Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Zero day is almost always used in the context of “the bug was unknown and first seen during an attacks”.

The alternative definition (that zero day means purely day of publicizing) would mean that if you had two bugs in a product and you notified the vendor of one. Then three months later published both, they would both be zero days, and should be treated as such.

A 0day means publicizing a bug without the vendor themselves having the potential to have a fix.

Very simply: if a virus comes out attacking a known but unfixed bug in MS software no one would call it a zero day. Every article would say it was a bug that Microsoft knew about but hadn’t fixed.



As GP said, lots of people use this amorphous term differently. Antivirus company ESET, for one, explicitly disagrees with your example:

'...The name “zero-day” comes from the fact that no patch yet exists to mitigate the vulnerability being exploited.'

https://www.welivesecurity.com/2015/02/11/security-terms-exp...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: