In March this year, the Apache Software Foundation announced that it had discovered a major flaw in its software. Now, this vulnerability is well known, which can be called the fatal point that Iquifax company has not fixed: hackers can steal sensitive information of 65.438+45 million Americans. China, a hacker prevention company, is one step ahead. Within one day of Apache's announcement, China's National Security Information Vulnerability Database (CNNVD) published the details of this software vulnerability. It took three days to appear in the official US database. At that time, researchers have recorded the wave of hacker attacks around the world using this error code.
According to the research report released by the network security company "Record the Future" on June+10/October 19, 65438, China usually has great advantages. According to the report, according to the analysis of the newly discovered vulnerabilities in the database 17940 between China and the United States in the past two years, the average time for both parties to release the newly discovered vulnerability information is 20 days.
Christopher alberg, CEO of Record the Future, said: "The time gap is a bit cruel. Hackers exploit vulnerabilities very quickly, because hackers know that the best way to get into computer systems is to find unpatched vulnerabilities. "
The research results of Record the Future company are only the latest evidence that the public reporting system of software vulnerabilities in the United States is struggling. The National Vulnerability Database (national vulnerability database, NVD) establishes and updates the catalogue of Common Vulnerability and Risk Exposure (CVEs) at any time, which is maintained by Matt Company, a non-profit company. When Matt Company created this directory in 1999, it provided experts with the names of common vulnerability threats replaced by various aliases. Since 2005, the national vulnerability database has also increased the content and resources that institutions can use to solve vulnerabilities. Maintaining network security and updating should take this as a reference standard.
Give greater China a compliment!
Misunderstandings about not investing in funds