Zero Day Vulnerabilities

24th February 2020 | Cybrary Zero Day Vulnerabilities


A Zero Day Vulnerability is a security flaw that is unknown to the software vendor or the business it is found in and there isn’t a patch released yet for the vulnerability. The term “zero day” refers to the fact that the developers have had zero days to fix the security flaw that has been recently found in their software or hardware. A “Zero Day Attack” occurs when a vulnerability that isn’t yet patched (possibly not even known) by developers of hardware or software is exploited by hackers.  This exploit allows hackers to breach a system through the software or hardware “zero-day” vulnerability.

In July of 2014, Google started the “Zero Day Initiative”, which was the creation of a program that consisted of security analysts from Google tasked with finding Zero Day Vulnerabilities; this team is called “Project Zero”. Project Zero researchers find vulnerabilities in hardware and software solutions and reports these findings to the manufacturer of the product. They work together to fix the security flaw and publicly release patches once the hole has been filled.

Project Zero is similar to Bug Bounty Programs, which is a deal that is offered by many websites, organizations, and software developers where individuals can receive recognition and monetary payment for reporting bugs or vulnerabilities in a vendors product offerings

Related Terms: Bug Bounty Programs, Responsible Disclosure, Vulnerability

Related Readings:

Hackers Exploit Zero-Day in WordPress Plugin to Create Rogue Admin Accounts

Data Breach at Mitsubishi Electric Caused by Zero-Day Vulnerability in Antivirus Software

Sources:

“Meet ‘Project Zero,’ Google’s Secret Team of Bug-Hunting Hackers”

“Announcing Project Zero”

Symantec

How does this relate to Businesses?

How you respond to Zero-Day Vulnerabilities as an business depends on whether you develop hardware (HW) or software (SW) yourself, or whether you consume other companies hardware and software.

My Business does not develop Hardware or Software – what should I Do?

For businesses that do not develop HW or SW, then you simply need to have a Vulnerability Alert Management Policy and process in place to deal with the security vulnerabilities that get announced for the HW and SW you consume.  This process defines how quickly you have to patch your equipment with respect to the criticality or size of the risk you face.  For risks that represent a total breach of your networks, where exploit code is available, and you have Internet enabled ports and protocols for the services being attacked, your policy will state – stop everything else and patch now.   Given the advent and speed of AI zero-day discovery tools, turn on automatic patching.  To wait invites a breach as AI can reverse engineer new critical patches in minutes and hours.  Update your VAMP processes to allow for this, even at the cost of downtime.  Far better to experience downtime outages than a breach in our opinion.

My Business develops Hardware and/or Software  – What do I need to do?

New Approach: For businesses developing hardware or software, you need to find and use AI zero-day discovery tool on yourself.  Do Not release code until you have remediated AI derived bugs in your Hardware and Software.
Old approach: For businesses developing HW or SW, you should build a Bug Bounty and responsible disclosure program or process into your development processes.  On your website, list how to report critical bugs in your software and the appropriate way to report them.

If you would like to learn more about Zero Day Vulnerabilities, watch this short video:

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

When “Apple Support” Calls You Back, Hang Up

When “Apple Support” Calls You Back, Hang Up

Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: This week's blog has a...

Read more
Meet Manic: The Android Malware With a Sneaky Backup Plan

Meet Manic: The Android Malware With a Sneaky Backup Plan

Every so often a piece of malware comes along with a trick clever enough to make security researchers pause and...

Read more
SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

Author: Craig Taylor I cannot visit a coffee shop, go for a round of golf, have a friendly conversation with...

Read more