Skip to main content

2015 saw more zero-day exploits but it took less time to fix them

A pair of hands on a laptop keyboard with two displays.
Image used with permission by copyright holder
Zero-day attacks can be an infuriating quandary for developers. With the right exploit, skilled hackers can find a security hole in a piece of software and use it to hold hostage data from the software’s users. Because it puts developers in a hurry to fix the issue immediately, before threats begin to impact its users, this type of attack is known as a zero-day exploit — as in the developer has zero days to release a patch before things go haywire.

In 2012, there were 14 zero-day exploits out in the wild. By 2013, this increased to 23, and in 2014, there was only one more discovered, making the total 24. After that, unfortunately, and as security firm Symantec points out, the zero-day exploit situation did not improve, nor did it only moderately worsen. Instead, from 2014 to 2015, the number of classified zero-day exploits jumped 225 percent, from an already daunting 24 to a distressing 54.

The drastic upturn in last year’s exploits is due in part to the Hacking Team breach, which unleashed six of these zero-day exploits on its own, inspiring Adobe and other developers to accelerate their fixes.

“It is difficult to defend against new and unknown vulnerabilities,” reads Symantec’s yearly Internet Threat Report, “particularly zero-day vulnerabilities for which there may be no patch, and attackers are trying hard to exploit them faster than vendors can roll out patches.”

The report notes that the most popular exploit kit in 2015, Angler, took advantage of these new zero days to conduct over 19.5 million attacks that were, in turn, blocked by Symantec.

Over the last year, the most common victim of zero-day attacks was Adobe Flash, which infamously survived 10 vulnerabilities, comprising 17 percent of the total zero-day attacks in 2015. While this is clearly not something a company should take pride in, that was an improvement over 2014 when Flash’s zero-day exploit count stood at an unfortunate 12. Notably, though, Microsoft also endured 10 zero days in 2015.

On the bright side, however, Adobe has been a serious contributor to the reduction in the amount of time it took developers to issue zero-day patches in 2015. Compared to the average 59 days it took in 2014 and even the four it took in 2013, the average repair time of just one day in 2015 isn’t too shabby.

Meanwhile, the total time of exposure was seven days last year, as opposed to 295 days in 2014 and 19 days in 2013.

So even though we’re now seeing more zero-day attacks than ever, the time it is taking to address them is diminishing rapidly. That could arguably put us in a better place than before.

Editors' Recommendations

Gabe Carey
Former Digital Trends Contributor
A freelancer for Digital Trends, Gabe Carey has been covering the intersection of video games and technology since he was 16…
Get this Asus laptop with a year of Microsoft Office for $199
asus vivobook go laptop deal amazon march 2024 lifestyle

You don't need to spend several hundreds of dollars on a new laptop that you'll use as a productivity tool because there are budget-friendly options like the Asus Vivobook Go L510MA. It's actually currently even cheaper from Walmart after an $80 discount, which brings its price down to just $199 from $279 originally. There's no telling how much time is remaining before the offer expires though, so if you want to take advantage of it, you're going to have to proceed with the purchase as soon as possible.

Why you should buy the Asus Vivobook Go L510MA
For a laptop that will be able to handle basic activities like doing online research, building reports, and browsing social media, you can't go wrong with the Asus Vivobook Go L510MA. It's equipped with the Intel Pentium Silver N5030 processor and 4GB of RAM, which are a far cry from the specifications of the best laptops, but it will be enough for simple tasks. The device also comes with a 15.6-inch screen with Full HD resolution, which is pretty large and sharp for its price, but it's still portable as it only weights about 3.5 pounds with a thickness of just 0.72 of an inch.

Read more
These are the 10 best gaming PCs I’d recommend to anyone
Graphics card in the CLX Hathor PC.

We review dozens of gaming PCs each year. In 2024, there are a ton of great options, but we've narrowed them down to a list of the 10 best gaming desktops that deserve your hard-earned money.

In 2024, we still recommend the Alienware Aurora R16 because of its fantastic design, solid performance, and decent value. However, there are several other options depending on your needs and budget. If you want a deeper look into how we evaluate gaming PCs, make sure to read about how we review desktops.

Read more
Samsung’s crazy 57-inch curved 4K monitor is $700 off today
The Samsung Odyssey Neo G9 57-inch mini-LED gaming monitor placed on a desk.

Your investment in gaming PC deals will  go to waste if you don't upgrade your screen, and if you're willing to splurge for the best possible gaming experience, you'll want to go for the 57-inch Samsung Odyssey Neo G9 curved gaming monitor. It's pretty expensive at its original price of $2,500, so you're going to want to take advantage of any discounts that are available. Fortunately, Samsung has slashed its price by $700 so it's down to $1,800 -- it's still not cheap, but once you're playing your favorite games on this monitor, you'll quickly understand why it's worth every single penny.

Why you should buy the 57-inch Samsung Odyssey Neo G9 curved gaming monitor
The Samsung Odyssey Neo G9 curved gaming monitor features a 57-inch screen with dual 4K Ultra HD resolution and a 1000R curvature, so it will fully immerse you in the worlds of the video games that you play with its lifelike details and vivid colors. It also supports HDR 1000 for better visual accuracy, and it uses Quantum Matrix technology for controlled brightness and improved contrast.

Read more