DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Cybercriminals are exploiting new industry vulnerabilities 43% faster than 1H 2023

DigitalCIO Bureau by DigitalCIO Bureau
May 20, 2024
in Tech News
0
Fortinet, Google Cloud Join Hands For SASE PoP Expansion
75
SHARES
1.3k
VIEWS
Share on FacebookShare on Twitter

Fortinet has announced the release of the FortiGuard Labs 2H 2023 Global Threat Landscape Report. The latest semi-annual report is a snapshot of the active threat landscape and highlights trends from July to December of 2023, including analysis on the speed with which cyber attackers are capitalising on newly identified exploits from across the cybersecurity industry and the rise of targeted ransomware and wiper activity against the industrial and OT sector.

“The 2H 2023 Global Threat Landscape Report from FortiGuard Labs continues to shine a light on how quickly threat actors are taking advantage of newly disclosed vulnerabilities. In this climate, both vendors and customers have a role to play. Vendors must introduce robust security scrutiny at all stages of the product development life cycle and dedicate themselves to responsible radical transparency in their vulnerability disclosures. With over 26,447 vulnerabilities across more than 2,000 vendors in 2023 as cited by NIST, it is also critical that customers maintain a strict patching regimen to reduce the risk of exploitation,” said Derek Manky, Chief Security Strategist & Global VP Threat Intelligence, FortiGuard Labs

Key findings from the second half of 2023 include:

  • Attacks started on average 4.76 days after new exploits were publicly disclosed: Like the 1H 2023 Global Threat Landscape Report, FortiGuard Labs sought to determine how long it takes for a vulnerability to move from initial release to exploitation, whether vulnerabilities with a high Exploit Prediction Scoring System(EPSS) score get exploited faster, and whether it could predict the average time-to-exploitation using EPSS data. Based on this analysis, the second half of 2023 saw attackers increase the speed with which they capitalised on newly publicised vulnerabilities (43% faster than 1H 2023). This shines a light on the need for vendors to dedicate themselves to internally discovering vulnerabilities and developing a patch before exploitation can occur (mitigate instances of 0-Day vulnerabilities). It also reinforces that vendors must proactively and transparently disclose vulnerabilities to customers to ensure they have the information needed to effectively protect their assets before cyber adversaries can exploit N-day vulnerabilities.
  • Some N-Day vulnerabilities remain unpatched for 15+ years: It’s not just newly identified vulnerabilities that CISOs and security teams must worry about. Fortinet telemetry found that 41% of organisations detected exploits from signatures less than one month old and nearly every organisation (98%) detected N-Day vulnerabilities that have existed for at least five years. FortiGuard Labs also continues to observe threat actors exploiting vulnerabilities that are more than 15 years old, reinforcing the need to remain vigilant about security hygiene and a continued prompt for organisations to act quickly through a consistent patching and updating program, employing best practices and guidance from organisations such as the Network Resilience Coalition to improve the overall security of networks.
  • Less than 9% of all known endpoint vulnerabilities were targeted by attacks: In 2022, FortiGuard Labs introduced the concept of the “red zone,” which helps readers better understand how likely it is that threat actors will exploit specific vulnerabilities. To illustrate this point, the last three Global Threat Landscape Reports have looked at the total number of vulnerabilities targeting endpoints. In 2H 2023, research found that 0.7% of all CVEs observed on endpoints are actually under attack, revealing a much smaller active attack surface for security teams to focus on and prioritise remediation efforts.
  • 44% of all ransomware and wiper samples targeted the industrial sectors: Across all of Fortinet’s sensors, ransomware detections dropped by 70% compared to the first half of 2023. The observed slowdown in ransomware over the last year can best be attributed to attackers shifting away from the traditional “spray and pray” strategy to more of a targeted approach, aimed largely at the energy, healthcare, manufacturing, transportation and logistics, and automotive industries.
  • Botnets showed incredible resiliency, taking on average 85 days for command and control (C2) communications to cease after first detection: While bot traffic remained steady relative to the first half of 2023, FortiGuard Labs continued to see the more prominent botnets of the last few years, such as Gh0st, Mirai, and ZeroAccess, but three new botnets emerged in the second half of 2023, including: AndroxGh0st, Prometei, and DarkGate.
  • 38 of the 143 advanced persistent threat (APT) groups listed by MITRE were observed to be active during 2H 2023: FortiRecon, Fortinet’s digital risk protection service, intelligence indicates that 38 of the 143 Groups that MITRE tracks were active in the 2H 2023. Of those, Lazarus Group, Kimusky, APT28, APT29, Andariel, and OilRig were the most active groups. Given the targeted nature and relatively short-lived campaigns of APT and nation-state cyber groups compared to the long life and drawn-out campaigns of cybercriminals, the evolution and volume of activity in this area is something FortiGuard Labs will be tracking on an ongoing basis.

Dark Web Discourse

The 2H 2023 Global Threat Landscape Report also includes findings from FortiRecon,  which give a glimpse into the discourse between threat actors on dark web forums, marketplaces, Telegram channels, and other sources. Some of the findings include:

  • Threat actors discussed targeting organisations within the finance industry most often, followed by the business services and education sectors.
  • More than 3,000 data breaches were shared on prominent dark web forums.
  • 221 vulnerabilities were actively discussed on the darknet, while 237 vulnerabilities were discussed on Telegram channels.
  • Over 850,000 payment cards were advertised for sale.

Turning the Tide Against Cybercrime

With the attack surface constantly expanding and an industry wide cybersecurity skills shortage, it’s more challenging than ever for businesses to properly manage complex infrastructure composed of disparate solutions, let alone keep pace with the volume of alerts from point products and the diverse tactics, techniques, and procedures threat actors leverage to compromise their victims.

Turning the tide against cybercrime requires a culture of collaboration, transparency, and accountability on a larger scale than from just individual organisations in the cybersecurity space. Every organisation has a place in the chain of disruption against cyberthreats. Collaboration with high-profile, well-respected organisations from both the public and private sectors, including CERTs, government entities, and academia, is a fundamental aspect of Fortinet’s commitment to enhance cyber resilience globally.

It’s through constant technology innovation and collaboration across industries and working groups, such as Cyber Threat Alliance, Network Resilience Coalition, Interpol, the World Economic Forum (WEF) Partnership Against Cybercrime, and WEF Cybercrime Atlas, that will collectively improve protections and aid in the fight against cybercrime globally.

Tags: Fortinet
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

GISEC Global 2026 launches Cyber First, bringing world leaders to Dubai to shape the new digital order

by DigitalCIO Bureau
September 3, 2026
0
GISEC Global 2026 launches Cyber First, bringing world leaders to Dubai to shape the new digital order

World's third largest cybersecurity event enters a new era at Dubai Exhibition Centre with expanded global footprint, flagship leadership summit and new quantum security agenda Artificial intelligence is...

Read moreDetails

TCS to harmonise Metro’s IT application landscape and support scalable growth

by DigitalCIO Bureau
September 3, 2026
0
TCS to harmonise Metro’s IT application landscape and support scalable growth

TCS will help international wholesaler METRO simplify its technology environment, reduce operational complexity and transition from country-specific systems to a more centrally governed operating model Tata Consultancy Services...

Read moreDetails

Palo Alto Networks Acquires Console to Agentify Security

by DigitalCIO Bureau
September 2, 2026
0
Palo Alto Networks Acquires Console to Agentify Security

Transforming how customers benefit from agentic-driven workflows that are purpose-built for the AI era Palo Alto Networks announced it has acquired Console, an AI-native platform that enables agentic...

Read moreDetails

ServiceNow and Aramco Digital sign collaboration agreement to enable AI-powered enterprise transformation at scale

by DigitalCIO Bureau
September 2, 2026
0
ServiceNow and Aramco Digital sign collaboration agreement to enable AI-powered enterprise transformation at scale

ServiceNow and Aramco Digital, the technology subsidiary of Aramco, announced the signing of a Collaboration Agreement to enable AI-powered workflows and accelerate enterprise transformation across the Aramco ecosystem....

Read moreDetails

Accenture has Acquired COMWARE to Strengthen Accenture Edge and Accelerate Digital Core Reinvention for Mid-Market Companies in Japan

by DigitalCIO Bureau
September 1, 2026
0
Accenture has Acquired COMWARE to Strengthen Accenture Edge and Accelerate Digital Core Reinvention for Mid-Market Companies in Japan

Accenture has acquired COMWARE. The deal was announced on August 27, 2026, and officially closed on August 31, 2026. The acquisition will further strengthen Accenture Edge, a new...

Read moreDetails
Next Post
Tenable Discloses Exploitation of Apache Tomcat Servers by Kinsing Malware

Tenable Discloses Exploitation of Apache Tomcat Servers by Kinsing Malware

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

SolarWinds AI Launches to Transform IT Service Management

SolarWinds AI Launches to Transform IT Service Management

May 22, 2024
Dynatrace Appoints James McCready as VP for Asia Pacific and Japan

Dynatrace Appoints James McCready as VP for Asia Pacific and Japan

March 6, 2024

Optiva selected by Tier 1 Telecom operator in the Middle East

August 19, 2019

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Collaboration CrowdStrike Cybersecurity Digital Transformation E-books Enterprises Fortinet Gartner Generative AI Google Cloud HCLTech IBM India Infographics Infosys Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Partnership ServiceNow Sophos Strategic Partnership Tata Consultancy Services TCS Tenable Veeam Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?