39:51About this session
David Carver, who manages the reporting team at Recorded Future, reviews 2020 vulnerability trends in three tiers he calls the ugly, the bad and the good. The ugly: across roughly thirty major vendors, the median gap between disclosure and in-the-wild exploitation fell to zero days both for mid-2019 to mid-2020 and for the first half of 2020, the average to under three days, and even excluding zero-days the median lead time was about 25 days; exploited flaws cluster at CVSS 7 to 10 with low exploit complexity and are dominated by remote code execution. The bad: Microsoft Patch Tuesday disclosures rose about 30 percent year over year, Oracle set a record in July, and exploited bugs hit current product versions rather than legacy ones, while pandemic remote devices stretch patch teams. The good: six of the ten most discussed vulnerabilities on underground forums carried over from the previous year, mostly Microsoft, so patching a short list neutralises much of the attacker base; new exploit kits are declining; and the complexity-by-severity chart offers a simple triage order for each Patch Tuesday.
In the first half of 2020, and compared to 2019, there has been an increase in the number of vulnerabilities that organizations need to review and patch on a regular basis, particularly for Microsoft, as demonstrated by trends in numbers of Patch Tuesday disclosures. However, for the last two years, there has also been a decline in the average amount of time between vulnerability disclosure and exploitation. In this session, our researcher will discuss why effective patch prioritization is imperative for enterprises and individual users.
Key takeaways
- Plan for a median of zero days between disclosure and exploitation for major vendors; the scan-assess-patch cycle for critical RCE flaws must be measured in hours.
- Triage each Patch Tuesday by taking critical, low-complexity, remote-code-execution bugs first, then medium and high complexity.
- Build a baseline from the ten most discussed vulnerabilities on criminal forums; six of ten carry over each year and eight of ten in 2019 were Microsoft.
- Do not assume current versions are safe; 2020 exploited flaws hit Windows 10 and Exchange 2019, not just legacy systems.
- Treat any trend, negative or positive, as something you can write a policy for, unlike black-swan events.