SIGNAL//DESK
cybersrc: NIST CSRC

zero-day

A security flaw in software that the creators don't know about yet, meaning there is no official fix available to protect users.

A software vulnerability that is publicly disclosed or actively exploited before the vendor has developed or released a patch, leaving systems defenseless.

A software vulnerability for which no vendor-supplied remediation exists, characterized by the absence of a patch at the time of discovery or exploitation, thereby providing zero days of lead time for mitigation.

evolution

  1. 1990-01 · history
    First public usage

    The term 'zero-day' began appearing in underground bulletin board systems to describe software exploits released before a vendor could provide a fix.

  2. 2004-01 · history
    Mainstream adoption

    The term entered the mainstream cybersecurity lexicon as media outlets began reporting on the increasing frequency of zero-day attacks against enterprise software.

  3. 2010-06 · history
    Stuxnet discovery

    The discovery of Stuxnet, which utilized four distinct zero-day vulnerabilities, marked a turning point in the use of zero-days for state-sponsored cyber warfare.

  4. 2017-04 · history
    EternalBlue leak

    The Shadow Brokers leak of the EternalBlue zero-day exploit demonstrated the massive global impact of weaponized vulnerabilities when they fall into the public domain.

seen in events


← all terms