Hacker News new | ask | show | jobs
by badRNG 1517 days ago
> To me the most interesting leak/investigation that can come out of NSO is what happens once a 0-day is patched, is there downtime? do customers need to wait for a software update? is there automatic rotation of exploits?

I'd have to think NSO Group has the finances to bank at least a few 0-click, zero-days. It seems that the price of such vulnerabilities is increasing however. Zerodium, a large zero-day broker, is paying up to 2.5 million USD for 0-click Android and 2 million USD for iOS: https://zerodium.com/program.html

1 comments

It still boggles my mind that input sanitization/validation hasn't gotten a formal discipline around it.

It's boring and tedious, yet crucial.