All the latest UK technology news, reviews and analysis

Zero-day attacks thrive in 2006

by Shaun Nichols

16 Nov 2006

Be the first to comment

  • Tweet this
IT security
Zero-day exploits target undisclosed or recently discovered vulnerabilities

Online attackers are increasingly use zero-day flaws and targeting a wider array of applications, according to the annual Top 20 Security Attack Targets report from the Sans Institute

Zero-day exploits target undisclosed or recently discovered vulnerabilities which have yet to be patched.

The attacks are often not detected by security software, and can be much more effective in compromising systems and installing malware.

Although Microsoft's Internet Explorer is still a favourite target, attackers are increasingly switching to other applications.

The Sans Institute reported a threefold increase in the number of attacks targeting Microsoft Office in 2006.

The organisation spotted 45 vulnerabilities in Office classified as either 'serious' or 'critical', nine of which were also reported as active zero-day exploits.

Excel and PowerPoint experienced sharp increases in the number of reported vulnerabilities.

Sans attributed this in part to the prevalence of Office and the fact that the suite does not have as much security protection as programs such as web browsers.

The report also pointed to a rise in attacks against two emerging technologies: VoIP and web-based applications.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

11%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Support Analyst

IT Support Analyst (initial 6 month fixed term) Cirencester...

Java Developer - Grad / Web / Mobile - Manchester

Java Developer - Graduate / Budding Superstar opportunity...

Solutions Consultant - JEE, PHP, Project Lead - Midlands

Solution Consultant - JEE, Support, Project Lead, SQL...

C++ Developer - Financial Vendor

C++ Developer - C++, STL, Boost, Delphi, Concurrency...

To send to more than one email address, simply separate each address with a comma.