterprise environments, the question is no longer simply whether systems are patched. It is whether organizations retain the ability to enforce change across millions of endpoints before exposure turns into disruption. And that challenge is becoming more urgent as the endpoint’s role continues to evolve,” said the report.