Zero Day — IT Glossary | ITU Online IT Training
+1 855.488.5327 customerservice@ituonline.com Mon – Fri: 9:00am – 5:00pm ET

Zero Day

Commonly used in Cybersecurity

Ready to start learning?Individual Plans →Team Plans →

A zero-day is a security vulnerability in software that is exploited by hackers before the software vendor becomes aware of it and releases a patch to fix the issue. This means the vulnerability is unknown to the vendor and often also to the users, making it especially dangerous.

How It Works

A zero-day vulnerability arises when a flaw or weakness in a software system is discovered by malicious actors before the developers or security community are aware of it. Once identified, hackers can develop exploits that take advantage of the vulnerability to gain unauthorized access, install malware, or cause other security breaches. Because the vendor has not yet issued a fix or patch, there is no immediate way for users to defend against the attack. The term "zero-day" reflects that the vulnerability has been known for zero days, meaning no time has elapsed for the vendor to respond or mitigate the threat.

In many cases, hackers may sell zero-day exploits on underground markets or use them directly in targeted attacks. Once the vulnerability becomes publicly known, the vendor works to develop and release a patch or update to eliminate the threat. Until that patch is available, systems remain vulnerable, and attackers can exploit the flaw repeatedly.

Common Use Cases

  • Hackers exploit zero-day vulnerabilities to breach corporate networks undetected.
  • Cybercriminals use zero-day exploits to distribute malware or ransomware.
  • Nation-state actors employ zero-day vulnerabilities for espionage or sabotage missions.
  • Security researchers discover and report zero-day flaws to vendors for patching before exploitation occurs.
  • Organizations implement intrusion detection systems to monitor for signs of zero-day attack activity.

Why It Matters

Zero-day vulnerabilities are a critical concern for IT professionals, security teams, and organisations because they represent a window of opportunity for attackers to compromise systems before defenses can be updated. Understanding zero-day threats is essential for developing proactive security measures, such as intrusion detection and threat intelligence. For certification candidates and cybersecurity practitioners, knowledge of zero-day exploits is fundamental for assessing risk, managing vulnerabilities, and implementing effective incident response strategies. As cyber threats evolve rapidly, staying informed about zero-day vulnerabilities helps organisations maintain resilience against sophisticated attacks.

Ready to start learning?Individual Plans →Team Plans →
Discover More, Learn More
Understanding the Security Operations Center: A Deep Dive Discover how a Security Operations Center enhances your cybersecurity defenses, improves incident… What Is a Security Operations Center (SOC)? Discover what a security operations center is and how it enhances organizational… Step-by-Step Guide to Implementing a Security Operations Center in Your Organization Discover how to effectively implement a security operations center in your organization… Building a Security Operations Center: A Complete SOC Setup Blueprint Discover how to build a comprehensive Security Operations Center to enhance cybersecurity… Understanding SOC Functions: The Complete Guide to Security Operations Center Operations Discover how SOC functions support security monitoring, threat detection, and incident response… Counterintelligence and Operational Security in Cybersecurity: A Guide for CompTIA SecurityX Certification Discover essential strategies to enhance your cybersecurity skills by understanding counterintelligence and…