Telecommunications
ITEXPO begins in:
New Coverage :
Asterisk
|
Fax Software
|
SIP Phones
|
Small Cells
ONLINE COMMUNITIES
Industries
Cable Technology
DNS
Financial Technology
Gadgets
Green Technology
HTML5
HealthTechzone
Information Technology
iPhone
Mobility Commerce Insider
MobilityTechzone
M2M Evolution
Managed Service Providers
Robotics Technology
Satellite Technology
Smart Grid
Sports Technology
Technology Jobs
TechZone360
Video World Insider
Publications
Customer Interaction Solutions
Cloud Computing
Internet Telephony
Next Gen Mobility
Snapshots
Buyers' Guide
Media Kit
Markets
Accounts Receivable Management
CaaS
Education Technology
Government Technology
Healthcare Technology
Insurance Technology
Legal Technology
News Centers
Avaya News
IBM News
Cisco News
Microsoft News
Skype News
SAP News
Salesforce News
Service Provider
Election 2012
Enterprise
Developer
Reseller
Consumer
Resources
Online Communities
eBooks
White Papers
Podcasts
Research Reports
Webinars
Videos
Free eNewsletter
TMCnet News for iPhone
Events
Astricon
ChannelVision Expo (CVx)
Cloud4SMB Expo
Cloud Communications Expo
DevCon5
ITEXPO West 2012
M2M Evolution Conference
Mobile Commerce Zone Conference & Expo
Mobility Tech Conference & Expo
Putting SIP To Work - Free Seminar
MSPAlliance MSPWorld
SIP Trunking-UC Seminars
SUITS Conference
Super Wi-Fi Summit
Video World Conference & Expo
WebRTC Expo
International
Europe
Asia
Africa
Latin America
Middle East
Australia
Blogs
Rich Tehrani
Tom Keating
Erik Linask
more...
Videos
Business Process Outsourcing
Call Center Services
Call Center Software
Call Recording
Cloud Data Center
Conferencing
Contact Center on Demand
Contact Center Solutions
Customer Service Software
Dark Fiber
Dialer Software
Email Hosting
Embedded M2M Solutions
Enterprise Call Recording
Enterprise Solutions
Fax
Free Predictive Dialer
Hosted IVR
IVR
Knowledge Management
Machine to Machine Solutions
Live Chat
Next Generation Communications
Network Management
Network Packet Broker
Office 365
Outbound Call Center
Session Border Controller
SIP Phones
SIP Trunking
Unified Communications
Unified Communications Software
VoIP Routers
Wireless Backhaul
TMCnet LOGIN
SUBSCRIPTIONS
FREE Magazine Subscriptions
FREE eNewsletters
IMPORTANT
What's Hot This Week
Buyers' Guide
Awards/Who's who
Research
ABOUT TMC
Technology Marketing Corporation
Contributors
Contact Us
Corporate News
PR Resources
Management
Directions
Media Kit
TMCnet Services
Employment
WEBINARS
TMCnet CHANNELS
ACD Software
Appliance Deployment
BPA (3rd Party Remote Call Monitoring)
Bring Your Own Device
Business Process Automation
Business VoIP
Business VoIP Providers
Call Accounting
Call Center
Call Center Business
Call Center Certification
Call Center Furniture
Call Center Hiring
Call Center Management
Call Center On Demand
Call Center Scheduling
Call Center Software
Call Center Solutions
Call Center Training
Call Center Workforce Optimization
Call Recording
Citrix Application Performance Management
Cloud Based Contact Center
Cloud Business
Cloud Communications
Cloud CRM
Cloud Hosting
Contact Center Outsourcing
Contact Center Software
Contact Center Transformation
Data Center Power
Dialer Software
E911 Hosted Solutions
Enterprise Mobile Solutions
Enterprise SBC
Ethernet Extender
Fax Over IP
Fax Software
Fax VoIP
FoIP
Google Apps - News
Hadoop
Hosted Call Center
Hosted Contact Center
Hosted Softswitch
IP Communications
IP Fax
IP Phones
IP Softswitch
IP Transit
IVR
IVR Service Provider
IVR System
Master Agent
Middleware Management
Mobile Device Management
Mobile Security Management
Mobile VoIP
MPLS
Network Diagramming
Out of Band Management
Outbound Dialer
Power Protection
Predictive Dialer
RCS VoLTE
SaaS Licensing
SIM Server
Small Cells
SMARTnet
Softswitch
Software Licensing
Software Monetization
Speech Analytics
Telecom Expense Management
Telecom Platform Deployment
Telemarketing Software
Text Messaging
Toll Free Number
Virtual Call Center
Virtual Office
Virtual PBX
Voice Peering
VoIP Call Center
VoIP Call Recording
VoIP Gateways
VoIP Monitoring
VoIP Service Provider
VoIP Switch
Wholesale VoIP
Wi-Fi Network
Workforce Management
Workforce Optimization
Share
|
More
[April 12, 2012]
New Report Finds Core Vulnerabilities Persist in Web Applications, Increasing Evidence of New Hybrid Vulnerabilities
(Marketwire Via Acquire Media NewsEdge) CAMPBELL, CA -- (Marketwire) -- 04/12/12 -- Cenzic Inc., the leading provider of application security intelligence to reduce security risks, today announced the release of the Cenzic Trends Report for 2011 through Q1 2012. The report details the continued threat of vulnerabilities within Web applications, mobile applications, and outlines specific vulnerabilities with cloud-based implications.
The report reveals an alarming trend for security professionals, in the form of continued prevalence of critical application layer vulnerabilities, such as Cross Site Scripting (XSS) and SQL Injection. Though there are existing fixes for these well-known vulnerabilities, these flaws continued to dominate with XSS climbing to a staggering 38 percent of total Web vulnerabilities, increasing slightly from the second half of 2010. SQL Injection accounted for 15 percent of the total number of Web vulnerabilities.
"As businesses worry about the next big security threat, they fail to realize the threats that are right in front of them," said John Weinschenk, CEO of Cenzic. "From an industry-wide perspective, the fact that the amount well-known vulnerabilities continue to persist is a signal that education, diligence, and proper coding during the development phase are a necessity in today's cyber world. Real change can only happen by adhering to these principles." The Trends Report also details the vulnerabilities related to cloud and mobile device usage, noting a total of 89 mobile vulnerabilities were made public in 2011, while out of a set of 1201 publically reported vulnerabilities 855 had cloud-based security implications. As mobile devices continue to be used to access online cloud computing platforms, emerging hybrid vulnerabilities haved developed as well.
"The growing demand for cloud applications and mobile devices that access them is creating a unique problem," continued Weinschenk. "Each has its own set of security issues, but when used in tandem, they can produce hybrid vulnerabilities that compound threats and increase the complexity of secure coding. By exploiting vulnerabilities in a mobile application a hacker can open up an attack vector to a preexisting vulnerability on the cloud based application, and vice versa." Key findings of the Cenzic Trends Report include: Web vulnerabilities In the first two months of 2012, 59 percent of all reported security vulnerabilities were Web vulnerabilities In 2011, Cross Site Scripting (XSS) accounted for 38 percent of total Web vulnerabilities Mobile vulnerabilities A total of 89 mobile vulnerabilities were made public in 2011 and so far in 2012 (Jan-Feb) 11 mobile vulnerabilities have been made public. Sensitive Information Disclosure (28 percent) and Session Authentication and Authorization (28 percent) make up the bulk of the vulnerabilities. Cloud vulnerabilities In 2011, out of a set of 1201 publically reported vulnerabilities 855 had cloud based security implications Specific security vulnerabilities were found in cloud-based applications including EyeOS, OrangeHRM, The Parallels Plesk Panel, Oracle Fusion Middleware, Batavi E Commerce, deV!ls ClanPortal, and more.
To download a PDF version of the full report, please visit
http://info.cenzic.com/2012-Applicaiton-Security-Trends-Report.html
Important LinksCenzic Mobile Application Security Solution Cenzic Website Cenzic Twitter Cenzic Facebook Tweet this: Cenzic report reveals new stats on Web security, vulnerabilities About CenzicCenzic provides the leading application security intelligence platform to continuously assess Cloud, Mobile and Web applications to reduce online security risk. Cenzic's solutions scale from single applications to enterprise-level deployments with hybrid approaches that enable testing of applications at optimal levels. Cenzic helps brands of all sizes protect their reputation and manage security risk in the face of malicious attacks. Cenzic's solutions are used in all parts of the software development lifecycle, and most importantly in production, to protect against new threats even after the application has been deployed. Cenzic's application security intelligence platform is architected to handle web, cloud and mobile applications and is the first to provide risk reduction recommendations for business, application developers and specific applications. Today, Cenzic secures more than half a million online applications and trillions of dollars of commerce for Fortune 1000 companies, all major security companies, government agencies, universities and SMB companies.
Media Contact: Dave Struzzi Kulesa Faul 212-228-7972 dave@kulesafaul.com Source: Cenzic
[
Back To Homepage
]
FREE Telecomm
eNewsletter
Real time alerts