Top US credit unions have multiple web app security problems
One in ten web applications are running on old components that contain known vulnerabilities
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Security researchers have discovered problems in the web applications deployed by the top ten credit unions in the US.
Researchers at Outpost24 analyzed the top US credit unions’ web application attack surface to evaluate their security. They found 1,224 publicly exposed web applications running over 107 domains, with 10% running on old components containing known vulnerabilities.
Outpost24 selected its US Credit Unions list based on a Segmint list of the Largest US Credit Unions by Assets. Researchers examined each union’s public-facing web security environments against the seven most common attack vectors hackers use during reconnaissance to ascertain a risk score between one and 100. The risk score comprised security mechanisms, page creation methods, degree of distribution, authentication, input vectors, active contents, and cookies.
The research found that the top three attack vectors against the US credit unions targeted active content technologies, followed by authentication and page creation methods.
“It’s no big surprise to see Active Content Technologies (ACT) as the biggest scorer. As soon as an application runs scripts, the attack surface could increase if a website has been developed using multiple active content technologies, some more vulnerable than others, to build and create their applications”, said Nicolas Renard and Stephane Konarkowski, security consultant at Outpost24.
Researchers said that, overall, the attack surface score for the top ten credit unions was 16.39 out of 58.24. However, research showed the worst offender from the top ten returned a disproportionately higher attack surface score of 34.08, outweighing everyone else on the list and showing a great disparity in the security posture between credit unions.
However, this score was significantly lower when compared to US retailers, which scored 48.3. According to the researchers, this is likely because of the highly regulated business model credit unions operate in that requires them to demonstrate a standard level of security hygiene to protect the company assets and customer data against cyber criminals.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Researchers also examined the components used to develop the web applications and discovered there were, on average, 17 open port 80 among the credit unions. They said this can be dangerous when the service listening on the port is misconfigured, unpatched, vulnerable to exploits, or has poor network security rules.
Researchers said it is essential for security teams to identify open ports and close unused ones or install firewalls on hosts to monitor and filter port traffic to “prevent any security issues from creeping in.”
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Ubuntu vulnerability exposes enterprises to root escalation, complete system compromiseNews The high-severity Ubuntu vulnerability allows an unprivileged local attacker to escalate privileges through the interaction of two standard system components
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization
-
Microsoft patches six zero-days targeting Windows, Word, and more – here’s what you need to knowNews Patch Tuesday update targets large number of vulnerabilities already being used by attackers
-
Experts welcome EU-led alternative to MITRE's vulnerability tracking schemeNews The EU-led framework will reduce reliance on US-based MITRE vulnerability reporting database
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
Two Fortinet vulnerabilities are being exploited in the wild – patch nowNews Arctic Wolf and Rapid7 said security teams should act immediately to mitigate the Fortinet vulnerabilities


