ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hidden vulnerabilities and data leaks

Pauline Losson at CybelAngel explores the unseen threats beyond the corporate IT perimeter

 

In the age of digital transformation, organisations raced to equip employees and customers with access to the tools and systems needed to accommodate rapidly shifting requirements and to build business resilience.

 

The crisis mode of this transformation is now behind us. However, the deployment of new technologies has provided a fertile ground for cyber attackers taking advantage of the increased digital attack surface and exploiting new points of vulnerability. 

 

In line with this evolution, we need to re-think how to protect data so that organisations have full visibility of hidden vulnerabilities, even those that are beyond their network perimeter.

 

Organisations now need to monitor across the web, from the vast numbers of interconnected devices to the extended supply chain that includes suppliers, partners, and vendors, all of which could pose a risk to their network.

 

So, the key issue is how do you shine a light on these blind spots, and mitigate the risks presented by an ever-expanding attack surface? 

 

Understanding the essence of a security breach

When it comes to exploiting hidden vulnerabilities, threat actors have a so-called ‘attack sales funnel’. They start with scanning for open ports, ghost accounts, and exposed credentials across the entire open digital space. This includes scanning the surface web, deep web, and dark web for publicly exposed connected devices and misconfigured collaborative cloud tools.

 

Once the required data is obtained to launch an attack, actors move on to testing for specific CVEs (Common Vulnerabilities and Exposures). Now all that remains is attempting a Remote Code Execution (RCE) and gaining access to the system.

 

The whole process starts with leaked sensitive data sitting exposed on the open web. But how is this exposed in the first place?

 

According to CybelAngel’s 2021 industry report, cloud storage is one of the key sources of data exposure for an organisation. In fact, cloud storage leaks increased by 150% last year. Companies may, for example, accidentally leave their critical cloud systems such as AWS S3 buckets, Azure, and Google databases exposed to the public internet. When such critical storage systems are not protected with secured encryption or have over-privileged permissions, threat actors can simply access the database and exfiltrate sensitive information.

 

Considering the greater demand for online services and software developers, it’s not surprising that we found a 66% increase in source code leaks last year. The reasons for this are two-fold: a labour shortage required more companies to outsource their development; and the rapid rate at which digital transformation had to take place due to the global pandemic.

 

These public repositories are often beyond the visibility of the security team, meaning that such risks remain unmanaged and unidentified by organisations.

 

There’s also the issue of ghost or stale accounts. When employees leave a company, their accounts may not be removed from every system and application. These accounts serve as an entry point for threat actors to gain initial access and start exploiting network vulnerabilities without being detected.

 

These are just a handful of examples of how organisations are potentially exposing sensitive data, and enabling attackers to identify and exploit hidden vulnerabilities across the organisation. There are also other factors such as employees leaking confidential information, network back doors created by poor system integration, and outsourcing technical operations. The iceberg runs deep.

 

Therefore, it is evident that organisations have to look beyond their network perimeters to manage the critical risks of data leaks and hidden vulnerabilities.

 

How to extend visibility beyond the security perimeter?

Organisations need to look beyond their networks and continuously monitor the open web to identify leaked data and hidden vulnerabilities that can give attackers the keys to the kingdom. However, as security teams are already burdened with internal security tasks, stretching their responsibilities further can take a toll on an organisation’s resources.

 

The most feasible approach is to implement automated solutions; external risk protection platforms continuously monitor the enterprise systems, as well as every layer of the internet in real-time to identify any data leaks and hidden vulnerabilities.

 

Such solutions use augmented intelligence technology - a combination of AI and human-led analysis to identify data leaks based on an organisation’s keywords and provide actionable remediation information. External risk protection solutions provide visibility into the deepest layers of the internet, identifying any stale accounts, shadow IT, leaked data, and hidden vulnerabilities traced back to your network.

 

Businesses should also employ proactive security policies such as Zero Trust and effective IAM solutions to manage all user accounts and access privileges within their networks. These efforts should be supported by implementing proactive security awareness training and establishing good password practices across the entire workforce.

 

Data leaks might be inevitable but incorporating these measures along with automated solutions can help organisations effectively manage the risks of leaked data and address the hidden vulnerabilities before threat actors can exploit them.

 


 

Pauline Losson is Cyber Operations Director at CybelAngel

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543