Business Daily Media

Business Marketing

.

Trend Micro ZDI Surpasses 1000 Published Advisories in 1H 2023 In Continued Commitment to Coordinated Disclosure

Security leader to announce critical Microsoft zero-days at Black Hat USA 2023

HONG KONG SAR - Media OutReach - 18 August 2023 - Trend Micro (TYO: 4704; TSE: 4704), a global cybersecurity leader, announced at Black Hat USA 2023 that its Zero Day Initiative program has published advisories addressing over 1000 unique vulnerabilities in 2023.

The real-world impact if these vulnerabilities were to be weaponized would amount to time and financial losses of over 10 times the cost of prevention.

"Our proactive investment of millions each year into vulnerability research and purchases saves billions in recovery for both our customers and the industry as a whole," said Kevin Simzer, COO at Trend. "A concerning trend is being documented of companies lacking transparency around vulnerability disclosure vendor patching, which pose a threat to the security of the digital world."

Today, Trend is calling for an end to silent patching – the practice of slowing or diluting public disclosure and documentation of vulnerabilities and patches. It is a major roadblock to fighting cybercrime but is all too common among major vendors and cloud providers.

During a session at Black Hat USA 2023, Trend Research representatives revealed that silent patching has become particularly common among cloud providers. Companies are more frequently refraining from assigning a Common Vulnerabilities and Exposures (CVE) ID for public documentation and are instead privately issuing patches.

The lack of transparency or version numbers for cloud services hinders risk assessment and deprives the wider security community of valuable information for enhancing overall ecosystem security.

At last year's Black Hat event, Trend warned of a growing number of incomplete or faulty patches and an increasing reluctance among vendors to deliver authoritative information on patches in plain language. The gap has since worsened, with some companies deprioritizing patching altogether, leaving their customers and industries exposed to unnecessary and increasing risk.

Urgent action is needed to prioritize patching, address vulnerabilities and foster collaboration among researchers, cybersecurity vendors and cloud service providers to fortify cloud-based services and protect users from potential risks.

Trend is committed to transparent vulnerability patching and aims to enhance security postures industry-wide through its Zero Day Initiative program. Through its commitment to transparent disclosure, Trend's ZDI issued today advisories on several zero-day vulnerabilities including:

ZDI-CAN-20784 Github (CVSS 9.9)

  • This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft GitHub. Authentication is required to exploit this vulnerability
  • The flaw exists within the configuration of Dev-Containers. The application does not enforce the privileged flag within a dev container configuration. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor

ZDI-CAN-20771 Microsoft Azure (CVSS 4.4)

  • This vulnerability allows remote attackers to disclose sensitive information on Microsoft Azure. An attacker must first obtain the ability to execute high-privileged code on the target environment in order to exploit this vulnerability
  • The flaw exists within the handling of certificates. The issue results from the exposure of a resource to the wrong control sphere. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.

For a full list of advisories published by Trend Micro's ZDI, visit: https://www.zerodayinitiative.com/advisories/published/

Trend Micro's ZDI pioneered the vulnerability marketplace with a focus on disrupting attackers by legitimately purchasing vulnerability research that can then be disclosed to affected vendors to address before the information is made public.

Hashtag: #trendmicro #ZDI #cybersecurity #cloudsecurity



The issuer is solely responsible for the content of this announcement.

About Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,500+ employees across 70 countries, Trend Micro enables organizations to simplify and secure their connected world.

News from Asia

Liverpool FC and AXA Celebrate Continued Growth of Its Successful Partnership Until 2029

LIVERPOOL, UK - Media OutReach Newswire - 30 April 2024 - 2018: AXA signed as LFC's Official Insurance Partner 2019: AXA becomes principal partner and the club's Official Train...

Chubb Promotes Kate Burke to Head of International Personal Lines, Asia Pacific

SINGAPORE - Media OutReach Newswire - 30 April 2024 - Chubb today announced that Kate Burke has been promoted to Head of International Personal Lines (IPL), Asia Pacific, effective 1 May 2024...

Job Title Inflation in Hong Kong: 6 in 10 expect promotion within 12 – 18 months

HONG KONG SAR - Media OutReach Newswire - 30 April 2024 - Job title inflation, a common practice in Hong Kong[1] and Greater China, has recently become a global trend. According to Robert Walters...

DC and Zebra Comics Announce Collaboration on Joker: The World Anthology

Anthology to Include an Original Story Featuring a Never-Before-Seen Version of the Clown Prince of Crime, Created by African Storytellers DOUALA, CAMEROON - EQS Newswire - 30 April 2024 - Z...

Jiangxi's Cultural and Tourism Promotion Shines in Malaysia, Inviting Tourists to Explore Picturesque Jiangxi

KUALA LUMPUR, MALAYSIA – Media OutReach Newswire – 30 April 2024 - On April 18th local time, the opening ceremony of the Southeast Asia Cultural and Tourism Promotion Season themed "Jiangxi's Scen...

Huangshan Tourism Group partners with Alipay to launch "International Visitor Friendly Scenic Spot" ahead of May Day holiday

HUANGSHAN, CHINA - Media OutReach Newswire - 30 April 2024 - Huangshan Tourism Group, which operates "the loveliest mountain of China" Huangshan, announced its partnership with Alipay, the leading...

Sahel elites must move away from 'zero-sum' policies, report urges

LOS ANGELES, UNITED STATES - Newsaktuell - 30 April 2024 - A dual economic strategy focusing on domestic economic development and international partnerships to address the underlying challenges fac...

Report: BRICS+ likely new counterpoint to G7-led geopolitical order

LOS ANGELES, UNITED STATES - Newsaktuell - 30 April 2024 - The expansion of the BRICS group of nations into what has informally been named BRICS+ could highlight a geopolitical shift, with the new ...

Luxshare Precision Announces 2023 Annual Results

Net Profit Exceeds RMB10 Billion for the First Time with Diversified Synergistic Business Presence SHENZHEN, CHINA - Media OutReach Newswire - 30 April 2024 - On April 24th, Luxshare Precision unv...

Revolutionizing Racing and Trading: AlphaX Teams Up with F2 Sensation Enzo Fittipaldi

SYDNEY, AUSTRALIA - Media OutReach Newswire - 1 May 2024 - AlphaX, a leading cryptocurrency exchange dedicated to shaping the future of trading, proudly announces its groundbreaki...

Popular

Helga’s latest hot off the press, environment-friendly news

BIG CHANGES AT HELGA’S MAKE A BIG IMPACT ON THE ENVIRONMENT    The brand is on a mission to be the kindest bread in Australia, and the most sustainable.   At Helga’s we know that every grain of care counts and today we hav...

75 percent of Asia Pacific consumers do not feel responsible for their own data security

F5’s latest Curve of Convenience 2020 report shows that application users in Asia Pacific routinely overlook high-profile breaches in favour of seamless user experience; seven in ten consumers knowingly share or store person...

Deputy Elevates Executive Team with Key Strategic Appointments

Deputy, the global people platform for shift work, is pleased to announce the appointments of Alla MacDonald as Senior Vice President of Strategic Finance and Operations and Keshila Vallot Shannon as Senior Vice President of G...