Key Takeaways
A zero-day exploit targets a software flaw the vendor has not patched, giving defenders no advance warning before attackers strike.
Zero-day exploits don’t only surface on desktop applications. They also surface across browsers, operating systems, network appliances, mobile devices, and software supply chains.
Group-IB combines Threat Intelligence, Managed XDR, and a Malware Detonation Platform to detect zero-day activity before a CVE or signature exists. 

What is a Zero Day Exploit?

 

What Is a Zero-Day Exploit?

A zero-day exploit is a cyber-attack method that targets a security flaw that has not been publicly documented or patched yet.  Vendors have zero days to prepare a fix, while attackers already have working code that can breach vulnerable systems, hardware, or firmware.

If threat actors weaponize the flaw before software developers can release a patch, the incident is labeled a zero-day attack. Traditional signature-based tools rarely detect it in time because defenders don’t know the weakness.

Zero-day software vulnerabilities can surface almost anywhere in the technology stack, taking the shape of:

  • Weak input handling. SQL injection, buffer overflows, or type-confusion bugs.
  • Missing controls. Absent sensitive data encryption, insufficient authentication, or broken access logic.
  • Faulty implementations. Flawed cryptographic algorithms, insecure URL redirects, or logic errors that bypass password checks.

The Zero-Day Lifecycle

The zero-day lifecycle is the sequence of stages a vulnerability moves through, from when it first appears in code to when attackers weaponize it at scale. A zero-day vulnerability can remain unpatched in software or firmware for days, months, or even years before anyone discovers it. 

In the best-case scenario, security researchers or the vendor’s engineers stumble upon the flaw first, giving them time to create and distribute a fix. Unfortunately, attackers sometimes discover and weaponize the weakness before defenders do.

The following table outlines phases 1 through 6, from initial dormancy to detection.

Phase What happens Typical duration (industry data) Key notes
1. Dormancy A flaw exists in code or firmware but no one knows about it. Months → years (no reliable median) Bugs often lurk in legacy modules or obscure logic until a crash, fuzz test, or code review exposes them.
2. Discovery A researcher, vendor, or attacker stumbles on the flaw. 0 days (instant) → indefinite If a threat actor is first, the bug usually goes straight to a private broker or an in-house toolkit.
3. Weaponization A proof-of-concept becomes a working exploit; the payload is wrapped into kits or macro droppers. Days to disclosure, sometimes before a patch exists. The exploitation window keeps shrinking. Attackers increasingly weaponize a vulnerability within days of disclosure and, in some campaigns, before any patch exists. Group-IB’s Ransomware in 2026: Same Business, New Rules research this pattern in the CL0P group, which builds or acquires zero-day exploits and hits widely deployed platforms, exfiltrating data from an entire customer base before extortion begins. 
4. Initial attacks Quiet, low-volume testing against select targets. Hours → a few days APTs and red-teamers validate reliability before burning the bug at scale.
5. Detection & triangulation SOCs detect crashes, anomalous telemetry, or dark-web chatter; analysts reverse-engineer payloads. 1 – 7 days (maturity-dependent) Group-IB Managed XDR teams often flag zero-day artifacts within the first week, thanks to cross-endpoint and network telemetry correlation.
6. Private disclosure Researcher or CERT notifies the vendor under embargo. Same day for critical infrastructure Coordinated disclosure buys vendors time to code while keeping exploit code out of public repos.

The table below continues with phases 7 through 12, covering disclosure through commoditization.

Phase What happens Typical duration (industry data) Key notes
7. Patch development & QA Vendor codes, signs, and regression tests a fix (or mitigation). Varies by vendor and severity Turnaround depends heavily on the vendor’s release process and the flaw’s severity. Regardless of speed, the exploitation window now often closes before this step even begins, as attackers exploit flaws before patches ship (see phase 3).
8. Patch release CVE issued; bulletin and binaries shipped. Immediate Attackers diff the new binary against the old one within hours to locate the fixed routine.
9. Mass-exploitation window Attackers weaponize patch diff and scan the internet for laggards. Within days of disclosure, sometimes before Attackers move quickly once a patch diff or proof-of-concept becomes public, scanning the internet for anyone still exposed. The European Union Agency for Cybersecurity (ENISA) found in its Threat Landscape 2025 report that vulnerability exploitation now drives 21.3 percent of all intrusions, with attackers weaponizing newly disclosed flaws within days, sometimes before defenders have any chance to respond.
10. Patch deployment/remediation Organizations roll out updates, isolate compromised hosts, and rotate secrets. Hours → weeks Delay depends on asset inventory accuracy and change-management culture.
11. Public PoC saturation Exploit code and off-the-shelf exploitation frameworks flood GitHub, and scanners add checks. Weeks → months The flaw graduates from zero-day to well-known n-day status, though it stays lethal on unmaintained systems.
12. Commoditization Exploit code is bundled into crimeware kits (e.g., BlackHole) and used in drive-by campaigns. Months, sometimes < 30 days Group-IB’s investigation into the BlackHole case found it accounted for 40% of infections once the author packaged multiple n-day exploits together.

How Does a Zero-Day Exploit Work?

A zero-day exploit works when the threat actor takes a hidden flaw, an overlooked error in software, firmware, or hardware, and turns it into code a threat actor can run against a target. 

Once a threat actor confirms the flaw is exploitable, they quickly build a working proof of concept and package it into a delivery method, such as a phishing attachment, a malicious file, or a crafted network request. 

Attackers usually run small, targeted tests with the exploit code to confirm it can bypass defenses without triggering alarms before escalating their campaigns.

Types of Zero-Day Exploits

Zero-day exploits are not limited to one category of software. Attackers pursue whatever product category offers the most reliable access or the widest reach, from the browser on an employee’s laptop to the network appliances sitting at the edge of a corporate network. 

The five categories below show where zero-day exploitation is concentrated today.

Browsers and web application exploits

Browser and web application exploits exploit weaknesses in the software people use to go online, allowing attackers to run harmful code as soon as someone visits a malicious or hacked page.

Browsers used to be one of the most exploited zero-day categories, but that share has dropped in recent years. Attackers have increasingly shifted focus toward enterprise software and edge technologies, which now offer a wider and more reliable attack surface. 

Some of this decline may be optical rather than real, since improved attacker operational security can mask browser activity that still goes undetected. Vendor hardening is one likely reason, though improved attacker operational security may also be masking some activity. 

Operating system exploits

Operating system exploits target flaws in the core software that runs a device, giving attackers the deepest level of access once they succeed.

Enterprise and edge technologies, not consumer browsers, are now the primary zero-day battleground. Group-IB’s Ransomware in 2026: Same Business, New Rules analysis found that the most active ransomware groups now break in through known vulnerabilities in internet-facing devices from vendors including Fortinet, VMware, Veeam, Citrix, and SimpleHelp. 

The pattern also shows up in government data. The Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities catalog grew by 245 entries in 2025, bringing its total to 1,484, and Microsoft again the single most-added vendor at 39. 

Network and security appliance exploits

Network and security appliance exploits target the firewalls, VPNs, and edge devices sitting at the perimeter of a company’s infrastructure, and they have become a favorite entry point for state-sponsored groups.

These devices often run without endpoint detection and response tools installed, creating a blind spot for defenders and making compromises harder to detect. Group-IB Attack Surface Management continuously maps internet-facing appliances like these, flagging exposed or unpatched devices before attackers do.

Mobile device exploits

Mobile device exploits target smartphones and tablets, often through zero-click techniques that require no interaction from the victim.

Mobile devices remain a prime target for the most advanced attackers. As platform vendors harden iOS and Android, attackers increasingly chain multiple bugs together to reach the same level of access they once got from a single flaw. Group-IB’s Pegasus Spyware: What It Is and How to Detect It analysis breaks down how these zero-click exploits take over a phone without any victim action.

The pattern is still playing out. In 2025, Citizen Lab confirmed a zero-click iMessage exploit, tracked as CVE-2025-43200, that was used to deploy Paragon’s Graphite spyware against journalists, including Italian reporter Ciro Pellegrino.

Supply chain and third-party software exploits

Supply chain and third-party software exploits target the vendors, libraries, and tools embedded inside another company’s product, so a single flaw can compromise every downstream customer at once.

According to Group-IB High-Tech Crime Trends Report 2026, supply chain attacks became the dominant force reshaping the global cyber threat landscape in 2025, as attackers increasingly exploit trusted vendors, open-source packages, and software dependencies to reach hundreds of downstream organizations through a single compromise.

Top 10 Zero-Day Examples You Need to Know

Zero-day bugs stop being abstract the moment you see how quickly they upend real systems, from web browsers to uranium centrifuges. Each case below shows the same storyline: a hidden flaw, a hectic scramble by defenders, and a lasting lesson for everyone else.

1. WinRAR archive spoofing (April–August 2023)

As Group-IB documented, CVE-2023-38831 lets attackers craft ZIP/RAR files that disguise malicious scripts as benign images or PDFs. Crypto-trading communities took the first hit. Victims double-clicked a “chart.png,” unknowingly launching malware that drained exchange accounts.

WinRAR 6.23 closed the gap, but only after multiple Advanced Persistent Threats (APTs) weaponized the bug, evidence that even venerable utilities require constant scrutiny.

  • Vulnerability: CVE-2023-38831 allowed a rigged ZIP/RAR file to display a fake image or text icon that silently executes hidden malware on double-click.
  • Impact: Stealer payloads (DarkMe, Remcos) drained online-trading accounts for four months until WinRAR sealed the flaw in version 6.23 on Aug 2, 2023.

2. Stuxnet (first uncovered in 2010)

Disguised as ordinary Windows drivers, Stuxnet chained four brand-new Windows flaws, including the notorious LNK shortcut bug, to hop from a USB stick to Siemens industrial controllers inside Iran’s Natanz enrichment plant.

Once resident, it subtly sped up and slowed down centrifuges until they shook themselves apart. The attack marked the first time malicious code inflicted physical damage on critical infrastructure, forcing data security teams everywhere to treat even “air-gapped” networks as fair game.

  • Main vulnerability: Four fresh Microsoft Windows flaws, most notably the LNK shortcut bug (CVE-2010-2568) that auto-executed code from a USB stick.
  • Potential Impact: Spun Iranian centrifuges in and out of tolerance and became the first malware to potentially damage industrial equipment.

3. Zoom UNC-Path injection (April 2020)

At the height of pandemic home-working, researchers showed that Zoom chat turned UNC strings into live links. On Windows, that quirk leaked NTLM hashes and, in crafted cases, enabled remote code execution.

Zoom patched the issue within 48 hours and launched a headline-grabbing 90-day security sprint, proof that popularity can make any software an instant target.

  • Main vulnerability: Chat messages turned UNC paths into clickable links, leaking NTLM hashes and enabling remote code execution on Windows.
  • Impact: Privacy panic during the early lockdown. Zoom patched the flaw within 48 hours and launched a full-scale revamp of its network security measures.

4. ProxyLogon, Microsoft Exchange (March 2021)

A four-part exploit chain led by CVE-2021-26855 let attackers bypass authentication on on-premises Exchange servers, drop web shells, and run code with SYSTEM privileges. The Chinese group HAFNIUM hit tens of thousands of organizations, including government agencies, before admins could apply patches.

Even after fixes landed, web shells persisted on compromised servers, illustrating how post-exploitation cleanup is as vital as patching itself.

  • Main vulnerability: A Server-Side Request Forgery (SSRF) authentication bypass (CVE-2021-26855) chained to file-write bugs for full remote code execution.
  • Impact: HAFNIUM planted web shells on tens of thousands of mail servers, forcing emergency patches and one-click mitigation scripts.

5. PrintNightmare, Windows Print Spooler (June 2021)

A leaked proof-of-concept for CVE-2021-34527 showed that anyone with network access could make the Print Spooler install a malicious driver and execute code as SYSTEM.

Because the Spooler is enabled by default across Windows versions, ransomware crews quickly folded the bug into their playbooks. Microsoft’s patch cycle ran for months as edge-case bypasses kept surfacing, a lesson in how complex subsystems can be stubborn to secure.

  • Main vulnerability: A Windows Print Spooler remote code execution flaw (CVE-2021-34527) that lets attackers gain SYSTEM privileges or gain in from the network.
  • Impact: An instant favorite for ransomware operators. Patching proved tricky, leading to a summer of follow-up patches as new bypasses surfaced.

6. Kaseya VSA supply-chain attack (July 2021)

REvil operators exploited a flaw in the authentication logic of Kaseya’s on-prem VSA management servers. They pushed ransomware to roughly 1,500 downstream companies in one weekend, freezing supermarket tills and MSP networks alike.

The incident highlighted the cascading security risks in software supply chains and the need for zero-trust controls between vendor tools and customer assets.

  • Main vulnerability: Authentication and logic flaws in Kaseya’s remote-management servers.
  • Impact: REvil pushed ransomware to roughly 1,500 downstream companies, demonstrating how a single MSP tool could compromise organizations worldwide.

7. Log4Shell, Apache Log4j (December 2021)

A single ${jndi:ldap://…} string in a log message triggered unauthenticated remote code execution in Java applications worldwide. Log4j is used in everything from games to cloud back-ends, so scanning began within hours and has never really stopped. 

Mitigations arrived quickly, but the library’s ubiquity ensured opportunistic miners, botnets, and advanced persistent threats found targets well into 2022.

  • Main vulnerability: A single JNDI lookup string (CVE-2021-44228) allows anyone to run arbitrary code inside applications that use the Log4j logging library.
  • Impact: Global scanning within hours. Thousands of cloud and on-premises systems hijacked for crypto-mining, data theft, and ransomware.

8. Google Chrome V8 Type-Confusion (March 2022)

Google spotted in-the-wild exploitation of CVE-2022-1096, a type-confusion bug in the V8 JavaScript engine. A malicious web page could escape Chrome’s sandbox and run code on the host operating system.

With three billion users at stake, Google shipped a fix in two days and urged an immediate browser restart, a reminder to treat “update Chrome” pop-ups as non-negotiable.

  • Main vulnerability: CVE-2022-1096 in the JavaScript engine opened the door to browser-level takeover from a malicious page.
  • Impact: Google urged its three billion users to restart Chrome, proof that browser zero-days remain profitable targets for attackers.

9. Barracuda ESG remote command injection (May 2023)

Tracked as CVE-2023-2868, a TAR-file parsing flaw let threat actors install backdoors on Barracuda Email Security Gateways dating back to 2013. Because appliances often sit at network edges, attackers harvested sensitive information from email and pivoted deeper. Barracuda’s guidance was blunt: replace affected appliances rather than just patch them.

  • Main vulnerability: A TAR-file parsing flaw (CVE-2023-2868) that allowed remote command injection on edge appliances.
  • Impact: The threat actor UNC4841 installed backdoors on ESG boxes worldwide, prompting Barracuda to recommend hardware replacements. 

10. MOVEit transfer SQL injection (May 2023)

The CL0P ransomware gang exploited a pre-authentication SQL injection (CVE-2023-34362) to extract data from file-transfer servers used by federal agencies and Fortune 500 firms. Victims faced double extortion: pay or watch stolen HR records and financials leak online.

The speed from zero-day to data breach notices showed how quickly dedicated operators can monetize a fresh flaw.

  • Main vulnerability: An unauthenticated SQLi in a popular file-transfer platform.
  • Impact: CL0P ransomware gang grabbed terabytes from government agencies and Fortune 500 firms, igniting 2023’s biggest data-extortion wave.

Why Zero-Day Exploits Are Hard to Defend Against

Zero-day exploits create a distinct set of defensive challenges compared to known vulnerabilities. The five factors below explain why they remain one of the hardest threats to stop.

No available patch at the time of discovery

The lack of a patch makes it a zero-day exploit, since the vendor has not released a fix by the time attackers begin using it.

Security teams cannot close the gap through patch management alone. Detection and containment controls must carry the weight during the exposure window, since nothing is in place to install.

Limited detection capabilities

Limited detection capabilities stem directly from the flaw being unknown. Traditional antivirus and signature-based tools rely on a known pattern to match against, and a zero-day exploit has none.

Behavior-based detection, covered later in this guide, closes part of that gap by flagging what an exploit does instead of what it looks like.

High value to threat actors

A zero-day’s value to threat actors comes from how reliably it works. A working exploit against a widely used product can breach almost any target running that software, which is why buyers pay a premium.

Group-IB’s High-Tech Crime Trends Report 2025 recorded a 58 percent increase in APT-attributed attacks in 2024, underscoring how much state-sponsored and financially motivated groups now invest in such access.

Commercial surveillance vendors have become a major force in the zero-day market. The U.K. National Cyber Security Center’s commercial cyber proliferation assessment found that at least 80 countries have purchased commercial intrusion software or spyware over the past decade, and the agency judges that off-the-shelf spyware can now almost certainly rival the capabilities of some state-linked advanced persistent threat groups.

The U.S. Treasury sanctioned the Intellexa Consortium in 2024 over its Predator spyware, which uses one-click and zero-click exploits that require no victim interaction. Citizen Lab has independently confirmed zero-click spyware exploits from both NSO Group and Paragon deployed against journalists and civil society figures within the past year.

Potential for widespread exploitation

The potential for widespread exploitation grows quickly once a zero-day becomes public, as attackers race to weaponize the flaw before organizations finish patching. As mentioned earlier in the zero-day lifecycle, independent research found that nearly 29 percent of exploited vulnerabilities in 2025 were already under attack on or before the day their CVE was published, leaving defenders no lead time. 

Log4Shell remains a clear example of the same dynamic playing out at scale, since the flaw was still being scanned for months after the initial patch shipped.

Difficulty assessing organizational exposure

Difficulty assessing organizational exposure arises because most companies lack a complete, up-to-date inventory of all assets, libraries, and third-party dependencies running in their environments. 

Group-IB Vulnerability Assessment service helps map these blind spots, including configuration errors and missing patches, before they lead to costly incidents.

Understanding Zero-Day Vulnerabilities

A zero-day vulnerability is a security flaw that is unpatched and unknown to the vendor (and therefore unpatched). It can exist in vulnerable operating systems, applications, drivers, firmware, or cloud services. 

What makes it different from any other flaw is timing. No fix exists yet, and defenders don’t know it’s there, so mitigation is impossible until someone discovers it.

Here is the difference between the two terms, for better clarity:

1. Zero-day exploit

The crafted method, such as a script, payload, macro, malicious link, etc., that takes advantage of the zero-day vulnerability to bypass security solutions.

It is tied to a specific vulnerability and is often sold privately or embedded in malware kits.

2. Zero-day attack

In simple terms, a zero-day attack is a real-world operation in which criminals (or red-teamers) deploy a zero-day exploit to steal data, plant zero-day malware, or disrupt services.

It is only observable after the exploit is already in use, and its impact ranges from silent espionage to headline-grabbing breaches.

How Can Organizations Detect Zero-Day Attacks

Organizations detect zero-day attacks by monitoring abnormal behavior rather than waiting for a known signature, since no signature exists for an undisclosed flaw yet. The methods below work together rather than on their own.

  • Behavioral and anomaly detection across endpoints, network traffic, and cloud workloads flags unusual process activity even without a matching signature.
  • Threat intelligence and dark web monitoring surface early chatter about a new exploit before it appears in a CVE.
  • Sandbox detonation of suspicious files and links reveals malicious behavior in an isolated environment before it reaches a live system.
  • Asset and attack surface visibility shows security teams exactly what is exposed, so they can prioritize monitoring on the highest-risk systems.

According to a Forrester study cited in Group-IB’s Managed XDR case study, organizations using behavior-based detection respond to threats 20 percent faster and achieve a return on investment of over 272 percent.

How to Protect Against Zero-Day Attacks

Protecting against zero-day attacks means layering detection, containment, and rapid response, since prevention alone cannot close a gap that has no patch yet. Here is how Group-IB’s platform addresses each stage. Here’s how you can protect yourself against zero-day attacks:

1. Up-front discovery through threat intelligence

Group-IB’s reverse-engineering team actively hunts for unknown flaws. The WinRAR archive-spoofing bug (CVE-2023-38831) is a recent zero-day example. 

As soon as the team confirmed exploitation on trading forums, they pushed Indicators of Compromise (IOCs) and YARA/Sigma rules to customers through the Threat Intelligence feed, days before the vendor patch arrived.

Group-IB detailed this process in Under the Hood Part 1, which breaks down how its Threat Intelligence Database correlates adversary infrastructure across investigations.

2. Managed XDR

Group-IB Managed XDR platform integrates endpoint telemetry, network traffic analytics, and a cloud-based Malware Detonation Platform. Behavioral models surface the tell-tale spikes, crashes, or outbound beacons that betray an unknown exploit, even when no CVE or signature exists.

3. Malware detonation platform

Whenever an email attachment, ZIP archive, or URL looks even slightly suspicious, the platform opens it in an isolated sandbox, a locked-down virtual computer that can’t access your real network. The sandbox then runs four steps:

  1. Run the file to see what it does.
  2. Records every step the malware tries, including processes launched, registry edits, and network calls, to build a complete activity map.
  3. Extracts any hidden payloads or downloaded files for deeper analysis.
  4. Generates fresh indicators of compromise (IOCs), including hashes, domain names, and unusual behaviors, and instantly feeds them to the XDR system.

4. Business email protection

Many zero-days arrive as email attachments or links. Group-IB Business Email Protection detonates inbound files and rewrites URLs in real time, blocking weaponized content before it hits users’ inboxes.

What you can do today:

  • Subscribe to real-time threat intelligence feeds, whether Group-IB’s or another reputable source, and pipe the IOCs into your SIEM or endpoint security.
  • Layer detection. Pair endpoint behavior analytics with network anomaly monitoring so zero-day activity has fewer places to hide.
  • Automate sandbox detonation for email and web traffic so staff never become the first line of defense.
  • Audit and tighten the patch cadence. CISA’s updated Binding Operational Directive 26-04 now sets remediation timelines based on exploitation risk rather than a flat deadline. Prioritize any flaw already listed in CISA’s Known Exploited Vulnerabilities catalog, and verify rollout with automated asset scans
  • Aim for a 72-hour SLA on critical CVEs and verify completion with an asset-management scan.
  • Watch the dark web. Early chatter about exploits targeting your software stack is often the first alarm bell you’ll get. Ingest fresh IOCs and exploit chatter into your SIEM so defensive rules can update before attackers pivot.

How Can Group-IB Help Organizations Prevent Zero-Day Exploits

Group-IB helps organizations close the zero-day gap with layered detection, real-time threat intelligence, and rapid response, catching exploit activity before a CVE or signature even exists. 

Zero-day threats prove that even well-maintained computer systems have blind spots. This guide explored how these unseen flaws emerge, how quickly exploits appear, and the real-world attacks, from Stuxnet to WinRAR, that underscore the stakes.

The common thread is time. Attackers move quickly, and defenders must move even faster, with layered intrusion detection of suspicious activities, rapid patching, and potential threat-intelligence-driven responses.

How Group-IB helps:

  • Managed XDR correlates endpoint, network, and email telemetry to flag abnormal crashes, hooks, and outbound beacons that reveal exploitation, often hours before a CVE even exists.
  • Threat Intelligence and dark web monitoring deliver live indicators of emerging exploits, such as the WinRAR case (CVE-2023-38831), so your controls can update ahead of mass attacks or lateral movement.
  • Malware Detonation Platform safely “opens” suspicious files and URLs in a hardened sandbox, extracts their behaviors, and auto-publishes new detection logic across every protected endpoint.

Contact our experts today to close the gap between discovery and defense.

Frequently Asked Questions

How do attackers usually discover zero-day vulnerabilities?

arrow_drop_down

Attackers often discover zero-day vulnerabilities through techniques such as fuzzing (automated input testing), reverse-engineering software updates, or buying them on dark-web exploit markets. Some advanced groups even develop custom tools to uncover flaws in popular apps and operating systems.

How are zero-day vulnerabilities sold or traded?

arrow_drop_down

Zero-day exploits are valuable commodities that can sell for hundreds of thousands, or even millions, of dollars on black markets, private exploit forums, or even to government-backed groups. Legitimate platforms like Zerodium and HackerOne also let ethical hackers responsibly disclose zero-days for a bounty.

Can antivirus or EDR tools detect zero-day attacks?

arrow_drop_down

Traditional antivirus struggles with zero-days because there’s no signature to match. Modern Endpoint Detection and Response (EDR) and XDR solutions use behavioral analysis and anomaly detection to flag suspicious activities, even if the specific exploit is unknown. Detection is not guaranteed, which is why zero-days are so dangerous.

What is the difference between a zero-day exploit and a zero-day vulnerability?

arrow_drop_down

A zero-day vulnerability is the underlying flaw itself, sitting unpatched inside software or firmware. A zero-day exploit is code or a technique that attackers use to exploit a flaw. A zero-day attack occurs when an attacker uses an exploit against a live target, rather than merely possessing working exploit code.

 

Can a zero-day vulnerability be patched?

arrow_drop_down

Yes, once a vendor discovers or is notified of a zero-day vulnerability, they typically release a patch. Turnaround time varies by vendor and severity, but the flaw is only classified as a zero-day until that fix exists.

 

How long does a zero-day vulnerability remain unpatched?

arrow_drop_down

It depends on when the flaw is discovered. A vulnerability can sit dormant and unknown for months or years before anyone finds it. Once a vendor is notified, the patch development window is typically much shorter, though it still varies with the flaw’s severity and the vendor’s own release process.

 

Are zero-day exploits always used in targeted attacks?

arrow_drop_down

No. Some zero-days, like Log4Shell, get scanned and exploited opportunistically at massive scale within hours of disclosure. Others, like the FORCEDENTRY exploit, are used narrowly against specific high-value individuals such as journalists or activists. The same flaw can move from targeted to widespread once proof-of-concept code becomes public.

 

How can organizations identify whether they have been affected by a zero-day attack?

arrow_drop_down

Organizations typically identify a zero-day attack by correlating unusual behavior, such as unexpected process activity, outbound connections, or crashes, against fresh IOCs published after a vulnerability is disclosed. Reviewing endpoint and network logs against these indicators, rather than waiting for a formal vendor advisory, is usually the fastest way to confirm exposure.

 

What should an organization do after discovering a zero-day attack?

arrow_drop_down

The immediate priority is containment. Isolate the affected systems, rotate any exposed credentials, and preserve logs for investigation. From there, apply the vendor patch or mitigation as soon as it becomes available, and review what else in the environment could be affected by the same exposure.

Group-IB’s Incident Response team can help contain the incident and determine the scope of compromise, with 24/7 responders available to investigate the root cause and support a safe recovery.

Group-IB: Fight
against cybercrime