What Is a Zero-Day Attack? Examples, Detection & Defense

A zero-day attack exploits a software flaw before a patch exists. Learn how zero-day attacks work, 2025 exploitation trends, real examples, and defenses.
Published on
Monday, September 21, 2026
Updated on
September 20, 2026

Zero-day attack is a cyberattack that exploits a software, firmware, or hardware vulnerability before the vendor knows about it or can release a patch. Attackers use the flaw while no fix, advisory, or detection signature exists, so standard patching and signature-based tools offer no protection during that window.

Zero-day attacks reward whoever learns about a flaw first. A state-sponsored group, a spyware vendor, or a ransomware crew that holds an unpatched exploit reaches systems that are fully up to date, which makes these attacks especially damaging against firewalls, VPN gateways, and other internet-facing systems.

Defenders cannot patch a flaw that nobody has disclosed to the vendor. Zero-day defense therefore relies on limiting what an exploit reaches, detecting what the exploit does after it runs, and patching fast once disclosure starts the clock.

Zero-Day Vulnerability vs. Zero-Day Exploit vs. Zero-Day Attack

The three terms describe different stages of the same problem: the flaw, the tool that abuses the flaw, and the real-world use of that tool.

  • Zero-day vulnerability: An undisclosed or unpatched security flaw, such as a memory corruption bug in an operating system or an authentication bypass in a VPN appliance. CloudSEK's guide to zero-day vulnerabilities covers the flaw itself in depth.
  • Zero-day exploit: The code or technique that reliably triggers the vulnerability, such as a crafted request that achieves remote code execution.
  • Zero-day attack: The deployment of that exploit against a real target, followed by a payload such as a web shell, spyware, or ransomware.

A vulnerability exists for months or years before anyone finds it, and an exploit exists in a researcher's lab without ever harming anyone. Only deployment against a live system makes it an attack.

How a Zero-Day Attack Works

A zero-day attack works by turning an undisclosed flaw into a working exploit and using it before the vendor ships a fix. The full lifecycle runs through these stages:

  1. Flaw introduction: A developer ships vulnerable code, and the flaw remains unnoticed in production systems.
  2. Discovery: An attacker, exploit broker, or researcher finds the flaw before the vendor does.
  3. Weaponization: The finder builds a reliable exploit, including chains of several flaws that escape a sandbox or gain full control.
  4. Silent exploitation: Attackers use the exploit against selected targets, installing backdoors, stealing credentials, or moving laterally while defenders see nothing unusual.
  5. Vendor awareness: Incident responders, threat researchers, or the vendor's own telemetry detect the activity and report it.
  6. Disclosure and patch: The vendor assigns a CVE, publishes an advisory, and releases a fix or mitigation.
  7. N-day exploitation: Other attackers study the patch, build their own exploits, and target every system that has not yet applied the update.

Publication of a CVE moves the vulnerability into databases such as the National Vulnerability Database (NVD), and the attack stops being a zero-day in the strict sense. Unpatched systems stay exposed after disclosure, and that post-disclosure race causes much of the real-world damage.

Where Attackers Get Zero-Day Vulnerabilities

Attackers obtain zero-day vulnerabilities by finding flaws through their own research, buying exploits from brokers or vendors, and increasingly using AI to speed discovery.

  • Fuzzing: Automated tools send malformed input to software until it crashes in an exploitable way.
  • Reverse engineering and patch diffing: Analysts disassemble binaries, or compare a patched version against the old one, to locate the flawed code.
  • Manual code and logic review: Researchers study authentication flows and business logic, where automated scanners miss design mistakes.
  • AI-assisted discovery: Language models help find logic flaws and write exploit code faster than manual research alone.
  • Commercial exploit markets: Brokers and commercial surveillance vendors buy exploits and sell capabilities to government customers.
  • Criminal forums: Sellers advertise exploits, labeled as zero-days whether or not they are, on underground forums that dark web monitoring programs watch.

Google Threat Intelligence Group documented AI-assisted zero-day development in a real criminal campaign in May 2026. A cybercrime group used an AI model to help build a zero-day exploit that bypassed two-factor authentication in a popular open-source web administration tool.

The vendor patched the flaw after Google's alert, before the planned mass exploitation campaign launched.

CloudSEK's analysis of how threat actors discover and exploit vulnerabilities in the wild traces the same path from discovery to mass scanning once exploit code circulates.

Zero-Day Exploitation Trends and Common Targets

Zero-day exploitation has shifted toward enterprise infrastructure, especially security appliances and edge devices, while browser exploitation has fallen. Google Threat Intelligence Group's 2025 Zero-Days in Review reported these findings:

targets of zero day attack
  • Volume: 90 zero-days were exploited in the wild in 2025, up from 78 in 2024 and below the record of 100 in 2023.
  • Enterprise focus: 43 zero-days, or 48% of the total, targeted enterprise technologies, the highest number and share GTIG has recorded.
  • Operating systems: Desktop and mobile operating systems accounted for 44% of exploited zero-days, up from 40% in 2024.
  • Mobile devices: Mobile zero-days rose from 9 in 2024 to 15 in 2025, and many attacks chained 3 or more flaws.
  • Commercial surveillance vendors: For the first time, these vendors accounted for more attributed zero-day exploitation than traditional state-sponsored espionage groups.
  • Financially motivated actors: 9 zero-days were linked to financially motivated groups, including 2 ransomware operations.

Edge devices draw state-sponsored attackers because they operate at the network boundary, hold privileged access, and rarely run endpoint detection and response (EDR) agents. China-nexus groups such as UNC5221 and UNC3886 focused heavily on security appliances in 2025, a pattern tied to long-term advanced persistent threat access.

Real-World Zero-Day Attack Examples

ToolShell: Microsoft SharePoint Zero-Day Exploitation (2025)

In July 2025, attackers exploited CVE-2025-53770 and CVE-2025-53771 in on-premises Microsoft SharePoint servers, a chain known as ToolShell. The flaws bypassed fixes for bugs first demonstrated at the Pwn2Own Berlin contest in May 2025.

Microsoft attributed exploitation to Linen Typhoon, Violet Typhoon, and Storm-2603, a China-based actor that deployed ransomware. Attackers stole ASP.NET machine keys, so Microsoft told customers to rotate those keys after patching, because the stolen keys kept working on patched servers.

MOVEit Transfer: Cl0p Mass Data Theft (2023)

In late May 2023, the Cl0p extortion group exploited a SQL injection zero-day, CVE-2023-34362, in Progress Software's MOVEit Transfer file-sharing application. Cl0p stole files from organizations worldwide without deploying encryption.

Cl0p then used the stolen data for extortion, a model tracked in ransomware threat intelligence.

Log4Shell: A Zero-Day in a Shared Library (2021)

Log4Shell, CVE-2021-44228, was a remote code execution flaw in Apache Log4j 2, a logging library embedded in a vast number of Java applications.

Its exploitation window as a true zero-day was short, but remediation dragged on because many organizations did not know which products contained the library.

Stuxnet: Zero-Days Used for Physical Sabotage (2010)

Stuxnet used 4 Windows zero-day vulnerabilities to spread through networks and reach industrial control systems at Iranian nuclear facilities. It altered centrifuge speeds while reporting normal readings, which made it one of the first cyberattacks to cause physical damage.

Zero-Day vs. N-Day Attacks

A zero-day attack exploits a flaw before a patch exists, while an N-day attack exploits a flaw after the vendor has disclosed and patched it, targeting systems that remain unpatched.

Attribute Zero-Day Attack N-Day Attack
Public awareness Flaw is undisclosed or known only to attackers Flaw is published with a CVE and vendor advisory
Patch availability No patch exists at the time of exploitation A patch or mitigation exists but is not applied
Typical attackers State-sponsored groups, spyware vendors, well-funded criminal groups Broad criminal activity, including automated mass scanning
Detection options Behavioral detection, anomaly analysis, and threat hunting Signatures, vulnerability scanners, and published indicators
Primary defense Exposure reduction, segmentation, and runtime detection Fast patching, virtual patching, and asset inventory

CISA's Known Exploited Vulnerabilities (KEV) catalog lists flaws with confirmed exploitation and gives US federal agencies deadlines to fix them. Private organizations use the same catalog to decide which N-day patches go first.

Why Are Zero-Day Attacks Difficult to Detect?

Zero-day attacks are difficult to detect because most security tools rely on prior knowledge of a threat, and a zero-day provides none.

  • No signature: Antivirus and intrusion prevention rules have nothing to match against a new exploit.
  • No CVE: Vulnerability scanners cannot flag a flaw that no database lists.
  • No patch to verify: Patch compliance reports show fully updated systems as safe.
  • Trusted processes: Exploits run inside legitimate services, such as a web server or VPN daemon, so activity looks like normal operation.
  • Blind spots on appliances: Firewalls and VPN gateways rarely support EDR agents, leaving little telemetry for investigators.

How to Detect Zero-Day Attacks

To detect zero-day attacks, security teams watch the behavior an exploit causes after it runs, not the exploit itself.

Detection combines runtime monitoring, log correlation, and proactive threat hunting.

Zero-Day Behavioral Indicators to Monitor

  • Web servers, mail servers, or VPN services spawning command shells or scripting engines.
  • New files written to web directories, a common sign of web shells.
  • Memory-only code execution and unexpected process injection.
  • Privilege escalation from a service account to administrator or SYSTEM.
  • Outbound connections from servers to unfamiliar domains or IP addresses.
  • Configuration changes, new accounts, or modified binaries on edge appliances.

Zero-Day Detection Layers

EDR watches process behavior and memory on endpoints and servers, and network detection and response (NDR) flags unusual traffic and lateral movement.

A SIEM correlates both with authentication and cloud logs, while sandboxes open suspicious attachments in isolation before they reach users.

Edge appliances need separate coverage because many cannot run EDR agents. Forward their logs to the SIEM, run vendor integrity checking tools where available, and compare running configurations against known-good baselines.

Threat Hunting for Zero-Day Activity

Threat hunting starts from a hypothesis, such as a newly reported exploitation technique against a product the organization runs, and searches existing telemetry for matching behavior.

Hunters map techniques to the MITRE ATT&CK framework and draw hypotheses from threat intelligence on active campaigns, which finds intrusions that never triggered an automated alert.

Zero-Day Attack Prevention and Mitigation

No control prevents every zero-day attack, but organizations reduce what an exploit reaches before exploitation, contain it during exploitation, and close exposure quickly after disclosure.

Zero-Day Controls Before Exploitation

  • Inventory every internet-facing asset with external attack surface management, and remove management interfaces from public exposure.
  • Segment networks so a compromised appliance or server cannot reach critical systems directly.
  • Enforce least privilege and a zero trust access model for users, services, and administrators.
  • Enable exploit mitigations such as address space layout randomization, control-flow protections, and application allowlisting.
  • Isolate high-risk activity, such as web browsing and attachment opening, in sandboxes or remote browser isolation.
  • Keep immutable, offline backups for systems that ransomware operators target.

Zero-Day Controls During Exploitation

  • Deploy EDR and NDR with automated isolation for hosts that show exploit behavior.
  • Apply virtual patches through web application firewalls or intrusion prevention rules once exploitation details emerge.
  • Disable or restrict the affected feature when a vendor publishes a mitigation before a full patch.
  • Collect forensic evidence from affected appliances before rebooting or reimaging them.

Zero-Day Controls After Disclosure

  • Patch affected systems on an emergency timeline, prioritizing internet-facing assets and flaws listed in the KEV catalog.
  • Rotate keys, certificates, and credentials that the exploit exposed, because patching does not revoke stolen secrets.
  • Hunt for web shells, new accounts, and persistence mechanisms created before the patch.
  • Validate remediation by rescanning exposed assets and confirming the vulnerable version no longer runs.

Zero-Day Attacks in Cloud Services and Software Supply Chains

Zero-Day Risk in Cloud Environments

Cloud providers patch zero-days in the managed services they operate, and customers of those services do not deploy the fix themselves.

Customers still patch the operating systems, containers, and third-party applications they run on virtual machines, a split defined by the shared responsibility model in cloud security.

Zero-Day Risk in the Software Supply Chain

A zero-day in a widely used library, build tool, or managed file transfer product reaches every organization that uses it at the same time.

Software bills of materials (SBOMs) show where a vulnerable component runs, which shortens the search that followed Log4Shell and similar software supply chain attacks.

Zero-Day Attack FAQs

Why is it called a zero-day attack?

The name means the vendor has had zero days to fix the flaw since learning about it, because attackers exploited it before or at the moment of discovery.

Can antivirus stop zero-day attacks?

No, not reliably. Signature-based antivirus needs a known pattern, so zero-day attacks require behavioral detection, EDR, exploit mitigations, and network segmentation.

Do Apple devices get zero-day attacks?

Yes. Google Threat Intelligence Group counted 8 zero-days exploited in the wild in Apple products during 2025.

What is a zero-click exploit?

A zero-click exploit compromises a device without any user action, for example, through a malicious message processed automatically by a messaging app.

How long do vendors take to patch a zero-day?

It varies by vendor. Google Project Zero's disclosure policy gives vendors 90 days for new bugs and 7 days for bugs already exploited in the wild.

Can a zero-day attack start from an email?

Yes. A malicious attachment or message triggers a flaw in the email client, document viewer, or preview component when the file is opened or rendered.

Zero-Day Exploitation Intelligence With CloudSEK Threat Intelligence

After disclosure, the first practical question for a security team is whether attackers are actively using the flaw, and against which products and industries.

CloudSEK Threat Intelligence tracks actively exploited CVEs, exploitation timelines, and dark web discussion of vulnerabilities, including exploit sale listings and threat actor activity against specific technologies.

That context helps teams decide which patches, virtual patches, and threat hunts go first during the gap between disclosure and full remediation. No intelligence source reveals a flaw that attackers have kept entirely private, so runtime detection and exposure reduction remain the controls for the true zero-day window.

Related Posts
What is Malware Sandboxing? How It Works and Its Limits
Malware sandboxing runs suspicious files in an isolated environment to observe their behavior safely. How malware sandboxing works, its types, and evasion.
What is Google Dorking? Operators, Risks, and Defense
Google dorking uses advanced search operators to find sensitive data exposed on the web. How it works, what it exposes, and how to defend against it.
6 Best Digital Risk Protection (DRP) Platforms in 2026
CloudSEK XVigil, Recorded Future, ZeroFox, Rapid7, Group-IB, and Flare cover key DRP needs across external risk, takedown, SOC workflows, scams, and illicit monitoring.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.