Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/25/2010
02:05 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

IBM Report: Stealthy Attacks, Vulnerability Disclosures Rise

X-Force report says 35 percent of vulnerabilities affecting virtualization servers also affect the hypervisor

Covert and obfuscated attacks on organizations have increased by more than 50 percent in the past year worldwide, according to newly released report by IBM's X-Force research team.

The new IBM X-Force 2010 Mid-Year Trend and Risk Report also found that the total number of new vulnerabilities disclosed had increased 36 percent over the same period last year, to 4,396 for the first half of '10. And 55 percent of these bugs had not been fixed by the end of the first half.

"We knew this was coming for a few months before we put the data together, but it was still a surprise to us in some respects. Last year, we saw an 11 percent decrease in vulnerability disclosure," says Tom Cross, manager of XForce Research. "If you had asked me a year ago, I would not have expected this volume of disclosure."

The leap in the number of exposed flaws is both good news and bad news. "It means we're doing a lot more work to catalog them ... in some respects, applications are more secure because we are getting these vulns out in the open and getting patches out there. It's a process," Cross says.

Meanwhile, organizations around the globe are facing more hidden attacks -- these attacks rose 52 percent in the first half of 2010 versus the same period in '09 -- where the attackers hide their malicious code behind JavaScript, as well as PDF files to avoid detection, according to IBM. This category includes the infamous advanced persistent threats or APTs, which try to remain in a network undetected as long as possible to steal information.

"We're seeing people struggling with the constantly increasing sophistication of attacks," IBM's Cross says. "A lot of these attacks are obfuscated."

PDFs can also be obfuscated as well, he says. And there was a 37 percent increase in PDF-borne exploits in April of this year than the average for the first half of 2010, according to the report, mostly due to a major spam run that used PDFs to push Zeus and Pushdo bots.

The report also confirmed worries about mixing apps and operations within a virtualized server that require different levels of security: 35 percent of the vulnerabilities that affect virtualization servers also affect the hypervisor. So if an attacker wrests control of one virtual machine on a server, he or she may be able to hack into other more secure virtual systems on the same server, according to the report.

"You shouldn't be tying in different domains with different security requirements on the same physical hardware," Cross says. "A hypervisor is a piece of software, and it can have vulnerabilities like other pieces of software."

Not surprisingly, Web application vulnerabilities led the vulnerability disclosure list, making up 55 percent of all disclosures, with the number at anywhere from 3,000 to 4,000 finds per year. That number doesn't include custom Web apps, according to the report, so it's likely an even larger number. Cross-site scripting (XSS) and SQL injection were at the top of the list.

A copy of the full report from IBM X-Force is available for download here.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Google's new See No Evil policy......
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31664
PUBLISHED: 2021-06-18
RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information.
CVE-2021-33185
PUBLISHED: 2021-06-18
SerenityOS contains a buffer overflow in the set_range test in TestBitmap which could allow attackers to obtain sensitive information.
CVE-2021-33186
PUBLISHED: 2021-06-18
SerenityOS in test-crypto.cpp contains a stack buffer overflow which could allow attackers to obtain sensitive information.
CVE-2021-31272
PUBLISHED: 2021-06-18
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.
CVE-2021-31660
PUBLISHED: 2021-06-18
RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.