‘Zero-day’ hacks hit record in 2021, Google researchers say


In recent years, hackers have used the ‘zero-day’ attack technique to install advanced spyware on smartphones that was then used to spy on journalists, politicians, human rights activists and others. — Using phone photo created by Dragana_Gordic - www.freepik.com

After a year dominated by high-profile ransomware attacks and supply chain compromises, researchers from Alphabet Inc’s Google have identified another ignominious cyber milepost for 2021: a record number of “zero-day” exploits.

A zero-day exploit is a previously unknown bug which leaves software vendors exactly zero days to secure it. That makes the technology in question particularly valuable to hackers – and a nightmare for cybersecurity professionals.

Hackers exploited a total of 58 zero-day flaws impacting major software providers in 2021, according to a report published Tuesday by Google’s Project Zero, a team of elite bug hunters. That compares to 25 flaws in 2020 and 21 in 2019.

It’s the highest number of zero-days ever recorded by Project Zero since tracking began in 2014. The trend could be due to an improvement in detection from the likes of Microsoft Corp, Apple Inc and Google, who now disclose their findings around zero-day issues, rather than a rise in hacks, Maddie Stone, a security researcher at Project zero, said in a blog post about the findings.

In recent years, hackers have used the attack technique to install advanced spyware on smartphones that was then used to spy on journalists, politicians, human rights activists and others. Suspected Chinese state-sponsored hackers, meanwhile, exploited such flaws last year to compromise Microsoft Exchange servers.

Google’s Stone said there were some surprises among the data. Despite the recent focus on spyware being misused, cybersecurity researchers are still struggling to find zero-days that allow hackers to take control of targets’ phones.

“We know that messaging applications like WhatsApp, Signal, Telegram, etc are targets of interest to attackers and yet there’s only one messaging app, in this case iMessage, zero-day found this past year,” she wrote. The team has uncovered two such flaw since 2014, including an issue in WhatsApp in 2019 and a flaw in iMessage in 2021.

Stone said the “majority of people on the planet” don’t have to fear being at risk of being targeted by a zero-day attack. Still, she said such attacks end up having a broad impact.

“These zero-days tend to have an outsized impact on society so we need to continue doing whatever we can to make it harder for attackers to be successful.” – Bloomberg

Article type: free
User access status:
Subscribe now to our Premium Plan for an ad-free and unlimited reading experience!

Spyware , zero-click attacks , zero-day , malware

   

Next In Tech News

PepsiCo confirms Tesla Semi truck deliveries to start in December
EU crypto rules set to cap dollar-pegged stablecoins
Biden signs order to implement EU-U.S. data privacy framework
National Scam Response Centre – urgently needed to stop millions lost to scams
India's IT hub directs Uber, others to stop three-wheeler services
Budget 2023: NSRC set up to combat rising online scams
Budget 2023: Keluarga Malaysia to enjoy faster Internet speed, cheaper 5G
Budget 2023: Mixed reaction towards lower allocation for esports
Stellantis to halt production at Melfi plant in Italy next week - union
India's RBI to soon commence pilot project of digital rupee

Others Also Read