Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

02:05 PM
Connect Directly

IBM Report: Stealthy Attacks, Vulnerability Disclosures Rise

X-Force report says 35 percent of vulnerabilities affecting virtualization servers also affect the hypervisor

Covert and obfuscated attacks on organizations have increased by more than 50 percent in the past year worldwide, according to newly released report by IBM's X-Force research team.

The new IBM X-Force 2010 Mid-Year Trend and Risk Report also found that the total number of new vulnerabilities disclosed had increased 36 percent over the same period last year, to 4,396 for the first half of '10. And 55 percent of these bugs had not been fixed by the end of the first half.

"We knew this was coming for a few months before we put the data together, but it was still a surprise to us in some respects. Last year, we saw an 11 percent decrease in vulnerability disclosure," says Tom Cross, manager of XForce Research. "If you had asked me a year ago, I would not have expected this volume of disclosure."

The leap in the number of exposed flaws is both good news and bad news. "It means we're doing a lot more work to catalog them ... in some respects, applications are more secure because we are getting these vulns out in the open and getting patches out there. It's a process," Cross says.

Meanwhile, organizations around the globe are facing more hidden attacks -- these attacks rose 52 percent in the first half of 2010 versus the same period in '09 -- where the attackers hide their malicious code behind JavaScript, as well as PDF files to avoid detection, according to IBM. This category includes the infamous advanced persistent threats or APTs, which try to remain in a network undetected as long as possible to steal information.

"We're seeing people struggling with the constantly increasing sophistication of attacks," IBM's Cross says. "A lot of these attacks are obfuscated."

PDFs can also be obfuscated as well, he says. And there was a 37 percent increase in PDF-borne exploits in April of this year than the average for the first half of 2010, according to the report, mostly due to a major spam run that used PDFs to push Zeus and Pushdo bots.

The report also confirmed worries about mixing apps and operations within a virtualized server that require different levels of security: 35 percent of the vulnerabilities that affect virtualization servers also affect the hypervisor. So if an attacker wrests control of one virtual machine on a server, he or she may be able to hack into other more secure virtual systems on the same server, according to the report.

"You shouldn't be tying in different domains with different security requirements on the same physical hardware," Cross says. "A hypervisor is a piece of software, and it can have vulnerabilities like other pieces of software."

Not surprisingly, Web application vulnerabilities led the vulnerability disclosure list, making up 55 percent of all disclosures, with the number at anywhere from 3,000 to 4,000 finds per year. That number doesn't include custom Web apps, according to the report, so it's likely an even larger number. Cross-site scripting (XSS) and SQL injection were at the top of the list.

A copy of the full report from IBM X-Force is available for download here.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "This is the last time we hire Game of Thrones Security"
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2019-12-09
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
PUBLISHED: 2019-12-09
SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.
PUBLISHED: 2019-12-09
Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.
PUBLISHED: 2019-12-09
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.
PUBLISHED: 2019-12-09
Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.