Overview
Direct Answer
A zero-day vulnerability is a software security flaw unknown to the vendor and the public, which attackers can exploit before the organisation has released or deployed a patch. The term derives from the vendor having zero days to prepare a defensive response.
How It Works
An attacker discovers and weaponises a previously unknown code defect before the software developer becomes aware of it. This timeline advantage allows malicious actors to conduct attacks against unprotected systems whilst defenders lack both awareness and remediation options. The vulnerability remains exploitable until the vendor identifies the flaw, develops a patch, and users apply it.
Why It Matters
These vulnerabilities pose exceptional risk because organisations cannot rely on patching to mitigate harm during the disclosure lag. Financial institutions, critical infrastructure operators, and government agencies prioritise zero-day detection and response due to the potential for undetected breaches, system compromise, and regulatory violations. The absence of preventative patches elevates incident response costs and operational disruption significantly.
Common Applications
Zero-day exploits have targeted web browsers, operating system kernels, and enterprise software. Financial trading platforms and government networks face particular targeting. Vulnerability brokers and security research firms specialise in identification and disclosure of such flaws before weaponisation occurs.
Key Considerations
Detection and attribution prove difficult since attack signatures do not yet exist. Organisations must balance risk acceptance with investment in behaviour-based detection, threat intelligence, and network segmentation to limit blast radius when exploitation occurs.
More in Cybersecurity
Denial of Service Attack
Offensive SecurityAn attack designed to make a machine or network resource unavailable by overwhelming it with traffic.
Security Orchestration Automation and Response
Defensive SecurityTechnology that automates security operations by orchestrating tools and processes for incident response.
Next-Generation Firewall
Defensive SecurityAn advanced firewall that goes beyond traditional packet filtering to include application awareness and intrusion prevention.
Identity Threat Detection and Response
Identity & AccessSecurity solutions focused on detecting and responding to identity-based attacks such as credential theft, privilege escalation, and compromised service accounts.
Security Operations Centre
Defensive SecurityA centralised facility where security professionals monitor, detect, analyse, and respond to cybersecurity incidents.
AI Security
Offensive SecurityThe discipline of protecting AI systems from adversarial attacks, data poisoning, model theft, and prompt injection while ensuring the secure deployment of AI in production environments.
Security Information and Event Management
Offensive SecurityTechnology that aggregates and analyses security data from across an organisation to detect threats.
Privileged Access Management
Identity & AccessSecurity solutions that control and monitor access for users with elevated permissions to critical systems.