Google Details the Biggest Zero-Day Vulnerabilities Found So Far This Year

The company analyzed 18 zero-day vulnerabilities in the first six months of 2022.

By Nathaniel Mott, PC Mag

Half of the actively exploited zero-day vulnerabilities discovered in the first half of the year have been variants of existing security flaws, according to a new report from Google Project Zero.

"As of June 15, 2022, there have been 18 0-days detected and disclosed as exploited in-the-wild in 2022," Google Project Zero security researcher Maddie Stone says in the report. "When we analyzed those 0-days, we found that at least nine of the 0-days are variants of previously patched vulnerabilities. At least half of the 0-days we’ve seen in the first six months of 2022 could have been prevented with more comprehensive patching and regression tests."

It's easy to imagine the zero-day life cycle as something like this: A hacker finds a flaw, figures out how to exploit it, then uses it until someone releases a patch to fix it, at which point the hacker needs to discover a brand-new vulnerability. (And, of course, the people using the vulnerable product finally decide to install that patch.)


Comments

Popular posts from this blog

FBI, CISA warn US hospitals of targeted BlackCat ransomware attacks

Nissan North America data breach impacts over 53,000 employees

Why Your VPN May Not Be As Secure As It Claims