TRENDS
- The United States is on top of the list with 1400 unique attackers.
- The exploit events were SQL Injection, Cross Site Scripting Miscellaneous, Command Execution, Denial of Service and Attack Response.
- The Top Alarm was Bruteforce Attach SSH with 187 Occurrences.
TOP ATTACKER COUNTRIES
| Country | No. of Attackers | Percentage |
|---|---|---|
| United States | 1400 | 26.0% |
| China | 1368 | 25.4% |
| Russian Federation | 347 | 6.4% |
| Brazil | 304 | 5.6% |
| France | 243 | 4.5% |
| India | 206 | 3.8% |
| Vietnam | 204 | 3.8% |
| Republic of Korea | 158 | 2.9% |
| Netherlands | 126 | 2.3% |
| United Kingdom | 112 | 2.1% |
| Australia | 108 | 2.0% |
| Canada | 104 | 1.9% |
| Italy | 102 | 1.9% |
| Taiwan | 97 | 1.8% |
| Germany | 97 | 1.8% |
| Indonesia | 91 | 1.7% |
| Ukraine | 85 | 1.6% |
| Thailand | 83 | 1.5% |
| Colombia | 81 | 1.5% |
| Egypt | 75 | 1.4% |

THREAT GEOLOCATION

TOP ATTACKING HOSTS

TOP ALARMS
| Alarm | No. of Occurrences |
|---|---|
| Bruteforce Authentication - SSH | 187 |
| OTX Indicators of Compromise - PULSE | 147 |
| Database Attack - Stored Procedure Access - Attack | 98 |
| WebServer Attack - Attack | 33 |
| Attack Tool detected - Attack | 29 |
Comparison to Previous Week
| Alarm | No. of Occurrences |
|---|---|
| OTX Indicators of Compromise - PULSE | 110 |
| Database Attack - Stored Procedure Access - Attack | 42 |
| Bruteforce Authentication - SSH | 30 |
| Attack Tool detected - Attack | 24 |
| WebServer Attack - Attack | 8 |
EXPLOIT EVENT TYPES

OPEN THREAT EXCHANGE
| Pulses Subscribed | Indicators | Last Updated | Number of Alarms | Number of Events |
|---|---|---|---|---|
| 5,708 | 870,491 | 2018-09-24 00:24:02 | 5,400 | 11,776 |
VULNERABILITIES
2018-09-21
Cisco IOS XE Software CVE-2018-0150 Default Credentials Security Bypass Vulnerability
securityfocus.com/bid/103539
2018-09-20
Ghostscript Multiple Security Bypass Vulnerabilities
securityfocus.com/bid/105122
Multiple Bluetooth Drivers CVE-2018-5383 Security Bypass Vulnerability
securityfocus.com/bid/1048793
Microsoft Windows JET Database Engine Remote Code Execution Vulnerability
securityfocus.com/bid/105376
Foreman CVE-2018-14643 Authentication Bypass Vulnerability
securityfocus.com/bid/105375
2018-09-19
Adobe Flash Player CVE-2018-15967 Unspecified Information Disclosure Vulnerability
securityfocus.com/bid/105315
ISC BIND CVE-2018-5741 Security Bypass Vulnerability
securityfocus.com/bid/105379
Citrix ShareFile StorageZones Control Directory Traversal and Information Disclosure Vulnerabilities
securityfocus.com/bid/105377
Cisco WebEx Network Recording Player Multiple Remote Code Execution Vulnerabilities
securityfocus.com/bid/105374
Adobe Acrobat and Reader CVE-2018-12848 Arbitrary Code Execution Vulnerability
securityfocus.com/bid/105360
Western Digital My Cloud CVE-2018-17153 Authentication Bypass Vulnerability
securityfocus.com/bid/105359
Adobe Acrobat and Reader APSB18-34 Multiple Information Disclosure Vulnerabilities
securityfocus.com/bid/105358
Symantec Messaging Gateway CVE-2018-12243 XML External Entity Injection Vulnerability
securityfocus.com/bid/105330
Symantec Messaging Gateway CVE-2018-12242 Authentication Bypass Vulnerability
securityfocus.com/bid/105329
2018-09-17
Apache SpamAssassin CVE-2018-11780 Remote Code Execution Vulnerability
securityfocus.com/bid/105373
