By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: 70% of exploited flaws disclosed in 2023 were zero-days
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > 70% of exploited flaws disclosed in 2023 were zero-days
Tech News

70% of exploited flaws disclosed in 2023 were zero-days

By admin 3 Min Read
Share
SHARE

Google Mandiant security analysts warn of a worrying new trend of threat actors demonstrating a better capability to discover and exploit zero-day vulnerabilities in software.

Specifically, of the 138 vulnerabilities disclosed as actively exploited in 2023, Mandiant says 97 (70.3%) were leveraged as zero-days.

This means that threat actors exploited the flaws in attacks before the impacted vendors knew of the bugs existence or had been able to patch them.

From 2020 until 2022, the ratio between n-days (fixed flaws) and zero-days (no fix available) remained relatively steady at 4:6, but in 2023, the ratio shifted to 3:7.

Google explains that this is not due to a drop in the number of n-days exploited in the wild but rather an increase in zero-day exploitation and the improved ability of security vendors to detect it.

This increased malicious activity and diversification in targeted products is also reflected in the number of vendors impacted by actively exploited flaws, which has increased in 2023 to a record 56, up from 44 in 2022 and higher than the previous record of 48 vendors in 2021.

Overview of Mandiant's findings
<strong>Overview of Mandiant&#8217;s findings</strong>

Response times getting tighter

Another significant trend was recorded regarding the time taken to exploit (TTE) a newly disclosed (n-day or 0-day) flaw, which has now dropped to just five days.

For comparison, in 2018-2019, TTE was 63 days, and in 2021-2022, TTE was 32 days. This gave system administrators plenty of time to plan the application of patches or implement mitigations to secure impacted systems.

However, with the TTE now falling to 5 days, strategies like network segmentation, real-time detection, and urgent patch prioritization become a lot more critical.

On a related note, Google does not see a correlation between the disclosure of exploits and TTE.

In 2023, 75% of exploits were made public before exploitation in the wild had started, and 25% were released after hackers were already leveraging the flaws.

Two examples highlighted in the report to showcase that there’s no consistent relationship between public exploit availability and malicious activity are CVE-2023-28121 (WordPress plugin) and CVE-2023-27997 (Fortinet FortiOS).

Timeline of exploitation for two flaws
<strong>Timeline of exploitation for two flaws</strong><br /><em>Source: Google</em>

In the first case, exploitation started three months after disclosure and ten days after a proof-of-concept was published.

In the FortiOS case, the flaw was weaponized almost immediately in public exploits, but the first malicious exploitation event was recorded four months later.

Difficulty of exploitation, threat actor motivation, target value, and overall attack complexity all play a role in TTE, and a direct or isolated correlation with PoC availability is flawed according to Google.

You Might Also Like

TCS Recognised as One of the World’s Top 50 Brands by Kantar BrandZ; Brand Value Soars 28% YoY to $57.3Bn

Home Depot Promo Codes & Coupons: 50% Off | May 2025

Supporting career development in the biotech space

Top 10 Best Practices for Effective Data Protection

We Hand-Picked the 24 Best Deals From the 2025 REI Anniversary Sale

TAGGED: Actively Exploited, Google, N-day, PoC, Vulnerability, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article Neon EVM Adopts Network Extensions to Redefine Solana’s Product Categories
Next Article UltiHash’s Sustainable Data Infrastructure Tackles AI Storage Challenges
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Rockstar’s Next Move Might Be a GTA 4 Remaster, But a Basic Port Won’t Cut It
Gaming News
TCS Recognised as One of the World’s Top 50 Brands by Kantar BrandZ; Brand Value Soars 28% YoY to $57.3Bn
Tech News
New Zealand man arrested in $265M crypto scam tied to FBI probe
Crypto
Conservatives block Trump’s big tax breaks bill in a stunning setback
Politics
Home Depot Promo Codes & Coupons: 50% Off | May 2025
Tech News
Tony Bellew reveals personal 'heartbreak' over Everton's move from Goodison Park
Sports
For Trump, adulation and no risk of protests made the Gulf a dream trip
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Rockstar’s Next Move Might Be a GTA 4 Remaster, But a Basic Port Won’t Cut It

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Rockstar’s Next Move Might Be a GTA 4 Remaster, But a Basic Port Won’t Cut It
May 17, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?