The Cyber Security Review | Monday, October 25, 2021
Older exploits are much cheaper and more popular among cybercriminals who are shopping in underground forums.
FREMONT, CA: While the world grapples with the impact of the covid-19 pandemic, business ecosystems are bombarded with tons of cyberattacks. Organizations must focus on catching efforts on the vulnerabilities that pose the biggest risk, even several years old. It is often observed that exploits are sold in underground forums that are more than three years old. Cybercriminals know that businesses are struggling to prioritize and catch their vulnerabilities and several types of research indicate that delays are frequently taken advantage of. The lifespan of a vulnerability or exploit does not depend upon when a patch is released to stop it. Older exploits actually are much cheaper and hence more popular among cybercriminals who are shopping in the underground forums. To stop such attacks, virtual patching still remains one of the most effective solutions.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Several old exploits are sold regularly in the underground forums, such as CVE-2012-0158 Microsoft RE. Known as the dirty cow exploit, this exploit has been going in for five years. In 2020, 700000 devices worldwide were detected WannaCry. 47% of cybercriminals in the past two years have targeted Microsoft products. Is also a decline in the market for zero-day and N-day vulnerabilities over the past few years. This is due to the popularity of bug bounty programs and the rise of Access-as-a-Service. Access-as-a-Service is as efficient as an exploit, but it is already programmed for the buyer, sold in the underground forums at prices starting from USD 1000.
The various exploits are creating an avalanche of risks for organizations around the world. Considering that nearly 50 new CVEs were released every day in 2020, the presence of a security team and prioritization and deployment of patches promptly has never been more critical. Today, the time to patch average is nearly around 51 days for an organization patching a new vulnerability. To make these security protocols more efficient, virtual patching is a crucial component. Given that the technology is based on intrusion prevention, it provides users with a hassle-free way to protect their vulnerabilities and divert unknown threats indefinitely.
More in News