A zero-day is a vulnerability that attackers exploit before the vendor knows about it or before a patch exists. The name comes from the number of days the vendor has had to fix it: zero. Defenders have no signature, no patch, and no warning. The attacker has the advantage until the flaw is discovered and fixed. Zero-days are valuable. Governments and criminal groups pay millions for them. The exploit broker market is real and lucrative.
Zero-days are rare compared to known vulnerabilities. Most breaches use flaws that were patched months or years ago. The patch was available. Nobody applied it. That is why patching matters more than zero-day defense. When a zero-day does appear, the response is urgent. Vendors work around the clock on a fix. Defenders apply mitigations, tighten monitoring, and watch for indicators of compromise. Some zero-days are exploited in targeted attacks against specific victims. Others are used in widespread campaigns. Stuxnet used multiple zero-days to sabotage Iran's nuclear program. That was a nation-state operation with years of development. Most zero-days are less dramatic. They are used quietly, against targets that never know they were hit. The best defense is layered: patching, segmentation, monitoring, and incident response. No single control stops a zero-day. Together they buy time until a patch arrives.
Zero-day facts
- No patch exists at time of exploitation
- Highly valuable on exploit markets
- Rare compared to known vulnerability exploits
- Used in both targeted and widespread attacks
- Mitigations and monitoring are the interim defense
A zero-day is a race. The vendor races to patch. The attacker races to exploit. The defender races to detect.
Comments
No comments yet. Be the first to share a thought.
Leave a comment