Attackers are getting worryingly good at exploiting zero-days, Google Mandiant says | usagoldmines.com

The exploitation of zero-day vulnerabilities, flaws that were abused before the developers built a fix, is growing faster than the exploitation of n-day vulnerabilities (those for which a patch is already available).

This is according to a new report from Google’s cybersecurity researchers Mandiant, who describe it as a “worrying trend”.

The researchers recently analyzed 138 exploited vulnerabilities that were disclosed in 2023, and concluded that 70% were abused as zero-days, while 30% were n-days. In previous years, the ratio was closer to 60% for zero-days, and 40% for n-days, meaning the crooks are growing increasingly reliant on zero-day vulnerabilities.

Social engineering

“While we have previously seen and continue to expect a growing use of zero-days over time, 2023 saw an even larger discrepancy grow between zero-day and n-day exploitation as zero-day exploitation outpaced n-day exploitation more heavily than we have previously observed,” the researchers explained.

Besides the increase in the numbers, the average time-to-exploit (TTE) has also decreased, suggesting that the attackers are exploiting these flaws faster than ever before. Two years ago, the average TTE was 32 days. Last year, it was merely five days, meaning the flaws are getting abused almost immediately.

But there is a silver lining to the research. Mandiant says organizations have gotten better at detecting zero-days, which also resulted in higher numbers in the report. It is quite possible that in previous years, a larger portion of these attacks went unnoticed. Companies have also gotten better at patching. They do it faster, and more frequently nowadays, forcing the hackers to move faster themselves. Hence the shorter TTE.

Looking into the future, Mandiant says the trend of zero-day exploitation is expected to grow, especially with improved detection tools. Zero-days are likely to remain a highly coveted approach for threat actors because they offer a critical window of attack before patches can be applied.

If this trend continues, Mandiant anticipates time-to-exploit will fall even further.

More from TechRadar Pro

What are zero-day vulnerabilities?Here’s a list of the best firewalls todayThese are the best endpoint protection tools right now
​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

iPhone Roadside Assistance via Satellite Feature Now Available in UK Tim Hardwick | usagoldmines.com
Apple MacBook Pro M4 leaks have exploded recently – and another heavy hint has just dropped that the...
Xiaomi is working on a smart ring, and it could come with a groundbreaking new feature stephen.warwi...
Firm hacked after accidentally hiring North Korean cyber criminal | usagoldmines.com
How Can Dynamics 365 Integrated Maps Help Overcome the 5 Biggest Territory Management Challenges? De...
Why I pay for Bitwarden even though it’s the best free password manager | usagoldmines.com
How to try a new laptop at home before you commit to buying it | usagoldmines.com
iPad Mini 7 Charging Speed Likely Remains at 20W Hartley Charlton | usagoldmines.com
Canceling your tech subscriptions will finally become less painful thanks to new ‘click-to-cancel’ r...
Another company just beat Samsung to Android 15 – and it’s not who you’d expect jamie.richards@futur...
The end of Kindle buttons –Amazon discontinues Kindle Oasis, the last model with physical page-turn ...
Polar says your health data is safe following cybersecurity attack matt.evans@futurenet.com (Matt Ev...
Businesses are struggling to harness the full power of AI | usagoldmines.com
Want the new DJI Air 3? An impromptu import ban has made it harder to buy in the US hamish.hector@fu...
Apple Secretly Developed Long-Range EV Battery Tech with China's BYD Tim Hardwick | usagoldmines.com
Microsoft has seemingly removed the $1 Xbox Game Pass offer just in time for the Call of Duty: Black...
Samsung prepares to unleash even faster GDDR7 VRAM early in 2025 – rocket fuel for Nvidia’s RTX 5080...
Astro Bot's first free DLC is available today with more coming over the next four weeks | usagoldmi...
Microsoft finally remembered to make another Xbox Series X wrap and the latest is Call of Duty: Blac...
Project 007: everything we know so far | usagoldmines.com
The NHS is in an IT ‘stone age’, staff struggle with creaking infrastructure | usagoldmines.com
Experts issue a health warning over standing desks, but you still shouldn't be sitting down all day ...
80% of customers are skeptical of AI use - here's what businesses can do | usagoldmines.com
An upcoming iPhone feature will make it easier to detect spam calls | usagoldmines.com
Rampant ransom payments highlight need for urgent action on cyber resiliency | usagoldmines.com
I’ve used Kindles since the first version, and here’s what Amazon is getting right about AI with the...
4 ways you can use ChatGPT's Canvas mode to improve your daily life erichs211@gmail.com (Eric Hal Sc...
What's New on Disney+ in November 2024 Emily Long | usagoldmines.com
What You Should Know About Apple's 5G Modem Juli Clover | usagoldmines.com
Quordle today – hints and answers for Thursday, October 17 (game #997) marc.mclaren@futurenet.com (M...
NYT Strands today — hints, answers and spangram for Thursday, October 17 (game #228) marc.mclaren@fu...
NYT Connections today — hints and answers for Thursday, October 17 (game #494) marc.mclaren@futurene...
Men accused of DDoSing some of the world’s biggest tech companies Dan Goodin | usagoldmines.com
iPad 11 Now Seems Unlikely to Launch This Year Joe Rossignol | usagoldmines.com
Amazon Launches First Kindle With Color Display Juli Clover | usagoldmines.com
DNA confirms these 19th century lions ate humans Jennifer Ouellette | usagoldmines.com
Raw Cider Is Just As Unsafe As Raw Milk Beth Skwarecki | usagoldmines.com
The Most Cliched Halloween Costumes to Avoid This Year Stephen Johnson | usagoldmines.com
Apple's Chief People Officer Leaves Company After 20 Months Juli Clover | usagoldmines.com
“Rumors of my death are severely exaggerated” — Intel CEO assures users x86 is “thriving” as it fina...
X’s depressing ad revenue helps Musk avoid EU’s strictest antitrust law Ashley Belanger | usagoldmin...
Best laptops 2024: Premium, budget, gaming, 2-in-1s, and more | usagoldmines.com
New TCL Dongle Connects Your Devices to T-Mobile 5G Network Tim | usagoldmines.com
Be Careful When Cleaning Your MacBook's (Mostly Fake) Speaker Grille Pranay Parab | usagoldmines.com
You Can Get Microsoft Project Pro on Sale for $18 Right Now Sponsored by StackCommerce | usagoldmine...
Micro nuclear reactors are being built that can deliver 5MW of power for up to 100 months, producing...
iPad mini 7 specs reveal 5 potentially annoying limitations mark.wilson@futurenet.com (Mark Wilson) ...
X-Peng EV flaunts new AI-powered autonomous driving powers, but it's still a long road to hands-free...
This tiny Ryzen 9 PC can drive three, yes three, 8K monitors thanks to a low profile video card with...
Logitech’s sleek Pebble 2 wireless mouse is only $18 right now | usagoldmines.com
The Samsung Galaxy Watch 6 Is $170 Right Now Daniel Oropeza | usagoldmines.com
When to Carve Your Pumpkins so They Don’t Rot Before Halloween Lindsey Ellefson | usagoldmines.com
Surgeons at UCSD Find Apple Vision Pro Promising for Minimally Invasive Surgery Juli Clover | usagol...
Apple Will Let Verified Businesses Display Logos in Apps Like Mail, Phone, and Wallet Juli Clover | ...
Is this the end of WD as an SSD brand? Sandisk takes over SSD, memory cards and USB flash drives fro...
FTC “click to cancel” rule seeks to end free trial traps, sneaky auto-enrollments Ashley Belanger | ...
Student was punished for using AI—then his parents sued teacher and administrators Jon Brodkin | usa...
There’s another massive meat recall over Listeria—and it’s a doozy Beth Mole | usagoldmines.com
Crucial Google Chrome update closes 17 security flaws | usagoldmines.com
Windows 11’s Clipboard History is broken after problematic 2024 update | usagoldmines.com
Our favorite thumb drive SSD is fast, compact, and cheaper than ever | usagoldmines.com
Avoid an Allergic Reaction by Testing Your Halloween Makeup Now Beth Skwarecki | usagoldmines.com
What to Look for (and Avoid) When Selecting a Pumpkin Lindsey Ellefson | usagoldmines.com
Apple Releases New macOS Sequoia 15.1 Public Beta With Apple Intelligence Juli Clover | usagoldmines...
Security leaders can't catch a break, with many on the verge of quitting benedict.collins@futurenet....
Best USB-C monitors 2024: These displays have a hidden talent | usagoldmines.com
Intel shows off Panther Lake, its next big bet in PC processors | usagoldmines.com
Google Flights Will Finally Let You Filter by “Cheapest” Kellen | usagoldmines.com
What Is a Good Debt-to-Income Ratio When Applying for a Mortgage Meredith Dietz | usagoldmines.com
Netflix’s Sweet Bobby: My Catfish Nightmare isn’t the only catfishing documentary worth streaming th...
Nvidia CEO - AI could be the largest technological leap we’ve ever seen | usagoldmines.com
Critical severity flaw warning issued by CISA for SolarWinds Web Help Desk | usagoldmines.com
New power delivery tech could save Google, Microsoft tens millions of dollars annually; Vertical PD ...
Amazon joins Google in investing in small modular nuclear power John Timmer | usagoldmines.com
Microsoft confirms bug that leaves ~9GB of undeletable files in Windows 11 | usagoldmines.com
Guard your packages from porch pirates with a Loxx Boxx, now $100 off | usagoldmines.com
Wednesday Question: Pixel Owners, How’s Android 15 Treating You? Tim | usagoldmines.com
Amazon's First Color Kindle Is Here Michelle Ehrhardt | usagoldmines.com
The 18 Best Low-Budget Horror Movies That Aren't 'Terrifier 3' Ross Johnson | usagoldmines.com
My Favorite Amazon Deal of the Day: Samsung ViewFinity S50GC UltraWide Monitor Daniel Oropeza | usag...
Apple's Supply Chain Gears Up for MacBook Pro Models With M4 Chips Joe Rossignol | usagoldmines.com
Another day, another huge Windows 11 24H2 update bug, this time triggering the dreaded Blue Screen o...
Apple's App Store is back to normal after a brief issue with downloading apps jacob.krol@futurenet.c...
Alibaba releases new translation-focused AI model for international ecommerce, trade, and everyday l...
Invincible season 3 finally has a release date and teaser trailer – and the Prime Video superhero se...
Samsung's Frame TVs now offer art from MoMA, and it looks fantastic | usagoldmines.com
Deepfake lovers swindle victims out of $46M in Hong Kong AI scam Benj Edwards | usagoldmines.com
Windows Security won’t start? Here’s how to get it back | usagoldmines.com
The FCC takes aim at broadband data caps | usagoldmines.com
YouTube gets shared playlists and a sleep timer in latest update | usagoldmines.com
Windows users are exposed to over 600 million cyber attacks every day | usagoldmines.com
A 27-inch 1440p IPS monitor for just $100? This is an unbeatable deal! | usagoldmines.com
Amazon Takes Up to $64 Off Apple Watch Ultra 2 and Series 10 in New Sales Mitchel Broussard | usagol...
App Store is Down for Many Users Joe Rossignol | usagoldmines.com
Apple’s latest study proves that AI can’t even solve basic grade-school math problems allisa.james@f...
Meta could be hit with lawsuits over social media harm for teens | usagoldmines.com
Top tech conferences: The ultimate tech events guide for October 2024 benedict.collins@futurenet.com...
Forget about all the M4 MacBook leaks – Microsoft Surface Laptop with Intel Lunar Lake CPU just appe...
$250 Analogue 3D will play all your N64 cartridges in 4K early next year Kyle Orland | usagoldmines....
I switched to a vertical monitor: 5 reasons I’m in love | usagoldmines.com

Leave a Reply