Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Watts & Wheels S1E8: 'Tesla lands in Africa, just not here'

      Watts & Wheels S1E8: ‘Tesla lands in Africa, just not here’

      24 August 2026

      MTN’s Iranian dead end

      24 August 2026
      MTN is cutting airtime credit while its rivals lean on it

      MTN is cutting airtime credit while its rivals lean on it

      24 August 2026
      You still can't choose who sells you electricity in South Africa

      You still can’t choose who sells you electricity in South Africa

      24 August 2026
      MTN is spending less on the best network in South Africa - Ralph Mupita

      MTN is spending less on the best network in South Africa

      24 August 2026
    • World
      Russia building its own Starlink - and faster than expected - Vadym Skibitskyi

      Russia building its own Starlink – and faster than expected

      11 August 2026
      Meta AI will now tell parents if their teen is in crisis

      Meta AI will now tell parents if their teen is in crisis

      17 July 2026
      IBM shares crash 25% as AI upends software spending - Arvind Krishna

      IBM shares crash 25% as AI upends software spending

      15 July 2026
      Jony Ive's first OpenAI device: an AI smart speaker - Jony Ive and Sam Altman

      Jony Ive’s first OpenAI device: an AI smart speaker

      15 July 2026
      Stripe, Advent in talks to buy PayPal for $53-billion

      Stripe, Advent in talks to buy PayPal for $53-billion

      15 July 2026
    • In-depth
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
      What Wi-Fi 8 will mean for wireless networks

      What Wi-Fi 8 will mean for wireless networks

      1 June 2026
    • TCS
      Meet the CIO | Discovery's Derek Wilcocks on AI, guardrails and growth

      Meet the CIO | Derek Wilcocks on how AI personalised Vitality

      13 August 2026
      TCS | Money just became native to the internet - Steven Boykey Sidley

      TCS | Money just became native to the internet – Steven Boykey Sidley

      12 August 2026
      TCS+ | Specops' Darren James on continuous trust in an AI world

      TCS+ | Specops’ Darren James on continuous trust in an AI world

      7 August 2026
      TCS+ | How AI is turning hardware into a subscription service - Shane van der Merwe Merchant West

      TCS+ | How AI is turning hardware into a subscription service

      6 August 2026
      TCS+ | Why South African workers must become supervisors of digital labour - Accelera Digital Group Cliff de Wit

      TCS+ | Why South African workers must become supervisors of digital labour

      31 July 2026
    • Opinion
      The author, Jannie van Zyl

      Selling vapour is corporate suicide in slow motion

      16 July 2026
      Brazil's online gambling crackdown is a lesson for South Africa

      How Amazon outmanoeuvred Starlink in South Africa

      15 July 2026
      The Popia problem with agentic AI - Herman Haasbroek

      The Popia problem with agentic AI

      14 July 2026
      The author, Fanie van Rooyen

      South Africa can still catch the AI wave – here’s how

      7 July 2026
      The author, Fanie van Rooyen

      The AI utopia South Africa can’t afford

      1 July 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM Telecom
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Company News » Skybox research reveals a perilous threat landscape

    Skybox research reveals a perilous threat landscape

    By Skybox Security12 May 2022
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    The latest Skybox Vulnerability and Threat Trends Report is now out, and it presents some eye-opening statistics and trends that security analysts at Skybox Research Lab have been tracking over the past year. For anyone interested in the on-the-ground realities confronting security professionals these days, the report makes for compelling reading.

    Get the 2022 report here

    This year’s findings chart a threat landscape that’s expanding and diversifying at a blistering clip. We observed record growth in new vulnerabilities affecting a wide variety of products. In particular, vulnerabilities in operational technology (OT) skyrocketed, nearly doubling versus the previous year. As vulnerabilities emerged, threat actors moved ever more quickly to weaponise them. New exploits increasingly took aim at the latest vulnerabilities, while malware producers nimbly tuned their product mix to capitalise on cybercrime hotspots such as cryptojacking and ransomware. Let’s take a closer look at our key findings:

    Vulnerabilities have more than tripled over the past 10 years

    Source: Skybox Security

    New vulnerabilities smashed records, hitting an all-time high in 2021, with 20 175 new CVE (common vulnerabilities and exposures). That’s up 10% from 2020 — the biggest percentage jump we’ve seen since 2018 and the first time new vulnerabilities have topped 20 000 for a single year.

    This latest crop of vulnerabilities adds to a mountain of accumulated security debt. The total number of CVEs published over the last 10 years reached 166 938 in 2021 — a three-fold increase over a decade.

    OT vulnerabilities nearly double in one year

    As rapid as the rise in overall vulnerabilities was, security flaws in OT products grew even faster, increasing by 88% year over year. These vulnerabilities are especially worrying given the precarious state of OT security. The number of OT devices deployed in enterprises has risen dramatically in recent years. Many of these systems have few or no cybersecurity controls in place and are increasingly connected to networks, exposing them to attacks. Learn how Skybox “scan less” vulnerability detection helps you find “unscannable” OT vulnerabilities.

    Cryptojacking and ransomware top new malware charts

    Malware producers are turning out a widening array of products and services keyed to the latest cybercrime trends. The number of new cryptojacking and ransomware programs grew by 75% and 42% respectively, reflecting a growing demand for these increasingly lucrative and popular forms of exploit. Easy-to-use malware, exploit kits and malware-as-a-service (MaaS) have made it remarkably simple for non-expert hackers to mount attacks and reap rapid financial returns.

    Faster weaponisation of vulnerabilities

    One of the more notable trends we identified is the shrinking interval between the appearance of vulnerabilities and the development of exploits designed to take advantage of them. We found 168 vulnerabilities that were published in 2021 and targeted by exploits within the same year. That’s 24% more than the number of vulnerabilities published and subsequently targeted by exploits in 2020. It’s another sign that threat actors are upping their game and moving more aggressively to cash in on emerging opportunities.

    Among those newly discovered vulnerabilities that were promptly exploited is the notorious Log4Shell vulnerability — a flaw in the massively popular Log4j open-source library that’s used in hundreds of millions of devices. The Log4Shell vulnerability was publicly disclosed in early December 2021. By the end of the month, there were already known 15 malware programs designed to exploit it.

    As vulnerabilities mount, attacks follow

    These trends leave security teams between a rock and a hard place. Proliferating vulnerabilities are creating more opportunities for breaches, and new malware and exploits are making it easier than ever for bad actors to capitalise on those opportunities.

    It’s a worst-of-both-worlds combination, emboldening threat actors and leading to more frequent and more audacious cyberattacks. In 2021 we witnessed some of the most brazen incidents to date:

    • Zero-day attacks more than doubled in 2021⁠1. A series of zero-day attacks exploited vulnerabilities in Microsoft Exchange Server, impacting tens of thousands of organisations.
    • Supply-chain attacks, such as those targeting IT software from SolarWinds and Kaseya, as well as the Log4Shell vulnerability.
    • Critical infrastructure attacks, wreaking havoc on vital operations and services. Examples include the Colonial Pipeline ransomware attack that disrupted fuel supplies in the south-eastern US.

    The average cost of data breaches hit $4.24-million, up nearly 10% from 20202

    Source: Skybox Security

    Clearly the old vulnerability management playbook that many organisations still rely on is badly out of step with today’s threat landscape. Traditional, reactive measures such as scanning and patching are too little, too late in a world where the attack surface is exploding, vulnerabilities are rampant (and are often difficult or impossible to scan and patch), and threat actors are increasingly aggressive. It’s time to get out of reactive mode and embrace a truly proactive security posture.

    In future instalments of this series, we’ll dive deeper into the report’s findings and discuss what they mean for the future of vulnerability management. Subscribe to our blog to catch the latest.

    Learn more about the Skybox Research Lab.

    References

    1. 2021 has broken the record for zero-day hacking attacks, Technology Review, MIT, September 23, 2021.
    2. 2021 Cost of a Data Breach Report, IBM, July 28, 2021.
    • This promoted content was paid for by the party concerned
    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Skybox Skybox Security
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleHelm goes global with Dr. Oetker
    Next Article Vodacom affiliate Safaricom optimistic about Ethiopia licence despite delays

    Related Posts

    4 tips for exposure management of your business applications - Skybox Security

    4 tips for exposure management of your business applications

    19 February 2025
    Network professionals lose nearly half their week to manual tasks that could be automated - Skybox Security report

    Network professionals lose nearly half their week to manual tasks that could be automated

    3 December 2024

    Skybox: half of firms fear security incidents due to siloed network and security teams

    17 October 2024
    Add A Comment

    Comments are closed.

    Company News
    From data cabling to leading Lenovo at Pinnacle ICT - Inge Middlemas

    From data cabling to leading Lenovo at Pinnacle ICT

    24 August 2026
    Paratus Uganda first to market with Starlink service

    Paratus Uganda first to market with Starlink service

    21 August 2026
    Smarter operations take centre stage at Electra Mining Africa 2026

    Smarter operations take centre stage at Electra Mining Africa 2026

    20 August 2026
    Opinion
    The author, Jannie van Zyl

    Selling vapour is corporate suicide in slow motion

    16 July 2026
    Brazil's online gambling crackdown is a lesson for South Africa

    How Amazon outmanoeuvred Starlink in South Africa

    15 July 2026
    The Popia problem with agentic AI - Herman Haasbroek

    The Popia problem with agentic AI

    14 July 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Watts & Wheels S1E8: 'Tesla lands in Africa, just not here'

    Watts & Wheels S1E8: ‘Tesla lands in Africa, just not here’

    24 August 2026
    From data cabling to leading Lenovo at Pinnacle ICT - Inge Middlemas

    From data cabling to leading Lenovo at Pinnacle ICT

    24 August 2026

    MTN’s Iranian dead end

    24 August 2026
    MTN is cutting airtime credit while its rivals lean on it

    MTN is cutting airtime credit while its rivals lean on it

    24 August 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}