Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 5 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Routers Replace PCs as Primary Threat Vector in Evolving Device Risk Landscape

New Forescout Vedere Labs Riskiest Devices 2026 Report Released at RSA

by Guru Writer
March 23, 2026
in Featured
risky deivces
Share on FacebookShare on Twitter

Forescout has identified a sharp shift in enterprise cyber risk, with network infrastructure now surpassing traditional endpoints as the most vulnerable part of organisational environments.

In its latest Riskiest Connected Devices in 2026 report, based on analysis of millions of assets in its Device Cloud, the company highlighted how the threat landscape from a device perspective is changing. Notably, 75% of the riskiest device types were not on the list just two years ago, underlining the speed at which new attack surfaces are emerging.

A key finding is the rise of network infrastructure as the primary risk category, with routers overtaking computers and accounting for around one-third of the most critical vulnerabilities. On average, routers and switches now carry nearly 32 vulnerabilities per device.

The report also introduced 11 device types appearing on the high-risk list for the first time, including serial-to-IP converters, RFID readers, BACnet routers and medical image printers. Many of these sit outside traditional IT security controls, making them harder to monitor, patch, or even identify.

According to Forescout, this reflects the broader trend of organisations are deploying more specialised, often unmanaged devices across IT, OT, IoT and IoMT environments that create new entry points for attackers.

Barry Mainz, CEO at Forescout, warned that adversaries are exploiting these gaps. “Many of these devices lack proper hardening, use default credentials, and are rarely monitored in the same way as endpoints,” he said. “Once attackers gain access, they can move laterally across the network, bypassing perimeter-focused defences. Containment is now critical to limiting impact.”

The findings also point to growing exposure from legacy systems, particularly as Windows 10 approaches end of support. Legacy operating systems remain widespread in sectors such as retail (39%), healthcare (35%) and financial services (29%). Meanwhile, commonly overlooked devices such as printers, switches and IP phones frequently run outdated firmware.

At the same time, protocol usage trends are shifting, increasing risk further. SSH is now the second most observed protocol across environments, while insecure Telnet usage continues to rise, particularly in financial services and manufacturing, despite its lack of encryption.

Daniel dos Santos, VP of Research at Forescout, noted that attackers are targeting devices that bridge environments. “We’re seeing ransomware actors leverage routers and IP cameras, while malware moves from IT into OT and even medical systems,” he said. “Security strategies must evolve to provide visibility and control across all connected domains.”

Overall, the report demonstrated how risk is no longer concentrated in traditional endpoints but is spreading across a diverse and often unmanaged device ecosystem, requiring organisations to rethink how they identify, prioritise and contain threats.

ShareTweet
Previous Post

Black Duck Launches Signal to Tackle the Security Risks of AI-Generated Code

Next Post

MIWIC26: Motunrayo Fransisca Ogundipe, Cybersecurity Analyst at TikTok

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol