After a year dominated by high-profile ransomware attacks and supply chain compromises, researchers from Alphabet Inc.’s Google have identified another ignominious cyber milepost for 2021: a record number of “zero-day” exploits.
A zero-day exploit is a previously unknown bug which leaves software vendors exactly zero days to secure it. That makes the technology in question particularly valuable to hackers -- and a nightmare for cybersecurity professionals.
Hackers exploited a total of 58 zero-day flaws impacting major software providers in 2021, according to a report published Tuesday by Google’s Project Zero, a team of elite bug hunters. That compares to 25 flaws in 2020 and 21 in 2019.
It’s the highest number of zero-days ever recorded by Project Zero since tracking began in 2014. The trend could be due to an improvement in detection from the likes of Microsoft Corp., Apple Inc. and Google, who now disclose their findings around zero-day issues, rather than a rise in hacks, Maddie Stone, a security researcher at Project zero, said in a blog post about the findings.
In recent years, hackers have used the attack technique to install advanced spyware on smartphones that was then used to spy on journalists, politicians, human rights activists and others. Suspected Chinese state-sponsored hackers, meanwhile, exploited such flaws last year to compromise Microsoft Exchange servers.
Google’s Stone said there were some surprises among the data. Despite the recent focus on spyware being misused, cybersecurity researchers are still struggling to find zero-days that allow hackers to take control of targets’ phones.
”We know that messaging applications like WhatsApp, Signal, Telegram, etc are targets of interest to attackers and yet
Read more on tech.hindustantimes.com