Site navigation

PoC Exploits Used 22 Minutes After Release, Report Finds

Elizabeth Greenberg

,

PoC exploits
Threat actors have increased their specialisations, enabling them to more rapidly take advantage of emerging vulnerabilities. 

Proof of concept (PoC) exploits are being rapidly weaponised by threat actors, even as soon as 22 minutes after they are made available to the public, new research from Cloudflare reveals.

The cybersecurity firm’s Application Security report which covers from April 2023 to March 2024, which delves into the threat landscape.

The report found that the speed at which these vulnerabilities are exploited outpaces defence and patch development, leaving organisations in the lurch as weaknesses are identified and proliferate across the public sphere.

For Cloudflare, this pushed the company to integrate their human written signatures of defence with a machine-learning approach to increase the speed of their response and reduce false positives.

The firm also said the speed of exploiting attack vectors has been enhanced by the specialisation of threat actors in certain vulnerabilities and attack types, meaning they can efficiently use weaknesses to their advantage.

Internet traffic was also studied in the report, with a shocking finding that 6.8% of all daily internet traffic is caused by distributed denial of service (DDoS) traffic, which is a common form of attack aiming to make online platforms inaccessible to users due to an oversaturation of traffic.

This is a marked increase from the 6% seen in the year prior, showing that DDoS attacks are on the rise. In total, DDoS comprised 37.1% of all mitigated application traffic, and HTTP DDoS attacks increased by 93% year on year.


Recommended reading


But this is still only the average – according the Cloudflare, malicious traffic can double, reaching 12% during global attack incidents.

This also suggests that bots are becoming increasingly common, and more effective in launching DDoS attacks. DDoS was found to be the number one attack type taken against web apps.

The report found that 93% of bots are potentially malicious, with one third (31.2%) of all traffic stemming from bots, 93% of which are unverified.

Elizabeth Greenberg

Staff Writer

Latest News

Editor's Picks Gaming

Xbox Rolls Out Disc-to-Digital Feature

Business Editor's Picks

Report: Scottish SMEs Face Mounting Cost and Revenue Pressures

Cybersecurity

Five Actions CISOs Can Take to Stay Ahead of Disruptions

Events Featured Finance

Just One Week to Go Until Fintech Summit 2026