🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
Zero-day attack is a cyberattack that exploits a software, firmware, or hardware vulnerability before the vendor knows about it or can release a patch. Attackers use the flaw while no fix, advisory, or detection signature exists, so standard patching and signature-based tools offer no protection during that window.
Zero-day attacks reward whoever learns about a flaw first. A state-sponsored group, a spyware vendor, or a ransomware crew that holds an unpatched exploit reaches systems that are fully up to date, which makes these attacks especially damaging against firewalls, VPN gateways, and other internet-facing systems.
Defenders cannot patch a flaw that nobody has disclosed to the vendor. Zero-day defense therefore relies on limiting what an exploit reaches, detecting what the exploit does after it runs, and patching fast once disclosure starts the clock.
The three terms describe different stages of the same problem: the flaw, the tool that abuses the flaw, and the real-world use of that tool.
A vulnerability exists for months or years before anyone finds it, and an exploit exists in a researcher's lab without ever harming anyone. Only deployment against a live system makes it an attack.
A zero-day attack works by turning an undisclosed flaw into a working exploit and using it before the vendor ships a fix. The full lifecycle runs through these stages:
Publication of a CVE moves the vulnerability into databases such as the National Vulnerability Database (NVD), and the attack stops being a zero-day in the strict sense. Unpatched systems stay exposed after disclosure, and that post-disclosure race causes much of the real-world damage.
Attackers obtain zero-day vulnerabilities by finding flaws through their own research, buying exploits from brokers or vendors, and increasingly using AI to speed discovery.
Google Threat Intelligence Group documented AI-assisted zero-day development in a real criminal campaign in May 2026. A cybercrime group used an AI model to help build a zero-day exploit that bypassed two-factor authentication in a popular open-source web administration tool.
The vendor patched the flaw after Google's alert, before the planned mass exploitation campaign launched.
CloudSEK's analysis of how threat actors discover and exploit vulnerabilities in the wild traces the same path from discovery to mass scanning once exploit code circulates.
Zero-day exploitation has shifted toward enterprise infrastructure, especially security appliances and edge devices, while browser exploitation has fallen. Google Threat Intelligence Group's 2025 Zero-Days in Review reported these findings:

Edge devices draw state-sponsored attackers because they operate at the network boundary, hold privileged access, and rarely run endpoint detection and response (EDR) agents. China-nexus groups such as UNC5221 and UNC3886 focused heavily on security appliances in 2025, a pattern tied to long-term advanced persistent threat access.
In July 2025, attackers exploited CVE-2025-53770 and CVE-2025-53771 in on-premises Microsoft SharePoint servers, a chain known as ToolShell. The flaws bypassed fixes for bugs first demonstrated at the Pwn2Own Berlin contest in May 2025.
Microsoft attributed exploitation to Linen Typhoon, Violet Typhoon, and Storm-2603, a China-based actor that deployed ransomware. Attackers stole ASP.NET machine keys, so Microsoft told customers to rotate those keys after patching, because the stolen keys kept working on patched servers.
In late May 2023, the Cl0p extortion group exploited a SQL injection zero-day, CVE-2023-34362, in Progress Software's MOVEit Transfer file-sharing application. Cl0p stole files from organizations worldwide without deploying encryption.
Cl0p then used the stolen data for extortion, a model tracked in ransomware threat intelligence.
Log4Shell, CVE-2021-44228, was a remote code execution flaw in Apache Log4j 2, a logging library embedded in a vast number of Java applications.
Its exploitation window as a true zero-day was short, but remediation dragged on because many organizations did not know which products contained the library.
Stuxnet used 4 Windows zero-day vulnerabilities to spread through networks and reach industrial control systems at Iranian nuclear facilities. It altered centrifuge speeds while reporting normal readings, which made it one of the first cyberattacks to cause physical damage.
A zero-day attack exploits a flaw before a patch exists, while an N-day attack exploits a flaw after the vendor has disclosed and patched it, targeting systems that remain unpatched.
CISA's Known Exploited Vulnerabilities (KEV) catalog lists flaws with confirmed exploitation and gives US federal agencies deadlines to fix them. Private organizations use the same catalog to decide which N-day patches go first.
Zero-day attacks are difficult to detect because most security tools rely on prior knowledge of a threat, and a zero-day provides none.
To detect zero-day attacks, security teams watch the behavior an exploit causes after it runs, not the exploit itself.
Detection combines runtime monitoring, log correlation, and proactive threat hunting.
EDR watches process behavior and memory on endpoints and servers, and network detection and response (NDR) flags unusual traffic and lateral movement.
A SIEM correlates both with authentication and cloud logs, while sandboxes open suspicious attachments in isolation before they reach users.
Edge appliances need separate coverage because many cannot run EDR agents. Forward their logs to the SIEM, run vendor integrity checking tools where available, and compare running configurations against known-good baselines.
Threat hunting starts from a hypothesis, such as a newly reported exploitation technique against a product the organization runs, and searches existing telemetry for matching behavior.
Hunters map techniques to the MITRE ATT&CK framework and draw hypotheses from threat intelligence on active campaigns, which finds intrusions that never triggered an automated alert.
No control prevents every zero-day attack, but organizations reduce what an exploit reaches before exploitation, contain it during exploitation, and close exposure quickly after disclosure.
Cloud providers patch zero-days in the managed services they operate, and customers of those services do not deploy the fix themselves.
Customers still patch the operating systems, containers, and third-party applications they run on virtual machines, a split defined by the shared responsibility model in cloud security.
A zero-day in a widely used library, build tool, or managed file transfer product reaches every organization that uses it at the same time.
Software bills of materials (SBOMs) show where a vulnerable component runs, which shortens the search that followed Log4Shell and similar software supply chain attacks.
Why is it called a zero-day attack?
The name means the vendor has had zero days to fix the flaw since learning about it, because attackers exploited it before or at the moment of discovery.
Can antivirus stop zero-day attacks?
No, not reliably. Signature-based antivirus needs a known pattern, so zero-day attacks require behavioral detection, EDR, exploit mitigations, and network segmentation.
Do Apple devices get zero-day attacks?
Yes. Google Threat Intelligence Group counted 8 zero-days exploited in the wild in Apple products during 2025.
What is a zero-click exploit?
A zero-click exploit compromises a device without any user action, for example, through a malicious message processed automatically by a messaging app.
How long do vendors take to patch a zero-day?
It varies by vendor. Google Project Zero's disclosure policy gives vendors 90 days for new bugs and 7 days for bugs already exploited in the wild.
Can a zero-day attack start from an email?
Yes. A malicious attachment or message triggers a flaw in the email client, document viewer, or preview component when the file is opened or rendered.
After disclosure, the first practical question for a security team is whether attackers are actively using the flaw, and against which products and industries.
CloudSEK Threat Intelligence tracks actively exploited CVEs, exploitation timelines, and dark web discussion of vulnerabilities, including exploit sale listings and threat actor activity against specific technologies.
That context helps teams decide which patches, virtual patches, and threat hunts go first during the gap between disclosure and full remediation. No intelligence source reveals a flaw that attackers have kept entirely private, so runtime detection and exposure reduction remain the controls for the true zero-day window.
