HomeSecurity3 out of 4 organizations are still vulnerable to Heartbleed

3 out of 4 organizations are still vulnerable to Heartbleed

password- heartbleed

A year after the Heartbleed vulnerability was disclosed , 74 percent of Global 2000 organizations are still vulnerable to OpenSSL, according to a new report from Venafi. Unlike the average software vulnerability , Heartbleed cannot be fixed by patching alone. Organizations also need to revoke old SSL certificates, issue new ones, and generate new keys.

From the report:
Venafi identified 580,000 hosts belonging to global organizations that have not been fully remediated. These partially remediated hosts have been patched against the Heartbleed vulnerability. However, these organizations have performed “lazy” remediation, failing to replace the old key, or failing to revoke the old certificate.

Why have these organizations done such a poor job of eliminating Heartbleed threats?
“It’s a combination of three factors: first, not knowing the right steps to take, second, not knowing where to find all the necessary keys and certificates, and third, not having the knowledge or systems that have the capability to replace keys and certificates quickly and in large quantities,” said Kevin BOCEK, vice president of security and threat at Venafi.

“Recently, a Ponemon Institute survey was released showing that 54% of organizations are unaware of how many keys and certificates they have in their possession and where they are being used.”

As Venafi points out in the report, Heartbleed attacks are not just theoretical. In August 2014, the first news story was the breach of Community Health Systems that exposed the personal information of 4.5 million patients. The Chinese APT 18 group breached the healthcare provider by exploiting security flaws in CHS. One of those flaws was an incomplete Heartbleed remediation.

“In general, organizations need to do a better job of being able to change keys and certificates,” says BOCEK. By being proactive, organizations should also be able to respond to breaches more quickly in the future. One thing is for sure: they should be using more encryption, more keys and certificates from now on.”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS