News

  • Report

Share

Facebook Twitter linkedin
2024.07.24

Announcement of "Cyber Attack Detection Report for Web Applications" for the second quarter of 2024 and "Products Affected by OpenSSH Vulnerability (CVE-2024-6387)"

Cyber Security Cloud, Inc. (Headquarters: Shinagawa-ku, Tokyo; Representative Director, President and CEO: Toshihiro Koike; hereinafter referred to as "the Company"), a global security manufacturer, will release the "Web Application Cyber Attack Detection Report (hereinafter referred to as "this report")" for the second quarter of 2024 (April 1 to June 30, 2024). This report aggregates, analyzes, and calculates cyber Shadankun", Cloud-based WAF provided by the Company that visualizes and blocks cyber attacks on web applications, and "WafCharm", a public cloud WAF automatic operation service. In addition, we will publish the results of an investigation into whether products monitored by the vulnerability information collection and management tool "SIDfm" are affected by the OpenSSH vulnerability (CVE-2024-6387).

<Report Summary>
・Detects approximately 3.2 million cyber attacks per day
・SQL injections increased by 32 million cases compared to last year
・Attacks targeting PHPUnit vulnerabilities increased by 8.5 million compared to last year
・Announcement of a list of products affected by the OpenSSH vulnerability (CVE-2024-6387)

■ Total number of attacks and trends: Approximately 3.2 million cyber attacks detected per day

From April 1 to June 30, 2024, the total number of cyber attacks on web applications detected by our company was 295,539,852. This equates to approximately 3.2 million attacks per day. The average number of attacks per host (※ 1) was 18,134. In addition, the number of attacks detected increased by +173% compared to the same period last year, making it clear that cyber attacks, including ransomware, are on the rise.
(※1) Estimated calculation based on the total number of hosts protected by "Shadankun" (Web type: number of FQDNs, Server type: number of IPs) and the number of hosts protected by "WafCharm" (WebACLs).

■ Country of origin of the attack

Looking at the source of detected attacks by country compared to the same period in 2023, the top three countries in terms of number of attacks were the United States, Japan, the United Kingdom, Germany, and France.
There has been little change in the top countries, but Indonesia, which was 41st in April-June 2023, has risen to 10th place.

■Main attack types

Looking at the attack status of the main types of attacks during this survey period, although the total number has increased, the main trend has not changed significantly from 2023. The most common type of attack is "Web scan," which is a "precursor to an attack" such as exploring and investigating the target of the attack or searching for vulnerabilities with simple random attacks, accounting for 44%. Next is "Blacklisted user agent," an attack by bots using vulnerability scanning tools, accounting for 16% of the total. In addition, an increase in attacks targeting "PHPUnit," a PHP testing framework that was not previously ranked, was confirmed.

■ SQL injections increased by approximately 32 million cases compared to April-June 2023

SQL injection is an attack in which malicious SQL statements are injected into a site or application that dynamically creates SQL statements based on external input, resulting in unauthorized reading, alteration, or deletion of database data. When an SQL injection vulnerability is exploited, the database can be manipulated from outside, resulting in the viewing, theft, modification, or deletion of data recorded in the database. Looking at the trends since January 2023, we can see that the number of detected SQL injection attacks is on the rise. In particular, the number of detections has been consistently increasing, with the increase being particularly noticeable in June 2024.


Compared to April to June 2023, we confirmed an increase in the total number of attacks of approximately 32 million.

■ Compared to April to June 2023, attacks targeting PHPUnit (CVE-2017-9841) increased sevenfold to approximately 8.5 million.

CVE-2017-9841 is a vulnerability in certain versions of PHPUnit, a PHP unit testing framework.
The PHPUnit vulnerability allows remote attackers to execute arbitrary PHP code, which is a dangerous vulnerability that allows attackers to perform a wide range of actions on the server via the PHP code.
Compared to April to June 2023, the number of detections has increased by approximately 8.5 million. This suggests that attackers are still targeting the exploitation of this somewhat old vulnerability, which was disclosed in 2017.

■ List of products affected by OpenSSH vulnerability (CVE-2024-6387) released

Following the public disclosure of an OpenSSH vulnerability named regreSSHion (CVE-2024-6387), SIDfm also registered and published vulnerability information on it on Tuesday, July 2. This vulnerability is caused by a race condition in the SIGALARM signal handler of the OpenSSH server, and if exploited, it may be possible for a system to be remotely taken over.
OpenSSH servers are widely used for remote management of devices and are also embedded in firewalls and routers that make up network infrastructure in addition to servers, so the impact of this vulnerability is of concern.

▼ List of impacts to products monitored by SIDfm
https://sid-fm.com/blog/archive/entry/20240705.htmlThe list published this time only includes vendors for which advisories have already been published. Information in the list may be added or updated as vendors publish or update their advisory information in the future. The latest information will be updated on SIDfm blog as it becomes available.

■Comment from Cyber Security Cloud, Inc. Representative Director, CTO Yoji Watanabe
We have released the "Cyber Attack Detection Report for Web Applications" for the second quarter of 2024. The data presented in this report reflects the current situation in which cyber threats are becoming more sophisticated as technology evolves. In particular, the increase in SQL injection attacks and PHPUnit vulnerability attacks poses a significant security risk to companies.

Between April 1 and June 30, 2024, we detected an average of approximately 3.2 million cyber attacks per day. In particular, the increase of 32 million SQL injection attacks compared to last year and the increase of 8.5 million attacks targeting PHPUnit vulnerabilities indicate the need to take prompt and effective measures.

We are continuously updating and strengthening our security solutions using the latest technology. As attack methods evolve day by day, we are required to continue evolving accordingly. It is extremely important for website operators to continuously collect information on the latest security trends and threats and take appropriate measures. Security settings are not something that can be done once and then finished; it requires a constant process of vigilance and updating. By implementing appropriate security measures, it is possible to protect your website from attackers and maintain the trust of your users.

About Cyber Security Cloud, Inc.
Address: 13th floor, JR Tokyu Meguro Building, 3-1-1 Kami-Osaki, Shinagawa-ku, Tokyo
Representative: Toshihiro Koike Representative Director, President and CEO
Established: August 2010
URL: https://www.cscloud.co.jp
With the mission of "creating a cyberspace that people all over the world can use safely and securely," we are a Japanese security manufacturer that provides vulnerability information collection and management tools and fully managed security services for cloud environments, centered on web application security services that make full use of the world's leading cyber threat intelligence. As one of the global companies in cybersecurity, we will contribute to solving social issues related to cybersecurity and provide added value to society.