2022 sees a 26% increase in vulnerability discovery, with browsers leading the way

2022 sees a 26% increase in vulnerability discovery, with browsers leading the way


In 2022, 25.2 thousand security vulnerabilities were reported, 26.5% more than the previous year; Chrome and Firefox lead the list of the most exploited

2022 ended with a total of more than 25,200 reported security vulnerabilities, an increase of 26.5% from the previous year, which also represents the growing focus of cybercriminals on software breaches. Chrome and Firefox browsers lead the list, with the most reported openings, with the browsers representing the largest category in the top 10 software.

Last year, 2,500 security vulnerabilities were reported in the browser Googlewhile managed by mozilla he finished second with 2,100. Oracle’s Mysql environment appears in third place, while Safari, by Appleand Internet Explorer, from Microsoft, round out the top 5, all with 1,100 each. The list ends with Thunderbird (1,100), Firefox Esr (870), OnCommand Insight (781), Gitlab (771), and Office (733).

Despite the high average, with around 70 vulnerabilities discovered and reported per day, the threat rate is low, with only 3.4% of detected breaches of a critical nature. Here, according to data from the computer security company ESET, which released the study, there is a drop of 5.8% compared to 2021. However, the moment is one of alertness for users and rapid application of updates.




2022 sees a 26% increase in vulnerability discovery, with browsers leading the way

“The most used applications will always be the ones that are most likely to be exploited by cybercriminals,” explains Mario Micucci, security researcher at ESET Latin America. “This information helps get a better overview of how malicious actors work, who are trying to reach as many people as possible.”

It highlights the example of Google Chrome, with no fewer than nine highly dangerous zero-day vulnerabilities fixed during 2022. This number, as well as the leadership in the list of reported threats, speaks directly to the presence of the browser as a leader in its market, with scams involving violations found in it having the greatest potential for success.

The old loopholes remain a danger to users

Of all the vulnerabilities exploited by attackers in 2022, the most common is remote code execution, with over 4,000 cases, representing 22% of all such reports. Followed by those of cross-site scripting such as 3.4 thousand), when undue codes are inserted into legitimate pages, with buffer overflows (2.2 thousand) and connection overload up to causing denial of service in the sequence (2 thousand). The top 5 is rounded out by SQL injection, with 1,700.

The ESET survey highlights that, of the five most common breaches in attacks against users, two have already been fixed 10 years ago. Both appear in the Windows operating system and allow remote code execution or remote access to the device without authentication, indicating that the absence of updates remains as big a risk as the vulnerabilities themselves.

“There is still a lack of user awareness,” Micucci adds. “The validity of these vulnerabilities should ring alarm bells for them to implement good security practices that include installing security updates and patches to prevent potential incidents.”

This warning also applies to apps that are part of the 2022 list. The ideal is to always keep them, but also all the others, updated and with the most recent versions. Using antivirus and other security software on PCs and smartphones also helps defend against common and well-known scams, as well as indicating the need for protective actions.

Trending on Canaltech:

+The best content in your email for free. Choose your favorite Terra newsletter. Click here!

Source: Terra

You may also like