Trends
- The top attacker country was the United States with 1101 unique attackers (26.96%)
- The top Exploit event was SQL injection with 80% of occurrences
Top Attacker by Country
Country | Occurrences | Percentage |
---|---|---|
United States | 1101 | 26.96% |
China | 1004 | 24.58% |
Brazil | 216 | 5.29% |
France | 202 | 4.95% |
Russian Federation | 202 | 4.95% |
Republic of Korea | 174 | 4.26% |
India | 163 | 3.99% |
United Kingdom | 145 | 3.55% |
Vietnam | 119 | 2.91% |
Canada | 105 | 2.57% |
Germany | 105 | 2.57% |
Netherlands | 104 | 2.55% |
Taiwan | 92 | 2.25% |
Australia | 76 | 1.86% |
Greece | 66 | 1.62% |
Italy | 57 | 1.40% |
Indonesia | 56 | 1.37% |
Singapore | 51 | 1.25% |
Spain | 46 | 1.13% |
Threat Geo-location
Top Attacking Hosts
Host | Occurrences |
---|---|
58.242.83.39 | 18 |
197.231.221.211 | 16 |
71.6.202.198 | 11 |
Top Network Attackers
Origin AS | Announcement | Description |
---|---|---|
AS4837 | 58.242.0.0/15 | China Unicom AnHui province network |
AS37560 | 197.231.220.0/22 | Cyberdyne S.A |
AS10439 | 71.6.128.0/17 | CariNet, Inc |
Top Event NIDS and Exploits
Top Alarms
Type of Alarm | Occurrences |
---|---|
Attack Tool detected - Attack | 290 |
OTX Indicators of Compromise - PULSE | 134 |
Bruteforce Authentication - SSH | 2 |
Comparison from last week
Type of Alarm | Occurrences |
---|---|
OTX Indicators of Compromise - PULSE | 119 |
Database Attack - Stored Procedure Access - Attack | 89 |
WebServer Attack - Attack | 45 |
Bruteforce Authentication - SSH | 28 |
Trojan Injection - IDS Event | 4 |
CVE
This is a list of recent vulnerabilities for which exploits are available.
ID: CVE-2019-1862
Title: Cisco IOS XE Software Web UI Command Injection Vulnerability
Vendor: Cisco
ID: CVE-2019-1649
Title: Cisco Secure Boot Hardware Tampering Vulnerability
Vendor: Cisco
ID: CVE-2019-5018
Title: SQLite Use After Free Remote Code Execution Vulnerability
ID: CVE-2019-5021
Title: Alpine Linux Docker Image Hard Coded Credentials Authentication Bypass Vulnerability
Vendor: Alpine Linux
ID: CVE-2019-3400
Title: Atlassian JIRA Cross Site Scripting Vulnerability
Vendor: Atlassian
ID: CVE-2019-2725
Title: Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
Vendor: Oracle
ID: CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091
Title: Intel Processor MDS Vulnerabilities
Vendor: Intel
Vulnerabilities
Fuji Electric Alpha7 PC Loader Out-of-Bounds Read Denial of Service Vulnerability
2019-05-16
securityfocus.com/bid/108359
Symantec Messaging Gateway CVE-2019-9699 Information Disclosure Vulnerability
2019-05-16
securityfocus.com/bid/108303
Dnsmasq VU#973527 Multiple Security Vulnerabilities
2019-05-15
securityfocus.com/bid/101085
Mozilla Firefox ESR CVE-2017-7843 Security Bypass Vulnerability
2019-05-15
securityfocus.com/bid/102112
Mozilla Firefox MFSA2017-27 Multiple Security Vulnerabilities
2019-05-15
securityfocus.com/bid/102039
Drupal Novalnet Payment Module- Ubercart Module SQL Injection Vulnerability
2019-05-15
securityfocus.com/bid/75039
Multiple Cisco Products CVE-2019-1818 Directory Traversal Vulnerability
2019-05-15
securityfocus.com/bid/108352
Multiple Cisco Products CVE-2019-1819 Directory Traversal Vulnerability
2019-05-15
securityfocus.com/bid/108351
Multiple Cisco Products Multiple Remote Code Execution Vulnerabilities
2019-05-15
securityfocus.com/bid/108339
Cisco Firepower Threat Defense Software CVE-2019-1833 Security Bypass Vulnerability
2019-05-15
securityfocus.com/bid/108338
Multiple Cisco Products Multiple SQL Injection Vulnerabilities
2019-05-15
securityfocus.com/bid/108337
Cisco Video Surveillance Manager CVE-2019-1717 Information Disclosure Vulnerability
2019-05-15
securityfocus.com/bid/108336
Cisco Small Business Series Switches CVE-2019-1806 Denial of Service Vulnerability
2019-05-15
securityfocus.com/bid/108335
Microsoft Office Access Connectivity Engine CVE-2019-0945 Remote Code Execution Vulnerability
2019-05-14
securityfocus.com/bid/108192
Siemens LOGO! Soft Comfort ICSA-19-134-03 Deserialization Arbitrary Code Execution Vulnerability
2019-05-14
securityfocus.com/bid/108368
Multiple Schneider Electric Products CVE-2019-6821 Security Bypass Vulnerability
2019-05-14
securityfocus.com/bid/108366
Singularity CVE-2019-11328 Insecure Permissions Local Privilege Escalation Vulnerability
2019-05-14
securityfocus.com/bid/108360