A significant proportion of enterprise assets are currently running end-of-life (EOL) operating systems, posing a growing security risk as these systems no longer receive regular feature updates or bug fixes. According to research conducted by runZero, 8.56% of assets across hundreds of U.S. enterprises are operating on EOL systems, with 5% already beyond extended support and thus missing critical security patches. The prevalence of these unsupported systems is particularly high in industries such as retail, machinery, electronics manufacturing, healthcare, and social services, where legacy applications are often essential for core business functions. In healthcare and social services, the use of unsupported operating systems can directly impact patient safety due to their integration with critical care applications. The situation is set to worsen dramatically with the upcoming end-of-life date for Windows 10 on October 14, 2025. After this date, approximately one-third of all enterprise Windows assets will lose official support, causing the overall percentage of EOL systems in enterprises to surge from 5% to around 16%. This transition, referred to as the 'Winpocalypse,' will disproportionately affect sectors already struggling with legacy dependencies, especially healthcare and social services, which are expected to see the steepest increases in exposure. Many organizations remain reliant on Windows 10 and earlier versions due to business-critical applications that cannot be easily migrated or upgraded. The persistence of these 'undead' systems is often due to forgotten servers or specialized equipment, such as medical devices, that are incompatible with newer operating systems. Attackers exploit these vulnerabilities by using network reconnaissance to identify and compromise outdated systems, which are often overlooked in standard security assessments. Internet scans reveal only a portion of the risk, as many legacy systems are not directly exposed but remain accessible to attackers who have breached the network perimeter. Security experts emphasize the need for organizations to establish a baseline inventory of EOL systems and to assess their unique risk profiles, rather than assuming complete eradication of unsupported assets is feasible. The looming Windows 10 deadline has prompted renewed calls for enterprises to accelerate migration plans and to implement compensating controls where immediate upgrades are not possible. Failure to address the growing population of EOL systems will significantly expand the attack surface available to cybercriminals, increasing the likelihood of successful breaches. The research underscores the urgency for proactive asset management, regular vulnerability assessments, and strategic planning to mitigate the risks associated with legacy operating systems. Organizations are advised to prioritize the replacement or isolation of unsupported systems, especially those integral to critical business operations. The findings highlight the intersection of operational necessity and cybersecurity risk, illustrating the complex challenges enterprises face in balancing legacy support with modern security requirements. As the Windows 10 end-of-life approaches, the need for comprehensive risk management strategies becomes ever more pressing for organizations across all sectors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced that Windows 10 support ended on 2025-10-14 and said Office 2016 and Office 2019 also reached end of support that day. It added that newer perpetual Office versions may still run on Windows 10 but will no longer be supported on that configuration, and urged customers to move to Windows 11 or Microsoft 365.
Dark Reading published coverage describing how outdated and unsupported operating systems continue to remain active across enterprise environments, emphasizing the security challenges they create. The article reflects broader reporting on the persistence of legacy systems as a current enterprise risk.
runZero published new research highlighting the security risks posed by legacy and end-of-life assets in enterprise networks. The report frames unsupported systems as an ongoing exposure and calls attention to their prevalence in modern environments.
Microsoft lifecycle guidance stated that Windows 10 version 22H2 is the final feature update supported through 2025-10-14 and added that paid Extended Security Updates will be available after end of support. The guidance also reiterated that unsupported Windows versions no longer receive security patches or technical assistance.
Microsoft announced that Windows 10 version 21H2 Enterprise, Enterprise multi-session, and Education editions would reach end of updates on 2024-06-11. After that date, those editions would no longer receive monthly security and preview updates.
6 references tracked. Mallory keeps watching after this page renders.
support.microsoft.com
Open sourcesupport.microsoft.com
Open sourcerunzero.com
Open sourcedarkreading.com
Open sourcewindows.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.