Zero Day Vulnerabilities

24th February 2020 | Cybrary Zero Day Vulnerabilities


A Zero Day Vulnerability is a security flaw that is unknown to the software vendor or the business it is found in and there isn’t a patch released yet for the vulnerability. The term “zero day” refers to the fact that the developers have had zero days to fix the security flaw that has been recently found in their software or hardware. A “Zero Day Attack” occurs when a vulnerability that isn’t yet patched (possibly not even known) by developers of hardware or software is exploited by hackers.  This exploit allows hackers to breach a system through the software or hardware “zero-day” vulnerability.

In July of 2014, Google started the “Zero Day Initiative”, which was the creation of a program that consisted of security analysts from Google tasked with finding Zero Day Vulnerabilities; this team is called “Project Zero”. Project Zero researchers find vulnerabilities in hardware and software solutions and reports these findings to the manufacturer of the product. They work together to fix the security flaw and publicly release patches once the hole has been filled.

Project Zero is similar to Bug Bounty Programs, which is a deal that is offered by many websites, organizations, and software developers where individuals can receive recognition and monetary payment for reporting bugs or vulnerabilities in a vendors product offerings

Related Terms: Bug Bounty Programs, Responsible Disclosure, Vulnerability

Related Readings:

Hackers Exploit Zero-Day in WordPress Plugin to Create Rogue Admin Accounts

Data Breach at Mitsubishi Electric Caused by Zero-Day Vulnerability in Antivirus Software

Sources:

“Meet ‘Project Zero,’ Google’s Secret Team of Bug-Hunting Hackers”

“Announcing Project Zero”

Symantec

How does this relate to Businesses?

How you respond to Zero-Day Vulnerabilities as an business depends on whether you develop hardware (HW) or software (SW) yourself, or whether you consume other companies hardware and software.

My Business does not develop Hardware or Software – what should I Do?

For businesses that do not develop HW or SW, then you simply need to have a Vulnerability Alert Management Policy and process in place to deal with the security vulnerabilities that get announced for the HW and SW you consume.  This process defines how quickly you have to patch your equipment with respect to the criticality or size of the risk you face.  For risks that represent a total breach of your networks, where exploit code is available, and you have Internet enabled ports and protocols for the services being attacked, your policy will state – stop everything else and patch now.   Given the advent and speed of AI zero-day discovery tools, turn on automatic patching.  To wait invites a breach as AI can reverse engineer new critical patches in minutes and hours.  Update your VAMP processes to allow for this, even at the cost of downtime.  Far better to experience downtime outages than a breach in our opinion.

My Business develops Hardware and/or Software  – What do I need to do?

New Approach: For businesses developing hardware or software, you need to find and use AI zero-day discovery tool on yourself.  Do Not release code until you have remediated AI derived bugs in your Hardware and Software.
Old approach: For businesses developing HW or SW, you should build a Bug Bounty and responsible disclosure program or process into your development processes.  On your website, list how to report critical bugs in your software and the appropriate way to report them.

If you would like to learn more about Zero Day Vulnerabilities, watch this short video:

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

The Ransomware an AI Model Built Without Trying

The Ransomware an AI Model Built Without Trying

Researchers went looking for a fake photo upscaler and found something stranger: a ransomware kit an AI model...

Read more
CyberHoot Goes Fully Passwordless: Native Passkey Support Arrives for Administrators

CyberHoot Goes Fully Passwordless: Native Passkey Support Arrives for Administrators

For four years, CyberHoot has argued the same thing on its blog: passwords are major weak link. They get reused,...

Read more
Don’t Score an Own Goal: Outsmart World Cup 2026 Scams

Don’t Score an Own Goal: Outsmart World Cup 2026 Scams

The 2026 FIFA World Cup kicked off on June 11th across the United States, Canada, and Mexico. Six million fans...

Read more