What is a zero-day attack?

09 April 2021

Did you hear about it? That this month four zero-days were found in Microsoft Exchange software? And that there have been several zero-day attacks? Fortunately, Microsoft has now patched these zero-day vulnerabilities in Exchange Server. A zero-day is a leak or exploit that is already being used at the time the manufacturer discovers the vulnerability. It may even be that the zero-day has been in use for some time.

What is a zero-day attack?

What is a zero-day attack?

A zero-day often appears as a system process, making it unrecognized by antivirus scanners. When a zero-day is used, it is called a zero-day attack. Once a zero-day is discovered by the manufacturer, a security patch is developed. Often this takes some time, during which attacks continue.

 

Why is a zero-day dangerous?

Because the vulnerability in the software had not yet been discovered by Microsoft, criminals could exploit it. The zero-day is used to gain access to organizations' systems.

By using exploits and administrator credentials, bank details can be altered, sensitive company information accessed, and email addresses misused. A fraudulent email can be sent from a trusted address to all debtors, stating that the account number has changed and payments should be made to the new account. This allows the hacker to make a large profit and harm the organization.

 

How can a Zero-Day be prevented?

Preventing an attack is very difficult. Always ensure devices and software are updated. Also use a good antivirus and firewall. It is very important that administrator credentials are regularly updated, not widely shared, and the password is secure.

Share page: