Google's Threat Intelligence Group found that roughly half of all zero-day exploits it tracked last year targeted vulnerabilities in enterprise technology — a striking shift from prior years when consumer-facing products like browsers and mobile operating systems were the primary zero-day targets. Enterprise technology includes networking equipment, security software, virtual private networks, email servers, and the specific infrastructure products whose deployment most directly connects thousands of organizations to the internet and to each other. Targeting enterprise tech is particularly attractive for sophisticated attackers because a single vulnerability in a widely deployed firewall or VPN product can provide access to thousands of organizations simultaneously. |
The shift toward enterprise targeting reflects a maturation of sophisticated cyber attacker strategy. Consumer products — browsers, operating systems, phone software — have been subject to intense security scrutiny from both vendors and independent researchers for decades, making zero-days increasingly expensive to find and quick to patch once discovered. Enterprise technology has historically received less rigorous security research attention, partly because its complexity and cost make it less accessible to independent security researchers and partly because vendors have been slower to adopt the security development practices whose implementation most directly reduces the vulnerability density that zero-day hunters most commonly exploit. |