Business Daily Media

Men's Weekly

.

Trend Micro ZDI Surpasses 1000 Published Advisories in 1H 2023 In Continued Commitment to Coordinated Disclosure

Security leader to announce critical Microsoft zero-days at Black Hat USA 2023

HONG KONG SAR - Media OutReach - 18 August 2023 - Trend Micro (TYO: 4704; TSE: 4704), a global cybersecurity leader, announced at Black Hat USA 2023 that its Zero Day Initiative program has published advisories addressing over 1000 unique vulnerabilities in 2023.

The real-world impact if these vulnerabilities were to be weaponized would amount to time and financial losses of over 10 times the cost of prevention.

"Our proactive investment of millions each year into vulnerability research and purchases saves billions in recovery for both our customers and the industry as a whole," said Kevin Simzer, COO at Trend. "A concerning trend is being documented of companies lacking transparency around vulnerability disclosure vendor patching, which pose a threat to the security of the digital world."

Today, Trend is calling for an end to silent patching – the practice of slowing or diluting public disclosure and documentation of vulnerabilities and patches. It is a major roadblock to fighting cybercrime but is all too common among major vendors and cloud providers.

During a session at Black Hat USA 2023, Trend Research representatives revealed that silent patching has become particularly common among cloud providers. Companies are more frequently refraining from assigning a Common Vulnerabilities and Exposures (CVE) ID for public documentation and are instead privately issuing patches.

The lack of transparency or version numbers for cloud services hinders risk assessment and deprives the wider security community of valuable information for enhancing overall ecosystem security.

At last year's Black Hat event, Trend warned of a growing number of incomplete or faulty patches and an increasing reluctance among vendors to deliver authoritative information on patches in plain language. The gap has since worsened, with some companies deprioritizing patching altogether, leaving their customers and industries exposed to unnecessary and increasing risk.

Urgent action is needed to prioritize patching, address vulnerabilities and foster collaboration among researchers, cybersecurity vendors and cloud service providers to fortify cloud-based services and protect users from potential risks.

Trend is committed to transparent vulnerability patching and aims to enhance security postures industry-wide through its Zero Day Initiative program. Through its commitment to transparent disclosure, Trend's ZDI issued today advisories on several zero-day vulnerabilities including:

ZDI-CAN-20784 Github (CVSS 9.9)

  • This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft GitHub. Authentication is required to exploit this vulnerability
  • The flaw exists within the configuration of Dev-Containers. The application does not enforce the privileged flag within a dev container configuration. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor

ZDI-CAN-20771 Microsoft Azure (CVSS 4.4)

  • This vulnerability allows remote attackers to disclose sensitive information on Microsoft Azure. An attacker must first obtain the ability to execute high-privileged code on the target environment in order to exploit this vulnerability
  • The flaw exists within the handling of certificates. The issue results from the exposure of a resource to the wrong control sphere. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.

For a full list of advisories published by Trend Micro's ZDI, visit: https://www.zerodayinitiative.com/advisories/published/

Trend Micro's ZDI pioneered the vulnerability marketplace with a focus on disrupting attackers by legitimately purchasing vulnerability research that can then be disclosed to affected vendors to address before the information is made public.

Hashtag: #trendmicro #ZDI #cybersecurity #cloudsecurity



The issuer is solely responsible for the content of this announcement.

About Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,500+ employees across 70 countries, Trend Micro enables organizations to simplify and secure their connected world.

News from Asia

Jupiter Neurosciences Launches Nugevia™ Website and Opens Pre-Orders for Groundbreaking Longevity Supplements

Targeting the Multi-Trillion Dollar Longevity MarketHONG KONG SAR - Media OutReach Newswire - 27 August 2025 - Jupiter Neurosciences, Inc. (NASDAQ: JUNS) ("Jupiter" or the "Company"), a clinical-s...

HID Unveils Next-Generation FIDO Hardware and Centralized Management at Scale

The Next Generation of HID’s FIDO Portfolio Features Hardware Authenticators and a Centralized Management Experience that Simplifies Passkey DeploymentHONG KONG SAR - Media OutReach Newswire - 27 ...

Marking 30 Years of Excellence, EtonHouse International Education Group Pledges $3 Million to EtonHouse Community Fund to Strengthen Community Impact

SINGAPORE - Media OutReach Newswire - 27 August 2025 - Marking 30 years of excellence in education, EtonHouse International Education Group, together with E-Bridge Pre-School, has pledged $3 milli...

Trend Micro Named a Leader in Exposure Management by IDC MarketScape

Measurable reduction of operational silos and cyber risk delivered with Trend Vision One™ Cyber Risk Exposure ManagementHONG KONG SAR - Media OutReach Newswire - 27 August 2025 - Trend Micro Inc...

Genius Mind Expands Service Scope Beyond Academics to Include Coding, Financial Literacy, and AI Skills

SINGAPORE - Media OutReach Newswire - 27 August 2025 - Genius Mind, one of Singapore's trusted names in home-based education matching, has announced the expansion of its offerings to include codi...

Better Than Normal Launches Integrated AI Marketing and Coaching System for Singapore’s Service Professionals

SINGAPORE - Media OutReach Newswire - 27 August 2025 - Better Than Normal Pte Ltd, a Singapore-based brand strategy and AI marketing consultancy, is transforming how service-based professionals es...

Atlas Consolidated Secures USD 18.1 Million Series B Funding led by Tin Men Capital to Accelerate Global Adoption of HugoHub

The Asia-based Banking-as-a-Service provider aims to significantly accelerate the growth of HugoHub, Atlas’s modular cloud-native digital banking platform SINGAPORE - Media OutReach Newswire - 27 ...

Together Diamonds Launches in Singapore as the First Keepsake Diamond Atelier for Life’s Milestones, Not Just Memorials

SINGAPORE - Media OutReach Newswire - 27 August 2025 - Together Diamonds, Singapore's first homegrown keepsake diamond atelier, has officially launched with a mission to transform life's mileston...

TCMA leads Thai cement industry to reaffirm climate action leadership towards Net Zero 2050 at 2025 TCMA Technical Conference and Exhibition

BANGKOK, THAILAND - Media OutReach Newswire - 27 August 2025 - Thai Cement Manufacturers Association (TCMA) successfully hosted its flagship event, the "2025 TCMA Technical Conference and Exhibi...

Tanoto Foundation Develops Impactful Future Leaders at Tanoto Scholars Gathering 2025

SINGAPORE - Media OutReach Newswire - 27 August 2025 - High unemployment among educated youth and a lack of leadership readiness are significant challenges on Indonesia's path to its "Golden Indon...

Workplace DMs, Reinvented: Deputy Messaging, Purpose-Built For Shift-Based Teams

Deputy, the global people platform for shift-based businesses, has launched Deputy Messaging, a fully integrated, real-time communication tool designe...

Revolutionizing Fulfillment: How Virtual Warehousing is Changing the Game?

The e-commerce landscape is evolving more rapidly than ever, and the way businesses are managing their fulfillment is also revolutionizing. At the...

SME lender Dynamoney welcomes new CEO, Brett Thomas

Strengthens growth ambitions and signals expanded offering Dynamoney, a leading commercial finance provider for Australian SMEs,  has today appoint...

The cost of ignoring AI governance in business

Artificial intelligence (AI) is no longer the promise of a distant future: it's active, embedded, and already shaping decisions across industries. H...

Quickli launches new SMSF product as free beta for limited time only

The leading technology provider for Australian mortgage brokers, Quickli, has answered the prayers of brokers yet again with the launch of a stand...

Portable Monitors for Coding and Programming Students

Today, coding and programming require more focus and efficiency. But, the most essential thing it demands is ample screen space. Students can stru...

Sell by LayBy