Posts

Showing posts with the label Zero-Day

Google Details the Biggest Zero-Day Vulnerabilities Found So Far This Year

The company analyzed 18 zero-day vulnerabilities in the first six months of 2022. By Nathaniel Mott,  PC Mag Half of the actively exploited zero-day vulnerabilities discovered in the first half of the year have been variants of existing security flaws, according to a new report from Google Project Zero. "As of June 15, 2022, there have been 18 0-days detected and disclosed as exploited in-the-wild in 2022," Google Project Zero security researcher Maddie Stone says in the report . "When we analyzed those 0-days, we found that at least nine of the 0-days are variants of previously patched vulnerabilities. At least half of the 0-days we’ve seen in the first six months of 2022 could have been prevented with more comprehensive patching and regression tests." It's easy to imagine the zero-day life cycle as something like this: A hacker finds a flaw, figures out how to exploit it, then uses it until someone releases a patch to fix it, at which point the hacker needs to...

New Microsoft Office zero-day used in attacks to execute PowerShell

By Ionut Ilascu , Bleeping Computer Security researchers have discovered a new Microsoft Office zero-day vulnerability that is being used in attacks to execute malicious PowerShell commands via Microsoft Diagnostic Tool (MSDT) simply by opening a Word document. The vulnerability, which has yet to receive a tracking number and is referred to by the infosec community as 'Follina,' is leveraged using malicious Word documents that execute PowerShell commands via the MSDT. This new Follina zero-day opens the door to a new critical attack vector leveraging Microsoft Office programs as it works without elevated privileges, bypasses Windows Defender detection, and does not need macro code to be enabled to execute binaries or scripts.

Chinese hackers behind most zero-day exploits during 2021

Image
By Bill Toulas, Bleeping Computers Threat analysts report that zero-day vulnerability exploitation is on the rise, with Chinese hackers using most of them in attacks last year. Zero-day vulnerabilities are security weaknesses in software products that are either unknown or have not been fixed at the time of discovery Zero-day disclosures are of particular interest to hackers because they have a wider exploitation window until vendors address the flaws and clients start applying the updates. Number of recorded zero-day exploits (Mandiant) Typically, this window of opportunity lasts for at least a couple of days, and since not all admins apply security updates immediately, the number of vulnerable targets remains high for a while. 2021 zero-day landscape According to an analysis from cybersecurity firm Mandiant, last year there were 80 cases of zero-days exploited in the wild, 18 more than 2020 and 2019 combined. Most of them were attributed to cyberespionage operations from state-backed...

Even the most complex cyberattacks are too easy

Image
By Joseph Marks, Washington Post Welcome to The Cybersecurity 202! Whatever else 4/20 may signify, it's also the second birthday of this guy here. Happy birthday, Jet! Below : European lawmakers on a committee investigating spyware get cracking, and a former eBay executive is pleading guilty in a bizarre cyberstalking scheme.  ‘Zero day’ cyber attacks should be harder to pull off The most complex and time-consuming cyberattacks are still far too easy to pull off, according to a new report from Google’s Project Zero division. These attacks, called zero days, are typically pulled off by extremely sophisticated hackers such as those employed by government intelligence agencies and top-end private companies like the controversial spyware vendor NSO Group. They’re more likely to give hackers long-lasting access to the technology they exploit and the ability to do far more damage.  Ideally, such hacks would take so much time, effort and expertise that only the cream of the crop cou...

Newly found zero-click iPhone exploit used in NSO spyware attacks

Image
By Sergiu Gatlan, Bleeping Computers Digital threat researchers at Citizen Lab have discovered a new zero-click iMessage exploit used to install NSO Group spyware on iPhones belonging to Catalan politicians, journalists, and activists. The previously unknown iOS zero-click security flaw dubbed HOMAGE affects some versions before iOS 13.2 (the latest stable iOS version is 15.4). It was used in a campaign targeting at least 65 people with NSO's Pegasus spyware between 2017 and 2020, together with the Kismet iMessage exploit and a WhatsApp flaw. Among the victims of these attacks, Citizen Lab mentioned Catalan Members of the European Parliament (MEPs), every Catalan president since 2010, as well as Catalan legislators, jurists, journalists, and members of civil society organizations and their families. "Among Catalan targets, we did not see any instances of the HOMAGE exploit used against a device running a version of iOS greater than 13.1.3. It is possible that the exploit was f...

Google Chrome emergency update fixes zero-day used in attacks

Image
By Lawrence Abrams,  Bleeping Computer Google has released Chrome 100.0.4896.127 for Windows, Mac, and Linux, to fix a high-severity zero-day vulnerability actively used by threat actors in attacks. "Google is aware that an exploit for CVE-2022-1364 exists in the wild," Google said in a security advisory released today. While Google states that this Chrome update will roll out over the next few days/weeks, users can receive it immediately by going into the Chrome menu > Help > About Google Chrome. The browser will also automatically check for new updates and install them the next time you close and relaunch Google Chrome. As this bug is actively exploited in attacks, it is strongly advised that you perform a manual check for new updates and relaunch the browser to apply them.