CyberWorldOps — Cybersecurity news, vulnerabilities and CVE intelligence

Wiki Article

Ransomware Operators Are Not Looking for Zero-Days
The image of ransomware as an elite operation using unknown vulnerabilities is comforting,
because it implies nothing could have been done. The evidence says otherwise, and the reality is
less flattering.
The economics point the other way
A zero-day is expensive to acquire, single-use in practice, and burned the moment it is detected.
Against that, a two-year-old flaw in an internet-facing VPN appliance costs nothing, works on
thousands of targets, and needs no research at all. Ransomware is a volume business. Volume businesses do not buy bespoke tooling when a
commodity one converts at the same rate.
What actually gets used
Post-incident reporting consistently lands on the same categories: known vulnerabilities in perimeter
devices — VPN concentrators, file transfer appliances, remote access gateways — with patches
available, sometimes for years. Valid credentials, bought or phished, requiring no vulnerability at all.
And exposed remote desktop services, still. Two of those three are not vulnerabilities in any meaningful sense. They are access.
Why perimeter devices keep appearing
They are internet-facing by design, so reachable by definition. They are frequently outside standard
patch management, because they are appliances rather than servers. They often cannot run an
endpoint agent, so compromise is quiet. And they sit at a trust boundary, which is exactly where an
attacker wants to land. An organisation with disciplined workstation patching and a two-year-old VPN firmware has not
reduced its risk much. It has moved it to the one device where it is least visible.
The subset worth acting on
CISA flags catalogue entries known to be used in ransomware campaigns — several hundred of
them at present. That subset is unusually actionable: these are not vulnerabilities that might be
exploited, they are ones documented in real ransomware intrusions, with patches that exist. CyberWorldOps publishes that subset alongside the rest of the catalogue at https://
cyberworldops.eu/en/cve/kev, with the ransomware-associated entries counted separately.
The uncomfortable conclusion
If ransomware ran on zero-days, defence would be nearly impossible and nobody would be at fault.
It runs mostly on published vulnerabilities with available patches, and on credentials that should not
have worked. That is worse news about the past and known exploited vulnerabilities much better news about the future, because everything on
that list is fixable with work that is already understood.
*Word counts: 640 / 660 / 610 / 590 / 590. All original, none published on cyberworldops.eu.*

Report this wiki page