According to a new analysis by Intruder, 60% of organizations have at least one HTTP panel exposed, 49% have a risky port or service, 42% have an internet-facing database, and 30% have publicly accessible files or information that should not be. The top 10 exposures include MySQL (26%), Postgres (16%), API documentation (15%), WordPress admin panels (15%), RDP (11%), SNMP (9%), phpMyAdmin (8%), UPnP (8%), NTP (7%), and RPC Portmapper (7%). The report emphasizes that attack surface reduction—removing unnecessary exposures—is often overlooked compared to patching.
CVEs: CVE-2019-0708, CVE-2026-11645
Malware: PLEASE_READ_ME ransomware
Companies: Intruder
Products: MySQL, Postgres, WordPress, phpMyAdmin, MongoDB, Elasticsearch
Original source: thehackernews.com