Site navigation

Published Vulnerabilities Surge by 43% in H1 2024

Staff Writer

,

VPN statistics 2024
New research from Forescout has found an increase in published vulnerabilities and ransomware incidents, with major threat groups targeting VPN vulnerabilities and state-sponsored actors using hacktivist personas as a disguise.

A new report from Forescout reveals that published vulnerabilities increased by 43% in the first half of 2024 compared to the same period in 2023, with attackers frequently exploiting flaws in virtual private networks (VPNs) and other perimeter devices to gain initial access.

The data shows that 23,668 new vulnerabilities have been published so far this year, however only 87 Common Vulnerabilities and Exposures (CVEs) were added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) vulnerabilities catalogue, a 23% fall compared to H1 2023.

This year, more than two-thirds of CVEs were rated as low (25%) or medium (39%) CVSS scores, compared to the same period last year, when about two-thirds of vulnerabilities were classified as medium (39%) or high (27%).

These vulnerabilities impacted 39 vendors – a 17% drop from the first half of 2023. Microsoft was the most affected company (17%), followed by Google (8%), Apple (6%), D-Link (6%), Ivanti (6%), Android (5%), and Cisco (5%).

The study also found that 20% of new exploited vulnerabilities were targeted at VPN or network infrastructure appliances, noting that VPNs have been a primary target during this period with global threat actors exploiting a series of vulnerabilities in widely used solutions.

The report tracked 387 of these threat actors in 2024, of which 50% were cyber-criminals, including ransomware groups, 40% were state-sponsored actors, and 10% were hacktivists.

Forescout found that the majority of these threat actors originated from China, Russia and Iran, with a trend becoming apparent for state-sponsored actors to use hacktivist personae to conduct some of their attacks. 


Recommended reading


According to the study, notable examples of this trend so far in 2024 include the Ikaruz Red Team, believed to be affiliated with China, which deployed ransomware to disrupt the government of the Philippines, and the BlackJack group, thought to be affiliated with Ukrainian intelligence, which used custom malware to disable thousands of sensors monitoring Moscow’s sewage system.

To mitigate such attacks, Daniel dos Santos, senior director of research at Forescout, commented on the firm’s blog: “We encourage organisations to prioritise extending visibility, risk assessment and proactive controls to cover the increased attack surface of VPNs and network perimeter assets and appliances being exploited. 

“In addition, we urge organisations to follow specific recommendations for disconnecting internet-exposed operational technology and replacing SSL VPNs.”

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data