IT vulnerabilities 'reach 4-year low'
2009-09-02
The number of IT vulnerabilities has reached its lowest level for the past four years, according to a new half-year report by the IBM Internet Security Systems (ISS) X-Force team.
High severity disclosures fell by nearly 30 per cent compared to 2008, driven by improvements across client-side and web application vulnerability categories.
Commenting on the report, ISS X-Force threat manager Holly Stewart told v3.co.uk: "This lull is most likely representative of a tapping out of low-hanging fruit in the areas in which we have seen a decline.
"As new areas of research open up, or new tools emerge that make research and vulnerability discovery easier, we will see another uptick in the disclosure rate."
Meanwhile, IT intrusion injection attacks increased significantly, with a spike in SQL injection attacks in the early part of the year which saw attacks rise by 46 per cent in April and 76 per cent in May.
Vulnerability disclosures by the Mozilla Firefox browser surpassed those of the new Internet Explorer.
The number of malicious web links discovered in the first six months of 2009 also increased compared to the first half of 2008, rising by 508 per cent, according to the report.
Read more security news.





