• Login
No Result
View All Result
My Blog
  • Home
  • World
  • Politics
  • Business
  • Science
  • Tech
    Meet Some Indian Startups On This Journey

    Meet Some Indian Startups On This Journey

    Power Up: Anker GaNPrime Charger

    Power Up: Anker GaNPrime Charger

    The Dark Side of ChatGPT: Employees & Businesses Need to Prepare Now

    The Dark Side of ChatGPT: Employees & Businesses Need to Prepare Now

    How AI and ML Are Making Digital Lending More Flexible For the MSME Sector

    How AI and ML Are Making Digital Lending More Flexible For the MSME Sector

    Samsung To Manufacture Premium Galaxy S23 Smartphones In India

    Samsung To Manufacture Premium Galaxy S23 Smartphones In India

    How Start-Ups are Helping Reinvent Maritime Shipping Industry

    How Start-Ups are Helping Reinvent Maritime Shipping Industry

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Entertainment
    • All
    • Movie
    • Music
    • Sports
    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Prediction Engines Are Like Karma: You Get What You Stream

    Prediction Engines Are Like Karma: You Get What You Stream

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

  • Lifestyle
    • All
    • Fashion
    • Health
    • Travel
    Normotim Reviews

    Normotim Reviews: A Beacon of Hope for Depression Fighters | Normopharm’s Success Stories

    nurse

    Everything You Need To Know About Nurse Residency

    Drug detox

    Are you the right candidate for medical detox?

    The Benefit of Using Sunscreen Protection

    The Benefit of Using Sunscreen Protection

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    What are the major reasons to form gall bladder stones?

    What are the major reasons to form gall bladder stones?

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
  • More
    • Directions
  • Home
  • World
  • Politics
  • Business
  • Science
  • Tech
    Meet Some Indian Startups On This Journey

    Meet Some Indian Startups On This Journey

    Power Up: Anker GaNPrime Charger

    Power Up: Anker GaNPrime Charger

    The Dark Side of ChatGPT: Employees & Businesses Need to Prepare Now

    The Dark Side of ChatGPT: Employees & Businesses Need to Prepare Now

    How AI and ML Are Making Digital Lending More Flexible For the MSME Sector

    How AI and ML Are Making Digital Lending More Flexible For the MSME Sector

    Samsung To Manufacture Premium Galaxy S23 Smartphones In India

    Samsung To Manufacture Premium Galaxy S23 Smartphones In India

    How Start-Ups are Helping Reinvent Maritime Shipping Industry

    How Start-Ups are Helping Reinvent Maritime Shipping Industry

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Entertainment
    • All
    • Movie
    • Music
    • Sports
    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Prediction Engines Are Like Karma: You Get What You Stream

    Prediction Engines Are Like Karma: You Get What You Stream

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

  • Lifestyle
    • All
    • Fashion
    • Health
    • Travel
    Normotim Reviews

    Normotim Reviews: A Beacon of Hope for Depression Fighters | Normopharm’s Success Stories

    nurse

    Everything You Need To Know About Nurse Residency

    Drug detox

    Are you the right candidate for medical detox?

    The Benefit of Using Sunscreen Protection

    The Benefit of Using Sunscreen Protection

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    What are the major reasons to form gall bladder stones?

    What are the major reasons to form gall bladder stones?

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
  • More
    • Directions
No Result
View All Result
My Blog
No Result
View All Result
Home National

Sloppy Software Patches Are a ‘Disturbing Trend’

by lacygibson
August 11, 2022
in National, World
0
Sloppy Software Patches Are a ‘Disturbing Trend’
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter


the whole purpose The main purpose of vulnerability disclosure is to notify software developers of flaws in their code so that they can create fixes or patches and improve the security of their products. But after 17 years and more than 10,000 vulnerability disclosures, the Zero Day Initiative called out “disturbing trends” today at the Black Hat security conference in Las Vegas and announced plans to apply some counter pressure.

Owned by security firm Trend Micro since 2015, ZDI is a program that buys vulnerability discovery from researchers and handles disclosures to vendors. In exchange, Trend Micro, which makes antivirus tools and other defense products, gets a wealth of information and telemetry that it can use to track research and hopefully protect its customers. The group estimates that it has processed about 1,700 disclosures so far this year. But ZDI warns that, from a bird’s-eye view, it finds that the overall quality of vendor patches has been declining in recent years.

Increasingly, the group purchased a vulnerability from a researcher, patched it, and then sometimes needed multiple rounds of patching shortly after ZDI purchased another report on how to bypass the patch and avoidance. ZDI also said it noted a worrying trend in which companies are disclosing less specific information about vulnerabilities in their public security alerts, making it harder for users around the world to assess the severity of vulnerabilities and prioritize patches — This is a real concern for large enterprises. Institutions and critical infrastructure.

“Over the past few years, we’ve definitely noticed a noticeable drop in the quality of security patches,” said ZDI member Dustin Childs. “Incomplete or flawed patches are irresponsible.”

ZDI researchers say there are many reasons for bad patches. Figuring out how to fix software flaws can be a delicate and delicate process, and sometimes companies lack the expertise or investment to generate elegant solutions to these important problems. Organizations may be in a rush to close bug reports and clean up their roster, and they may not be spending the necessary time to conduct a “root cause” or “variant” analysis and assess potential issues in order to fully address the deeper issues.

Whatever the reason, bad patches are a real problem. In late June, Google’s Project Zero vulnerability hunt team found that at least half of the new vulnerabilities it tracks exploited by attackers in the wild through 2022 are variants of previously patched vulnerabilities.

“Over time, a combination of things led us to believe that we actually had a bigger problem than most people understand,” said Brian Gorenc, who runs ZDI.

Like other organizations heavily involved in disclosure, especially Project Zero, ZDI provides developers with a deadline for how long they must release a patch before details about the vulnerability can be released publicly. The standard deadline for ZDI is 120 days from the date of disclosure. But in response to the prevalence of bad patches, the group today announced a new set of deadlines for previously patched bugs.

Based on the severity of the vulnerability, how easy it is to bypass the patch, and how likely ZDI believes the vulnerability is to be exploited by an attacker, the group is now setting a deadline of 30 days for critical vulnerabilities and 60 days by mistake to provide some protection for existing patches , and 90 days in all other cases. The move follows a tradition of using public disclosure as an important leverage point — one of a handful of security proponents — to make necessary improvements in a way that incentivizes developers to deal with high-risk software flaws that could affect users around the world.

“Weaponization of failed patches in various exploits is absolutely widespread now,” said ZDI’s Childs. “This is a real problem that will have a real impact on users, and we’re trying to incentivize vendors to put it in the first place. Do it.”

Tags: black hatDisturbingmalicious softwarePatchesSafetySloppysoftwareTrendVulnerability
lacygibson

lacygibson

Next Post
Gabrielle Zevin Believes Games Show People Who They Really Are

Gabrielle Zevin Believes Games Show People Who They Really Are

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

What All Entrepreneurs Need to Know About Web3

What All Entrepreneurs Need to Know About Web3

1 year ago
Butterfly Learnings Raises $1.5 Million In Seed Funding

Butterfly Learnings Raises $1.5 Million In Seed Funding

1 year ago

Popular News

    Connect with us

    • Contact
    • Read Latest News Around The World – Frapios
    Write Us at: [email protected]

    Copyright Reserved © 2022

    No Result
    View All Result
    • Home
    • Politics
    • World
    • Business
    • Science
    • National
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Travel
    • Tech
    • Health
    • Food

    Copyright Reserved © 2022

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In