Glossary term

Zero-Day

A vulnerability being exploited before the vendor has a patch available, so defenders have had zero days to prepare. Once a patch exists it is no longer a zero-day.

Browse Attack Techniques →

Related entries

More glossary terms

Command and Control (C2)
The infrastructure an attacker uses to send instructions to compromised hosts and receive data back. Modern C2 blends into normal HTTPS traffic to avo...
CVSS
Common Vulnerability Scoring System. A 0 to 10 severity score built from exploitability and impact metrics, used to prioritise patching alongside cont...
CVE
Common Vulnerabilities and Exposures. A public identifier such as CVE-2021-44228 assigned to a specific vulnerability, giving everyone one unambiguous...
Patch Management
The process of identifying, testing and deploying updates across an estate on a defined schedule, with exceptions tracked rather than silently skipped...
CWE
Common Weakness Enumeration. A catalogue of the underlying defect class, for example CWE-89 for SQL injection, independent of any particular product o...
← Back to glossary

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used