Zero-Day
/ˈzɪə.roʊ deɪ/ · Noun · Security & Infosec · Origin: 1996
Definitions
Zero-Day (also written as 0-day) is a software vulnerability that is unknown to the vendor or developer and has no available patch, giving defenders zero days of advance warning to protect their systems. Zero-day vulnerabilities are particularly dangerous because they can be exploited before the software maker or security community is even aware they exist. The term also refers to zero-day exploits (code that takes advantage of the vulnerability) and zero-day attacks (actual attacks using the exploit). Zero-day vulnerabilities are highly valued on both sides of cybersecurity: nation-state intelligence agencies and offensive security firms pay hundreds of thousands to millions of dollars for zero-days in widely deployed software like operating systems, browsers, and mobile devices. The market for zero-days includes legitimate bug bounty programs, gray-market brokers like Zerodium, and black-market channels. Notable zero-day attacks include Stuxnet (which used multiple zero-days to damage Iranian nuclear centrifuges) and the 2021 Microsoft Exchange Server vulnerabilities. Once a zero-day is discovered and patched, it becomes an N-day vulnerability.
In plain English: A security hole in software that the makers don't know about yet, so there's no fix available. Attackers who find it first can break in before anyone can stop them.
Example: "The zero-day in Log4j sent half the internet scrambling over a weekend."
Etymology
- 1990s
- Warez scene uses 'zero-day' for software cracked on release day
- ~1996
- Security researchers adopt the term for unpatched vulnerabilities
- 2010
- Stuxnet reveals state-sponsored zero-day stockpiling
- 2021
- Log4Shell makes 'zero-day' a household word
Origin Story
From warez scene slang to cybersecurity's most feared term
In the underground software piracy ('warez') scene of the early 1990s, prestige was measured by speed. A 'zero-day' release meant cracked software available on the same day as its official release — zero days of waiting. It was the ultimate bragging right.
Security researchers in the mid-1990s borrowed the term but shifted its meaning. A zero-day vulnerability meant the software vendor had zero days of advance warning — the flaw was being exploited before anyone knew it existed, leaving zero days to develop a patch.
The term entered mainstream consciousness with high-profile incidents like Stuxnet (2010), which used four zero-days simultaneously to sabotage Iranian nuclear centrifuges. Today, zero-days are traded on a shadowy market where a single vulnerability in a major product can fetch millions of dollars.
Context: Warez/BBS scene, early 1990s
Fun fact: The zero-day exploit market has a tiered pricing structure: an iOS zero-day can fetch $2-5 million, while a WordPress zero-day might go for $5,000.