Security firm FireEye has released a new report analyzing eleven zero-day vulnerabilities it discovered over the past year. The company used the same technology to uncover two more zero-day vulnerabilities earlier this year.
“Today’s advanced threats to businesses rely on new and unknown security circumvention techniques,” explains FireEye’s Zheng Bu.
“The old security model for dealing with known threats, which relies on signature-based solutions, is simply incapable of stopping zero-day threats. The number of zero-day attacks analyzed in the paper indicates why organizations must adopt a new approach to security, combining next-generation technology with human expertise.”
FireEye discovered the following vulnerabilities in 2013: CVE-2012-4792, CVE-2013-0422, CVE-2013-0634, CVE-2013-0640, CVE-2013-0641, CVE-2013-1493, CVE-2013-1347, CVE-2013-3893, CVE-2013-5065, CVE-2013-3918 and CVE-2014-0266.
These vulnerabilities were exploited by hackers to carry out attacks against the US Department of Labor and the Council on Foreign Relations, in the LadyBoyle espionage campaign, in the Tobfy ransomware attacks, as well as in the Sunshop, Deputy Dog, and Operation Ephemeral Hydra campaigns.
“Modern cyber threats can easily bypass security mechanisms and can be used to penetrate corporate networks, as well as to intercept extremely valuable data”
The report also highlights that the system-level protections that many organizations have in place are becoming less effective against zero-day attacks. Cybercriminals have begun to find ways to bypass even DEP and ASLR protections.
The full report on zero-day vulnerabilities identified by FireEye in 2013 is available on website . The document also contains some recommendations for organizations on how to protect their networks against cyberattacks based on zero-day vulnerabilities.

