Organisations Urged to Act Quickly as Cybercriminals Plan Attack in Six Days, Says Positive Technologies

Published:

Positive Technologies Warn Organizations of Impending Cybersecurity Threat

Positive Technologies has issued a warning to organisations, stating they have just six days until cybercriminals potentially strike. A recent study by Positive Technologies revealed that vulnerability exploitation has been one of the top three most popular attack methods on organisations for the past five years. In fact, in 2022-2023, over 2,700 companies worldwide had their confidential data stolen by attackers exploiting just one vulnerability.

According to Fedor Chunizhekov, Head of Security Analytics at Positive Technologies, cybercriminals are increasingly attracted to vulnerability exploitation, with about one-third of all successful cyberattacks being attributed to this method. On average, an experimental exploit becomes available within six days of a critical vulnerability disclosure, leading to discussions on dark web forums and the development of ready-to-use exploits for mass attacks.

The study also highlighted commonly mentioned vulnerabilities in popular products such as WinRAR, Fortinet, and the Java-based Spring Framework. Messages discussing remotely exploited vulnerabilities make up 70% of cybercriminal discussions on the dark web.

Delaying vulnerability fixes can have serious consequences for organisations, as evidenced by previous incidents where data was stolen, websites were defaced, and ransomware attacks occurred due to exploitation of vulnerabilities.

To prevent the exploitation of vulnerabilities and potential cyberattacks, experts recommend that organisations regularly inventory and classify their assets, prioritize assets based on importance and vulnerability severity, conduct security analyses, and closely monitor the dark web for threats. It is crucial for organisations to set realistic timelines for vulnerability remediation and closely monitor the patching process to ensure their IT infrastructure remains secure.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Citrix warns of active exploitation of vulnerabilities in NetScaler ADC and Gateway

Citrix has issued a security bulletin detailing eight vulnerabilities in its NetScaler ADC and Gateway products, with two—CVE-2026-88771 and CVE-2026-88772—confirmed as actively exploited. These...

ShinyHunters resumes exploitation of Oracle PeopleSoft vulnerability, warns Mandiant

A new campaign by the hacking group ShinyHunters is exploiting a vulnerability in Oracle's PeopleSoft, as reported by Mandiant. This vulnerability, identified as CVE-2026-35273,...

CrowdStrike recognized as leader in Forrester Wave for proactive security platforms

CrowdStrike has been recognized as a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026, achieving the highest score in the Strategy category...

Microsoft tracks Storm-2570’s consistent tactics across multiple ransomware deployments

Microsoft has identified Storm-2570, a ransomware affiliate, as a significant threat actor employing consistent tactics across various ransomware deployments, including Qilin, DragonForce, Anubis, and...