2017 Has Broken the Record for Security Vulnerabilities2017 Has Broken the Record for Security Vulnerabilities
Some 40% of disclosed vulns as of Q3 are rated as severe, new Risk Based Security data shows.
November 15, 2017
2017 has already broken the record for the most security vulnerabilities - and that's only as of the third quarter of this year.
There were some 16,006 vulnerabilities disclosed through September 30, which is more than all of 2016, when there were 15,832, according to new data published today by Risk Based Security. The number of bugs as of Q3 represents an increase of 38% over Q3 2016. According to Risk Based Security, that's 6,295 more security vulnerabilities than those reported in the CVE and National Vulnerability Database.
"Any security product or tool that relies on CVE/NVD is putting your organization at serious risk," said Jake Kouns, CISO for Risk Based Security.
The firm's new Q3 2017 VulnDB QuickView report shows that the number of severe vulnerabilities is still high, with nearly 40% ranked above 7.0 on the CVSSv2 score. And 31.6% of disclosed vulnerabilities this year also are being abused in public exploits.
See the full report here.
Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.
About the Author(s)
Tricks to Boost Your Threat Hunting GameNov 06, 2023
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
The State of Supply Chain Threats
How to Deploy Zero Trust for Remote Workforce Security
How to Use Threat Intelligence to Mitigate Third-Party Risk
Securing the Remote Worker: How to Mitigate Off-Site Cyberattacks
How Enterprises Are Managing Application Security Risks in a Heightened Threat Environment