The cyber-arms market refers to the trade of software vulnerabilities, exploits, and hacking tools. In recent years, companies such as Zerodium and NSO Group have emerged to operate in the legal segment of this market. These firms acquire exploits both through in-house research and by offering public bounty programs, where they publish price lists detailing substantial payouts, ranging from tens of thousands to millions of dollars, for previously unknown vulnerabilities that meet specific criteria (for example, $1 million for a verified iOS remote code execution exploit)