www.lesswrong.com/posts/gutiw8MBrYDiD2u5z/models-finding-software-vulnerabilitie...
2 corrections found
The lag time between "patch shipped" and "patch reverse engineered and weaponized by a criminal organization" was already so long that most people didn't notice new bugs when they came out.
Patch-to-exploit delays were often short, not generally "so long." Google/Mandiant reported that in 2023, 12% of n-day flaws were exploited within one day, 29% within one week, and over half within one month of patch availability.
Full reasoning
Official threat-intelligence reporting contradicts the idea that the gap between a patch shipping and criminal weaponization was generally very long.
Google/Mandiant's 2024 analysis of vulnerabilities exploited in 2023 says n-day exploitation was most likely to occur within the first month of a patch being available: 12% of n-days were exploited within one day, 29% within one week, and 56% within one month. The same report says the average time-to-exploit in 2023 was five days.
Google/Mandiant had also previously reported that for non-zero-day vulnerabilities there was often only "hours or a few days" between patch release and the first observed attacker exploitation.
Some vulnerabilities do take longer to weaponize, but this sentence states the lag was already broadly so long that people mostly did not notice new bugs when they came out. The available threat-intelligence data shows the opposite trend: many patched vulnerabilities were exploited very quickly after disclosure or patch release.
2 sources
- How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends | Google Cloud Blog
Twelve percent (5) of n-days were exploited within one day, 29% (12) were exploited within one week, and over half (56%) were exploited within one month. ... In 2023, we observed the largest drop in TTE thus far, with an average of just five days.
- Think Fast: Time Between Disclosure, Patch Release and Vulnerability Exploitation — Intelligence for Vulnerability Management, Part Two | Google Cloud Blog
For these non-zero-day vulnerabilities, there was a very small window (often only hours or a few days) between when the patch was released and the first observed instance of attacker exploitation.
It used to be that the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards
Historical botnets did considerably more than DDoS, spam, or simple credential scraping. DOJ records show botnets were already being used to steal banking credentials, execute fraudulent transfers, and distribute ransomware.
Full reasoning
This sentence materially understates what botnet operators were already doing before current AI systems.
Older Justice Department releases describe botnets being used for bank-account takeover and wire fraud, not just DDoS or spam. For example, DOJ said the Bugat/Dridex botnet was used to steal banking credentials and then initiate fraudulent electronic funds transfers of millions of dollars from victims' accounts. DOJ also said Coreflood was used to monitor users' banking sessions and cause fraudulent transfers of funds.
And botnets were also used to spread ransomware well before the current AI wave. DOJ's 2017 Kelihos takedown said the botnet was used for harvesting login credentials, sending spam, and installing ransomware and other malicious software.
So the claim that the "worst thing" botnet operators used to do was DDoS/spam/crypto-or-card scraping is contradicted by official records showing large-scale bank fraud and ransomware distribution.
3 sources
- Bugat Botnet Administrator Arrested and Malware Disabled | United States Department of Justice
A sophisticated malware package designed to steal banking and other credentials from infected computers ... The indictment alleges that Ghinkul and his co-conspirators used the malware to steal banking credentials and then, using the stolen credentials, to initiate fraudulent electronic funds transfers of millions of dollars from the victims’ bank accounts...
- Department of Justice Takes Action to Disable International Botnet | United States Department of Justice
Coreflood allows infected computers to be controlled remotely for the purpose of stealing private personal and financial information ... and using that information to steal funds. ... Coreflood was used to take over an online banking session and caused the fraudulent transfer of funds to a foreign account.
- Justice Department Announces Actions to Dismantle Kelihos Botnet | United States Department of Justice
The Kelihos botnet ... was used to facilitate malicious activities including harvesting login credentials, distributing hundreds of millions of spam e-mails, and installing ransomware and other malicious software.