Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

02:05 PM
Connect Directly

IBM Report: Stealthy Attacks, Vulnerability Disclosures Rise

X-Force report says 35 percent of vulnerabilities affecting virtualization servers also affect the hypervisor

Covert and obfuscated attacks on organizations have increased by more than 50 percent in the past year worldwide, according to newly released report by IBM's X-Force research team.

The new IBM X-Force 2010 Mid-Year Trend and Risk Report also found that the total number of new vulnerabilities disclosed had increased 36 percent over the same period last year, to 4,396 for the first half of '10. And 55 percent of these bugs had not been fixed by the end of the first half.

"We knew this was coming for a few months before we put the data together, but it was still a surprise to us in some respects. Last year, we saw an 11 percent decrease in vulnerability disclosure," says Tom Cross, manager of XForce Research. "If you had asked me a year ago, I would not have expected this volume of disclosure."

The leap in the number of exposed flaws is both good news and bad news. "It means we're doing a lot more work to catalog them ... in some respects, applications are more secure because we are getting these vulns out in the open and getting patches out there. It's a process," Cross says.

Meanwhile, organizations around the globe are facing more hidden attacks -- these attacks rose 52 percent in the first half of 2010 versus the same period in '09 -- where the attackers hide their malicious code behind JavaScript, as well as PDF files to avoid detection, according to IBM. This category includes the infamous advanced persistent threats or APTs, which try to remain in a network undetected as long as possible to steal information.

"We're seeing people struggling with the constantly increasing sophistication of attacks," IBM's Cross says. "A lot of these attacks are obfuscated."

PDFs can also be obfuscated as well, he says. And there was a 37 percent increase in PDF-borne exploits in April of this year than the average for the first half of 2010, according to the report, mostly due to a major spam run that used PDFs to push Zeus and Pushdo bots.

The report also confirmed worries about mixing apps and operations within a virtualized server that require different levels of security: 35 percent of the vulnerabilities that affect virtualization servers also affect the hypervisor. So if an attacker wrests control of one virtual machine on a server, he or she may be able to hack into other more secure virtual systems on the same server, according to the report.

"You shouldn't be tying in different domains with different security requirements on the same physical hardware," Cross says. "A hypervisor is a piece of software, and it can have vulnerabilities like other pieces of software."

Not surprisingly, Web application vulnerabilities led the vulnerability disclosure list, making up 55 percent of all disclosures, with the number at anywhere from 3,000 to 4,000 finds per year. That number doesn't include custom Web apps, according to the report, so it's likely an even larger number. Cross-site scripting (XSS) and SQL injection were at the top of the list.

A copy of the full report from IBM X-Force is available for download here.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...