Zero-day attacks
Zero-day attacks
* Many applications have vulnerabilities
– We’ve just not found them yet
* Someone is working hard to find the
next big vulnerability
– The good guys share these with developers
* Attackers keep these yet-to-be-discovered
holes to themselves
– They want to use these vulnerabilities for personal gain
* Zero-day
– The vulnerability has not been detected or published
– Zero-day exploits are increasingly common
* Common Vulnerabilities and Exposures (CVE)
– https://cve.mitre.org/
Zero-day vulnerabilities