Business Daily Media

Men's Weekly

.

Trend Micro ZDI Surpasses 1000 Published Advisories in 1H 2023 In Continued Commitment to Coordinated Disclosure

Security leader to announce critical Microsoft zero-days at Black Hat USA 2023

HONG KONG SAR - Media OutReach - 18 August 2023 - Trend Micro (TYO: 4704; TSE: 4704), a global cybersecurity leader, announced at Black Hat USA 2023 that its Zero Day Initiative program has published advisories addressing over 1000 unique vulnerabilities in 2023.

The real-world impact if these vulnerabilities were to be weaponized would amount to time and financial losses of over 10 times the cost of prevention.

"Our proactive investment of millions each year into vulnerability research and purchases saves billions in recovery for both our customers and the industry as a whole," said Kevin Simzer, COO at Trend. "A concerning trend is being documented of companies lacking transparency around vulnerability disclosure vendor patching, which pose a threat to the security of the digital world."

Today, Trend is calling for an end to silent patching – the practice of slowing or diluting public disclosure and documentation of vulnerabilities and patches. It is a major roadblock to fighting cybercrime but is all too common among major vendors and cloud providers.

During a session at Black Hat USA 2023, Trend Research representatives revealed that silent patching has become particularly common among cloud providers. Companies are more frequently refraining from assigning a Common Vulnerabilities and Exposures (CVE) ID for public documentation and are instead privately issuing patches.

The lack of transparency or version numbers for cloud services hinders risk assessment and deprives the wider security community of valuable information for enhancing overall ecosystem security.

At last year's Black Hat event, Trend warned of a growing number of incomplete or faulty patches and an increasing reluctance among vendors to deliver authoritative information on patches in plain language. The gap has since worsened, with some companies deprioritizing patching altogether, leaving their customers and industries exposed to unnecessary and increasing risk.

Urgent action is needed to prioritize patching, address vulnerabilities and foster collaboration among researchers, cybersecurity vendors and cloud service providers to fortify cloud-based services and protect users from potential risks.

Trend is committed to transparent vulnerability patching and aims to enhance security postures industry-wide through its Zero Day Initiative program. Through its commitment to transparent disclosure, Trend's ZDI issued today advisories on several zero-day vulnerabilities including:

ZDI-CAN-20784 Github (CVSS 9.9)

  • This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft GitHub. Authentication is required to exploit this vulnerability
  • The flaw exists within the configuration of Dev-Containers. The application does not enforce the privileged flag within a dev container configuration. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor

ZDI-CAN-20771 Microsoft Azure (CVSS 4.4)

  • This vulnerability allows remote attackers to disclose sensitive information on Microsoft Azure. An attacker must first obtain the ability to execute high-privileged code on the target environment in order to exploit this vulnerability
  • The flaw exists within the handling of certificates. The issue results from the exposure of a resource to the wrong control sphere. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.

For a full list of advisories published by Trend Micro's ZDI, visit: https://www.zerodayinitiative.com/advisories/published/

Trend Micro's ZDI pioneered the vulnerability marketplace with a focus on disrupting attackers by legitimately purchasing vulnerability research that can then be disclosed to affected vendors to address before the information is made public.

Hashtag: #trendmicro #ZDI #cybersecurity #cloudsecurity



The issuer is solely responsible for the content of this announcement.

About Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,500+ employees across 70 countries, Trend Micro enables organizations to simplify and secure their connected world.

News from Asia

Pharm-D Health Science’s ELDON formalises brand ambassador partnership with Malaysian media personalities Chan Fong and Henley Hii as Brand earns Malaysia Book of Records recognition

MoU signing and Malaysia Book of Records recognition underscore sustained consumer trust for ELDON, at a time when Malaysians are paying closer attention to sleep, stress and lifestyle balance KUA...

1win and MMA Legend Jon Jones Fulfill Over 100 Wishes in Global Holiday Initiative

WILLEMSTAD, CURAÇAO - Media OutReach Newswire - 6 January 2026 - 1win Charity, together with MMA legend Jon Jones, has successfully concluded its global campaign 1wish Season – a holiday initiati...

Allianz Risk Barometer 2026: Cyber remains top business risk but AI fastest riser at #2 in Asia Pacific

Cyber, especially ransomware attacks, ranks as the #1 risk for companies of all sizes (36% of responses) Artificial Intelligence is the biggest riser and jumps from #...

Shape the Era, Pioneer the Times — Ge Jun 2026 New Year Eve’s Talk Opens in Guangzhou, Offering Forward-Looking Perspectives for Entrepreneurs

HONG KONG SAR - Media OutReach Newswire - 14 January 2026 - Initiated by Ge Jun, Chairman and CEO of TOJOY Enterprise Services, Shape the Era, Pioneer the Times — Ge Jun 2026 New Year Eve's Talk ...

Dusit records all-time high hotel signings in 2025, positions for a strong year of openings in 2026

Landmark deals across India, Japan, the Maldives, the Middle East, and Southeast Asia underscore strong developer confidence and the enduring appeal of Dusit’s diversified brand portfolio. BANGKOK...

Kryston Catering Launches Year of the Golden Horse Collection for Seamless Reunion Celebrations

From intimate family dinners to grand corporate feasts, Kryston's Chinese New Year menus bring abundance and prosperity to every table. Let the spirit of reunion take centre stage while hosts embra...

Flyer King Repositions Its Brand for 2026, Launches New Slogan

“The First Choice for Brand Event Planning” to Lead Integrated Service Upgrade** HONG KONG SAR - Media OutReach Newswire - 14 January 2026 - Founded in 2013 with a focus on street promotions and f...

Xtep Expands Overseas: Deep Restructuring of Malaysian Channels Marks Entry into Intensive Global Strategy Phase

KUALA LUMPUR, MALAYSIA - Media OutReach Newswire - 14 January 2026 - Running shoes brand Xtep has announced that it will form a joint venture with Bonia, a distributor with over 50 years of market...

Bolton opens its first "Bolton Food Research & Innovation Center" to advance innovation and science towards a more sustainable seafood industry

SINGAPORE - Media OutReach Newswire - 14 January 2026 - Bolton, with its Food Business Unit, has inaugurated today its first Research & Innovation Center, marking a major milestone in its long...

SL Aesthetic Group Celebrates 22 Years of Growth and Innovation Across Singapore and Southeast Asia

SINGAPORE - Media OutReach Newswire - 12 January 2026 - SL Aesthetic Group celebrates its 22nd anniversary, marking its growth from a single clinic into a multi-brand medical aesthetics and health...

Refunds to Revenue: AI and loyalty perks help retailers in post-holiday hangover

Australian retailers are turning to artificial intelligence to simplify and automate returns and exchanges, while strengthening loyalty programs a...

Stop reading from the script: Why authenticity is the customer success secret weapon

I’ve been in customer service for years now. As my team has grown, the number one piece of advice I give is to be your...

From Check-in to Touchdown: How AI and smarter systems are transforming the travel industry

Richard Valente, VP of Customer Experience Strategy at TP in Australia, explores how IT-BPM outsourcing is revolutionising the travel sector throu...

Online Christmas shoppers fund climate and biodiversity projects via HealthPost's Click Sphere for Good initiative

Online shoppers with HealthPost’s Flora & Fauna have made 11,000 contributions towards climate and biodiversity projects when ordering parcel ...

US landmark settlement protects SMEs, highlighting flaws in the RBA's proposed blanket card surcharging ban for Australia

Aussie SMEs warn RBA not to ignore global trends, with the current sledgehammer approach threatening business viability and increasing inflation ...

Thryv Australia named Employer of Choice for third consecutive year at Australian Business Awards

Thryv® (NASDAQ: THRY), Australia’s provider of the leading small business marketing and sales software platform, has been awarded the Employer of ...