What is a zero-day attack?
09 April 2021Did you hear about it? That this month four zero-days were found in Microsoft Exchange software? And that there have been several zero-day attacks? Fortunately, Microsoft has now patched these zero-day vulnerabilities in Exchange Server. A zero-day is a leak or exploit that is already being used at the time the manufacturer discovers the vulnerability. It may even be that the zero-day has been in use for some time.
What is a zero-day attack?
A zero-day often appears as a system process, making it unrecognized by antivirus scanners. When a zero-day is used, it is called a zero-day attack. Once a zero-day is discovered by the manufacturer, a security patch is developed. Often this takes some time, during which attacks continue.
Why is a zero-day dangerous?
Because the vulnerability in the software had not yet been discovered by Microsoft, criminals could exploit it. The zero-day is used to gain access to organizations' systems.
By using exploits and administrator credentials, bank details can be altered, sensitive company information accessed, and email addresses misused. A fraudulent email can be sent from a trusted address to all debtors, stating that the account number has changed and payments should be made to the new account. This allows the hacker to make a large profit and harm the organization.
How can a Zero-Day be prevented?
Preventing an attack is very difficult. Always ensure devices and software are updated. Also use a good antivirus and firewall. It is very important that administrator credentials are regularly updated, not widely shared, and the password is secure.