Monday , May 27 2024
vulnarabalities

Fortinet report
Attackers exploiting vulnerabilities 50% faster, just 4.76 days

Fortinet reported that in the second half of 2023, the average time form the disclosure of a vulnerability to its active exploitation in the wild decreased to just 4.76 days a 43% reduction compared to the 1st half of the year.

Fortinet’s 2H Global landscape report indicate that hackers to rush to infiltrates’ the networks to deploy malicious payloads giving less chance to the organization to patch the vulnerable system.

Researcher claimed: Biometrics of Indian Forces Exposed

Jeremiah Fowler, a security researcher, claimed to discover a major vulnerability in India's data security. He found an unprotected database...
Read More
Researcher claimed: Biometrics of Indian Forces Exposed

NSA Releases Guidance on Zero Trust Maturity

The NSA released an information sheet called "Advancing Zero Trust Maturity Throughout the Application and Workload Pillar." This sheet will...
Read More
NSA Releases Guidance on Zero Trust Maturity

Data protection is sovereignty: Mohammad A. Arafat
INFOCOM Dhaka ends promoting cyber resiliency

The two day long 7th edition of INFOCOM, India's biggest business, technology, and leadership event, themed "Sustainable Disruption", concluded today...
Read More
Data protection is sovereignty: Mohammad A. Arafat  INFOCOM Dhaka ends promoting cyber resiliency

Phoenix Summit 2024
Two days phoenix summit ended successfully at Dhaka

TheTeamPhoenix, a non-profit organization, successfully hosted Phoenix Summit 2024, the largest cyber security event in Bangladesh, from May 23-24. This...
Read More
Phoenix Summit 2024  Two days phoenix summit ended successfully at Dhaka

CISA Added Apache Flink CVE-2020-17519 Vulnerability to KEV

CISA warns Apache Flink users about a critical vulnerability. Cybercriminals are exploiting this flaw to compromise systems. Apache Flink is...
Read More
CISA Added Apache Flink CVE-2020-17519 Vulnerability to KEV

Cisco released software updates for CVE 2024-20360

Cisco, a global network solutions leader, has reported a security issue with its Firepower Management Center (FMC) software. This vulnerability,...
Read More
Cisco released software updates for CVE 2024-20360

Ivanti Patches Critical RCE Flaws in Endpoint Manager

Ivanti on Tuesday declare to patch for several products, including fixes for critical vulnerabilities in Endpoint Manager (EPM). Ivanti resolved...
Read More
Ivanti Patches Critical RCE Flaws in Endpoint Manager

German police warn of cyberattacks via Office 365

ompanies in Germany are facing a new wave of cyberattacks. The State Criminal Police Office of North Rhine-Westphalia has issued...
Read More
German police warn of cyberattacks via Office 365

Hacktivists group target Philippines government ransomware attack

SentinelOne researchers found that the Ikaruz Red Team is targeting the Philippines government using different ransomware builders like LockBit, Vice...
Read More
Hacktivists group target Philippines government ransomware attack

CISA ALERT
CISA Warns Exploiting NextGen Healthcare Mirth Connect Flaw

The US cybersecurity agency, CISA, added a flaw in NextGen Healthcare's Mirth Connect product to its catalog of Known Exploited...
Read More
CISA ALERT  CISA Warns Exploiting NextGen Healthcare Mirth Connect Flaw

Derek Manky, Chief Security Strategist at Fortinet’s FortiGuard Labs said, “The pressure on already stretched cyber-defense resources has intensified with the time-to-exploit decreasing significantly to just 4.76 days,”.

“The ability to quickly sift through a prioritized list of vulnerabilities, effectively managing these ‘ticking time bombs,’ is now more critical than ever.”

According to the report, more than 6,00,000 network sensors capture threat event of live production environment across the globe where 41% organizations detected actively exploitation less than one month old. Threat actor leveraging this narrow window to breach the systems through unpatched vulnerabilities.

Fortinet observed in the 2nd half of 2023, Hackers were in the target of IOT devices and vendors like D-link, Zyxel, Mikro Tik and Dasan. Caitlin Condon, senior manager of security research at Rapid7 said, “A large number of vulnerabilities are being exploited before security teams have any time to implement patches or other mitigations,”.

In 2023, There were some widely exploited vulnerabilities which impacted a range of famous software platforms and applications like

PaperCut NG (CVE-2023-27350) – Exploited by LockBit ransomware
Google Chrome (CVE-2023-0699) – Exploited by LockBit ransomware
Fortra GoAnywhere (CVE-2023-0669) – Exploited by Cl0p ransomware
MOVEit Transfer (CVE-2023-34362) – Exploited by Cl0p ransomware
Citrix NetScaler ADC and Gateway (CVE-2023-4966) – Exploited by LockBit ransomware.

Security experts are recommended that organizations use a combination of scanning and detection technologies, thoroughly list all public-facing assets, and priorities patching based on actual threat activity. Click here to read out the Fortinet’s Global Threat Landscape Report 2H 2023.

Check Also

cisco

Cisco released software updates for CVE 2024-20360

Cisco, a global network solutions leader, has reported a security issue with its Firepower Management …

Leave a Reply

Your email address will not be published. Required fields are marked *