Zero-day vulns are increasingly likely to be bought and sold by malware vendors targeting the Middle East with their dodgy wares, according to FireEye. "While not every instance of zero-day exploitation can be attributed to a tracked group, we noted that a wider range of tracked actors appear to have gained access to these …

  1. amanfromMars 1 Silver badge

    IT's not Rocket Science ...... Courtesy of Mr Dillinger

    Kaspersky also recently found an uptick in malicious activity targeting the Middle East as a whole, something that appears to be a rising trend from threat intel companies' findings.

    No shit, Sherlock/Shylock/Kaspersky. Is that where real wealth and lots of hot money is found for extensive spending?

  2. Sorry that handle is already taken. Silver badge

    A zero-day is a software vulnerability that has zero days between the time it is discovered and the time that someone is found to be using it for criminal purposes
    I understood that they're so named because they're already being exploited on "day zero" of (i.e. before) patch availability.

    1. big_D Silver badge

      Yes, Zero Day effectively means that the flaw exists and is being actively exploited (or is in the public domain, having been irresponsibly disclosed) and no patch has yet been forthcoming (often because the maintainers of the software found out about it at the same time as everybody else.

  3. sanmigueelbeer Silver badge

    DarkHotel (APT-C-06) Attacked Chinese Institutions Abroad via Exploiting SangFor VPN Vulnerability

    DarkHotel was the same group that hacked (or attempted to) the World Health Organization for information about COVID-19.

    Someone is very, very desperate.

