Market for software exploits is often focused on Microsoft flaws, years
Full article639 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Holes in popular software can yield major profits for criminals.
Every month Microsoft releases software updates to fix vulnerabilities across the company’s vast line of technology products.
The ritual, known as Patch Tuesday, often involves security experts urging users to update their software, and researchers gaining some public recognition after months of quietly working to mitigate the flaws.
A new study from antivirus vendor Trend Micro found that cybercriminal forums continue to advertise exploits for a vulnerability years after a patch has been released, though, with sellers adjusting prices to market demand and bundling multiple old exploits together to maximize profits.
The study, which spanned nearly two years and numerous illicit marketplaces, found that nearly half of the software exploits requested on forums were for vulnerabilities that were at least three years old. The demand for exploits is also catered to the popularity of software: Microsoft products accounted for 47% of the exploits that forum users requested, according to Trend Micro.
The data shows that holes in popular software act as cash cows for criminals in instances when corporate, personal or government users don’t update their software. The findings also come amid an apparent shakeup in cybercriminal forums after the ransomware attack that prompted the shutdown of Colonial Pipeline, the main artery for delivering fuel to the East Coast. XSS, one of the more popular Russian-language forums, claimed it would ban ransomware sales after the incident.
While zero-day software flaws, or those unknown to the vendor, can fetch tens of thousands of dollars on the forums, other hacking tools are cheap or even free. On an English-language forum, Trend Micro found JavaScript exploits for $40 and Microsoft Word exploits for $100.
“Patching yesterday’s popular vulnerability can be more important than today’s critical one,” Mayra Rosario Fuentes, senior threat researcher at Trend Micro argued Monday at a presentation at the RSA Conference. She was previewing the research, which Trend Micro will release in July.
While it is unclear if XSS’s supposed ban on ransomware will stick, Trend Micro reported on other market forces that are shaping underground forums. Some vendors rely on their reputation for delivering high-end exploits and only make a handful of sales per year, with the price of an exploit reaching half a million dollars, according to the research. Other exploit sellers count on bargain hunters only willing to cough up $100 here or there.
“Cybercriminals will use the cheapest tool to get the job done,” Rosario Fuentes said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/dark-web-hacking-tools-sale-trend-micro/