North Korea-backed hackers target security researchers with 0-day

ZeroCool@feddit.ch to Technology@lemmy.ml – 36 points –
North Korea-backed hackers target security researchers with 0-day
arstechnica.com
7

You are viewing a single comment

Can someone tell me what 0-day is?

It's a vulnerability that's discovered and exploited before it's known to or addressed by the maker/vendor. So in this case, the North Korean hackers were exploiting an unknown vulnerability in a software package commonly used by security researchers.

Thanks! That's pretty close to what I thought it was. However it looked like it was being referred to as a specific tactic or program. Thanks for clearing it up!

It's a computer vulnerability or exploit which has not been discovered before (or at least the software developer wasn't aware of it).

0-day comes from the number of days the software developers have been informed of the vulnerability. Normally security researchers will tell a company about an exploit and give them some time to fix it before telling the public.