A new report from Forescout reveals that published vulnerabilities increased by 43% in the first half of 2024 compared to the same period in 2023, with attackers frequently exploiting flaws in virtual private networks (VPNs) and other perimeter devices to gain initial access.
The data shows that 23,668 new vulnerabilities have been published so far this year, however only 87 Common Vulnerabilities and Exposures (CVEs) were added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) vulnerabilities catalogue, a 23% fall compared to H1 2023.
This year, more than two-thirds of CVEs were rated as low (25%) or medium (39%) CVSS scores, compared to the same period last year, when about two-thirds of vulnerabilities were classified as medium (39%) or high (27%).
These vulnerabilities impacted 39 vendors – a 17% drop from the first half of 2023. Microsoft was the most affected company (17%), followed by Google (8%), Apple (6%), D-Link (6%), Ivanti (6%), Android (5%), and Cisco (5%).
The study also found that 20% of new exploited vulnerabilities were targeted at VPN or network infrastructure appliances, noting that VPNs have been a primary target during this period with global threat actors exploiting a series of vulnerabilities in widely used solutions.
The report tracked 387 of these threat actors in 2024, of which 50% were cyber-criminals, including ransomware groups, 40% were state-sponsored actors, and 10% were hacktivists.
Forescout found that the majority of these threat actors originated from China, Russia and Iran, with a trend becoming apparent for state-sponsored actors to use hacktivist personae to conduct some of their attacks.
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Which Industries Face the Most Cyber-attacks?
- Ransomware Crisis Escalating Globally, New Report Shows
According to the study, notable examples of this trend so far in 2024 include the Ikaruz Red Team, believed to be affiliated with China, which deployed ransomware to disrupt the government of the Philippines, and the BlackJack group, thought to be affiliated with Ukrainian intelligence, which used custom malware to disable thousands of sensors monitoring Moscow’s sewage system.
To mitigate such attacks, Daniel dos Santos, senior director of research at Forescout, commented on the firm’s blog: “We encourage organisations to prioritise extending visibility, risk assessment and proactive controls to cover the increased attack surface of VPNs and network perimeter assets and appliances being exploited.
“In addition, we urge organisations to follow specific recommendations for disconnecting internet-exposed operational technology and replacing SSL VPNs.”





