Vulnerability Disclosures in 2018 So Far Outpacing Previous Years'
Nearly 17% of 10,644 vulnerabilities disclosed so far this year have been critical, according to new report from Risk Based Security.
There appears to be little relief in sight for organizations hoping for some respite from patching. A new report from Risk Based Security released today reveals that the number of vulnerabilities discovered in software products shows no signs of abating.
Between January 1 and June 30 of this year, a total of 10,644 vulnerabilities were published compared to 9,690 in the same period in 2017. The trend so far this year suggests that the total number of disclosed vulnerabilities in 2018 will comfortably exceed the 20,832 vulnerabilities that Risk Based Security published during 2017 — which itself represented a 31% increase over 2016.
About 17% of the reported flaws this year were deemed critical and had a severity rating of between 9.0 and 10.0 on the CVSS rating scale. That number is smaller than the 21.1% of flaws overall that garnered the same rating in Risk Based Security's report for the first half of 2017.
Somewhat expectedly a plurality of 2018 vulnerabilities – 46.3% - were Web-related flaws, and half of all reported vulns were remotely exploitable. Nearly one-third of the vulnerabilities so far this year in Risk Based Security's database have public exploits, but 73 have a documented solution.
A majority of the vulnerabilities are based on processing user or attacker-supplied input, and the software not properly-sanitizing that input, says Brian Martin, vice president of vulnerability intelligence for Risk Based Security. "We classify them as input manipulation issues that impact the integrity of the software," he notes.
Not All in the CVE & NVD
Significantly, Risk Based Security's vulnerability database contained more than 3,275 vulnerabilities that were not published in MITRE's CVE and the National Vulnerability Database (NVD) in the first half of 2018. Of these, more than 23% had a CVSS score between 9.0 and 10.0.
In other words, organizations relying purely on the CVS/NVD vulnerability data would likely not have been aware of more than 750 other critical vulnerabilities that were published elsewhere.
"The biggest takeaway is that the number of vulnerabilities being disclosed continues to rise, and will continue to do so for the foreseeable future," Martin says.
More importantly, the data shows that organizations cannot rely solely on the CVE database for their vulnerability data, he says.
His firm uses over 2,000 sources for its vulnerability data including mail lists such as Bugtraq and Full Disclosure, exploit websites such as ExploitDB and Packetstorm, and vendor resources such as customer forums. Other sources include formal advisories and knowledge base articles, and developer resources such as changelog, bug-tracking systems, and code commits, Martin says.
Risk Based Systems typically aggregates and processes newly disclosed vulnerabilities in less than 24 hours, depending on the disclosure and if additional analysis is needed. For some security vulnerabilities, the vendor discloses at roughly the same time as CVE and for others, it is weeks and even months, ahead of them, he notes.
Not So Fast
While Risk Based Security's statistics might suggest that software is becoming increasingly buggy, the reality appears a little more nuanced. According to Martin, there are likely many reasons why more flaws are being discovered in software products these days despite the heightened awareness and attention being paid to application security.
Among them is the fact that there are a lot more security researchers looking for and reporting security vulnerabilities these days compared to a few years ago. Tools for finding security vulnerabilities have improved as well and have become faster and more reliable than before, too.
And organizations that monitor and aggregate vulnerabilities are also improving their processes and software vendors themselves have become better at disclosing vulnerabilities reported to them, Martin notes.
- B2B Marketing Manager (Managed Services)
- Up to £45,000
Experienced B2B Marketing Manager is needed for a Managed Services / Cloud Technology provider in London. The B2B Marketing Manager will be responsible for the creation, implementation and improvement of UK digital marketing content, campaigns & strategy. MUST have current experience within a b2b IT environment. Experience with marketing automation platforms such as Marketo, Hubspot etc is highly desirable. New position, actively looking to interview and appoint before the new year. CH7643 London Up to £45,000 (Marketing Jobs, Marketing Manager Jobs, Cloud Computing Jobs)
- Mission Critical Shift Engineer
- Up to £42,000 Base
A Mission Critical Shift Engineer is needed for an international data centre business in St Albans The Mission Critical Shift Engineer will be responsible for M+E engineering (support, installations, reactive/pro-active works etc.) The role will work a continental shift pattern, 4 on – 4 off. Alternating between days and nights. Other responsibilities include; Optimisation of Data Centre Infrastructure Maintenance and upgrades of M+E infrastructure. Smooth operations of the data centre property Developing a draft specification of new and other electrical projects Commission of upgrades a new equipment Requirements Electrical Engineering Degree / HNC / HND NVQ Level 3 & Testing & Inspection Qualifications Current engineering experience in a Data Centre / Data Center Environment Unfortunately, our client is unable to provide sponsorship for this opportunity and the candidate must be commutable to London. (Data Centre Jobs, Data Center Jobs, Electrical Engineering Jobs, Electrical Engineer Jobs) Ref PG7616
- Sales Engineer (Telecoms & Cloud Services)
- Upto £85,000 + 20% bonus + benefits
Sales Engineer / Presales Consultant to focus on Cloud services is needed for this Global Tier 1 carrier. You will be working with Enterprise customers helping to design Cloud solutions. You will be responsible for working alongside sales providing presales technical consultancy around my client's cloud services. You will be responsible for providing support for new business opportunities in terms of responding to RFIs & RFPs, understanding customer network requirements, high-level network architecture & design (including supplier selection on a global basis) and technical handover to network implementation teams. This is a great opportunity to join a global player who are growing their Cloud services. You will require a successful track record in the telecommunications arena ideally from a global tier 1 ISP or network provider, with a demonstrable track record in designing complex enterprise solutions. A Sales Engineer needs to be technically astute and has had experience in the design, presentation, and implementation of Wide Area Networks (WAN). They need to understand a range of Layer 1, 2, and 3 technologies (Ethernet, SDH, MPLS, IP, etc) and build a solution based on the best technology to meet a customer’s requirements. In addition, they should have an understanding and experience in Infrastructure solution design for optimising end-user experience when interacting with enterprise platforms notably MS O365, SFDC, Azure and AWS Unified threat Management security solutions (i.e. firewall, IPS/IDS, web filtering and proxy) Network routing and switching protocols and technologies (esp. Cisco) SD-WAN and SDN technologies Skilled Experience in designing and deploying hybrid cloud architectures and managing migrations from physical to virtual environments If you have any questions about this role, give us a call on 0044208 663 4030 or contact/send your CV to email@example.com Ref RA7292 (Telecommunications Jobs, Telecoms Jobs, Cloud Computing Jobs, Cloud Jobs, Presales Jobs, Sales Engineer Jobs, Sales Engineering Jobs)
- Data Scientist (Analytics)
- Up to £50,000 Base
Data Scientist - Analytics London Up to £50,000 Base Ref: PG7641 We are currently working with a Services business who are currently looking for a Data Scientist (Analytics) who has client-facing experience within the insurance industry. The Data Scientist (Analytics) will be responsible for tasks such as; Developing, deploying & testing state of the art Machine learning technology Framing business questions, testing hypothesis, and demonstrating analytical models. Stakeholder Engagement Pricing Optimisation. BAU Experience Required Client Facing experience within Insurance business's Pricing Optimisation Machine Learning; Clustering, Regression, Decision trees etc. Strong background in Python including modelling knowledge, ideally Pyspark AWS Cloud (Data Processing & Cleaning)