Since the beginning of 2026, 22% of Russian companies have been found to have database services directly accessible from the internet. This does not mean that organizations have already been hacked, but it significantly simplifies the search for a potential entry point for attackers, Bi.Zone reported.
Another 18% of companies have RDP accessible from the outside — a service for remote connection to work computers. In such a case, attackers can try to guess the password or use credentials that have previously been leaked.
From July to September alone, specialists discovered about 90 thousand systems with active remote access services in the Russian segment of the internet. Against the backdrop of the Microsoft Remote Desktop Services vulnerability, some of them could turn into a particularly dangerous entry point: the error allowed arbitrary code execution without user action.
In addition, 15% of organizations had SMB protocol accessible from the outside, and 6% had LDAP. Through such services, attackers can collect information about corporate infrastructure, accounts, and other resources.
Experts advise regularly checking the external perimeter, closing unnecessary services, restricting access to those that are truly necessary, and promptly installing updates.