Zero-Day

/ˈzɪə.roʊ deɪ/ · Noun · Security & Infosec · Origin: 1996

Definitions

  1. Zero-Day (also written as 0-day) is a software vulnerability that is unknown to the vendor or developer and has no available patch, giving defenders zero days of advance warning to protect their systems. Zero-day vulnerabilities are particularly dangerous because they can be exploited before the software maker or security community is even aware they exist. The term also refers to zero-day exploits (code that takes advantage of the vulnerability) and zero-day attacks (actual attacks using the exploit). Zero-day vulnerabilities are highly valued on both sides of cybersecurity: nation-state intelligence agencies and offensive security firms pay hundreds of thousands to millions of dollars for zero-days in widely deployed software like operating systems, browsers, and mobile devices. The market for zero-days includes legitimate bug bounty programs, gray-market brokers like Zerodium, and black-market channels. Notable zero-day attacks include Stuxnet (which used multiple zero-days to damage Iranian nuclear centrifuges) and the 2021 Microsoft Exchange Server vulnerabilities. Once a zero-day is discovered and patched, it becomes an N-day vulnerability.

    In plain English: A security hole in software that the makers don't know about yet, so there's no fix available. Attackers who find it first can break in before anyone can stop them.

    Example: "The zero-day in Log4j sent half the internet scrambling over a weekend."

Etymology

1990s
Warez scene uses 'zero-day' for software cracked on release day
~1996
Security researchers adopt the term for unpatched vulnerabilities
2010
Stuxnet reveals state-sponsored zero-day stockpiling
2021
Log4Shell makes 'zero-day' a household word

Origin Story

From warez scene slang to cybersecurity's most feared term

In the underground software piracy ('warez') scene of the early 1990s, prestige was measured by speed. A 'zero-day' release meant cracked software available on the same day as its official release — zero days of waiting. It was the ultimate bragging right.

Security researchers in the mid-1990s borrowed the term but shifted its meaning. A zero-day vulnerability meant the software vendor had zero days of advance warning — the flaw was being exploited before anyone knew it existed, leaving zero days to develop a patch.

The term entered mainstream consciousness with high-profile incidents like Stuxnet (2010), which used four zero-days simultaneously to sabotage Iranian nuclear centrifuges. Today, zero-days are traded on a shadowy market where a single vulnerability in a major product can fetch millions of dollars.

Context: Warez/BBS scene, early 1990s

Fun fact: The zero-day exploit market has a tiered pricing structure: an iOS zero-day can fetch $2-5 million, while a WordPress zero-day might go for $5,000.

Related Terms