zero-day
A security flaw in software that the creators don't know about yet, meaning there is no official fix available to protect users.
A software vulnerability that is publicly disclosed or actively exploited before the vendor has developed or released a patch, leaving systems defenseless.
A software vulnerability for which no vendor-supplied remediation exists, characterized by the absence of a patch at the time of discovery or exploitation, thereby providing zero days of lead time for mitigation.
evolution
- 1990-01 · historyFirst public usage
The term 'zero-day' began appearing in underground bulletin board systems to describe software exploits released before a vendor could provide a fix.
- 2004-01 · historyMainstream adoption
The term entered the mainstream cybersecurity lexicon as media outlets began reporting on the increasing frequency of zero-day attacks against enterprise software.
- 2010-06 · historyStuxnet discovery
The discovery of Stuxnet, which utilized four distinct zero-day vulnerabilities, marked a turning point in the use of zero-days for state-sponsored cyber warfare.
- 2017-04 · historyEternalBlue leak
The Shadow Brokers leak of the EternalBlue zero-day exploit demonstrated the massive global impact of weaponized vulnerabilities when they fall into the public domain.
seen in events