Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Zerodium Paying Up to $500K for Mobile Messaging App Vulnerabilities

    Written by

    Sean Michael Kerner
    Published August 24, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Zerodium updated its exploit acquisition payout schedule on Aug.23, adding new targets and prices for zero-day exploits. Among the new targets are mobile messaging apps including WhatsApp, iMessage and Signal, for which Zerodium will pay up to $500,000 for a remote code exploit with local privilege escalation zero-day vulnerability.

      Zerodium is an independent, privately held company that launched in July 2015 and is in the business of acquiring zero-day exploits. The company first achieved global notoriety in September 2015 when it offered a $1 million award for an Apple iOS 9 zero-day. A year later in September 2016, Zerodium increased the iOS zero-day award to $1.5 million, which still remains the top award offered by the company for an exploit.

      The new $500,000 payout for mobile messaging vulnerabilities is being driven by demand from Zerodium’s customers that pay for access to the company’s security vulnerability information.

      “Signal, Telegram and other messaging apps are very popular among legitimate users but also among criminals,” Chaouki Bekrar, founder of Zerodium, told eWEEK. “Our government customers are in need of advanced capabilities and zero-day exploits that would allow them to track and monitor terrorists and criminals relying on these apps.”

      In terms of the large $500,000 bounty that Zerodium is offering for the mobile messaging apps, part of the high cost has to do with the difficulty of finding exploitable vulnerabilities on those platforms.

      “The high value for zero-day exploits affecting such apps comes mostly from the smaller attack surface that is available in these apps, compared to other software such as web browsers or file readers, which makes the discovery and exploitation of critical vulnerabilities in these messaging apps very challenging for security researchers,” Bekrar said.

      Messaging apps aren’t the only new mobile targets on Zerodium’s updated payout list. Zerodium will also pay up to $500,000 for remote code execution with local privilege escalation zero-day vulnerabilities on the default email apps bundled with mobile operating systems.

      In addition to the new mobile targets, Zerodium is adding new targets for servers and desktops. Among the payouts is a $30,000 award for a USB code execution vulnerability. USB vulnerabilities and exploits are not uncommon, though what Zerodium is looking for is somewhat more unique.

      “USB tricks are very common, but these are out of scope of our program as we are mainly looking for USB exploits taking advantage of vulnerabilities in the operating system (Windows and Mac),” Bekrar said. “Eligible attacks would be similar to CVE-2010-2568 as used by Stuxnet and co.”

      The CVE-2010-2568 issue was first patched by Microsoft in October 2010, though the Zero Day Initiative (ZDI) revealed in March 2015 that the patch in fact was not complete. As a result, Microsoft released an updated patch for the expanded vulnerability identified as CVE 2015-0096.

      Unlike other organizations that pay a bug bounty and then disclose vulnerabilities to the impacted vendors, Zerodium follows a commercial disclosure policy and reports all acquired vulnerabilities to its own clients. The Zerodium Zero-Day Research Feed is made available to Zerodium clients and includes security information about vulnerabilities as well as recommendations and protective measures.

      “We cannot disclose the total budget and amounts Zerodium is paying to security researchers to acquire their discoveries,” Bekrar said. “However, we can tell you that we are spending millions of dollars every year and are very proud to help talented researchers around the world make decent revenue with their hard work.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×