Romolo Tavani - stock.adobe.com

* Share this item with your network:

By

* [Alex Scroxton,](https://www.techtarget.com/contributor/Alex-Scroxton)
  Security Editor

Published: 21 Feb 2024 19:29

The total number of [Common Vulnerabilities and Exposures](https://www.techtarget.com/searchsecurity/definition/Common-Vulnerabilities-and-Exposures-CVE) (CVEs) reported in IT hardware and software products and services looks set to continue to grow in 2024, according to figures published by active cyber insurance specialist [Coalition](https://www.coalitioninc.com/en-gb), which predicts CVE volume will increase by 25% to 34,888 vulnerabilities – approximately 2,900 every month.

CVEs are the unique identifiers attached to newly disclosed security flaws, including zero-days. They follow the same format – CVE-2024-XXXXX – where the first set of digits represents the year, and the second is a number assigned out of a block.

The CVE programme is overseen out of the US by the [Mitre Corporation](https://www.mitre.org/), with support from the [Cybersecurity and Infrastructure Security Agency](https://www.cisa.gov/) (CISA). Mitre does not always assign CVE numbers – this is more usually done by a CVE Numbering Authority (CNA), of which there are many, including suppliers such as Cisco, IBM, Microsoft or Oracle, and security firms and researchers.

The system is designed to give security professionals and defenders a quick, easy and reliable way to recognise vulnerabilities, and for the security community, helps coordinate the development of patches and other solutions.

However, the system is not perfect. The number of CVEs is growing exponentially and security teams are stretched thin enough as it is, added to which, the system is not equipped to highlight practical real-world exploitation, so users must often rely on researchers and media coverage of “celebrity CVEs” – such as those behind the MOVEit incident or Citrix Bleed – to make sense of such issues.

“New vulnerabilities are published at a rapid rate and growing. With an influx of new vulnerabilities, often sprouting via disparate flagging systems, the cyber risk ecosystem is hard to track. Most organisations are experiencing alert fatigue and confusion about what to patch first to limit their overall exposure and risk,” said Tiago Henriques, head of research at Coalition.

“In today’s cyber security climate, organisations can’t be expected to manage all of the vulnerabilities on their own; they need someone to manage these security concerns and help them prioritise remediation.”

> “Most organisations are experiencing alert fatigue and confusion about what to patch first to limit their overall exposure and risk”
>
>
> **Tiago Henriques, Coalition**

Coalition said there were a number of drivers contributing to the surge of vulnerabilities. These include the commercialisation and professionalisation of cyber criminal activity, and the ever-growing use of underground forums where exploit kits, credentials and access to compromised networks are sold.

There has also been an increase in the number of CNAs, which has increased the number of vulnerabilities noted.

Additionally, the growing popularity of bug bounty programmes may also be having an impact, as ethical hackers are incentivised to look for problems that may otherwise go unnoticed.

Coalition noted that the growing number of vulnerabilitiess was also leading to an increased focus on finding new ones among threat actors.

All this is adding up to a headache for security teams, being frequently under-resourced as they are, as one cannot possibly expect them to respond to up to 3,000 issues every month.

Coalition claims the breadth of data it collects from around the web, including a network of honeypots, enables it to make sense of cyber risk and share actionable insights with its customers and the security community.

It has also developed its own exploit scoring system, which it hopes will ease some of the pressure and enable its policyholders to adopt a more risk-based, prioritised approach to their unique vulnerability profile, rather than patching in a blind panic [on the second Tuesday of the month](https://www.techtarget.com/searchsecurity/definition/Patch-Tuesday).

## MDR: An early warning system for defenders

Coalition’s report additionally highlighted how its network of honeypots and other threat-tracking tools has become particularly adept at spotting threat actor exploitation of impactful CVEs before they are disclosed.

The firm said that in the case of CVE-2023-34362, which led to the [mass abuse](https://www.computerweekly.com/news/366539413/Victims-of-MOVEit-SQL-injection-zero-day-mount-up) of Progress Software’s MOVEit managed file transfer tool by the Clop/Cl0p ransomware gang [from the end of May 2023](https://www.techtarget.com/searchsecurity/news/366539035/Zero-day-vulnerability-in-MoveIt-Transfer-under-attack), its honeypot network identified activity targeting MOVEit over a fortnight before Progress Software issued its first advisory.

It said events such as MOVEit, but also Citrix Bleed, could well have been much less problematic had more organisations had dedicated [managed detection and response (MDR)](https://www.techtarget.com/whatis/definition/managed-detection-and-response-MDR) solutions in place.

Coalition’s general manager for security, John Roberts, said he believed MDR could reduce attack response time by half.

“We’re at the point where just setting and forgetting a technology solution is not enough anymore, and experts need to be involved in vulnerability and risk management,” he said.

“With MDR, after technology detects suspicious activity, human experts can intervene in numerous ways, including isolating impacted machines or revoking privileges. Coalition has experience doing exactly this to stop cyber criminals mid-attack.”

### Read more about MDR

* Adopting extended detection and response and employing managed detection and response services may be the missing pieces [of the SOC modernisation puzzle](https://www.techtarget.com/searchsecurity/opinion/Why-enterprise-SecOps-strategies-must-include-XDR-and-MDR).
* Explore the differences and similarities between EDR vs XDR vs MDR and the role they play to help improve behavioural analysis [for better threat response](https://www.techtarget.com/searchsecurity/tip/EDR-vs-XDR-vs-MDR-Which-does-your-company-need).

#### Read more on Data breach incident management and recovery

* [##### Microsoft targets 130 vulnerabilities on July Patch Tuesday

  By: Tom Walat](https://www.techtarget.com/searchwindowsserver/news/366627292/Microsoft-targets-130-vulnerabilities-on-July-Patch-Tuesday)
* [##### Mitre warns over lapse in CVE coverage

  By: Alex Scroxton](https://www.computerweekly.com/news/366622813/MITRE-warns-over-lapse-in-CVE-coverage)
* [##### Hertz warns UK customers of Cleo-linked data breach

  By: Alex Scroxton](https://www.computerweekly.com/news/366622655/Hertz-warns-UK-customers-of-Cleo-linked-data-breach)
* [##### Perimeter security appliances source of most ransomware hits

  By: Alex Scroxton](https://www.computerweekly.com/news/366620362/Perimeter-security-appliances-source-of-most-ransomware-hits)

Latest News

* [Interview: Ankur Anand, group CIO, Nash Squared](https://www.computerweekly.com/news/366639074/Interview-Ankur-Anand-group-CIO-Nash-Squared)
* [Telefónica activates commercial Edge services in Spain](https://www.computerweekly.com/news/366639110/Telefonica-activates-commercial-Edge-services-in-Spain)
* [UK AI alignment project gets OpenAI and Microsoft boost](https://www.computerweekly.com/news/366639303/UK-AI-alignment-project-gets-OpenAI-and-Microsoft-boost)
* [View All News](https://www.computerweekly.com/news)

Download Computer Weekly

* In The Current Issue:
  + How charities are using customer applications to boost support
  + Post Office offered bailout to cover £104.4m IR35 tax bill linked to Horizon IT scandal
  + Interview: Mariano Albera, CTO, Checkout.com[Download Current Issue](https://www.computerweekly.com/ezine/Computer-Weekly/Charities-turn-to-tech-for-greater-impact)

Latest Blog Posts

* [GreenOps - BlackLine: Why GreenOps needs finance-grade control to deliver value](https://www.computerweekly.com/blog/CW-Developer-Network/GreenOps-BlackLine-Why-GreenOps-needs-finance-grade-control-to-deliver-value)
  – CW Developer Network
* [What to expect from ABBYY Ascend 2026](https://www.computerweekly.com/blog/CW-Developer-Network/What-to-expect-from-ABBYY-Ascend-2026)
  – CW Developer Network
* [View All Blogs](https://www.computerweekly.com/blogs)

Related Content

* [Coalition: Vulnerability scoring systems falling short](https://www.techtarget.com/searchsecurity/news/366570543/Coalition-Vulnerability-scoring-systems-falling-short)
  – Search Security
* [Rapid7 warns of alarming zero-day vulnerability trends](https://www.techtarget.com/searchsecurity/news/366585701/Rapid7-warns-of-alarming-zero-day-vulnerability-trends)
  – Search Security
* [MoveIt Transfer vulnerability targeted amid ...](https://www.techtarget.com/searchsecurity/news/366591974/MoveIt-Transfer-vulnerability-targeted-amid-disclosure-drama)
  – Search Security