{"id":8115,"date":"2024-08-29T15:44:22","date_gmt":"2024-08-29T08:44:22","guid":{"rendered":"https:\/\/thaipropertynews.com\/feeds\/?p=8115"},"modified":"2024-08-29T15:44:22","modified_gmt":"2024-08-29T08:44:22","slug":"tenable-research-uncovers-thousands-of-vulnerable-cyber-assets-amongst-southeast-asias-financial-sector","status":"publish","type":"post","link":"https:\/\/thaipropertynews.com\/feeds\/?p=8115","title":{"rendered":"Tenable Research Uncovers Thousands of Vulnerable Cyber Assets Amongst Southeast Asia&#8217;s Financial Sector"},"content":{"rendered":"<p class=\"prntac\">Over 26,500 internet-facing assets susceptible to potential exploitation<\/p>\n<p><span class=\"legendSpanClass\"><span class=\"xn-location\">SINGAPORE<\/span><\/span>, <span class=\"legendSpanClass\"><span class=\"xn-chron\">Aug. 29, 2024<\/span><\/span> \/PRNewswire\/ &#8212; New research conducted by\u00a0<a href=\"https:\/\/www.tenable.com\/\" target=\"_blank\" rel=\"noopener\">Tenable\u00ae, Inc.<\/a>, the exposure management company, has uncovered more than 26,500 potential internet-facing assets among <span class=\"xn-location\">Southeast Asia&#8217;s<\/span> top banking, financial services and insurance (BFSI) companies by market capitalisation across <span class=\"xn-location\">Indonesia<\/span>, <span class=\"xn-location\">Malaysia<\/span>, <span class=\"xn-location\">the Philippines<\/span>, <span class=\"xn-location\">Singapore<\/span>, <span class=\"xn-location\">Thailand<\/span> and Vietnam.\u00a0<\/p>\n<p>On <span class=\"xn-chron\">July 15, 2024<\/span>, Tenable examined the external attack surface of over 90 BFSI organisations with the largest market capitalisations across the region. The findings revealed that the average organisation possesses nearly 300 internet-facing assets susceptible to potential exploitation, resulting in a total of more than 26,500 assets across the study group.<\/p>\n<p><span class=\"xn-location\">Singapore<\/span> ranked the highest among the six countries assessed, with over 11,000 internet-facing assets identified across its top 16 BFSI companies. Over 6,000 of those assets are hosted in the United States.\u00a0 Next on the list is <span class=\"xn-location\">Thailand<\/span> with over 5000 assets. The distribution of internet-accessible assets underscores the need for cybersecurity strategies that adapt to the rapidly evolving digital landscape.<\/p>\n<div>\n<p class=\"prnml4\"><span class=\"prnews_span\">Country<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">Number of internet-facing assets amongst top 90 BFSI <br \/>companies by market capitalisation<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">1. Singapore<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">11,000<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">2. Thailand<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">5,000<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">3. Indonesia<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">4,600<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">4. Malaysia<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">4,200<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">5. Vietnam<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">3,600<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">6. Philippines<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">2,600<\/span><\/p>\n<\/div>\n<p>&#8220;The results of our study reveal that many financial institutions are struggling to close the priority security gaps that put them at risk. Effective exposure management is key to closing these gaps,&#8221; said <span class=\"xn-person\">Nigel Ng<\/span>, Senior Vice President, Tenable APJ. &#8220;By identifying and securing vulnerable assets before they can be exploited, organisations can better protect themselves against the growing tide of cyberattacks.&#8221;<\/p>\n<p>Cyber Hygiene Gaps\u00a0<br \/>The Tenable study revealed many potential vulnerabilities and exposed several cyber hygiene issues among the study group, including outdated software, weak encryption, and misconfigurations. These vulnerabilities provide cybercriminals with easily exploitable potential entry points, posing potential risk to the integrity and security of financial data.<\/p>\n<p>Weak SSL\/TLS encryption<br \/><span>A notable finding is that among the total assets, organisations had nearly 2,500 still supporting <\/span>TLS<span> 1.0\u2014a 25-year old security protocol introduced in 1999 and disabled by Microsoft in <span class=\"xn-chron\">September 2022<\/span>. This highlights the significant challenge organisations with extensive internet footprints face in identifying and updating outdated technologies.<\/span><\/p>\n<p>Misconfiguration increases external exposure<br \/>Another concerning discovery was that over 4,000 assets, originally intended for internal use, were inadvertently exposed and are now accessible externally. Failing to secure these internal assets poses a significant risk to organisations, as it creates an opportunity for malicious actors to target sensitive information and critical systems.<\/p>\n<p>Lack of encryption<br \/><span>There were over 900 assets with unencrypted final URLs, which can present a security weakness. When URLs are unencrypted, the data transmitted between the user&#8217;s browser and the server is not protected by encryption, making it vulnerable to interception, eavesdropping, and manipulation by malicious actors. This lack of encryption can lead to the exposure of sensitive information, such as login credentials, personal data, or payment details, and can compromise the integrity of the communication.<\/span><\/p>\n<p>API vulnerabilities amplify risk<br \/>The identification of over 2,000 API v3 out of the total number of assets among organisations&#8217; digital infrastructure poses a substantial risk to their security and operational integrity.<\/p>\n<p>APIs serve as crucial connectors between software applications, facilitating seamless data exchange. However, inadequate authentication, insufficient input validation, weak access controls, and vulnerabilities in dependencies within API v3 implementations create a vulnerable attack surface.<\/p>\n<p>Malicious actors can exploit such weaknesses to gain unauthorised access, compromise data integrity, and launch devastating cyber attacks.<\/p>\n<p>&#8220;The cybersecurity landscape is evolving faster than ever, and financial institutions must evolve with it, so they can know where they are exposed and take action to close critical risk&#8221; Ng added. &#8220;By prioritising exposure management, these organisations can better protect their digital assets, safeguard customer trust, and ensure the resilience of their operations in an increasingly hostile digital environment.&#8221;<\/p>\n<p>About Tenable<br \/>Tenable\u00ae is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company&#8217;s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for more than 44,000 customers around the globe. Learn more at <a href=\"http:\/\/tenable.com\/\" target=\"_blank\" rel=\"noopener\">tenable.com<\/a>.<\/p>\n<p>Notes to Editors:<\/p>\n<p>     Tenable examined the top 12-16 BFSI companies discoverable based on market cap.   In the context of this alert:       An asset is a domain name,\u00a0subdomain, or IP addresses and\/or combination thereof of a device connected to the Internet or internal network. An asset may include, but not limited to web servers, name servers, IoT devices, network printers, etc. Example: foo.tld, bar.foo.tld, x.x.x.xs.   The Attack Surface is from the network perspective of an adversary, the complete asset inventory of an\u00a0organisation including all actively listening services (open ports) on each asset.    <\/p>\n<p>\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p><!-- wp:html --><\/p>\n<p class=\"prntac\">Over 26,500 internet-facing assets susceptible to potential exploitation<\/p>\n<p><span class=\"legendSpanClass\"><span class=\"xn-location\">SINGAPORE<\/span><\/span>, <span class=\"legendSpanClass\"><span class=\"xn-chron\">Aug. 29, 2024<\/span><\/span> \/PRNewswire\/ &#8212; New research conducted by\u00a0<a href=\"https:\/\/www.tenable.com\/\" target=\"_blank\" rel=\"noopener\">Tenable\u00ae, Inc.<\/a>, the exposure management company, has uncovered more than 26,500 potential internet-facing assets among <span class=\"xn-location\">Southeast Asia&#8217;s<\/span> top banking, financial services and insurance (BFSI) companies by market capitalisation across <span class=\"xn-location\">Indonesia<\/span>, <span class=\"xn-location\">Malaysia<\/span>, <span class=\"xn-location\">the Philippines<\/span>, <span class=\"xn-location\">Singapore<\/span>, <span class=\"xn-location\">Thailand<\/span> and Vietnam.\u00a0<\/p>\n<p>On <span class=\"xn-chron\">July 15, 2024<\/span>, Tenable examined the external attack surface of over 90 BFSI organisations with the largest market capitalisations across the region. The findings revealed that the average organisation possesses nearly 300 internet-facing assets susceptible to potential exploitation, resulting in a total of more than 26,500 assets across the study group.<\/p>\n<p><span class=\"xn-location\">Singapore<\/span> ranked the highest among the six countries assessed, with over 11,000 internet-facing assets identified across its top 16 BFSI companies. Over 6,000 of those assets are hosted in the United States.\u00a0 Next on the list is <span class=\"xn-location\">Thailand<\/span> with over 5000 assets. The distribution of internet-accessible assets underscores the need for cybersecurity strategies that adapt to the rapidly evolving digital landscape.<\/p>\n<div>\n<p class=\"prnml4\"><span class=\"prnews_span\">Country<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">Number of internet-facing assets amongst top 90 BFSI <br \/>companies by market capitalisation<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">1. Singapore<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">11,000<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">2. Thailand<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">5,000<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">3. Indonesia<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">4,600<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">4. Malaysia<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">4,200<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">5. Vietnam<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">3,600<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\"> <\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">6. Philippines<\/span><\/p>\n<p class=\"prnml4\"><span class=\"prnews_span\">2,600<\/span><\/p>\n<\/div>\n<p>&#8220;The results of our study reveal that many financial institutions are struggling to close the priority security gaps that put them at risk. Effective exposure management is key to closing these gaps,&#8221; said <span class=\"xn-person\">Nigel Ng<\/span>, Senior Vice President, Tenable APJ. &#8220;By identifying and securing vulnerable assets before they can be exploited, organisations can better protect themselves against the growing tide of cyberattacks.&#8221;<\/p>\n<p>Cyber Hygiene Gaps\u00a0<br \/>The Tenable study revealed many potential vulnerabilities and exposed several cyber hygiene issues among the study group, including outdated software, weak encryption, and misconfigurations. These vulnerabilities provide cybercriminals with easily exploitable potential entry points, posing potential risk to the integrity and security of financial data.<\/p>\n<p>Weak SSL\/TLS encryption<br \/><span>A notable finding is that among the total assets, organisations had nearly 2,500 still supporting <\/span>TLS<span> 1.0\u2014a 25-year old security protocol introduced in 1999 and disabled by Microsoft in <span class=\"xn-chron\">September 2022<\/span>. This highlights the significant challenge organisations with extensive internet footprints face in identifying and updating outdated technologies.<\/span><\/p>\n<p>Misconfiguration increases external exposure<br \/>Another concerning discovery was that over 4,000 assets, originally intended for internal use, were inadvertently exposed and are now accessible externally. Failing to secure these internal assets poses a significant risk to organisations, as it creates an opportunity for malicious actors to target sensitive information and critical systems.<\/p>\n<p>Lack of encryption<br \/><span>There were over 900 assets with unencrypted final URLs, which can present a security weakness. When URLs are unencrypted, the data transmitted between the user&#8217;s browser and the server is not protected by encryption, making it vulnerable to interception, eavesdropping, and manipulation by malicious actors. This lack of encryption can lead to the exposure of sensitive information, such as login credentials, personal data, or payment details, and can compromise the integrity of the communication.<\/span><\/p>\n<p>API vulnerabilities amplify risk<br \/>The identification of over 2,000 API v3 out of the total number of assets among organisations&#8217; digital infrastructure poses a substantial risk to their security and operational integrity.<\/p>\n<p>APIs serve as crucial connectors between software applications, facilitating seamless data exchange. However, inadequate authentication, insufficient input validation, weak access controls, and vulnerabilities in dependencies within API v3 implementations create a vulnerable attack surface.<\/p>\n<p>Malicious actors can exploit such weaknesses to gain unauthorised access, compromise data integrity, and launch devastating cyber attacks.<\/p>\n<p>&#8220;The cybersecurity landscape is evolving faster than ever, and financial institutions must evolve with it, so they can know where they are exposed and take action to close critical risk&#8221; Ng added. &#8220;By prioritising exposure management, these organisations can better protect their digital assets, safeguard customer trust, and ensure the resilience of their operations in an increasingly hostile digital environment.&#8221;<\/p>\n<p>About Tenable<br \/>Tenable\u00ae is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company&#8217;s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for more than 44,000 customers around the globe. Learn more at <a href=\"http:\/\/tenable.com\/\" target=\"_blank\" rel=\"noopener\">tenable.com<\/a>.<\/p>\n<p>Notes to Editors:<\/p>\n<p>     Tenable examined the top 12-16 BFSI companies discoverable based on market cap.   In the context of this alert:       An asset is a domain name,\u00a0subdomain, or IP addresses and\/or combination thereof of a device connected to the Internet or internal network. An asset may include, but not limited to web servers, name servers, IoT devices, network printers, etc. Example: foo.tld, bar.foo.tld, x.x.x.xs.   The Attack Surface is from the network perspective of an adversary, the complete asset inventory of an\u00a0organisation including all actively listening services (open ports) on each asset.    <\/p>\n<p>\u00a0<\/p>\n<p><!-- \/wp:html --><\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[5,7],"tags":[],"class_list":["post-8115","post","type-post","status-publish","format-standard","hentry","category-cision-pr-newswire","category-cision-pr-newswire-en"],"_links":{"self":[{"href":"https:\/\/thaipropertynews.com\/feeds\/index.php?rest_route=\/wp\/v2\/posts\/8115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thaipropertynews.com\/feeds\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thaipropertynews.com\/feeds\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/thaipropertynews.com\/feeds\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8115"}],"version-history":[{"count":0,"href":"https:\/\/thaipropertynews.com\/feeds\/index.php?rest_route=\/wp\/v2\/posts\/8115\/revisions"}],"wp:attachment":[{"href":"https:\/\/thaipropertynews.com\/feeds\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thaipropertynews.com\/feeds\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thaipropertynews.com\/feeds\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}