IBM: Websites are 'Achilles' heel' of business security
By the end of 2008, more than half of all vulnerabilities disclosed during the year had no vendor-supplied patch.

Businesses are unwittingly becoming the biggest threat to their own customers, as criminals use legitimate websites as a launching pad against consumers.
This is according to IBM, which called websites the "Achilles' heel" for corporate IT security thanks to attackers focusing on web applications to infect end-user machines. Corporations were also making it worse by using "off-the-shelf" web applications which carried vulnerabilities.
In the Annual IBM X-Force Report, Big Blue said that more than half of all vulnerabilities were related to web applications, and of these, more than 74 per cent had no patch. By the end of 2008, 53 per cent of all vulnerabilities had no vendor-approved patch.
The vulnerabilities meant that the large scale SQL vulnerabilities which emerged in early 2008 were able to continue to grow in size throughout the year.
By the end of 2008 the volume of SQL attacks had jumped by 30 times the number of attacks seen in the summer.
"The purpose of these automated attacks is to deceive and redirect web surfers to web browser exploit toolkits," said Kris Lamb, of X-Force Research and Development, in a statement.
"This is one of the oldest forms of mass attack still in existence today. It is staggering that we still see SQL injection attacks in widespread use without adequate patching almost 10 years after they were first disclosed."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He added: "Cybercriminals target businesses because they provide an easy target to launch attacks against anyone that visits the web."
IBM also said that the security industry needed to realise that cybercriminals were motivated by money, and fully consider how attackers balanced the economic opportunity of vulnerability against the costs of exploitation.
Lamb said: "If the security industry can better understand the motivations of computer criminals, it can do a better job of determining when emergency patching is most needed in the face of immediate threats."
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
Put AI to work for IT operations
whitepaper Reduce the cost and complexity of managing hybrid applications
By ITPro
-
AI in the retail industry is spreading beyond the IT department
News AI has become a strategic imperative for retailers, delivering marked productivity gains
By Emma Woollacott
-
Maximizing contact center operations with generative AI assistants backed by responsible AI principles
whitepaper Reduce the cost and complexity of managing hybrid applications
By ITPro
-
IBM just launched powerful new open source AI models – here’s what you need to know
News Available under the Apache 2.0 license, IBM's Granite 3.0 models are trained on enterprise data and can out-perform the competition
By Emma Woollacott
-
Achieving business outcomes with generative AI
Webinar Take your hybrid cloud journey to the next level with generative AI
By ITPro
-
Wimbledon’s new Catch Me Up AI feature promises to keep fans up to date at the tournament – after it irons out some of the wrinkles
News The latest feature to come out of IBM’s partnership with Wimbledon will keep fans engaged from the early stages right through to the final with dynamic player insights
By Solomon Klappholz
-
AI demands new ways of data management
whitepaper The data leader’s guide for how to leverage the right databases for applications, analytics and generative AI
By ITPro
-
AI governance for responsible transparent and explainable AI workflows
whitepaper Build greater trust in your AI
By ITPro