Breaking
May 17, 2025

Report shows the threat of supply chain vulnerabilities from third-party products | usagoldmines.com


  • CyCognito report shows the risks posed by supply chain vulnerabilities
  • Third-party products are putting businesses at risk with undetected vulnerabilities
  • Web servers, cryptographic protocols, and web interfaces suffer the most

Critical vulnerabilities often go unnoticed in many digital systems, exposing businesses to significant security risks, new research has claimed.

With organizations increasingly reliant on third-party software and complex supply chains, cyber threats are no longer confined to internal assets alone, as many of the most dangerous vulnerabilities come from external sources.

The 2024 State of External Exposure Management Report from CyCognito provides an analysis of the risks organizations face today, particularly around web servers, cryptographic protocols, and PII-handling web interfaces.

Supply chain risk remains a growing concern

Third-party vendors play a crucial role in the operations of many companies, providing essential hardware and software. However, their involvement may introduce significant risks, particularly concerning misconfigurations and vulnerabilities in the entire supply chain.

Many of the most severe vulnerabilities like MOVEit Transfer flaw, Apache Log4J, and Polyfill were revealed to have links to third-party software.

Web servers are consistently among the most vulnerable assets in an organization’s IT infrastructure. CyCognito’s findings reveal web server environments account for one in three (34%) of all severe issues across surveyed assets. Platforms such as Apache, NGINX, Microsoft IIS, and Google Web Server are at the center of these concerns, hosting more severe issues than 54 other environments combined.

Beyond web servers, vulnerabilities in cryptographic protocols like TLS (Transport Layer Security) and HTTPS are also driving concern. The report indicates that 15% of all severe issues on the attack surface affect platforms using TLS or HTTPS protocols. Web applications that lack proper encryption are especially at risk, ranking #2 on the OWASP Top 10 list of security risks.

CyCognito’s report also hightlighted the insufficiency of Web Application Firewall (WAF) protections, especially for web interfaces handling personally identifiable information (PII).

The report shows only half of surveyed web interfaces that process PII were protected by a WAF, leaving sensitive information vulnerable to attacks. Even more concerning is the fact that 60% of the interfaces that expose PII also lack WAF protection.

Unfortunately, outdated approaches to vulnerability management often leaves assets exposed, amplifying the risks. Organizations must adopt a more proactive and comprehensive approach to managing external exposures.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Best SSDs: From SATA to PCIe 5.0, from budget to premium | usagoldmines.com

Apple's 20th Anniversary iPhone: What We Know So Far Juli Clover | usagoldmines.com

I Used 'Cover Your Tracks' to See What's Following Me Online, and Yikes Jake Peterson | usagoldmines...

Google's AI Overviews are often so confidently wrong that I’ve lost all trust in them | usagoldmine...

What Is Frame Generation, and Should You Use It In Your Games? Eric Ravenscraft | usagoldmines.com

Even More iPhone Safety Tips You Should Know Juli Clover | usagoldmines.com

RFK Jr. wants to ban fluoride supplements based on nonsense Beth Mole | usagoldmines.com

All These Beats Headphones Are on Sale During Amazon's Memorial Day Sale Daniel Oropeza | usagoldmin...

Nothing is making over-the-ear headphones and they might be better (and cheaper) than AirPods Pro Ma...

Spotify caught hosting hundreds of fake podcasts that advertise selling drugs Ashley Belanger | usag...

Epic is giving away Dead Island 2 this week. Grab it and save $50! | usagoldmines.com

The best gaming laptops: 5 top options for portable performance | usagoldmines.com

Arm’s ubiquitous CPU cores get new, less confusing names | usagoldmines.com

Do HBO’s owners have any actual idea what they’re doing with Max? | usagoldmines.com

This new VPN technology doesn’t want to know who you are – that’s why NymVPN stands out from the cro...

This Budget Outdoor Speaker Is Surprisingly Good, and It's Only $56 Right Now Daniel Oropeza | usago...

The empire strikes back with F-bombs: AI Darth Vader goes rogue with profanity, slurs Benj Edwards |...

Darth Vader Becomes Gemini-Powered Conversational AI in Fortnite Tim | usagoldmines.com

DEAL: Save Most on Galaxy S25 Edge When You Pre-Order, Free Doubled Storage (65% Off) Tim | usagoldm...

Tubi Has a New Category Filled With Classic Movies From the Criterion Collection Joel Cunningham | u...

A Step-by-Step Guide to Planting Your Summer Vegetables Amanda Blum | usagoldmines.com

MacRumors Giveaway: Win an Apple Watch Ultra 2 From GRID Studio Juli Clover | usagoldmines.com

Volkswagen says 'mind-blowing' electric GTI EVs are coming – here's what to expect and what I want t...

Global Russian hacking campaign steals data from government agencies | usagoldmines.com

AMD subtly confirms reveal date for its next Radeon GPU – an ideal time to compete with Nvidia at Co...

RICO crypto fraud investigation leads to twelve more arrests | usagoldmines.com

Forgive me Volvo, I was wrong: The 2025 V60 Cross Country review Jonathan M. Gitlin | usagoldmines.c...

OpenAI introduces Codex, its first full-fledged AI agent for coding Samuel Axon | usagoldmines.com

The remarkable timeline of a custom gene-editing therapy to save a newborn Beth Mole | usagoldmines....

Google to give app devs access to Gemini Nano for on-device AI Ryan Whitwam | usagoldmines.com

Acer’s Aspires have one big question mark: their U.S. price | usagoldmines.com

AMD or Intel? Acer’s Swift X 14 offers either, plus a GeForce 5070 | usagoldmines.com

Acer’s feathery Swift Edge AI laptop has the matte OLED you crave | usagoldmines.com

Acer’s new Predator gaming laptop uses graphene for supercharged cooling | usagoldmines.com

Annke NightChroma NC500 review: Standout low-light vision | usagoldmines.com

This Mini 4K Laser Projector Is $300 Off Right Now Naima Karp | usagoldmines.com

Google's New Accessibility Features Will Finally Make Small Text Easier to Read on Mobile Pranay Par...

Rumors Suggest You Might Want to Keep Your Switch 2 Docked Jake Peterson | usagoldmines.com

The MacRumors Show: CarPlay Ultra and Samsung's iPhone 17 Air Rival Hartley Charlton | usagoldmines....

Apple Pay, Apple Card, Wallet and Apple Cash Currently Experiencing Service Issues Juli Clover | usa...

Apple Says Fortnite for iOS Isn't Blocked Worldwide, Just the U.S. Juli Clover | usagoldmines.com

Carnivorous crocodile-like monsters used to terrorize the Caribbean Elizabeth Rayne | usagoldmines.c...

Microsoft’s Surface Laptop Studio series is probably dead | usagoldmines.com

Lexar’s 512GB microSD card is now $27, the lowest it’s ever been | usagoldmines.com

Microsoft is bringing back Windows 10’s second hand display after backlash | usagoldmines.com

Acer Has Its Own AI-Powered Smart Ring Tim | usagoldmines.com

How to Plant the Perfect Kitchen Garden in a Small Space Amanda Blum | usagoldmines.com

You Can Safely Delete These Preinstalled Apps From Your Samsung Galaxy David Nield | usagoldmines.co...

Hackers steal customer data in Nova Scotia Power cyberattack | usagoldmines.com

Bono says Apple wants to make the Vision Pro 'more affordable', so what's the holdup? lance.ulanoff@...

New Avengers: Doomsday behind-the-scenes images from Robert Downey Jr are getting Marvel fans excite...

What is the release date and time for The Last of Us season 2 episode 6? tom.power@futurenet.com (To...

Chrome patched this bug, but CISA says it's still actively exploited | usagoldmines.com

"A clear escalation in Russia’s crackdown on digital privacy tools" – experts warn against recent VP...

Samsung just launched the first-ever 500Hz OLED gaming monitor – but I think it's overkill | usagol...

The 2025 VW Tiguan caters to US tastes at an affordable price Michael Teo Van Runkle | usagoldmines....

Meta argues enshittification isn’t real in bid to toss FTC monopoly trial Ashley Belanger | usagoldm...

These $46 ‘electric scissors’ give me ASMR endorphins when I slice up Amazon boxes | usagoldmines.c...

Fake AI voice scammers are now impersonating government officials | usagoldmines.com

Windows 10 PCs are locking and crashing after May’s security update | usagoldmines.com

Report: Samsung Readies Upgraded Battery Tech, But It’s Not Silicon Carbon Tim | usagoldmines.com

SoundCloud Just Updated Their Terms of Service After AI Policy Backlash Stephen Johnson | usagoldmin...

The Coinbase Hack Compromised One Million Customers' Information Emily Long | usagoldmines.com

WSJ: Some Apple Vision Pro Buyers 'Feel Total Regret' Hartley Charlton | usagoldmines.com

iPhone 17 Air Could Debut Advanced Silicon Battery Tech Tim Hardwick | usagoldmines.com

Best Apple Deals of the Week: Sitewide Sales Hit Anker, Verizon, Samsung, and More, Plus BOGO Apple ...

Be on the lookout for deepfake and AI government officials, FBI warns | usagoldmines.com

Forget the Force, AI brings the late James Earl Jones’ iconic Darth Vader voice to Fortnite john-ant...

xAI says an “unauthorized” prompt change caused Grok to focus on “white genocide” Kyle Orland | usag...

Pokémon Scarlet/Violet frame rate fixes are among the Switch 2’s free game updates Andrew Cunningham...

Welcome to The Full Nerd newsletter, your weekly dose of hardcore PC hardware talk | usagoldmines.c...

This budget-friendly Ryzen 7 mini PC with 32GB RAM is only $272 | usagoldmines.com

Get Reddit’s favorite desk chair for 50% off while you can today | usagoldmines.com

What’s the best CPU for Adobe Premiere Pro? It’s complicated | usagoldmines.com

Celebrate Proton’s birthday and get 70% off one of the best VPNs | usagoldmines.com

This USB-C laptop stand also has 5 ports — and it’s only $34 right now | usagoldmines.com

VPNSecure faces backlash after axing lifetime subscriptions | usagoldmines.com

What's New on Disney+ in June 2025 Emily Long | usagoldmines.com

What's New on Hulu in June 2025 Emily Long | usagoldmines.com

TCL and Samsung reveal big updates to two OLED-beating technologies, but don't get excited for them ...

7 new movies and TV shows to watch on Netflix, Prime Video, Max, and more this weekend (May 16) tom....

NYT Connections hints and answers for Saturday, May 17 (game #706) | usagoldmines.com

NYT Strands hints and answers for Saturday, May 17 (game #440) | usagoldmines.com

Quordle hints and answers for Saturday, May 17 (game #1209) | usagoldmines.com

Climate needs a rebrand, and what’s driving change is surprising | usagoldmines.com

Audio-Technica's see-through turntable is so cool, it seems a shame to put your vinyl on it | usago...

Congress wants geotracking tech in high-end GPUs to keep them out of China's clutches | usagoldmine...

I'll say it: the Samsung Galaxy S25 Edge is the best-looking phone of the year so far jamie.richards...

Data streaming: protecting consumers in the AI era | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

‘Bread Baking for Beginners’ Will Give You All the Confidence You Need Allie Chanthorn Reinmann | us...

Personal information leaked in Coinbase cyberattack, cost could be $400 million | usagoldmines.com

My picks and advice for the Marvel Rivals best graphics settings for PS5, PS5 Pro, and Xbox Series X...

Acer announces new Swift and Aspire laptop line-ups – here are 4 big things you need to know about t...

Acer's surprise new device is nothing to do with your laptop – it's a fitness-tracking smart ring ma...

Lenovo Yoga 7i 2-in-1 review: Long-lasting, sturdy, and confused | usagoldmines.com

5 nifty USB-C gadgets you didn’t know you needed | usagoldmines.com

Apple Again Named the World's Most Valuable Brand Hartley Charlton | usagoldmines.com

Meta says no evidence it monopolized social media market, asks Judge to throw out antitrust case | ...

Two big Netflix video game movie adaptations just got their most exciting updates in years tom.power...