Zero-Day

Critical

Zero-Day

Definition

A Zero-Day (0-day) vulnerability is a security flaw that is unknown to the software vendor and for which no patch is available. The term 'zero day' means the developer has had zero days to fix the problem. These vulnerabilities are extremely valuable both to attackers and in legitimate security markets.

Impact

With no patch available, every affected system is vulnerableHigh value in exploit markets (hundreds of thousands of euros)Used in targeted attacks and APTs (Advanced Persistent Threats)Can remain undiscovered for months or yearsMassive impact when found in widely used software

Examples

Historic Zero-Day examples

Log4Shell (CVE-2021-44228) was a zero-day in Apache Log4j that enabled RCE and affected millions of Java applications globally. Before its disclosure, it is estimated to have been actively exploited for at least two weeks. The highest-paying bug bounty programs usually pay the largest amounts for critical zero-days.

External references

Practice Zero-Day with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
2,482

hunters training

62

labs from real hacks

1,630

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy
Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime