
We have recently published our Security Status Report 2023 H2. This report provides a comprehensive overview of cybersecurity in the past year's second half, compiling topics such as vulnerabilities, incidents, news, and trends.
Notably, over 29,000 vulnerabilities were documented in 2023. This figure significantly exceeds those of 2022, raising fundamental questions: Is current software less secure? Are software systems more susceptible to attacks, or are heightened efforts being made to uncover flaws? Regardless, this data highlights the necessity of developing more secure software.
The report also mentions significant vulnerabilities like Terrapin, which allowed man-in-the-middle attacks on the SSH protocol; and Marvin, an irreversible cryptographic flaw. Additionally, it notes how Chrome has been successfully attacked despite its high security level.
As for prominent incidents, the report includes the dismantling of a cyber scam criminal organization in Spain; the massive data exposure on the Dark Web under the 'Free Leaksmas' label; and the takedown of BulletProftLink, a phishing-as-a-service provider, in Malaysia.
In the mobile devices section, the report highlights the latest security and privacy features in Apple iOS 17 and Android 14:
- iOS 17 includes enhancements to the automatic deletion of single-use messages and the silencing of FaceTime calls from non-contacts.
- Android 14 prevents outdated applications and allows more granular media access permissions.
Regarding Operational Technology (OT) threat analysis, Aristeo, our threat capture and analysis system in the OT realm, detected over 322 million cybersecurity events in the second half of 2023. Phishing and malware downloads are the most common forms of attack.
The indicator-based threat study reveals that phishing is the most common type of attack in the URLs studied, accounting for 62.62% of the cases.
This report is a valuable tool for Cyber Security professionals and those interested in the field. It provides a detailed view of the main threats and trends, helping you to understand and stay protected in the current landscape.