Full Report
The average time it takes attackers to weaponize a vulnerability, either before or after a patch is released, shrank from 63 days in 2018-2019 to just five days last year
Analysis Summary
This article focuses on a general trend regarding the speed of zero-day exploitation rather than detailing the activities of a specific, named threat actor. Therefore, most sections will reflect this general observation or will be marked as "Not specified."
# Threat Actor: General Threat Actors Exploiting Zero-Days
## Attribution & Identity
**Actor identification, aliases, known associations:** The article discusses threat actors generally, noting they are rapidly improving at spotting and weaponizing software vulnerabilities. No specific named group or attribution is provided.
## Activity Summary
**Recent campaigns and operations described in the article:**
* Threat actors are leveraging software vulnerabilities immediately upon disclosure or prior to patches being released.
* In 2023, 97 out of 138 actively exploited vulnerabilities disclosed in the wild were zero-days.
* The average time taken to weaponize a vulnerability drastically shrank from 63 days (2018-2019) to just five days in the previous year (implied 2023).
## Tactics, Techniques & Procedures
- Exploiting disclosed vulnerabilities as **zero-days** (abused before patches are released).
- Exploiting disclosed vulnerabilities as **n-days** (vulnerabilities first exploited after patches are made available).
- Rapid weaponization of newly discovered flaws.
- **MITRE ATT&CK IDs:** Not specified.
## Targeting
- **Sectors:** Threat poses an escalating threat to businesses and individuals alike (General targeting).
- **Geography:** Not specified.
- **Victims:** Not specified.
## Tools & Infrastructure
- **Malware families used:** Not specified.
- **Infrastructure (C2, domains, IPs - defang URLs):** Not specified.
## Implications
The accelerating speed at which threat actors identify, exploit, and weaponize vulnerabilities (down to five days) signifies an escalating risk landscape, particularly for organizations relying on timely patching cycles. The high volume of zero-day exploitation indicates sophisticated rapid response capabilities among threat groups.
## Mitigations
- Focus on rapid vulnerability management to close the window between patch release and deployment.
- Defense against zero-day exploitation (e.g., robust endpoint detection, behavior analysis, and network segmentation).