What is a zero day?

Zero-day attacks: invisible risks for every company

Why unknown security vulnerabilities are so dangerous

Zero-day vulnerabilities are the nightmares of IT security, attacks before a patch exists. Companies are hit without warning: data loss, business interruption, reputational damage. It is precisely because zero-days remain undetected that prevention is crucial.

How you can better protect your company

The question: How can you protect your company from zero-day attacks when threats are not yet known?

What is a zero-day?

A zero-day (0-day) is an unpatched vulnerability that is unknown to the developers of software, hardware or firmware. “Zero-day” means that the affected parties have zero days to prepare for or defend against the attack because they are not yet aware of the vulnerability. Zero-day exploits are often traded on the black market or used by criminal hackers to exploit the vulnerability.

In general, the term zero-day refers to two things:

Zero-day vulnerabilities: A vulnerability, e.g. in an operating system, that is unknown to the developer and the anti-virus software.

Zero-day exploits: A cyber attack that takes advantage of a zero-day vulnerability. Zero-day exploits can be used to install various types of malware, steal sensitive data or credit card numbers and cause data breaches.

The name zero-day is derived from the number of days since a patch for the vulnerability has been available: Zero.

What are the risks of zero-day vulnerabilities?

Zero-day threats pose a significant risk to cyber security as they are unknown to the person responsible for fixing the vulnerability and may already be exploited.

BlueKeep (CVE-2019-0708), for example, is a remote code execution vulnerability that affects around one million systems (as of May 29, 2019) with older versions of Microsoft operating systems.

This zero-day vulnerability made headlines during Microsoft’s Patch Tuesday in May 2019 as it is wormable.

This means that successful cyberattacks using BlueKeep can spread in a similar way to the WannaCry EternalBlue exploit.

Microsoft saw BlueKeep as such a major cyber threat to information and cyber security that they released patches for unsupported and unavailable operating systems.

BlueKeep can be detected within minutes using tools such as Masscan and Zmap, which scan large parts of the internet, making it trivial for attackers to find vulnerable systems.

What makes a vulnerability a zero-day vulnerability?

Normally, security researchers find potential vulnerabilities in software programs, notify the software company to fix the security risk and, after a certain period of time, make it public via CVE.

Google’s Project Zero, for example, gives providers up to 90 days to close a vulnerability before they publish it. A period of seven days is granted for vulnerabilities classified as critical, and actively exploited vulnerabilities can be made public immediately.

The reason for this is that most companies are able to fix the vulnerability and distribute a software update (patch) to fix it.

And it generally works. Potential attackers need time to find out how they can best exploit the vulnerability.

However, there are situations where the discoverer chooses not to notify the software manufacturer and antivirus vendors.

Zero-day vulnerabilities and exploit codes are extremely valuable, not only to cybercriminals, but also to state actors who can use them to launch cyberattacks against hostile states.

What are common zero-day attack vectors?

Which attack vector is used in a zero-day attack depends on the type of zero-day vulnerability.

When users visit fraudulent websites, malicious code on the website can sometimes exploit zero-day vulnerabilities in web browsers such as Internet Explorer or Chrome.

Another common attack vector for exploiting zero-day vulnerabilities is email. Cybercriminals use email spoofing, phishing or spear phishing to launch attacks that need to be opened by the victim to execute the malicious payload.

The danger of zero-day attacks is that their attack vector is unknown and usually remains undetected by threat intelligence and security software.

Who are the typical targets of zero-day attacks?

  • Government agencies
  • Large companies
  • Individuals with access to valuable business data or intellectual property
  • Groups of individuals with vulnerable systems such as an outdated Android or Linux device
  • Hardware devices and their firmware
  • Internet of Things (IoT)
  • Enemies of the state

What are examples of zero-day attacks?

Microsoft Outlook / Fancy Bear (2023): The Russian state-sponsored APT group Fancy Bear exploited CVE-2023-23397 to attack Microsoft Exchange accounts. Notable because the flaw could be exploited without any user interaction.

Predator spyware via iOS/Chrome (2023): An exploit chain of three zero-days. Researchers from Citizen Lab and Google’s Threat Analysis Group revealed that the vulnerabilities were used to deliver the Predator spyware from the commercial surveillance vendor Cytrox. One of the targets was Ahmed Eltantawy, a former member of the Egyptian parliament, whose phone was infected between May and September 2023.

Citrix Bleed (2023): A vulnerability (CVE-2023-4966) in Citrix NetScaler ADC and NetScaler Gateway. It was one of the most frequently exploited bugs of the year and made the top 15 list of routinely exploited vulnerabilities. Exploitation continued into November. Among others, it was used by ransomware groups for attacks on financial service providers.

GoAnywhere MFT (2023): At the end of January 2023, the Clop group launched a campaign via a zero-day vulnerability (CVE-2023-0669) against the GoAnywhere MFT platform and, according to its own statements, exfiltrated data from around 130 victims within ten days. A pre-authentication command injection flaw that shows how file transfer solutions are becoming a preferred target.

MOVEit Transfer (2023): The Clop ransomware group exploited a SQL injection zero-day vulnerability (CVE-2023-34362) in the widely used managed file transfer software MOVEit. Progress Software warned of the previously unknown flaw on May 31, 2023, after a massive attack campaign was discovered that siphoned sensitive files from vulnerable servers. The attackers installed a web shell called LEMURLOOT for persistence and data exfiltration. It became one of the largest data thefts of the year, with hundreds of affected organizations, including authorities and large companies worldwide.

WannaCry: A ransomware worm exploited EternalBlue, a vulnerability in old versions of Windows with an outdated SMB protocol. The NSA discovered the vulnerability months before WannaCry, but did not publicize it. Cybercriminals stole EternalBlue and used it for WannaCry. WannaCry spread to hundreds of thousands of computers before Microsoft released a patch.

Stuxnet: A malicious computer worm that was first discovered in 2010 and is believed to have been in development since at least 2005. Stuxnet targeted SCADA systems at Iran’s Natanz uranium facility. The worm used five zero-day vulnerabilities to spread and bypass access controls. One vulnerability was patched, but many computers were not updated.

RSA: In 2011, attackers used an unpatched vulnerability in Adobe Flash Player to penetrate the network security of the security company RSA. The attackers used phishing and email spoofing to distribute infected Excel spreadsheets to small groups of RSA employees. The Excel files contained an embedded Flash file that exploited the zero-day vulnerability and installed the Remote Administration Tool (RAT) Poison Ivy. Once they had gained access, the attackers searched for sensitive data and transmitted it to their servers.

Operation Aurora: In 2009, suspected Chinese attackers gained unauthorized access to dozens of American companies, including Google, Adobe, Juniper Networks and Rackspace, by exploiting a zero-day vulnerability in several versions of Internet Explorer.

Sony Pictures: Sony Pictures fell victim to a zero-day malware attack at the end of 2014. The attackers exploited a vulnerability in the Server Message Block (SMB). This vulnerability led to a massive loss of data. Valuable company data was stolen. This included upcoming movies, confidential business plans and personal e-mail addresses, as well as the addresses of important Sony executives. The stolen data could be used specifically for corporate espionage.

How SAVECALL protects against zero-day attacks

There is no complete protection against zero-days, but the risk can be significantly reduced. This is exactly where SAVECALL comes in, vendor-neutral and provider-independent. First we give you transparency about your attack surface, for example with a vulnerability scan and a pentest. We then compare suitable solutions for threat detection and response, from XDR to modern managed security services, and focus on fast patch processes and the awareness of your employees. This creates multi-layered protection that makes even unknown threats visible earlier.

Conclusion: zero-days require a multi-layered defense

Zero-day attacks strike without warning and often remain undetected for a long time. A single product does not protect you; only a combination of transparency, fast patch management, modern threat detection and trained employees is effective. Those who combine these layers shorten the time to detection and limit the potential damage. The central question remains whether your company is already prepared today for an attack whose vector nobody knows yet.

Frank Frommknecht, Key Account Consultant at SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has supported companies for over 20 years in selecting and optimizing their IT and security solutions. His focus: making complex topics understandable from the customer’s perspective and finding the right solution strategically.

Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

Sources

Frequently asked questions

What is a zero-day?

A zero-day (0-day) is an unpatched vulnerability that is unknown to the developers of software, hardware or firmware. The term means that the affected parties have zero days to prepare for an attack, because they are not yet aware of the vulnerability. The name is derived from the number of days a patch has existed, namely zero.

What is the difference between a zero-day vulnerability and a zero-day exploit?

A zero-day vulnerability is the security gap itself, for example in an operating system, that is unknown to the developer and the antivirus software. A zero-day exploit is the actual attack that takes advantage of this vulnerability. Exploits can install malware, steal sensitive data or credit card numbers and cause data breaches.

Why are zero-day threats so dangerous?

Zero-day threats are dangerous because they are unknown to the person responsible for fixing them and may already be exploited. As no patch exists and classic signatures do not apply, attacks often remain undetected for a long time. Examples such as BlueKeep show that attackers can find vulnerable systems within minutes using scanning tools.

Which attack vectors do zero-day attacks use?

The attack vector depends on the type of vulnerability. Common ones are manipulated websites whose malicious code exploits gaps in web browsers, as well as emails via spoofing, phishing or spear phishing. The danger lies in the fact that the vector is unknown and is initially not detected by threat intelligence and security software.

Who are typical targets of zero-day attacks?

Typical targets are government agencies, large companies and individuals with access to valuable business data or intellectual property. Groups with vulnerable systems, such as outdated Android or Linux devices, as well as hardware, firmware and IoT devices are also targeted. Attacks hit both broadly scattered and specifically selected victims.

How can you protect yourself against zero-day attacks?

There is no complete security, but the risk can be significantly reduced. Fast patch processes, transparency about your own attack surface, modern threat detection such as XDR and regular employee awareness against phishing are important. SAVECALL provides vendor-neutral support in selecting and building suitable security solutions.

Articles you might also like

What drives you forward – & what drives

Book a free expert consultation