logo

New XM Cyber Research: 80% of Exposures from Misconfigurations, Less Than 1% from CVEs

ID: fdd5c5f0-4e53-51d4-b123-b38eb3a80e7b

STIX ID: report--fdd5c5f0-4e53-51d4-b123-b38eb3a80e7b

Feed Name: The Hacker News

Date Published: 2024-05-17

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

The XM Cyber report summary argues that most organizations over-focus on CVE patching while CVEs account for <1% of on-prem exposures and only ~11% of critical exposures; identity and Active Directory misconfigurations cause roughly 80% of exposures (with a third of critical asset risk), and just 2% of exposures lie on high-impact "choke points" that enable significant lateral movement — the recommendation is to prioritize exposure management, AD/credential hygiene, and remediation of choke points rather than attempting to fix all vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.