Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Apparent Inevitability Of Zero-Day Attacks On Businesses Is Farcical
Articles

The Apparent Inevitability Of Zero-Day Attacks On Businesses Is Farcical

ISBuzz TeamBy ISBuzz TeamApril 28, 20175 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Anyone would think zero-day attacks are unpreventable following a recent claim from one leading cyber-security vendor. FireEye this year claimed to have discovered “29 of the last 53 zero-day attacks”. 24 exploits remained undetected, yet this was still presented as some kind of monumental achievement. Such a statement leaves little comfort for the businesses who found themselves victims, so is it time to just give up completely and let the cyber criminals take over?

It certainly feels that way, even while threats intensify and Locky ransomware rears its ugly head in new forms with renewed malevolence.

Although businesses are finally waking up to the realisation that the big players in anti-virus technology can no longer protect us, many organisations seem to regard extortion via cyber-attack as an inevitable cost of business. There is no need for this defeatism, given the level of protection nowavailable from more innovative vendors using file-regeneration technology.

Zero-day exploits, lest we forget, are unrecognised attacks that come in a form not previously detected, and more often than not are hidden in email attachments until some unfortunate member of staff unwittingly clicks one open, triggering the download of ransomware or a massive theft of data. It is a type of crime that brings criminals serious rewards. One version of the CryptoWall ransomware is reckoned to have generated $325 million in 2015.

Unfortunately evidence is growing that conventional anti-virus defences are simply redundant as hackers and cyber-criminals become more sophisticated. Analysis by threat intelligence experts Virus Bulletin, for instance, shows that between 2015 and 2016, detection of previously unknown threats by many of the big names in anti-virus technology decreased from a midpoint around 80 per cent to between 67-70 per cent. Even detection of known threats fell from between 90 and 95 per cent to about 90 per cent.

But what really shoots the wheels off the anti-virus industry, is the survey’s revelation that some vendors achieved better testing results with their free products than they did with their premium. What do these vendors imagine is the point of paying for a premium service that is less effective than the free?

The Virus Bulletin analysis is no more reassuring about the security solutions specific to email offered by the likes of Kaspersky or Sophos. What appear to be high scores in eradicating spam still leave organisations wide open to zero-day threats, given the huge volumes of emails transmitted by every business on a daily basis. Hackers only need to get lucky once.

Despite this, remarkable claims are made by cyber security companies. Trend Micro has certification for 99.48 per cent protection against zero-days, “compared with a vendor average of 97.77 per cent”.

Mimecast and Symantec both lay claim to 100 per cent effectiveness, while MAfee, asserting that most zero-day threats come from the web, says it can achieve 99.5 per cent effectiveness by adding in-line file and code emulation technology to its web gateway solution.

Whatever the claims, it only takes one attack to devastate an organisation. All these technologies have, for instance, failed to prevent the recurrence of Locky, which is now in a “double-zip” form and often accompanied by the Kovter Trojan which is left behind to run click-fraud and malvertising even after organisations have paid up.

Surely everyone understands that statements about “100 per cent” effectiveness cannot be substantiated and are not borne out by the analysis? Perhaps, but we don’t have to lapse into fatalism about zero-day attacks.

Innovation and new approaches to security are available that will lock out all malware whether zero- day or an adaptation of what has been previously detected. The fact is that email attachments are now the main vector for attacks on businesses for the simple reason that there are billions in circulation every day and they are essential to everyday operations.

Research (from respected cloud services and threat intelligence company Webroot) has for example, demonstrated that 97 per cent of malware is now unique to a specific endpoint. This renders signature-based security virtually useless because such heavily customised malware is extremely difficult to detect.

Instead, file regeneration technology keeps every form of malware at the door. It checks that the common file-types used by criminals to hide their zero-day exploits conform to the manufacturer’s standard, conducting deep inspection of every email attachment down to byte-level. Within fractions of a second a clean, sanitised version of the file is rebuilt, which the organisation can use without any disruption to business operations.

Instead of throwing up their hands in the air or relying on claims of “100 per cent effectiveness” that they know cannot be fulfilled, organisations can use this kind of technology to regain control, setting their own policies and levels of risk in relation the requirements of departments or employees. It is a question of only allowing the known good to enter an organisation and being fully confident that the main source of zero-day threats has been completely blocked. Far more effective than relying on old perimeter anti-virus security or sitting there waiting to pay up and then deal with the appalling consequences after the attack has succeeded.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}