Skip to main content
  1. Home
  2. Computing
  3. News

2015 saw more zero-day exploits but it took less time to fix them

Add as a preferred source on Google

Zero-day attacks can be an infuriating quandary for developers. With the right exploit, skilled hackers can find a security hole in a piece of software and use it to hold hostage data from the software’s users. Because it puts developers in a hurry to fix the issue immediately, before threats begin to impact its users, this type of attack is known as a zero-day exploit — as in the developer has zero days to release a patch before things go haywire.

In 2012, there were 14 zero-day exploits out in the wild. By 2013, this increased to 23, and in 2014, there was only one more discovered, making the total 24. After that, unfortunately, and as security firm Symantec points out, the zero-day exploit situation did not improve, nor did it only moderately worsen. Instead, from 2014 to 2015, the number of classified zero-day exploits jumped 225 percent, from an already daunting 24 to a distressing 54.

Recommended Videos

The drastic upturn in last year’s exploits is due in part to the Hacking Team breach, which unleashed six of these zero-day exploits on its own, inspiring Adobe and other developers to accelerate their fixes.

“It is difficult to defend against new and unknown vulnerabilities,” reads Symantec’s yearly Internet Threat Report, “particularly zero-day vulnerabilities for which there may be no patch, and attackers are trying hard to exploit them faster than vendors can roll out patches.”

The report notes that the most popular exploit kit in 2015, Angler, took advantage of these new zero days to conduct over 19.5 million attacks that were, in turn, blocked by Symantec.

Over the last year, the most common victim of zero-day attacks was Adobe Flash, which infamously survived 10 vulnerabilities, comprising 17 percent of the total zero-day attacks in 2015. While this is clearly not something a company should take pride in, that was an improvement over 2014 when Flash’s zero-day exploit count stood at an unfortunate 12. Notably, though, Microsoft also endured 10 zero days in 2015.

On the bright side, however, Adobe has been a serious contributor to the reduction in the amount of time it took developers to issue zero-day patches in 2015. Compared to the average 59 days it took in 2014 and even the four it took in 2013, the average repair time of just one day in 2015 isn’t too shabby.

Meanwhile, the total time of exposure was seven days last year, as opposed to 295 days in 2014 and 19 days in 2013.

So even though we’re now seeing more zero-day attacks than ever, the time it is taking to address them is diminishing rapidly. That could arguably put us in a better place than before.

Gabe Carey
A freelancer for Digital Trends, Gabe Carey has been covering the intersection of video games and technology since he was 16…
Everything Apple announced at its September event: iPhone Duo, iPhone 18 Pro, new Apple Watches, and AirPods 5
Apple packed its biggest September event in years with a foldable iPhone, new watches, and smarter AirPods.
Computer, Electronics, Tablet Computer

The "Surprise and Shine" September launch event was one of Apple's crispest, most elaborate, and most loaded launch events in a while. Instead of leaving the minute details in the spec sheet or fine print, Apple actually included them in its keynote presentation, not just for its big reveal but for all the devices it unveiled on September 9, 2026. 

While the 'Surprise' bit was covered by the new iPhone Duo, 'Shine' probably refers to the new colors in the iPhone 18 Pro lineup. Beyond these, Apple also announced two new Apple Watches and a refresh for the regular AirPods (not the Pro ones). Given that there's a lot of ground to cover, here's everything Apple announced at its September 2026 event. 

Read more
Before You Pay More for DDR5, Think About How Much Memory You Need
The MSI Cubi 5 1MA makes a strong case for looking beyond the newest specs
MSI Cubi 5 1MA compact mini PC with Intel Core processor

There is an easy trap to fall into when buying a new PC. The newer specification usually sounds like the better one, so choosing DDR5 memory over DDR4 can seem like an obvious upgrade. But with memory prices climbing to unusually high levels, it is worth asking whether you will actually benefit from paying more for that extra speed.

For many people buying a PC primarily for work, the answer comes down to how they use it. Everyday tasks such as browsing, email, spreadsheets, presentations, and video calls generally do not need the extremely high memory bandwidth DDR5 offers. Having enough RAM to keep several of those tasks running comfortably can be far more relevant.

Read more
Adobe Acrobat’s latest update could make working with PDFs considerably easier
New Acrobat features make it easier to understand, refine and present information in PDFs
Page, Text, Clapperboard

This post is brought to you in paid partnership with Adobe

PDFs remain one of those unavoidable parts of working life. Reports, research papers, presentations, proposals, financial documents and client material still tend to arrive as PDFs, and the real problem is rarely opening or reading them. It is dealing with everything that comes after: finding the useful information in a lengthy document, understanding it quickly and eventually turning it into something presentable.

Read more