This statement is mr. Nguyen Gia Duc director, Fortinet Vietnam shared with reporters VietNamNettrivia event security annual Fortinet Accelerate Vietnam 2024 held in Hanoi recently.
Prove your mind, mr. Nguyen Gia Duc for or group study your mobile Labs sought to define the time period to a security vulnerability transfer from stage initial release to exploitation, whether the flaw has the high score of the scoring System to predict mining – EPSS have been exploited more quickly or not, and whether it can predict the time hackers exploit on average by using data from the system EPSS or not.
Based on this analysis, the expert Fortinet has pointed out that in the second half of last year, hackers have increased the speed advantage of the new vulnerability is announced, faster by 43% compared with the first half of the year 2023. This shows the importance of the supplier in the commitment discovered the flaw from a team of internal and developed patch before the extraction can occur, minimizing the case ‘sticky’ vulnerabilities, Zero-Day.
“It also emphasizes that the suppliers to be proactive and transparent in the disclosure of the vulnerability for organizations, enterprise customers to ensure they have the information necessary to be able to protect assets in an effective manner before an attacker can exploit the flaw”expert Fortinet recommendations.
With units use the products, technology solutions, mr. Nguyen Gia Duc for that they need to regularly review and assess the information security of the system of range management, in particular, is interested promptly update patch the vulnerability is a provider released.
According to experts, exploitation of vulnerabilities, especially the flaw has the high impact and severe exist in the solution technology common to ‘pedal’ intrusion into the system and from there hijack, steal information of the organization is one of the trends network attack highlights the recent years. However, in fact, still more units not interested in reviewing and patch the vulnerabilities, weaknesses, be warned.
In Vietnam, the role is the body of state management in the field of information security, network Administration, information Security (TT&TT) regular review, reviews, discovered the vulnerabilities on the system information of the agencies, organizations, businesses; there warn requires the unit patch, ensure the safety information for the system in accordance with the law.
Exchange at the plenary session of the Conference and exhibition secure cyberspace Vietnam – Vietnam Security Summit 2024 theme ‘Safety during the boom of artificial intelligence’, held last April 5 in Hanoi, representatives of the Ministry of TT&TT requires the agencies, organizations, businesses focus on the implementation of 6 solutions group, in which the periodic hunt down threats to the timely detection of signs of compromised system.
With the system has discovered security flaws, serious, after overcoming flaws, the unit should immediately implement the hunt for threats in order to determine the ability compromised earlier. Check out updates, patches, safety information for the system is important.
Agencies, organizations and businesses in the country are also recommended regular, continuous use of the platform support ensure the safety information of The TT&TT, develop, provide, including: platform, coordination, troubleshooting, information security, network nations; the foundation supports the investigation of; platform management and detection, early warning, risk safety information.

In the new information sharing, the Department of Safety information for System technical supervision of the Monitoring center, safe space network national – NCSC Department has recorded in January 5/2024 have 89.351 weakness, vulnerability, safety information exist in the server, workstation, system information of the agencies and organizations of The state.
Also in January 5/2024, system monitoring, scanning remote of the NCSC has detected more than 1,600 holes over 5,000 systems are open to the public on the Internet. In particular, the technical system of this unit recorded 12 new vulnerability is announced, there are serious effects that can be used by hackers to attack, tap into the system of agencies and organizations, including: CVE-2024-4671
“This is the flaw that exists on the popular products of many agencies, organizations and businesses. The proposed unit should perform a comprehensive inspection and vetting system, which helps determine your own system that uses the products affected by the flaw, not quickly put in place corrective measures timely to protect the safety information. At the same time, continuously updated information about the new holes, the trend attack on the space network”the expert Department of Safety information and recommendations.
Source: vietnamnet.vn

