www.channelinsider.com 98% of Enterprises Exhibit Security Exposure Risks, Vectra AI Reports
Article Content
- •98% of enterprise environments have attacker-relevant exposure conditions.
- •Over 30% of devices in analyzed environments were unmanaged, creating blind spots.
- •The rise of AI agents introduces new risks, with some environments having more AI agents than devices.
Vectra AI's 2026 State of Threat Exposure Management Report reveals that 98% of enterprise environments have attacker-relevant exposure conditions. The report highlights that traditional security measures are becoming ineffective due to the rise of AI agents, unmanaged devices, and dynamic infrastructure. Over 30% of devices in the observed environments were unmanaged, including IoT and legacy systems, creating significant blind spots. The prevalence of AI agents has led to environments where there are more AI agents than devices, introducing new risks. Common vulnerabilities include weak cryptography and exposed credentials. The report emphasizes the need for continuous exposure management and operational context to identify exploitable attack paths. Organizations must enhance asset discovery and identity monitoring to mitigate these risks effectively.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…