August 6, 2015 By Shane Schick 2 min read

A zero-day vulnerability is just a potential threat until it is weaponized or incorporated into an exploit kit, but research unveiled at this week’s Black Hat security conference showed the process of doing so is getting shorter all the time.

Those who aren’t attending Black Hat can get a good overview of the research, conducted by Malwarebytes, by watching a video the company posted. It outlines all the steps to turn zero-day exploits into full-fledged attacks, including discovering the vulnerability, reverse engineering it and testing it. While this process once took about eight days, the report’s analysis found many cybercriminals are now managing it in four.

As Infosecurity Magazine pointed out, a key example cited by Malwarebytes concerned one of the zero-day exploits involved in the Hacking Team leak. That could explain the accelerated nature of the exploit to some extent, since the Italian security company not only had details on the vulnerability in question but actual instructions on how to turn it against a prospective victim. Less than 24 hours later, the first attacks surfaced.

The pace of zero-day weaponization has rarely been calculated. The Register noted that new malware authors are likely to draw attention to their work, but as more high-profile data leaks come to light, the work started by Malwarebytes may become an important element of how large enterprises conduct a risk assessment and allocate the necessary security resources to defend against potential attacks. When you know the clock is ticking faster, it’s probably a good incentive to be better prepared.

In fact, Malwarebytes was not the only one presenting some troubling numbers at Black Hat 2015. BetaNews reported that Secunia released an early look at its own zero-day vulnerability research. Among other things, it showed that the industry has already detected 15 zero-day exploits this year. Given that 25 exploits were tracked over the entirety of 2014, it’s probably safe to say the situation is only getting worse, and cybercriminals getting more productive in deploying their attacks.

Softpedia added that, just as zero-day exploits are proliferating, so is the scope of platforms affected. Whereas Android might have been considered a prime target in the past, for instance, the Secunia report showed a rise of cybercriminals looking directly at Apple’s iOS. That means that no users are safe — and everyone needs to prioritize security and incident response plans if they want to successfully defend against attacks.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today