Skip to main content
  1. Home
  2. Computing
  3. News

2015 saw more zero-day exploits but it took less time to fix them

Add as a preferred source on Google

Zero-day attacks can be an infuriating quandary for developers. With the right exploit, skilled hackers can find a security hole in a piece of software and use it to hold hostage data from the software’s users. Because it puts developers in a hurry to fix the issue immediately, before threats begin to impact its users, this type of attack is known as a zero-day exploit — as in the developer has zero days to release a patch before things go haywire.

In 2012, there were 14 zero-day exploits out in the wild. By 2013, this increased to 23, and in 2014, there was only one more discovered, making the total 24. After that, unfortunately, and as security firm Symantec points out, the zero-day exploit situation did not improve, nor did it only moderately worsen. Instead, from 2014 to 2015, the number of classified zero-day exploits jumped 225 percent, from an already daunting 24 to a distressing 54.

Recommended Videos

The drastic upturn in last year’s exploits is due in part to the Hacking Team breach, which unleashed six of these zero-day exploits on its own, inspiring Adobe and other developers to accelerate their fixes.

“It is difficult to defend against new and unknown vulnerabilities,” reads Symantec’s yearly Internet Threat Report, “particularly zero-day vulnerabilities for which there may be no patch, and attackers are trying hard to exploit them faster than vendors can roll out patches.”

The report notes that the most popular exploit kit in 2015, Angler, took advantage of these new zero days to conduct over 19.5 million attacks that were, in turn, blocked by Symantec.

Over the last year, the most common victim of zero-day attacks was Adobe Flash, which infamously survived 10 vulnerabilities, comprising 17 percent of the total zero-day attacks in 2015. While this is clearly not something a company should take pride in, that was an improvement over 2014 when Flash’s zero-day exploit count stood at an unfortunate 12. Notably, though, Microsoft also endured 10 zero days in 2015.

On the bright side, however, Adobe has been a serious contributor to the reduction in the amount of time it took developers to issue zero-day patches in 2015. Compared to the average 59 days it took in 2014 and even the four it took in 2013, the average repair time of just one day in 2015 isn’t too shabby.

Meanwhile, the total time of exposure was seven days last year, as opposed to 295 days in 2014 and 19 days in 2013.

So even though we’re now seeing more zero-day attacks than ever, the time it is taking to address them is diminishing rapidly. That could arguably put us in a better place than before.

Gabe Carey
A freelancer for Digital Trends, Gabe Carey has been covering the intersection of video games and technology since he was 16…
Acer’s Swift Air 14 is a peppy MacBook Neo rival with some cool upgrades and a $699 ask
Computer, Electronics, Laptop

The race to build the next great affordable laptop is heating up, and Acer thinks it has a strong contender. The company today unveiled the Swift Air 14, a thin-and-light Windows laptop that combines a premium design, AI-ready hardware, and impressive battery claims for a starting price of just $699.

At a time when even mainstream laptops are creeping toward four-figure price tags, Acer’s latest machine feels refreshingly straightforward. It’s aimed at students, remote workers, and anyone who wants a laptop that looks and feels expensive without draining their bank account. The Swift Air 14 is powered by Intel’s new Core Series 3 processors and delivers up to 19 hours of battery life. That’s the sort of endurance that could realistically get many users through a full workday and beyond without scrambling for a charger.

Read more
Google Drive can now batch-scan your documents and spare you a few other frustrations, too
The automated scanning experience runs entirely on your device, without sending anything to Google’s servers.
Electronics, Phone, Mobile Phone

Scanning documents from a phone has always been a frustrating experience, especially on Android smartphones. You’ve to scan one page at a time, blurry captures you don't notice until after, or accidentally hovering over the same page twice; all these issues bother users on a day-to-day basis. 

Well, Google Drive's new document scanner redesign fixes all three problems at once. Announced by Sameer Samat, the President of Android Ecosystem at Google, the feature is now rolling out for Android users.

Read more
Microsoft wants Copilot to answer all your health-related questions and store your medical records
Copilot Health is Microsoft's most personal AI feature yet. It is built with 250 physicians, and explicitly designed not to replace your doctor.
Page, Text, Business Card

Copilot Health is now in preview, and Microsoft’s ambition for it is clear, an AI assistant that knows your health history, understands your fitness data, and can help you make sense of your medical records, all in one place. 

Copilot Health is a dedicated space within the Copilot chatbot at copilot.microsoft.com/health where you can get answers to your health-related questions. 

Read more