Security expert: You can’t just run a scanner, slap on a patch, and call it a day. The vast majority of attacks come after the vendor has released the patch. If you’re worried about the risk, it can’t hurt to get a reference from a company that can’t pay for a patch. NSS Labs: More than 100 zero-days were for sale this year alone, with one costing $2.5 million a year. For more information, go to www.security.com/securitywars.”]
Source: https://www.csoonline.com/article/2609441/zero-day-exploits–separating-fact-from-fiction.html