| ▲ | cubefox 2 hours ago | |
> A friendly reminder that a 0-day is a vulnerability that wasn't known until after a malicious actor exploited it. No, the full name was always "zero-day exploit". The number 0 refers to the days between the vulnerability being known by the vendor and the public availability of the exploit. So the vendor has zero days to create a security patch before the release of the exploit. The term "zero-day vulnerability" is a derived term to refer to a vulnerability affected by a zero-day exploit. Similarly, a "zero-day attack" is a derived term to refer to an attack carried out using a zero-day exploit. | ||