Vietnam.vn - Nền tảng quảng bá Việt Nam

Half of exploits for sale on the dark web target unpatched zero-day vulnerabilities

Báo Sài Gòn Giải phóngBáo Sài Gòn Giải phóng11/10/2024


From January 2023 to September 2024, Kaspersky Digital Footprint Intelligence experts discovered 547 ads for buying and selling exploit tools. The ads were posted on various dark web forums and anonymous channels on the Telegram app...

Exploit is a tool that cybercriminals use to exploit software vulnerabilities.
Exploit is a tool that cybercriminals use to exploit software vulnerabilities.

About half of these listings target zero-day and one-day exploits. However, the underground market is rife with scams, so it's difficult to verify whether the tools being sold are actually usable.

Additionally, Kaspersky also recorded the average price of buying and selling exploits for remote attacks as high as $100,000.

Exploit is a tool that cybercriminals use to exploit software vulnerabilities, such as Microsoft software, to perform illegal acts such as unauthorized access or data theft.

More than half of dark web postings (51%) were for sale or purchase of exploits targeting zero-day or one-day vulnerabilities.

Zero-day exploits target vulnerabilities that have not yet been discovered and fixed by the software vendor, while one-day exploits target vulnerabilities that have been discovered and fixed, but the system does not have the patch update installed.

Ảnh màn hình 2024-10-11 lúc 15.44.38.png
Statistics on the number of exploit listings for sale in the period 2023-2024. Source: Kaspersky Digital Footprint Intelligence.

“Cybercriminals can use exploits to steal corporate information or spy on an organization without being detected to achieve their goals,” said Anna Pavlovskaya, senior analyst at Kaspersky Digital Footprint Intelligence. “However, some exploits sold on the dark web may be fake or incomplete, and may not work as advertised. Furthermore, most transactions take place underground. These two factors make it extremely difficult to assess the true size of this market.”

The dark web marketplace offers a wide variety of exploits, the two most common of which are Remote Code Execution (RCE) and Local Privilege Escalation (LPE) tools.

According to an analysis of more than 20 advertisements, the average price of an exploit targeting RCE is around $100,000, while LPE exploits typically cost around $60,000.

Exploits targeting RCE vulnerabilities are considered more dangerous because attackers can take control of part or all of the system or access secure data.

KIM THANH



Source: https://www.sggp.org.vn/mot-nua-cong-cu-exploit-rao-ban-tren-web-den-nham-vao-lo-hong-zero-day-chua-duoc-khac-phuc-post763208.html

Comment (0)

No data
No data
Magical scene on the 'upside down bowl' tea hill in Phu Tho
3 islands in the Central region are likened to Maldives, attracting tourists in the summer
Watch the sparkling Quy Nhon coastal city of Gia Lai at night
Image of terraced fields in Phu Tho, gently sloping, bright and beautiful like mirrors before the planting season
Z121 Factory is ready for the International Fireworks Final Night
Famous travel magazine praises Son Doong cave as 'the most magnificent on the planet'
Mysterious cave attracts Western tourists, likened to 'Phong Nha cave' in Thanh Hoa
Discover the poetic beauty of Vinh Hy Bay
How is the most expensive tea in Hanoi, priced at over 10 million VND/kg, processed?
Taste of the river region

Heritage

Figure

Business

No videos available

News

Political System

Local

Product