Vulnerability Disclosures in 2018 So Far Outpacing Previous Years'
Nearly 17% of 10,644 vulnerabilities disclosed so far this year have been critical, according to new report from Risk Based Security.
There appears to be little relief in sight for organizations hoping for some respite from patching. A new report from Risk Based Security released today reveals that the number of vulnerabilities discovered in software products shows no signs of abating.
Between January 1 and June 30 of this year, a total of 10,644 vulnerabilities were published compared to 9,690 in the same period in 2017. The trend so far this year suggests that the total number of disclosed vulnerabilities in 2018 will comfortably exceed the 20,832 vulnerabilities that Risk Based Security published during 2017 — which itself represented a 31% increase over 2016.
About 17% of the reported flaws this year were deemed critical and had a severity rating of between 9.0 and 10.0 on the CVSS rating scale. That number is smaller than the 21.1% of flaws overall that garnered the same rating in Risk Based Security's report for the first half of 2017.
Somewhat expectedly a plurality of 2018 vulnerabilities – 46.3% - were Web-related flaws, and half of all reported vulns were remotely exploitable. Nearly one-third of the vulnerabilities so far this year in Risk Based Security's database have public exploits, but 73 have a documented solution.
A majority of the vulnerabilities are based on processing user or attacker-supplied input, and the software not properly-sanitizing that input, says Brian Martin, vice president of vulnerability intelligence for Risk Based Security. "We classify them as input manipulation issues that impact the integrity of the software," he notes.
Not All in the CVE & NVD
Significantly, Risk Based Security's vulnerability database contained more than 3,275 vulnerabilities that were not published in MITRE's CVE and the National Vulnerability Database (NVD) in the first half of 2018. Of these, more than 23% had a CVSS score between 9.0 and 10.0.
In other words, organizations relying purely on the CVS/NVD vulnerability data would likely not have been aware of more than 750 other critical vulnerabilities that were published elsewhere.
"The biggest takeaway is that the number of vulnerabilities being disclosed continues to rise, and will continue to do so for the foreseeable future," Martin says.
More importantly, the data shows that organizations cannot rely solely on the CVE database for their vulnerability data, he says.
His firm uses over 2,000 sources for its vulnerability data including mail lists such as Bugtraq and Full Disclosure, exploit websites such as ExploitDB and Packetstorm, and vendor resources such as customer forums. Other sources include formal advisories and knowledge base articles, and developer resources such as changelog, bug-tracking systems, and code commits, Martin says.
Risk Based Systems typically aggregates and processes newly disclosed vulnerabilities in less than 24 hours, depending on the disclosure and if additional analysis is needed. For some security vulnerabilities, the vendor discloses at roughly the same time as CVE and for others, it is weeks and even months, ahead of them, he notes.
Not So Fast
While Risk Based Security's statistics might suggest that software is becoming increasingly buggy, the reality appears a little more nuanced. According to Martin, there are likely many reasons why more flaws are being discovered in software products these days despite the heightened awareness and attention being paid to application security.
Among them is the fact that there are a lot more security researchers looking for and reporting security vulnerabilities these days compared to a few years ago. Tools for finding security vulnerabilities have improved as well and have become faster and more reliable than before, too.
And organizations that monitor and aggregate vulnerabilities are also improving their processes and software vendors themselves have become better at disclosing vulnerabilities reported to them, Martin notes.
- Information Security Risk Consultant, HMG, Public sector
A Public Sector Information Security Risk Consultant is needed for a long term project in the Yorkshire area. This is a Security consultancy role so travel to other client site locations across the country will be expected. The Public Sector Information Security Risk Consultant MUST have current security clearance and ideally have a breath of information and technology security experience. Broad knowledge across IT transformation, Cloud is also key. Public Sector Information Security Risk Consultant should be versed in working within the public sector HMG environments and be experienced in conducting security risk assessments on sizable IT systems. Broad experience across GRC, ISO27001, NIST is key. Career progression, personal development and excellent training provided. All details kept in the strictest of confidence Salary: £55,000 Location: Yorkshire Ref: GM7720 (Cyber Security Jobs, Information Security Jobs, IT Security Jobs, Cyber Security Jobs in Yorkshire)
- Greenfield opportunity SOC / Threat Hunting Services Lead
- £85,000+ Base
Exclusive Greenfield opportunity to DCL Search & Selection. We are looking for an experienced SOC / Threat Hunting Services Lead to build a NEW Security Operation Centre (SOC) / Threat hunting service within an existing security consultancy. This is a brand new service offering for the client. The successful SOC / Threat Hunting Services Lead must, therefore, have previous experience in building a SOC / Threat hunting (IR) service from the beginning. Everything including, but not limited to; selection of the systems, platforms, kitting out the physical office space. Customisation, setting the policies, playbooks, go to market collateral, recruitment (through DCL obviously) establish processes, management of the team, service delivery, refinement, development etc. Essentially the end to end creation of the capability and then the day to day management and expansion of the service. An in-depth technical background is essential, experience across SOC SIEM/ Threat Hunting (IR) tools, processes, techniques, operational etc The goal is to create, spin up and deliver a SOC/threat hunting (IR) offering to clients ASAP in 2020. Investment and board sign off approved. Apply today for more information or contact me directly on Chris.Holt@dclsearch.com or 07884666351. Candidates must be UK based and commutable to Bracknell. Sponsorship can not be provided to Non-EU Candidates. Ref CH7713 £85,000+ Base
- IT Managed Services Account Director
- Up to £80,000 + Double OTE
IT Managed Services Account Director We are currently working with a growing multi managed service provider who specialises in Cloud & Connectivity services who are currently looking for an IT Managed Services Account Director in London. The IT Managed Services Account Director will be responsible for selling (Increase revenue, develop pipeline etc.) into our client’s current enterprise customers selling public cloud solutions. The IT Managed Services Account Director should have Current experience selling public cloud solutions (preferably Microsoft Azure) into enterprise customers. Currently working for an IT managed services business Commutable to London, Home working is available (Non-EU candidates are not able to be sponsored). Consistent tenure in current and previous positions. Ref BD7703 Salary: Up to £80,000 + Double OTE (Cloud Jobs, Cloud Computing Jobs, Cloud Sales Jobs, Azure Jobs)
- Service Delivery Lead (Data Centre)
- Up to £60,000 Base
A State of the Art Data Centre business are looking for a Service Delivery Lead-in Wiltshire. The Service Delivery Lead will be responsible for maintaining and improving current services to our client's customers. The Service Delivery Lead will also be responsible for a service desk team (reviews, hiring, training etc.) Other responsibilities include: Acting as a senior point of escalation for any customer incidents making sure these are raised quickly and efficiently Root cause analysis Maintain and improve ITIL disciplines Experience required ITIL v3 Certified Current experience within a Data Centre / Data Center Environment Current experience within a Senior Service Desk role. Candidates must be UK based. Sponsorship is not available for Non-EU candidates. Ref BD7701 Up to £60,000 Base (Data Centre Jobs, Data Center Jobs, Service Delivery Jobs)