Site navigation

Report: Half of Dark Web Posts Exploit Zero-Day Vulnerabilities

Tom Quinn

,

Kaspersky dark web report
More than half of dark web posts for buying and selling exploits involve zero-day or one-day vulnerabilities, with attackers able to buy and sell ever more sophisticated cyber-attack tools online.

A new report from Kaspersky has found that more than half of dark web posts related to the buying and selling of exploits involve zero-day or one-day vulnerabilities. 

Between January 2023 and September 2024, the cybersecurity firm uncovered 547 listings found on dark web forums and shadow Telegram channels, frequently involving zero-day and one-day vulnerabilities which target either undiscovered software vulnerabilities, or those lacking the necessary patches.

According to Kaspersky’s findings, more than half of the posts (51%) involved these zero-day or one-day vulnerabilities, and are primarily being used by cybercriminals to gain unauthorised access to systems and steal sensitive data. 

The report claims that the average cost of remote code execution (RCE) vulnerabilities to businesses was around $100,000 (£76,365). RCE vulnerabilities are particularly dangerous, as they allow attackers to take control of a system remotely, and can lead to a full-scale attack that would compromise an entire web application or server.

According to Kaspersky, the dark web market for exploits showed fluctuations in activity throughout 2023 and 2024, the highest level of activity occurring in May 2024, with 50 exploit-related posts compared to an average of 26 posts per month before and after the spike.

Kaspersky said that one of the most expensive exploits listed during that time was for a Microsoft Outlook zero-day vulnerability, reportedly priced at nearly $2 million (£1.5 million). 

Alongside RCE vulnerabilities, local privilege escalation (LPE) vulnerabilities are among the most common. LPE exploits are a type of security threat that allows attackers to gain elevated privileges on a system, leaving organisations open to data theft, system damage, and the persistent access of malicious actors on their network.

Although LPE vulnerabilities allow attackers to gain higher privileges within a system, RCE vulnerabilities are considered more severe as they enable full remote control of targeted systems.


Recommended reading


“Exploits can target any program, but the most desirable and expensive ones often focus on enterprise-level software,” said Anna Pavlovskaya, senior analyst at Kaspersky Digital Footprint Intelligence.

“These tools enable cybercriminals to carry out attacks, which equate to substantial gains for them, such as stealing corporate information or spying on an organisation undetected. Overall, the exploit market remains stable; while activity fluctuates, the threat is always present. This highlights the need for cybersecurity hygiene practices, such as the regular patching and monitoring of digital assets on the dark web”.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data