Kaspersky says Thai businesses face nearly 500 cyberattacks per day due to lack of patching

164

Kaspersky reveals that unpatched systems expose Thai businesses to an average of 488 cyberattacks per day, and reveals statistics that organizations in Southeast Asia are attacked an average of 6,750 times per day.

October 10, 2568 Latest data from Kaspersky, a global cybersecurity and privacy company. revealed that Vulnerabilities in corporate networks in Thailand make them vulnerable to cyberattacks. In the first half of 2568 (January – June), Kaspersky's enterprise solutions blocked 1,195,673 exploits targeting organizations in Southeast Asia, an average of 6,750 per day.

Indonesia had the highest number of attacks in the region at 524,657, followed by Vietnam (301,880) and Malaysia (190,556). Thailand came in fourth, with 88,966 attacks targeting businesses and organizations in the country, averaging 488 attacks per day.

Exploits are malicious programs designed to exploit flaws or vulnerabilities in software or operating systems to gain unauthorized access. If left unaddressed or patched, these vulnerabilities can become a gateway for cybercriminals to attack.

According to another Kaspersky report, It states that in Q2 2568, the most common vulnerabilities worldwide targeted Microsoft Office products with unpatched security vulnerabilities. Kaspersky solutions detected the following vulnerabilities on the Windows platform:

  • CVE-2018-0802: Remote Code Execution Vulnerability in the Equation Editor Component
  • CVE-2017-11882: Another remote code execution vulnerability that also affects the Equation Editor.
  • CVE-2017-0199: A vulnerability in Microsoft Office and WordPad could allow an attacker to gain control of the system.

The report also shows that the top 10 most exploited vulnerabilities include both new and old unpatched zero-day vulnerabilities that organizations continue to overlook. Zero-day vulnerabilities are software vulnerabilities that attackers discover before vendors do, and because vendors are unaware of the vulnerability, there are no patches for the zero-day vulnerabilities, making attacks more likely to succeed.

Cybercriminals and advanced threat (APT) groups are also targeting widely used tools like remote access software, document editors, and data capture systems. Notably, low-code/no-code (LCNC) platforms and AI-powered application frameworks also made the list, signaling that attackers are accelerating the exploitation of new technologies as businesses adopt them. The primary goal remains the same: gaining access to systems and escalating privileges, enabling deeper and longer-term control over an enterprise network.

The LCNC platform is a development tool that enables everyday users to build applications through a visual interface and intuitive drag-and-drop components, with little to no traditional coding knowledge. These platforms enable both everyday users and professional IT teams to quickly build web and mobile applications by combining pre-built templates and connecting them through intuitive visual tools.

Adrian Hea, Managing Director, Asia Pacific, Kaspersky said “Our latest data highlights the significant and ongoing challenges facing organizations in Thailand and across Southeast Asia. Of particular concern is that attackers are not only exploiting new and sophisticated zero-day vulnerabilities, but also exploiting older, unpatched vulnerabilities that have been known risks for years. Our report is a clear call to action. Businesses must prioritize proactive vulnerability management to close the door on cybercriminals and protect their networks from long-term attacks.”

Web threats are one of the top threats to businesses and organizations in Southeast Asia. In the first half of 2568, Kaspersky's enterprise solutions detected and blocked 7,834,941 web threats in the region, an average of 43,049 per day.

Thailand had the highest number of web threat incidents in the region at 2,524,439, followed by Malaysia and Indonesia at 1,703,788 and 1,626,984, respectively.

Web threats refer to malware programs that target users while they are using the Internet. Web threats are not limited to online activities, but may involve the Internet at some stage to cause damage.

With ongoing attacks on organizations in Thailand, Kaspersky recommends the following:

  • Check for vulnerabilities only in secure virtual environments.
  • 24/7 infrastructure monitoring with a focus on perimeter protection
  • Maintain a robust patch management process by installing security updates promptly. To set up and automate this process, use Vulnerability Assessment and Patch Management and the Kaspersky Vulnerability Data Feed.
  • Deploy a reliable solution to detect and block malicious software on your organization's devices, coupled with comprehensive tools that include incident response scenarios, employee training programs, and a modern cyberthreat database.
  • Use the latest Threat Intelligence data to understand the tactics, techniques, and procedures (TTPs) used by threat actors.

 

Read news related to Technology circles around the world can be found here.





Money & Banking Magazine