Security vulnerabilities reached record levels in the first half of 2010, according to a new report from IBM. Released Wednesday, the company’s X-Force 2010 Mid-Year Trend and Risk Report documented more than 4,396 new vulnerabilities so far this year, an increase of 36 percent over the same period in 2009.
Currently, the report said, more than half — 55 percent — of these vulnerabilities “had no vendor-supplied patch at the end of the period.” Web-application vulnerabilities are cited as the most frequent threat, with more than half of all reported issues involving this area. But the report said even that assessment could be underestimated, since it doesn’t include custom-built web applications.
JavaScript, PDFs
The report was released by IBM’s X-Force team, the key security-research organization within the company. The team has collected and analyzed more than 50,000 vulnerabilities since 1997, and its Trend and Risk Report draws on that data, as well as an extensive database of intrusion events on customer networks worldwide.
A growing area of attacks with increasing complexity are occurring within JavaScript and Portable Document Format (PDF) files. Sophisticated attackers, the report noted, are breaking into networks without being spotted by traditional detection tools by using such techniques as “JavaScript obfuscation” to hide attacks within documents and web pages. Such attacks increased more than 50 percent year over year.
IBM’s X-Force team said it started to see “widespread use of PDF-based exploits” in the first half of this year, and now three of the top five browser exploits involve PDFs. In April, IBM detected nearly 37 percent more activity than average in this area. This was the same period when a “malicious spam campaign” involving PDFs was used to transmit the Zeus and Pushdo botnets, which the company called “some of the most insidious threats” around.
The good news is that…