HomeSecurityWhich companies disclosed the most vulnerabilities in Q2 2020?

Which companies disclosed the most vulnerabilities in Q2 2020?

The number of vulnerabilities disclosed by major tech companies appears to be returning to normal after a lower-than-usual rate in the first quarter of 2020 amid the COVID-19. VulnDB Security Risk analysts have expressed their opposition to the trend of companies disclosing all of their latest vulnerabilities on the same day, calling the trend the “Fujiwhara phenomenon.” Of the 11,121 vulnerabilities disclosed in mid-2020, 818 were disclosed within a few days. In addition, 312 vulnerabilities were disclosed on January 14, 508 on April 14, and 263 on June 9, while there were four other days this year when at least 187 vulnerabilities were disclosed.

vulnerabilities 2020

Disclosing a large number of vulnerabilities in a short period of time naturally puts a lot of pressure on both IT staff and vulnerability managers. Brian Martin, VP of Risk Based Security, reported that during April’s Fujiwhara event, 508 new vulnerabilities were disclosed, 79% of which came from seven vendors. Martin stressed that this is something that is expected to happen more often in the future, while also raising the question of who benefits from this all-at-once vulnerability disclosure that companies are making. Of course, paying customers are not the beneficiaries.


In the first half of 2020, 11,000 vulnerabilities were disclosed. While this number may seem high, in reality, vulnerabilities decreased by 8.2%, compared to the same period in 2019. However, the second quarter of the year showed that things are gradually returning to normal, following the outbreak of the COVID-19 pandemic.

companies-vulnerabilities-2020

Researchers highlighted that one of the most concerning trends is the lack of CVE. Of the vulnerabilities disclosed in the first half of 2020, 30% did not have a CVE identifier, while no information was available for 3% of the vulnerabilities identified.


A report focuses on the “Fujiwhara phenomenon” and the companies that disclose the highest number of vulnerabilities. According to the report, there were three days in 2020 (January 14, April 14, and July 14) that were a major event for IT professionals. These Fujiwhara events are usually rare, but in 2020, three occurred: January 14, April 14, and July 14. The last two observed before 2020 occurred in 2015, while the next two will occur in 2025 – starting on January 14. This shows the rarity of these events, but also why they stand out, as they entail more stress and greater risks for organizations.


Additionally, the report noted that the single Fujiwhara event in 2015 saw a total of 277 known vulnerabilities reported that day, less than half of the number disclosed during the Fujiwhara event in April this year. During the Fujiwhara event in April, 506 new vulnerabilities were disclosed, 79% of which came from seven vendors. Compared to other Patch Tuesdays this year, the highest reported “only” 273 new vulnerabilities on June 9. The researchers also noted the irrationality of vendors creating vulnerable software that puts paying customers at risk.


IT teams and vulnerability managers struggle to review and assess the sheer volume of vulnerabilities disclosed in a single day. Hundreds of vulnerabilities are disclosed in a short period of time, with the majority coming from tech giants like Microsoft and Adobe, affecting widely used products.

Microsoft-Adobe 2020


The worst part of all this is that the CVE mission has remained stagnant, meaning that organizations that depend on CVE/NVD for vulnerability information are not getting the help they need to identify and prioritize vulnerabilities that have been marked “critical.” 2020 has shown, among other things, that organizations need a comprehensive vulnerability management strategy.


Microsoft was one of the first companies to hold “Patch Tuesday” events, but Adobe eventually started participating in them in 2012, while other companies like SAP, Siemens, and Schneider Electric have also decided to join in. Apple ,Mozilla, Intel, Cisco , and other tech giants have also started disclosing vulnerabilities on the same day in an effort to make the process easier and less awkward.


The severity of the problem is demonstrated by the fact that in two days, 818 vulnerabilities were disclosed by companies, a number that represents 7.3% of the total vulnerability disclosures in the middle of the year. If Fujiwhara Day in July is included, three days would account for 10.5% of all vulnerabilities in 2020. Furthermore, instead of helping IT professionals, this has the exact opposite effect, while at the same time giving malicious actors a plethora of newly released vulnerabilities to exploit all on the same day. The report also added that software vendors may see these Fujiwhara Days as a way to hide their vulnerabilities in the chaos of hundreds of other vulnerabilities.

hackers vs companies

In the second quarter of 2020, Microsoft saw a 150% increase in vulnerabilities compared to the same period last year, with 762 disclosures. That number is much higher than any other vendor, including Oracle and Linux/Red Hat. Oracle had a total of 612 vulnerabilities, 420 of which came from the two Fujiwhara events. Microsoft’s high numbers are due to Windows 10. But it’s not just Windows 10. Different versions of Windows appear on the list four times. Organizations that rely heavily on Microsoft or Oracle products will be forced to test and evaluate a large number of issues multiple times.

The report also noted that Google Pixel/Nexus devices appeared on the list with 314 vulnerabilities, leading researchers to write that mobile devices may be more vulnerable to attacks than desktop systems.

Given the sheer volume of vulnerabilities being disclosed, organizations relying on CVE/NVD will struggle to find a quick and effective solution to address them. Finally, organizations are increasing their own risk by relying on CVE to provide complete and timely data. The current level of vulnerability disclosure that organizations face on a daily basis is more than CVE can handle.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS