<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

Winter Is Coming, NSA Releases Top 25 Exploits: Are You Ready?

Editor's note, October 2026: This article was first published in November 2020. It refers to the NSA advisory of 20 October 2020 on 25 publicly known vulnerabilities that Chinese state-sponsored actors were actively exploiting, including flaws in Pulse Secure Connect Secure, Citrix ADC, F5 BIG-IP, Microsoft Exchange, Windows Netlogon and MobileIron Core. Patches for all of them have long been available, and nearly all are now listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Since November 2021, that catalog has been the reference for which vulnerabilities attackers actually exploit, and it is the better starting point for patch priorities today. For a more recent case from mobile device management, read Public Security Announcement: Ivanti EPMM Vulnerabilities.

Are you ready? Well, that's a good question. Let's be honest, nobody is usually thrilled with system maintenance. Integration, deployment and even management can be fun, but maintenance is often seen as the "boring" task nobody wants to do. Still, it is critical to the health and security of your IT infrastructure, and ultimately of the whole organization.

Why maintenance is a security issue

A lack of proper maintenance does not only lead to poor performance but, more importantly, to security risks. This happens when security patches are not applied on a regular basis, or not applied promptly when a vendor releases a fix for a newly discovered vulnerability.

Many of our everyday solutions rely on an entire ecosystem of interconnected servers, supported by a number of subsystems and built on different platforms. They are designed with security in mind, but they cannot be completely shielded from the Internet, because devices need to reach them from anywhere, both for initial enrollment and for real-time management later on. That does not mean these systems are exposed to the wild: only a minimum number of ports are open, only certain types of connections are allowed, strong authentication is required and specific transport protocols ensure that only authorized devices can connect. But it still increases the attack surface that malicious actors can try to exploit to gain access to your network.

Security is a cornerstone of any externally facing solution, but even these solutions are not immune to security issues. Their software relies on hundreds or thousands of other modules, such as web servers and encryption libraries, any of which may turn out to be flawed at some point.

What happens when patches are missing

A well-known example is the Target breach of 2013, in which data from around 40 million payment cards was stolen. According to security journalist Brian Krebs, the attackers first broke into the retailer's network using network credentials stolen from an HVAC contractor. They uploaded their card-stealing malware to a small number of cash registers in Target stores to test whether it worked as intended. Next, they pushed the malware to most of Target's point-of-sale devices and collected card data from live customer transactions. The case shows how a weakness at a third party can become the way into a much larger network.

At the end of the day, the goal is to build and maintain an ecosystem of solutions that lets your business run efficiently from anywhere: corporate offices, on the road or in home offices. That only works if every component is kept up to date. Unpatched, Internet-facing systems remained a recurring theme in the months that followed, for example the Microsoft Exchange zero-days of March 2021 in Security Breach: Patch or Clash and the Java library flaw in Understanding the Log4j Vulnerability. For common configuration gaps, see 10 Common Cybersecurity Misconfigurations and How to Mitigate Them.

Want to know where your environment stands? ISEC7 SPHERE monitors compliance, patch levels and known vulnerabilities (CVEs) of the connected systems, and our team supports endpoint security projects from assessment to implementation. Contact us with any questions.