[ad_1] WPScan is on track to post a record-breaking year for WordPress plugin vulnerabilities submitted to its database, according to a collaborative mid-year security report the company published with Wordfence. In the first half of 2021, WPScan has recorded 602 new vulnerabilities, quickly surpassing the 514 reported during all of 2020. The report is based on attack data from Wordfence’s platform and data from WPScan’s vulnerability database, providing a more comprehensive picture of the current state of WordPress security than either company could present alone. One of the trends highlighted in the report is the increase in password attacks. Wordfence blocked more than 86 billion password attack attempts in the first half of 2021. Attackers use a variety of methods to gain access to WordPress sites, including testing sites against lists of compromised passwords, dictionary attacks, and more resource intensive brute force attacks. Wordfence found the standard login to be the primary password attack target for 40.4% of attempts, followed by XML-RPC (37.7%). Since these attacks seem to be increasing, the report recommends that site owners use 2-factor authentication on all available accounts, use strong secure passwords unique to each account, disable XML-RPC when not in use, and put brute force protection in place. Data from Wordfence’s Web Application Firewall shows more than 4 billion blocked requests due to vulnerability exploits and blocked IP addresses. The report includes a breakdown of the percentage of requests blocked by firewall per firewall rule. Directory Traversal accounts for 27.1% of requests. This is when an attacker attempts to access files without being authorized and perform an action such as reading or deleting a site’s /wp-config.php file, for example. This breakdown also highlights the fact that certain older vulnerabilities are still frequently targeted by attackers. The vast majority of the vulnerabilities you hear about in the WordPress ecosystem come from plugins, with themes making up a much smaller portion. The report notes that only three of the 602 vulnerabilities catalogued by WPScan in the first half of this year were found within WordPress core. In analyzing vulnerabilities by type, WPScan found that Cross-Site Scripting (XSS) vulnerabilities accounted for more than half of all them (52%), followed by Cross-Site Request Forgery (CSRF) at 16%, SQL Injection (13%), Access Control issues (12%), and File Upload issues (7%). Using scores from the Common Vulnerability Scoring System (CVSS), WPScan found that 17% of reported vulnerabilities were critical, 31% high, and 50% medium in severity. Both Wordfence and WPScan claim that the greater number of vulnerabilities reported this year is indicative of the growth of the WordPress ecosystem and a maturing, healthy interest in security. Themes and plugins aren’t getting more insecure over time but rather there are more people interested in discovering and reporting vulnerabilities. “First and foremost, we aren’t seeing a lot of newly introduced vulnerabilities in plugins and themes but rather we are seeing a lot of older vulnerabilities in older plugins and themes being reported/fixed that just weren’t detected until now,” Wordfence Threat Analyst Chloe Chamberland said. “Vulnerabilities aren’t being introduced as frequently and more vulnerabilities are being detected simply due to the higher activity of researchers which is in turn positively impacting the security of the WordPress ecosystem. Considering it isn’t newly introduced vulnerabilities that are being frequently discovered, I feel confident in saying that the increase in discoveries doesn’t indicate that the ecosystem is getting less secure at all but rather getting more secure.” Chamberland also said she believes there is a domino effect when vulnerabilities are disclosed to vendors and they learn from their accidents, causing them to develop more secure products in the future. “Speaking from experience as I spend a lot of my time looking for vulnerabilities in WordPress plugins, things have definitely been getting more secure from my perspective,” she said. “Today, I frequently find capability checks and nonce checks in all the right places along with proper file upload validation measures in place, and all the good stuff. It’s become harder to find easily exploitable vulnerabilities in plugins and themes that are being actively maintained which is a great thing!” The mid-year report is available as a PDF to download for free from the WPScan website. WPScan founder and CEO Ryan Dewhurst said he expects there will be an end of the year report for 2021. He has not yet discussed it with Wordfence but the companies are brainstorming about other ways they can collaborate. Like this: Like Loading… [ad_2] Source link
Continue readingTag Archives: Report
UK State of Open Report Finds 97% of UK Businesses Surveyed Use Open Source Software – WP Tavern
[ad_1] OpenUK, a WordPress-powered not-for-profit company, has released its State of the Open report with data from the UK in 2021. The company advocates for open source software, open source hardware, and open data, while providing a central point of collaboration for people working in the open sectors. The State of the Open report offers a broad overview of the UK’s open source ecosystem. This collection of research includes surveys of UK companies, interviews, industry reports, and analysis from different publications. It was sponsored by GitHub, SUSE, and the Open Invention Network, and conducted by Smoothmedia consulting firm under the direction of ethnographer and social researcher Dr. Jennifer Barth. Key findings in Phase 1 of the report include research demonstrating that open source software contributes an estimated £43.1 billion to the UK economy, with the UK ringing in as Europe’s largest contributor. Phase 2 covers open source adoption in the UK. Researchers found a staggering 97% of the 273 UK businesses surveyed use some form of open source software: We found that 97% of businesses of different sizes in all sectors of the UK economy use open source software technology. Although resources became a more pressing concern during the pandemic, 64% of businesses in our sample experienced business growth which translated into a high recruitment drive for roles relating to open source software in the past 12 months (see recruitment findings). Further, we find that almost half of businesses surveyed (48%) are using open source software more as digital adoption becomes embedded in organisational culture and business. Other key findings from Phase 2 include the following: 53% of non-tech organizations contribute to open source software projects 77% of UK public sector looks to open source for skills developmen Over half (54%) have written policies and processes for open source contributions 89% run open source software internally in their business Approximately two thirds (65%) contribute to open source software projects One interesting observation from the contribution data is that smaller companies are more likely to contribute back to open source than larger companies. Smaller companies are also more likely to use open source software in their businesses. From the #StateOfOpen report from @openuk_uk, it’s clear that businesses of all sizes make key use of open source. The report correlates company size and open source involvement, showing smaller companies more active in contributing to open source. https://t.co/A7dz3pjqFm pic.twitter.com/L5qeRrs9Xc — Aiven (@aiven_io) July 12, 2021 Survey respondents cited “saving on costs” as the main reason for adopting open source (75%), followed by more collaboration (72%), skill development (64%), the quality of code (61%), and security (52%). Phase 3 is planned to be published in September 2021. This report will focus on UK data with a methodology tailored to reveal the value of open source software to the digital economy. It will also include case studies that demonstrate the non-economic, intangible benefits of open source software, such as skills development and collaboration. The published reports are lengthy but will be of particular interest to companies working in the UK and Europe, especially consultancies that may need to justify using open source technologies in engineering decisions. OpenUK plans to conduct a further survey in 2022 as part of this effort to estimate the impact of open source on the UK economy. Like this: Like Loading… [ad_2] Source link
Continue reading