Microsoft: China Flaw Disclosure Law Part of Zero-Day Exploit Surge | SecurityWeek.Com

General News

Summary

The world’s largest software maker is warning that China-based nation state threat actors are taking advantage of a one-year-old law to “stockpile” zero-days for use in sustained malware attacks. According to a new report released Friday by Microsoft, China’s government hacking groups have become “particularly proficient at discovering and developing zero-day exploits” after strict mandates around early vulnerability disclosure went into effect. Microsoft made a direct connection between China’s vulnerability reporting regulation that went into effect September 2021 and a surge in zero-day attacks documented over the last two years. Microsoft documented multiple in-the-wild zero-day attacks linked to China’s state-backed hackers and noted that the time between the availability of security patches and exploitation continues to shrink rapidly. “These examples of newly identified vulnerabilities demonstrate that organizations have on average 60 days from the time a vulnerability is patched and a proof of concept (POC) code is made available online, and often picked up by other actors for reuse,” Microsoft said, pointing to a handful of attacks against software from SolarWinds, Zoho, Confluence and Microsoft’s own Exchange Server product.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
SaaS Cloud Computing Enterprise Software

Linked Companies

Microsoft
$1B+
Disqus
$5M to $10M