Months have passed since Heartbleed was discovered, and yet the majority of servers used by businesses around the world remain largely unprotected from this threat.
According to a new study by security solutions developer Venafi, 97% of public-facing servers at leading enterprises are still vulnerable to cyberattacks due to Heartbleed.
So cybercriminals can still exploit the vulnerability to hack legitimate websites, decrypt private communications, and steal sensitive data sent over SSL.
"Thousands of applications behind firewalls, including those from Cisco, Juniper, HP, IBM, Oracle, McAfee, Symantec, and many others, remain exposed," the report states.
To analyze the threats, Venafi Labs researchers examined the public-facing servers of 1,639 leading enterprises, with a total of more than 550,000 public-facing servers examined. However, only 3 percent of all servers had taken the necessary steps to effectively patch Heartbleed. The remaining 97 percent remain exposed to ongoing cyberattacks and malicious activity.
Kevin Bocek of Venafi states that to fully address Heartbleed, it is not enough to install the available patch, but it is necessary to replace all keys and certificates used to protect systems.
