northdan.
Vezi pagina în română

IT Glossary

What is a vulnerability?

The exploitable weakness: a software or configuration defect letting an attacker do what they should never be able to do.

Between the day a weakness becomes public and the day you install the patch, a race runs — and that race defines practical security more than any product does. A vulnerability is a defect with security consequences: the programming or configuration error letting somebody read data that is not theirs, execute code, bypass authentication or take control outright. The ecosystem around them has a mechanism worth understanding, because it can be used. Discovered vulnerabilities receive public identifiers, the universal catalogue names under which a weakness is tracked, together with severity scores running from negligible to critical; vendors publish patches; and from that moment automated scanners sweep the entire internet, continuously, looking for exactly the versions announced as vulnerable. For critical issues on internet-facing systems, mass exploitation begins within hours or days rather than months. Hence the golden rule of the whole discipline: patching speed matters more than any expensive tool, because the overwhelming majority of real incidents exploit known weaknesses with an existing, unapplied patch rather than the sophisticated unknown flaws reserved for large targets. Operationally that becomes four habits: an inventory of what you expose, a patching rhythm, periodic scanning, and somebody whose job it is to hear when something critical lands.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

The attack window cut to days

Patches applied on a rhythm close published weaknesses before automated scanners find you — the hygiene that prevents the majority of real incidents.

An attacker’s view of your own systems

Periodic scanning shows exactly what you expose and how seriously, producing a prioritised repair list before somebody else compiles the same list for other purposes.

Security budget spent on return

Knowing most incidents come from the known and unpatched, money goes first on inventory, updates and scanning rather than on expensive boxes over holes.

Frequently asked questions

What is a zero-day, and how much should it worry me?

A vulnerability exploited before the vendor has a patch, leaving zero days in which updating could have defended you. Realistically, for a mid-sized company the worry should be small: such flaws are expensive and get spent on large targets. Your overwhelming statistical risk is the opposite — old, public weaknesses with a patch that exists and has not been applied. Companies that panic at headlines while postponing routine updates are sheltering from lightning by standing in the pool.

We got an alert that software we use has a critical vulnerability — what are the steps?

In order: check whether your version is affected and whether the system is reachable from the internet, because critical plus exposed means now rather than tomorrow; apply the patch, or until it exists the mitigations the vendor published, such as disabling the affected feature or restricting access; and look for signs of exploitation that already happened, since for widely publicised issues the healthy assumption is that you were probably scanned. If administration is outsourced, the question is not whether they heard but when they are applying it.

Vulnerability scanning or a penetration test — what do we buy, and how often?

Both, in different roles. Scanning is automated, cheap and recurring, monthly or quarterly on exposed systems, and it catches the known: old versions and misconfiguration. Penetration testing is human, more expensive and occasional, yearly or after major changes, demonstrating real exploitability and finding what scanners cannot see, such as business logic and chained weaknesses. On a limited budget, patch discipline and recurring scanning come first, then testing on whatever matters most.

Related terms

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247