Mandiant researchers found that over 90 zero-day vulnerabilities and more than 40 known vulnerabilities were exploited in the wild.
Vulnerabilities Exploited:
By infosecbulletin
/ Saturday , November 2 2024
GitHub has launched an AI tool called 'Spark' that allows users to create apps using natural language, eliminating the need...
Read More
By infosecbulletin
/ Friday , November 1 2024
"A threat actor has reportedly claimed to gain root-level access to Titas Gas’s firewall server and is actively offering this...
Read More
By infosecbulletin
/ Friday , November 1 2024
Zimperium researchers have found a new version of FakeCall malware for Android that threatens financial security. This malware redirects users'...
Read More
By infosecbulletin
/ Friday , November 1 2024
Hikvision, a top provider of network cameras, has issued firmware updates to fix a security vulnerability that could reveal users'...
Read More
By infosecbulletin
/ Friday , November 1 2024
Global threat actors have significantly increased attacks on government sectors, with malware-driven attempts rising by triple digits in the first...
Read More
By infosecbulletin
/ Thursday , October 31 2024
Meetup of Bangladesh Kubernetes User Group was held at Banani Club 9294, Dhaka on Thursday, 31 October 2024. A lively...
Read More
By infosecbulletin
/ Thursday , October 31 2024
Bangladesh Bank issues alert on cyber threat. In its alert the central bank said, according to Bangladesh cyber security intelligence...
Read More
By infosecbulletin
/ Thursday , October 31 2024
Interbank, a major financial institution in Peru, has confirmed a data breach after a hacker leaked stolen data online. Formerly...
Read More
By infosecbulletin
/ Wednesday , October 30 2024
The US Cybersecurity and Infrastructure Security Agency (CISA) has released its first international strategic plan to enhance global cooperation in...
Read More
By infosecbulletin
/ Tuesday , October 29 2024
The Indian Cyber Crime Coordination Centre (I4C) has warned about illegal payment gateways set up by transnational cyber criminals using...
Read More
A comprehensive vulnerability analysis by “Mandiant” for 2023 uncovered “138” actively exploited “security vulnerabilities.”
They identified a significant prevalence of “97 zero-day vulnerabilities” and “41 n-day vulnerabilities” (the latter being exploited following the implementation of their respective patches). (those exploited after patch release).
The key finding was the considerable decrease in “Time-to-Exploit” (“TTE”), which fell to an average of just five days in 2023, compared to “32 days in 2021-2022,” “44 days in 2020-2021,” and “63 days in 2018-2019.”
The ratio of “n-day” to “zero-day” exploits changed to “30:70 in 2023,” down from the earlier ratio of about “38:62,” indicating a marked rise in “zero-day exploitation activities.”
Besides this, for “n-day vulnerabilities” specifically the exploitation timeline showed concerning trends:-
12% (5 vulnerabilities) were exploited within 24 hours of patch release.
29% (12 vulnerabilities) were exploited within a week.
56% were exploited within the first month.
A key case study is “CVE-2023-28121,” a vulnerability in the WooCommerce Payments plugin. This flaw highlighted how the availability of an exploit affected the timing of attacks, which occurred three months after it was disclosed.
Within three days of a weaponized exploit’s release, there were 1.3 million attacks per day.
Oracle Security Update, 334 Vulnerabilities Patched