Modern Australian
Men's Weekly

.

Trend Micro ZDI Surpasses 1000 Published Advisories in 1H 2023 In Continued Commitment to Coordinated Disclosure

Security leader to announce critical Microsoft zero-days at Black Hat USA 2023

HONG KONG SAR - Media OutReach - 18 August 2023 - Trend Micro (TYO: 4704; TSE: 4704), a global cybersecurity leader, announced at Black Hat USA 2023 that its Zero Day Initiative program has published advisories addressing over 1000 unique vulnerabilities in 2023.

The real-world impact if these vulnerabilities were to be weaponized would amount to time and financial losses of over 10 times the cost of prevention.

"Our proactive investment of millions each year into vulnerability research and purchases saves billions in recovery for both our customers and the industry as a whole," said Kevin Simzer, COO at Trend. "A concerning trend is being documented of companies lacking transparency around vulnerability disclosure vendor patching, which pose a threat to the security of the digital world."

Today, Trend is calling for an end to silent patching – the practice of slowing or diluting public disclosure and documentation of vulnerabilities and patches. It is a major roadblock to fighting cybercrime but is all too common among major vendors and cloud providers.

During a session at Black Hat USA 2023, Trend Research representatives revealed that silent patching has become particularly common among cloud providers. Companies are more frequently refraining from assigning a Common Vulnerabilities and Exposures (CVE) ID for public documentation and are instead privately issuing patches.

The lack of transparency or version numbers for cloud services hinders risk assessment and deprives the wider security community of valuable information for enhancing overall ecosystem security.

At last year's Black Hat event, Trend warned of a growing number of incomplete or faulty patches and an increasing reluctance among vendors to deliver authoritative information on patches in plain language. The gap has since worsened, with some companies deprioritizing patching altogether, leaving their customers and industries exposed to unnecessary and increasing risk.

Urgent action is needed to prioritize patching, address vulnerabilities and foster collaboration among researchers, cybersecurity vendors and cloud service providers to fortify cloud-based services and protect users from potential risks.

Trend is committed to transparent vulnerability patching and aims to enhance security postures industry-wide through its Zero Day Initiative program. Through its commitment to transparent disclosure, Trend's ZDI issued today advisories on several zero-day vulnerabilities including:

ZDI-CAN-20784 Github (CVSS 9.9)

  • This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft GitHub. Authentication is required to exploit this vulnerability
  • The flaw exists within the configuration of Dev-Containers. The application does not enforce the privileged flag within a dev container configuration. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor

ZDI-CAN-20771 Microsoft Azure (CVSS 4.4)

  • This vulnerability allows remote attackers to disclose sensitive information on Microsoft Azure. An attacker must first obtain the ability to execute high-privileged code on the target environment in order to exploit this vulnerability
  • The flaw exists within the handling of certificates. The issue results from the exposure of a resource to the wrong control sphere. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.

For a full list of advisories published by Trend Micro's ZDI, visit: https://www.zerodayinitiative.com/advisories/published/

Trend Micro's ZDI pioneered the vulnerability marketplace with a focus on disrupting attackers by legitimately purchasing vulnerability research that can then be disclosed to affected vendors to address before the information is made public.

Hashtag: #trendmicro #ZDI #cybersecurity #cloudsecurity



The issuer is solely responsible for the content of this announcement.

About Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,500+ employees across 70 countries, Trend Micro enables organizations to simplify and secure their connected world.

A First-Time Author’s Guide to Eco-Friendly Book Printing in Melbourne

Congratulations! You’ve done the hard part: you’ve actually finished a manuscript. That alone puts you ahead of countless people who say they’ll...

The Paint Job That Sells Homes: Design That Speaks Value Before You Step Inside

A proper paint job can do much more than simply modernize the color of the walls; it can affect how implicit buyers view a home. In real estate, curb ...

Global Humanitarian Alison Thompson Named 2026 NSW Australian of the Year — Why First Aid Knowledge Matters

Global humanitarian Alison Thompson OAM has been named the 2026 Australian of the Year for New South Wales, recognised for her decades of frontline re...

Modern Roller Shutters and Electric Roller Shutters: Security, Style, and Smart Living

When it comes to home and business security, few solutions offer the same balance of protection, convenience, and style as modern roller shutters. D...

What Is a Plunge Pool? A Complete Guide for Australian Backyards

Plunge pools have become one of Australia’s most sought-after outdoor features, offering a stylish, compact, and refreshing escape for homes of all ...

Gas Ducted Heating: Efficient, Reliable, and Cost-Effective Warmth for Melbourne Homes

Melbourne’s winters are known for their biting cold, and maintaining a comfortable indoor temperature becomes a top priority for homeowners. While...

Common Commercial Leasing Mistakes and How to Avoid Them

Leasing a commercial property is a major commitment that can shape the future of a business. Yet, many tenants and landlords overlook key details th...

Laser Skin Tightening: The Non-Surgical Way to Restore Youthful, Firm Skin

As we age, our skin naturally begins to lose its elasticity and firmness due to reduced collagen and elastin production. For those seeking to restor...

Car Rental Mistakes Most People Make

Car rental appears to be easy, but most travellers unintentionally get stuck in usual pitfalls that incur unnecessary expense and tension. Unseen ch...

Choosing the Right Aircon Store in Brisbane Northside

Picking the right air conditioning unit for your home is only half the battle. Just as crucial is finding a top-notch air conditioning store to back i...

Split System Maintenance Tips for Better Efficiency

Split system air conditioners are a staple in homes across Brisbane Northside, and for good reason. They are a cost effective, energy efficient soluti...

Nutifood, GippsNature Launch First Product in Vietnam - Australia Partnership

Executives from both companies expressed confidence in the roadmap’s long-term impact The debut signals stronger cross-border ambitions in premiu...

How Working with Lawyers Can Strengthen Your Legal Position

Engaging experienced lawyers in Melbourne is important when dealing with legal matters. Whether it involves business, property or personal law, the ...

The Role of Cantilever Racking in Handling Long and Bulky Items

In industries that handle oversized materials, finding the right storage system is essential for safety and efficiency. This is where cantilever rac...

House Builders Melbourne: Expert Craftsmanship for Modern Living

Building a home is more than just a construction project — it’s about creating a space where families grow, memories are made, and lifestyles ev...

Seamless Business Relocations Made Easy with Office Movers in Gold Coast

Relocating an office is a complex process that requires careful planning, coordination, and execution. From moving delicate electronics to arranging f...

DIY Air Conditioning Risks & How to Avoid Costly Repairs

When the scorching Queensland heat kicks in, the urge to grab a screwdriver and tackle your air conditioner fix to yourself is totally understandable...

WooCommerce Website Designer: Building High-Performance Online Stores That Drive Sales

A WooCommerce website designer plays a crucial role in helping businesses create high-performing, visually appealing, and conversion-focused online...