Forbes: Lazy Vulnerability Reporting & A Bit of Bias

It may have been almost two decades ago, I joked with colleagues that many Information Security news articles could just be done via Mad Libs. We later joked that breach notifications often appeared to be done via Mad Libs, using the same phrases with different organization names and the number of affected customers. Over the last few years, it seems Forbes has gotten lazy in their reporting on computer vulnerabilities.

First, a bit of background by querying Risk Based Security’s VulnDB, which I work on. While we track news articles on vulnerabilities, it is important to note that it is done in a best faith effort. We try to capture higher profile articles in the bigger publications within InfoSec and those outside the proverbial “echo chamber”, which includes Forbes, New York Times, Washington Post, Fox, etc. So by no means is this comprehensive, but it is important to understand the methodology which is using Google Alerts based on “CVE” strings. This started several years ago, maybe around 2015 give or take. Articles included before that were as they came across social media, referenced in modern disclosures, or some other current manner despite the publication date.

The first Forbes article we have associated goes back to June 17, 2001, covering a vulnerability in a GE Healthcare device. Up to 2010, almost every Forbes article we have is in a GE device along with one about Oracle and one about Linux Kernel. That alone is kind of interesting. From 2010 to 2020 we have Forbes articles covering a wide variety of vendors including Google, Onity, GE, Apple, Magento, PLX, and more. They also included articles covering big disclosures that covered multiple vendors of DVR systems, SIM cards, micro processors, and more. Last year, in 2020, Forbes produces a steady stream of articles for all the big vendors including Cisco, Microsoft, Apple, Google, Intel, Citrix, Zoom, and more.

This year though, it seems like Forbes got lazy. Perhaps it is burnout writing what is essentially the same article? You might think that, but no, because that is exactly what they started doing. Coverage is heavily based around Google Chrome and components in it, but disclosed via Google Chrome’s blog. Of the 48 vulnerabilities in 2021 cataloged by VulnDB, that have an associated Forbes article, only 12 are in non-Chrome products. What’s the gist of their coverage? Here’s three examples, see if you notice the similarities.

You may see the common phrase, “2 Billion Chrome Users”. Don’t worry, in a recent article that got increased to 2.6 billion! If it isn’t in the headline, you can find the phrase in almost every article talking about Chrome vulnerabilities. I get that these articles are repetitive, because there are only so many ways you can say Google fixed vulnerabilities in their browser.

That said, what’s more interesting to me is that they appear to have a single similar article for Mozilla Firefox vulnerabilities in all their time while continuing to encourage users to ditch Chrome. If I didn’t know better, I might think Forbes has chosen a side in the browser wars.

36 responses to “Forbes: Lazy Vulnerability Reporting & A Bit of Bias”

  1. jerichoattrition Avatar

    https://www.forbes.com/sites/gordonkelly/2021/11/16/google-chrome-hack-new-attacks-exploits-upgrade-chrome-now/ “Google Issues Warning For 2 Billion Chrome Users”

    Guess who didn’t get the memo.

  2. jerichoattrition Avatar

    https://www.forbes.com/sites/gordonkelly/2022/03/16/google-issues-warning-for-millions-of-chrome-users/ “Google Issues Warning For Millions Of Chrome Users” <– Millions, not billions now?

  3. jerichoattrition Avatar

    https://www.forbes.com/sites/gordonkelly/2022/03/23/microsoft-windows-11-windows-10-hack-attack-zero-day-new-windows-update/ “Microsoft Just Gave A Billion Users A Reason To Quit Windows” (Similar, with the ‘billion’ in the headline)

  4. jerichoattrition Avatar

    https://www.forbes.com/sites/daveywinder/2022/03/26/google-confirms-emergency-security-update-for-32-billion-chrome-users-attacks-underway/ “Google Issues Emergency Security Warning For 3.2 Billion Chrome Users—Attacks Underway”

    Also funny how 2022-03-02 it was “2 Billion” now 24 days later it is “3.2 Billion”?

  5. jerichoattrition Avatar

    https://www.forbes.com/sites/gordonkelly/2022/04/08/google-chrome-warning-new-hack-attack-vulnerability-upgrade-chrome-now/?sh=65a128177ebe “Google Issues Warning For Billions Of Chrome Users” [They wrote two articles about the same vuln, using similar headline. So lazy.]

  6. jerichoattrition Avatar

    https://www.forbes.com/sites/gordonkelly/2022/04/16/google-chrome-hack-attacks-zero-day-exploit-new-chrome-release/ “Google Issues Warning For Billions Of Chrome Users” [They wrote two articles about the same vuln again, on 4/16 the next 4/17]

  7. jericho Avatar

    https://www.forbes.com/sites/zakdoffman/2024/08/05/microsoft-warning-for-14-billion-windows-10-users-windows-11-free-upgrade/ – Interesting title is “Microsoft Update Warning—70% Of All Windows Users Now At Risk” but note the URL slug and “14 billion”.

  8. jericho Avatar

    https://www.forbes.com/sites/zakdoffman/2024/08/06/samsung-s24-ultra-galaxy-z-fold-6-z-flip-6-google-android-new-update-warning/ – “Samsung Issues Critical Update For Millions Of Galaxy Users—Google Warns Attacks Underway”

  9. jericho Avatar

    https://www.forbes.com/sites/zakdoffman/2024/08/07/google-issues-update-now-warning-for-millions-of-windows-10-windows-11-users/ – “Google Releases Critical New Chrome Update—1 Billion Windows Users Must Install” .. and we’re down to 1 billion!

  10. jericho Avatar

    https://www.forbes.com/sites/daveywinder/2024/09/27/new-chrome-security-warning-for-3-billion-windows-mac-linux-android-users/ – New Chrome Security Warning For 3 Billion Windows, Mac, Linux, Android Users

    We’re back to 3 billion!

  11. jericho Avatar
  12. jericho Avatar

    https://www.forbes.com/sites/zakdoffman/2025/06/03/google-issues-emergency-update-for-all-3-billion-chrome-users/ – Google Issues Emergency Update For All 3 Billion Chrome Users

    We’re back up to 3 billion!

  13. jericho Avatar

    https://www.forbes.com/sites/daveywinder/2025/10/23/update-now—google-issues-emergency-fix-for-35-billion-chrome-users/ — Act Now — Google Issues New Emergency Update For 3 Billion Chrome Users

    And now at 3.5 billion! Half a billion new users since June 4?!

Leave a Reply to jerichoattritionCancel reply

Discover more from Rants of a deranged squirrel.

Subscribe now to keep reading and get access to the full archive.

Continue reading