Total advisories: 1,000 ↑ (last month: 975)
Important conclusions from this month report are:
- With 1,000 advisories, we’re keeping the high pace with an average over 1,000 advisories per month. (last year ~730)
- This means a serious increase in the number of advisories: + 35.8% YTD (last month +38%)
- 21 (last month:14) Advisories do not have a CVE assigned to it including 1 highly critical (Gentoo) see below more info:
- Less than half (43%) of all vulnerabilities reported in this month have a “Remote Attack Vector” (last month 53.29%)
- The Secunia Research Team reported 1 Extremely critical advisories this month (Last month: 8) for Microsoft.
- Threat Intelligence indicates again that Moderately Critical Vulnerabilities are targeted by hackers.
- Threat Intel also indicates lower number of links to Cyber Exploits:
- 108 (last month:130) advisories contain at least one vulnerability linked to a Recent Cyber Exploit
- 349 (last month:340) advisories contained at least one vulnerability linked to a Historical Cyber Exploit.
- More than half of all advisories are disclosed by these 4 usual (Linux) suspect vendors (Linux, Red Hat,SUSE and Ubuntu)
- Interestingly among these vendors are also the ones with the most rejected advisories:
- Linux, RedHat, Ubuntu and SUSE reported 160 out of 248 advisories were rejected.
- The trend is continuing with Linux Foundation bombarding the community with many “vulnerabilities”, most of them without any threat or risk, nevertheless, researchers need to test and validate the information which is a lot of effort.
- Cisco contributed to half of all Networking related Advisories this month
- Last month we reported that 52.21%of all Secunia Advisories had a Threat (exploits, malware, ransomware, etc.) associated with them, this month the number has been LOWER to 54.40%
Using Threat Intelligence is going to help you with prioritizing what needs to be patched immediately.