Business Daily Media

Men's Weekly

.

Trend Micro ZDI Surpasses 1000 Published Advisories in 1H 2023 In Continued Commitment to Coordinated Disclosure

Security leader to announce critical Microsoft zero-days at Black Hat USA 2023

HONG KONG SAR - Media OutReach - 18 August 2023 - Trend Micro (TYO: 4704; TSE: 4704), a global cybersecurity leader, announced at Black Hat USA 2023 that its Zero Day Initiative program has published advisories addressing over 1000 unique vulnerabilities in 2023.

The real-world impact if these vulnerabilities were to be weaponized would amount to time and financial losses of over 10 times the cost of prevention.

"Our proactive investment of millions each year into vulnerability research and purchases saves billions in recovery for both our customers and the industry as a whole," said Kevin Simzer, COO at Trend. "A concerning trend is being documented of companies lacking transparency around vulnerability disclosure vendor patching, which pose a threat to the security of the digital world."

Today, Trend is calling for an end to silent patching – the practice of slowing or diluting public disclosure and documentation of vulnerabilities and patches. It is a major roadblock to fighting cybercrime but is all too common among major vendors and cloud providers.

During a session at Black Hat USA 2023, Trend Research representatives revealed that silent patching has become particularly common among cloud providers. Companies are more frequently refraining from assigning a Common Vulnerabilities and Exposures (CVE) ID for public documentation and are instead privately issuing patches.

The lack of transparency or version numbers for cloud services hinders risk assessment and deprives the wider security community of valuable information for enhancing overall ecosystem security.

At last year's Black Hat event, Trend warned of a growing number of incomplete or faulty patches and an increasing reluctance among vendors to deliver authoritative information on patches in plain language. The gap has since worsened, with some companies deprioritizing patching altogether, leaving their customers and industries exposed to unnecessary and increasing risk.

Urgent action is needed to prioritize patching, address vulnerabilities and foster collaboration among researchers, cybersecurity vendors and cloud service providers to fortify cloud-based services and protect users from potential risks.

Trend is committed to transparent vulnerability patching and aims to enhance security postures industry-wide through its Zero Day Initiative program. Through its commitment to transparent disclosure, Trend's ZDI issued today advisories on several zero-day vulnerabilities including:

ZDI-CAN-20784 Github (CVSS 9.9)

  • This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft GitHub. Authentication is required to exploit this vulnerability
  • The flaw exists within the configuration of Dev-Containers. The application does not enforce the privileged flag within a dev container configuration. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor

ZDI-CAN-20771 Microsoft Azure (CVSS 4.4)

  • This vulnerability allows remote attackers to disclose sensitive information on Microsoft Azure. An attacker must first obtain the ability to execute high-privileged code on the target environment in order to exploit this vulnerability
  • The flaw exists within the handling of certificates. The issue results from the exposure of a resource to the wrong control sphere. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.

For a full list of advisories published by Trend Micro's ZDI, visit: https://www.zerodayinitiative.com/advisories/published/

Trend Micro's ZDI pioneered the vulnerability marketplace with a focus on disrupting attackers by legitimately purchasing vulnerability research that can then be disclosed to affected vendors to address before the information is made public.

Hashtag: #trendmicro #ZDI #cybersecurity #cloudsecurity



The issuer is solely responsible for the content of this announcement.

About Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,500+ employees across 70 countries, Trend Micro enables organizations to simplify and secure their connected world.

News from Asia

‘War orphans’ express gratitude to Chinese foster parents

BEIJING, CHINA - Media OutReach Newswire - 21 February 2026 – Organized by the Japanese Repatriates and Japan-China Friendship Association, a delegation of 90 Japanese "war orphans," along with th...

Keeper Security Expands Relationship With Ingram Micro to Broaden Availability of Privileged Access Management in Singapore

Expansion strengthens cybersecurity resilience by delivering a modern, scalable privileged access solution SINGAPORE - Media OutReach Newswire - 23 February 2026 – Keeper Security, the leading ze...

Trad To Tech: Craftsmanship Growing Inside the Most Beautiful Homes as MIFF Leads the Way

KUALA LUMPUR, MALAYSIA - Media OutReach Newswire - 23 February 2026 - At the Malaysian International Furniture Fair (MIFF), a master craftsperson brings a solid wood tabletop to fruition, overseei...

Anaplan Launches AWS Data Center in Singapore to Enhance Global Reach and Support Local Enterprises

New location expands company’s global infrastructure, while offering faster data processing, robust security measures and regulatory compliance SINGAPORE - Media OutReach Newswire - 23 February ...

Lumen Technologies expands APAC cybersecurity capabilities in collaboration with Palo Alto Networks

SINGAPORE - Media OutReach Newswire - 23 February 2026 - Lumen Technologies has achieved the Palo Alto Networks NextWave Cortex XSIAM Select Specialisation Status in Singapore. This specialisation...

The World’s 100 Best Coffee Shops: Asia Pacific’s Notable Winners

Four Coffee Shops from Australia, Singapore and Malaysia Ranked in Top 10 SINGAPORE - Media OutReach Newswire - 23 February 2026 - The second edition of THE WORLD'S 100 BEST COFFEE SHOPS 2026 wi...

Esperanza Securities Introduces the First SFC-permitted Tokenized Investment for Live Entertainment in Asia Pacific

HONG KONG SAR - Media OutReach Newswire - 23 February 2026 - Esperanza Fintech (Securities) Limited ("Esperanza Securities", or "Company") announced today that, following the granting of the forma...

Tim Hortons® Singapore Marks Major Milestone with Official MUIS Halal Certification Ahead of the Festive Season

SINGAPORE - Media OutReach Newswire - 23 February 2026 - Tim Hortons® Singapore is pleased to announce that it has officially received Halal certification from the Majlis Ugama Islam Singapura (...

SICPA secures major European award for UK Vaping Duty Stamps Program

Swiss technology company SICPA secured a landmark traceability contract, in partnership with Spectra Systems Corporation’s subsidiary, Cartor Security Printers (Cartor), reinforcing its global lead...

Vinfast Middle East Signs MoU with PlusX Electric to Strengthen EV Ownership Experience in the UAE

DUBAI, UAE - Media OutReach Newswire - 23 February 2026 - VinFast today announced the signing of a Memorandum of Understanding (MoU) with PlusX Electric, a DEWA-approved EV charging and electric m...

Block's layoffs are a design win. Here's why

We spend millions designing features that save users 30 seconds. Block just saved thousands of employees 40 hours a week. That's not a crisis. That's...

Why I Decided to Build a Better Way to Build Homes

Why does building a home still feel like stepping into the unknown? In an industry where costs blow out and decisions come too late, certainty has...

Leonardo.Ai reveals new brand, expanding its creator-first platform for the next era of generative AI

The company has also launched its developer API to empower creators and builders to integrate AI into their workflows SYDNEY, Australia – 19 Febr...

Psychosocial injury risk starts inside workplace microcultures

Psychological injury is now one of the most expensive categories of workers compensation claims in Australia, with Safe Work Australia reporting t...

2025 Thryv Business and Consumer Report - Australian small businesses show grit under pressure

Australia’s small businesses are powering ahead with optimism, resilience and discipline, however, mounting pressures on costs, wellbeing and cons...

Security by Default: Why 2026 Will Force Organisations to Rethink Cloud and AI

financial accountability to how they run cloud and AI, according to leading Australian systems integrator, Brennan. Based on customer insights...