Google Details the Biggest Zero-Day Vulnerabilities Found So Far This Year
The company analyzed 18 zero-day vulnerabilities in the first six months of 2022.
By Nathaniel Mott, PC Mag
Half of the actively exploited zero-day vulnerabilities discovered in the first half of the year have been variants of existing security flaws, according to a new report from Google Project Zero.
"As of June 15, 2022, there have been 18 0-days detected and disclosed as exploited in-the-wild in 2022," Google Project Zero security researcher Maddie Stone says in the report. "When we analyzed those 0-days, we found that at least nine of the 0-days are variants of previously patched vulnerabilities. At least half of the 0-days we’ve seen in the first six months of 2022 could have been prevented with more comprehensive patching and regression tests."
It's easy to imagine the zero-day life cycle as something like this: A hacker finds a flaw, figures out how to exploit it, then uses it until someone releases a patch to fix it, at which point the hacker needs to discover a brand-new vulnerability. (And, of course, the people using the vulnerable product finally decide to install that patch.)
Comments
Post a Comment