10 security holes exploited by hackers in 2018
Microsoft accounted for 8 of the top 10 vulnerabilities in the world most exploited by hackers in 2018. The other two positions on this list belong to Adobe Flash and Google Android vulnerabilities. This is a statistic made by analysts from Recorded Future, which specializes in fraudulent attacks and trojan malware distribution campaigns. Although manufacturers have now released security patches for those vulnerabilities, not all users have upgraded to these patches, so the level of losses continues to increase.
The fact that Microsoft is the most popular target for hackers is understandable because its technology is widely used all over the world.
The most exploited flaw, topping this list is the remote code execution vulnerability CVE-2018-8174, with the Double Kill nickname. This vulnerability is located in Windows VBSsipt and can be exploited by hackers via Internet Explorer.
Second on this list is the Zero-day CVE-2018-4878 Flash Adobe, first discovered in February 2018. After only a few hours of discovery by researchers, an emergency patch was released, but a large number of users were still hacked through the CVE-2018-4878 vulnerability because they did not upgrade this patch . Currently, the CVE-2018-4878 vulnerability has appeared in many other exploit kits. One of the most notable exploit kits is Fallout, which is used to power the still-growing ransomware software to this day, ransomware GandCrab. But this vulnerability will disappear by 2020 thanks to available patches.
Discovered in December 2016, CVE-2017-11882, the Microsoft Office software security vulnerability ranks third in the list of most exploited vulnerabilities in 2018. CVE-2017-11882 allows malicious code runs at a time when a user opens a modified file containing malicious code that could put their computer at risk of malicious software being compromised.
Here is a list of the 10 most exploited security vulnerabilities in 2018:
You should read it
- Detects Zero-Day vulnerabilities on Windows PC operating systems that allow administrative rights
- Detects a vulnerability that threatens all Windows computers shipped from 2012 up to now
- Firefox releases urgent update to patch zero-day vulnerability being exploited by hackers
- Facebook Messenger sticks to a vulnerability that exposes users' contacts
- Serious vulnerability in Microsoft Word is being used by hackers to install malware on computers
- Google Chrome has an urgent update, patching a serious zero-day vulnerability being exploited by hackers
- Wi-Fi Vulnerability Leads to FragAttacks Attacks
- Google discovered a dangerous zero day vulnerability on many Samsung Galaxy, Huawei, Xiaomi and even Pixel phones
May be interested
- Smart paper has the ability to create electronic drawings in real timewith this set of products, users will just draw and write on paper, immediately a digital version will appear from time to time on adobe illustrator software to share or print.
- Apple confirmed the event on March 25, with many new services coming outapple today officially confirmed that they will hold a product launch event on march 25th.
- How to turn on Dark Mode on Chromedark mode (dark mode) seems to be becoming a very popular feature on online services and tools recently.
- Windows 7 is equipped with SHA-2 Support, which supports future updatesan update released by microsoft yesterday 12/3 has integrated sha-2 signing support for windows 7 sp1 and windows server 2008 r2 sp1.
- Facebook, Instagram and WhatsApp crashed globally not because of DDoS attackscurrently, social networks including facebook, instagram and whatsapp are experiencing service disruptions in vietnam and around the world. according to facebook's announcement, this incident is not due to ddos attack and said the company is troubleshooting.
- AnTuTu released version 7.2.6 update to prevent benchmark fraud on smartphonesin order to prevent some smartphone manufacturers from using some fraudulent tricks to get higher benchmark scores than competitors to entice users to buy their products, antutu has released a counter important date for their performance grading software.