TRENDS
- The United States is on top of the list with 1400 unique attackers.
- The exploit events were SQL Injection, Cross Site Scripting Miscellaneous, Command Execution, Denial of Service and Attack Response.
- The Top Alarm was Bruteforce Attach SSH with 187 Occurrences.
TOP ATTACKER COUNTRIES
Country | No. of Attackers | Percentage |
---|---|---|
United States | 1400 | 26.0% |
China | 1368 | 25.4% |
Russian Federation | 347 | 6.4% |
Brazil | 304 | 5.6% |
France | 243 | 4.5% |
India | 206 | 3.8% |
Vietnam | 204 | 3.8% |
Republic of Korea | 158 | 2.9% |
Netherlands | 126 | 2.3% |
United Kingdom | 112 | 2.1% |
Australia | 108 | 2.0% |
Canada | 104 | 1.9% |
Italy | 102 | 1.9% |
Taiwan | 97 | 1.8% |
Germany | 97 | 1.8% |
Indonesia | 91 | 1.7% |
Ukraine | 85 | 1.6% |
Thailand | 83 | 1.5% |
Colombia | 81 | 1.5% |
Egypt | 75 | 1.4% |
THREAT GEOLOCATION
TOP ATTACKING HOSTS
TOP ALARMS
Alarm | No. of Occurrences |
---|---|
Bruteforce Authentication - SSH | 187 |
OTX Indicators of Compromise - PULSE | 147 |
Database Attack - Stored Procedure Access - Attack | 98 |
WebServer Attack - Attack | 33 |
Attack Tool detected - Attack | 29 |
Comparison to Previous Week
Alarm | No. of Occurrences |
---|---|
OTX Indicators of Compromise - PULSE | 110 |
Database Attack - Stored Procedure Access - Attack | 42 |
Bruteforce Authentication - SSH | 30 |
Attack Tool detected - Attack | 24 |
WebServer Attack - Attack | 8 |
EXPLOIT EVENT TYPES
OPEN THREAT EXCHANGE
Pulses Subscribed | Indicators | Last Updated | Number of Alarms | Number of Events |
---|---|---|---|---|
5,708 | 870,491 | 2018-09-24 00:24:02 | 5,400 | 11,776 |
VULNERABILITIES
2018-09-21
Cisco IOS XE Software CVE-2018-0150 Default Credentials Security Bypass Vulnerability
securityfocus.com/bid/103539
2018-09-20
Ghostscript Multiple Security Bypass Vulnerabilities
securityfocus.com/bid/105122
Multiple Bluetooth Drivers CVE-2018-5383 Security Bypass Vulnerability
securityfocus.com/bid/1048793
Microsoft Windows JET Database Engine Remote Code Execution Vulnerability
securityfocus.com/bid/105376
Foreman CVE-2018-14643 Authentication Bypass Vulnerability
securityfocus.com/bid/105375
2018-09-19
Adobe Flash Player CVE-2018-15967 Unspecified Information Disclosure Vulnerability
securityfocus.com/bid/105315
ISC BIND CVE-2018-5741 Security Bypass Vulnerability
securityfocus.com/bid/105379
Citrix ShareFile StorageZones Control Directory Traversal and Information Disclosure Vulnerabilities
securityfocus.com/bid/105377
Cisco WebEx Network Recording Player Multiple Remote Code Execution Vulnerabilities
securityfocus.com/bid/105374
Adobe Acrobat and Reader CVE-2018-12848 Arbitrary Code Execution Vulnerability
securityfocus.com/bid/105360
Western Digital My Cloud CVE-2018-17153 Authentication Bypass Vulnerability
securityfocus.com/bid/105359
Adobe Acrobat and Reader APSB18-34 Multiple Information Disclosure Vulnerabilities
securityfocus.com/bid/105358
Symantec Messaging Gateway CVE-2018-12243 XML External Entity Injection Vulnerability
securityfocus.com/bid/105330
Symantec Messaging Gateway CVE-2018-12242 Authentication Bypass Vulnerability
securityfocus.com/bid/105329
2018-09-17
Apache SpamAssassin CVE-2018-11780 Remote Code Execution Vulnerability
securityfocus.com/bid/105373