Hacker News new | past | comments | ask | show | jobs | submit login

I don’t think the current title “internet explorer 0-day discovered” is correct.

An new way to exploit the zero-day was discovered. But not bug itself.

In late April, two security companies (Qihoo360 and Kaspersky) independently discovered a zero-day for Internet Explorer (CVE-2018-8174), which was used in targeted attacks for espionage purposes. This marks two years since a zero-day has been found (CVE-2016-0189 being the latest one) in the browser that won’t die, despite efforts from Microsoft to move on to the more modern Edge.




As I understand it, it was a 0-day exploit when it was discovered in "late April". (That is, it was exploing a then-unknown bug.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: