
A newly released RAND Corp. study found that zero-day vulnerabilities have an average life expectancy (time between first private discovery and public disclosure) of 6.9 years, making it a reasonable option to stockpile vulnerabilities for cyber defenders and attackers.The study, “Zero Days, Thousands of Nights: The Life and Times of Zero-Day Vulnerabilities and Their Exploits,” was based on access to a dataset of over 200 zero-day software vulnerabilities. Zero-days are software vulnerabilities unknown to the vendor and can be used…