Most of 2023’s Top Exploited Vulnerabilities Were Zero-Days
November 18 2024Zero-day vulnerabilities are more commonly used, according to the Five Eyes:
Key Findings
In 2023, malicious cyber actors exploited more zero-day vulnerabilities to compromise enterprise networks compared to 2022, allowing...
Read more
AIs Discovering Vulnerabilities
November 5 2024I’ve been writing about the possibility of AIs automatically discovering code vulnerabilities since at least 2018. This is an ongoing area of research: AIs doing source code scanning,...
Read moreNew Chrome Zero-Day
September 10 2024According to Microsoft researchers, North Korean hackers have been using a Chrome zero-day exploit to steal cryptocurrency.
Read moreUsing LLMs to Exploit Vulnerabilities
June 17 2024Interesting research: “Teams of LLM Agents can Exploit Zero-Day Vulnerabilities.”
Abstract: LLM agents have become increasingly sophisticated, especially in the realm of cybersecurity. Researchers have shown that LLM agents...
Read more
On the Zero-Day Market
May 24 2024New paper: “Zero Progress on Zero Days: How the Last Ten Years Created the Modern Spyware Market“:
Abstract: Spyware makes surveillance simple. The last ten years have seen a...
Read more
Another Chrome Vulnerability
May 14 2024Google has patched another Chrome zero-day:
On Thursday, Google said an anonymous source notified it of the vulnerability. The vulnerability carries a severity rating of 8.8 out of...
Read more
New iPhone Exploit Uses Four Zero-Days
January 4 2024Kaspersky researchers are detailing “an attack that over four years backdoored dozens if not thousands of iPhones, many of which belonged to employees of Moscow-based security firm Kaspersky.”...
Read moreEmail Security Flaw Found in the Wild
November 21 2023Google’s Threat Analysis Group announced a zero-day against the Zimbra Collaboration email server that has been used against governments around the world.
TAG has observed four different groups...
Read more
Critical Vulnerability in libwebp Library
September 27 2023Both Apple and Google have recently reported critical vulnerabilities in their systems—iOS and Chrome, respectively—that are ultimately the result of the same vulnerability in the libwebp...
Read more
Recent Comments