• Zine
  • Anonymous
  • Green
  • IT
  • Gadgets
  • Tech
  • Cloud
  • Data
  • Network
  • Security
  • Hosting
    • Sunset Host Co
    • Radio Host Co
  • Media
    • WSCA News
    • Sunset Crypto
    • Sustainable Action Now
    • Life.Style Magazine
    • Sunset Daily
    • Sunset Music News
    • Pro Merch Sports News
    • Explore New Jersey
    • Explore NJ News
    • The Zine Weekly
Facebook Twitter Instagram
Wednesday, May 11
Facebook Twitter Instagram
The Zine Weekly
  • Zine

    Anonymous appears to slam Elon Musk’s ‘left wing bias’ comment with new Twitter post

    May 11, 2022

    There’s Now A Hack To Get Apple CarPlay & Android Auto On Your Tesla

    May 11, 2022

    Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

    May 11, 2022

    Alkira launches free tool to tame cloud bloat

    May 11, 2022

    Ransomware attack prompts response from Oregon election officials

    May 11, 2022
  • Anonymous

    Anonymous appears to slam Elon Musk’s ‘left wing bias’ comment with new Twitter post

    May 11, 2022

    FACTBOX-The cyber war between Ukraine and Russia

    May 11, 2022

    CIA Expert Decodes Why Russia Which Even Hacked Into US Power Grids Is Failing In Cyber War In Ukraine

    May 10, 2022

    Anti-War Activists Stage ‘Guerrilla’ Protests on Victory Day

    May 9, 2022

    Deepfakes and espionage, but no cyber apocalypse from Vladimir Putin’s invasion

    May 9, 2022
  • Green

    Microgrid demo to lend a helping hand in India’s green energy transition

    May 9, 2022

    California prepares for energy shortfalls in hot, dry summer

    May 7, 2022

    Cryptocurrency’s dirty secret: Energy consumption

    May 5, 2022

    Stellantis pours billions more into Canada, electric

    May 3, 2022

    PortMiami, cruise lines pledge to expand technology to cut emissions from ships

    May 1, 2022
  • IT

    WebCitz.com Announces Plans to Offer Free Web Hosting for Non-Profit Churches

    May 11, 2022

    How will VR collaboration transform meetings?

    May 10, 2022

    New Windows 11 preview makes Microsoft accounts mandatory for (almost) all

    May 9, 2022

    Announcing Reliable VPS Server Hosting Provider with Malaysia, Kuala Lumpur, Teluk Intan based IP – TheServerHost

    May 9, 2022

    Cal Poly Pomona pursues digital student experience

    May 8, 2022
  • Gadgets

    KuCoin Crypto Exchange Raises $150 Million in Funding, Plans to Launch Crypto Wallet, NFT Site

    May 11, 2022

    New tool shows homeowners and renters the true cost of disasters

    May 10, 2022

    iPhone 12, iPhone 12 Mini on Sale With Up to Rs. 11,910 Discount via Amazon India, Flipkart

    May 9, 2022

    Portable fluorescent probe identifies bad cooking oil

    May 9, 2022

    Farhan Akhtar to Appear in Ms Marvel Series, Out June 8 on Disney+ Hotstar

    May 8, 2022
  • Tech

    4D composite printing could improve the wings of drones

    May 11, 2022

    How to delete unused styles using VBA in Word

    May 9, 2022

    Best Gas Credit Cards in May 2022

    May 6, 2022

    Eshoo faces rivals from left, right and center in bid to retain Congress seat | News

    May 4, 2022

    Netflix cancels Meghan Markle animated series Pearl

    May 2, 2022
  • Cloud

    Alkira launches free tool to tame cloud bloat

    May 11, 2022

    Ministry working to mitigate Merauke-Timika sea cable disruption

    May 10, 2022

    Cisco releases its Cloud Controls Framework to the public

    May 10, 2022

    Data Governance Market Collaborations Provide Effective And Impactful Solutions – IT Industry Today

    May 9, 2022

    Dell Technologies expands multi-cloud experiences

    May 8, 2022
  • Data

    Asia-Africa-Europe-1 submarine cable system to add Infinera’s ICE6

    May 10, 2022

    Russia’s invasion of Ukraine could hurt Europe IT outsourcing

    May 10, 2022

    Insider Tips for Automating Analytics

    May 9, 2022

    CSPi to Announce Fiscal Second Quarter Financial Results on

    May 8, 2022

    AAON (NASDAQ:AAON) Posts Quarterly Earnings Results, Beats Estimates By $0.06 EPS

    May 8, 2022
  • Network

    Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

    May 11, 2022

    Keto Start ACV Gummies -WARNING: Shocking Reported About Side Effects? Job – 101 ARW ANG

    May 10, 2022

    Visualization analysis of sEMG | JPR

    May 10, 2022

    Beware: This cheap and ‘homemade’ malware is surprisingly effective

    May 9, 2022

    How to set a default gateway with Netplan, now that gateway4 has been deprecated

    May 8, 2022
  • Security

    There’s Now A Hack To Get Apple CarPlay & Android Auto On Your Tesla

    May 11, 2022

    Alberta Court of Appeal to rule whether federal assessment law is unconstitutional

    May 10, 2022

    Manchin says he’d pass parts of Biden’s agenda. But Democrats may have to write the bill for him.

    May 8, 2022

    Work from home hack to make your cat think it can distract you, is a must-watch | Trending

    May 8, 2022

    Accolades for local cyber team

    May 7, 2022
  • Hosting
    1. Sunset Host Co
    2. Radio Host Co
    Featured

    Ransomware attack prompts response from Oregon election officials

    By Sunset Host CoMay 11, 20220
    Recent

    Ransomware attack prompts response from Oregon election officials

    May 11, 2022

    Announcing Reliable VPS Server Hosting Provider with Netherlands, NL, Amsterdam based IP – TheServerHost – IT Industry Today

    May 10, 2022

    Asure Announces First Quarter 2022 Financial Results

    May 10, 2022
  • Media
    1. WSCA News
    2. Sunset Crypto
    3. Sustainable Action Now
    4. Life.Style Magazine
    5. Sunset Daily
    6. Sunset Music News
    7. Pro Merch Sports News
    8. Explore New Jersey
    9. Explore NJ News
    10. The Zine Weekly
    Featured
    Recent

    Anonymous appears to slam Elon Musk’s ‘left wing bias’ comment with new Twitter post

    May 11, 2022

    There’s Now A Hack To Get Apple CarPlay & Android Auto On Your Tesla

    May 11, 2022

    Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

    May 11, 2022
The Zine Weekly
You are at:Home » Five Eyes reveals 15 most exploited vulnerabilities of 2021
Data Center

Five Eyes reveals 15 most exploited vulnerabilities of 2021

Sunset Host CoBy Sunset Host CoApril 27, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

A joint cybersecurity advisory highlighted the most commonly exploited flaws of 2021 and urged enterprises to implement timely patching protocols.

Issued as a warning, the Five Eyes released a statement Wednesday revealing which common vulnerabilities and exposures (CVEs) posed the biggest threat to enterprises in 2021 with risks continuing into 2022. While there were 15 overall, some of the most concerning bugs highlighted by the agencies included Log4Shell, ProxyLogon, ProxyShell and a flaw tracked as CVE-2021-26084 that affected Atlassian Confluence Server and Data Center.

Three additional vulnerabilities have been an ongoing issue since 2020, indicating a troublesome trend when it comes to applying updates.

That includes a Fortinet flaw published in 2019 tracked as CVE-2018-13379 and a bug known as CVE-2019-11510 that affected Pulse Secure’s virtual private network products. Lastly, the advisory listed CVE-2020-1472, also known as Zerologon, an escalation of privilege vulnerability discovered in Microsoft’s Netlogon Remote Protocol. Microsoft confirmed in-the-wild exploitation back in 2020.

“Their continued exploitation indicates that many organizations fail to patch software in a timely manner and remain vulnerable to malicious cyber actors,” the advisory said.

To further support that claim and highlight the ongoing patching problem, the advisory addressed concerns when it comes to proof-of-concept (POC) releases. While POCs offer valuable insight into a flaw that can help organizations protect against exploitation, threat actors can leverage those details in malicious attacks.

“For most of the top exploited vulnerabilities, researchers or other actors released [POC] code within two weeks of the vulnerability’s disclosure, likely facilitating exploitation by a broader range of malicious actors,” the advisory said.

Determining the right level of transparency is a controversial topic, as opinions differ among researchers organizations, and law enforcement. Log4Shell’s timeline represents one side of the coin. Disclosed in 2021, the flaw in Apache’s Log4j library allowed an “actor to take full control over the system.”

“The rapid widespread exploitation of this vulnerability demonstrates the ability of malicious actors to quickly weaponize known vulnerabilities and target organizations before they patch,” the advisory said.

Cisco Talos released Tuesday its Quarterly Report, which put Log4j exploitation as the second most commonly observed threat for Q1 of 2022, right behind ransomware. The security vendor even warned of possible exploitation by APT actors.

In a report updated this month, Yotam Perkal, head of vulnerability research as Rezilion, referred to Log4Shell as “one of the most critical vulnerabilities in recent years.” He analyzed Log4Shell activity four months after disclosure and found that as of April 20, “36% of the Log4j versions actively downloaded from Maven Central,” a code repository, remained vulnerable. Additionally, he noted the problem extends beyond the “significant attack surface that remains vulnerable” as active exploitation attempts are ongoing.

“We believe that one of the main reasons we still see a high number of vulnerable component downloads is the fact that people are unknowingly still using software that relies on vulnerable versions of Log4j,” Perkal wrote in the report.

Perkal also attributed it to inefficient vulnerability management, a lack of visibility and the use of vulnerable third-party software. Often, security teams have trouble prioritizing and keeping pace with the overwhelming number of flaws.

That is why prioritizing patching known exploited vulnerabilities, particularly the ones identified in the advisory, was a main mitigation step recommended by CISA and authorities from the U.K., Australia, New Zealand and Canada. Additionally, the co-authors advised system and software updates must be done in a “timely manner” and suggested the use of a centralized patch management system.

Share this:

  • Twitter
  • Facebook

Related

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAnnouncing Reliable VPS Server Hosting Provider with Switzerland, Zurich based IP – TheServerHost – IT Industry Today
Next Article Wall Street sees tepid gains after Tuesday’s big drop
Sunset Host Co
  • Website
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • Tumblr
  • LinkedIn

Related Posts

Asia-Africa-Europe-1 submarine cable system to add Infinera’s ICE6

May 10, 2022

Russia’s invasion of Ukraine could hurt Europe IT outsourcing

May 10, 2022

Insider Tips for Automating Analytics

May 9, 2022

Leave A Reply Cancel Reply

Categories
  • Anonymous (92)
  • Cloud (145)
  • Data Center (128)
  • Gadgets (166)
  • Green Tech (36)
  • Hosting solutions (89)
  • IT News (90)
  • Network (135)
  • Security (128)
  • Tech (95)
  • Web hosting (58)
  • Zine
  • Anonymous
  • Green
  • IT
  • Gadgets
  • Tech
  • Cloud
  • Data
  • Network
  • Security
  • Hosting
    • Sunset Host Co
    • Radio Host Co
  • Media
    • WSCA News
    • Sunset Crypto
    • Sustainable Action Now
    • Life.Style Magazine
    • Sunset Daily
    • Sunset Music News
    • Pro Merch Sports News
    • Explore New Jersey
    • Explore NJ News
    • The Zine Weekly

Subscribe to Updates

Get the latest tech news from the Zine at the Sunset Host Co. and the Radio Host Co.

Anonymous appears to slam Elon Musk’s ‘left wing bias’ comment with new Twitter post

May 11, 2022

There’s Now A Hack To Get Apple CarPlay & Android Auto On Your Tesla

May 11, 2022

Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

May 11, 2022

Alkira launches free tool to tame cloud bloat

May 11, 2022

Ransomware attack prompts response from Oregon election officials

May 11, 2022

KuCoin Crypto Exchange Raises $150 Million in Funding, Plans to Launch Crypto Wallet, NFT Site

May 11, 2022

FACTBOX-The cyber war between Ukraine and Russia

May 11, 2022

WebCitz.com Announces Plans to Offer Free Web Hosting for Non-Profit Churches

May 11, 2022
Copyright © 2022. The Zine Weekly, an SCA Entertainment & Media Company. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.