
A new survey conducted by agentic AI pentesting firm Ethiack claims to have found that 19% of the web servers used by UK telecoms firms “leave crucial security information in plain sight that offers a “roadmap” to cybercriminals“. But it’s not always quite as bad as they’re making out in the headline claim.
The study is said to have analysed more than 50,000 digital assets, including the customer portals, APIs, email servers and administrative systems of almost 600 telecoms providers operating across Europe. Several UK telecoms giants, including BT, Vodafone and Three UK, accounted for over 8,300 assets (although we don’t get any specific results for them) – more than any of the 30 countries included in the study.
So, what does that figure of 19% actually represent? Apparently, it reflects the UK web servers tested that were found to be “inadvertently revealing details of their software type and version in the HTTP response banners displayed by their webpages“. But as Ethiack correctly points out later in their piece, leaving details of a server’s software type and version on display “isn’t a vulnerability per se“, but they do suggest it may still be a “gift to sophisticated cybercriminals“.
Advertisement
In fairness, it’s fairly common for web servers to expose those details to the public by default (you often have to specifically configure them not to do so) and, even when they don’t expose such information, it’s usually still possible to infer the server and software environment via deeper probes and analysis of the systems / processes taking place. Completely masking this, especially when using third-part systems/software, is difficult without breaking things.
Regardless, automated vulnerability scanners and probes will often attempt to find vulnerabilities and break in via masses of common attempts, which will still occur even without identifying the specific software and server environment being used (i.e. it’s perhaps a bigger concern if you aren’t keeping things up-to-date). But Ethiack naturally have a vested interest in selling you their services, hence the hightened tone of their piece.
Jorge Monteiro, CEO of Ethiack, said:
“Revealing the type and version of the software your server runs gives away vital clues about your security posture and can leave you wide open to cyberattack.
Skilled and state-sponsored hackers, who use automation and AI to scan vast numbers of websites for exploitable risks, know how to exploit this information and can use it as a roadmap for an attack.”
As above, we’d again point out that cyberattack attempts/probes happen all the time against publicly exposed servers / IP addresses (see today’s other news), which is somewhat par for the course with the internet. On the other hand, a little bit of paranoia is usually a good thing when talking about network security, since nasty people often are out to get you online if they can and automated systems / probes never sleep.
However, UK telecoms firms were at least found to be less exposed than their foreign counterparts, with the European average standing at an alarming 47% of web servers vs 19% in the UK. The analysis also found that 37% of the SSL security certificates (encryption that keeps the connection between you and a website secure) in use on the websites of European telecom firms are either invalid, expired or misconfigured.
Advertisement
In total, Ethiack said their analysis identified 1,452 critical assets, including VPNs, admin panels and customer-facing systems, with “significant security weaknesses that could pose a direct risk to both the telecoms provider’s operations and customer data“. But we would have liked to see more details on the specifics here.
Jorge Monteiro added:
“By definition, telecom providers are among the most connected organisations in the world. That hyperconnectivity is both their strength and their biggest vulnerability.
Our analysis shows that many telecom firms struggle with basic security hygiene, not through negligence or error, but because their IT systems are highly complex and constantly evolving. The combination of legacy platforms, cloud infrastructure, third-party integrations and shadow IT environments expands the attack surface and creates blind spots for security teams – allowing small misconfigurations to crop up without anyone realising.
Cybercriminals now use AI to scan and exploit vulnerabilities 24/7, and the Time-to-Exploit – which tracks the average time between a software patch release and active exploitation – has plunged from days to just hours.
That’s why cybersecurity teams trying to keep pace with threat actors often feel like they’re running just to stand still, and why periodic security checks are no longer enough to manage rising risk levels.”
Perhaps explain in the prose it is penetration testing rather than pentesting. I only know as a layman working on governenment IT projects (usually too expensive, poor IT companies, plus or minus 100% on quotes and massive failure!).
I love those AI driven startups and the pile of nonsense they produce.