Zero-Day Vulnerability

  • 9 March 2021
  • 1 min read

From time to time, vulnerabilities have been identified on computer networks. This security bugs allow attackers to gain, damage, or expose unauthorized access to the device.

All tech companies and independent security researchers are constantly searching for new device flaws. When a bug is found, it is the task of the app developer to promptly release an update that resolves the security problem.

A zero-day (or 0-day) vulnerability is a system weakness that is identified by hackers even before developer becomes informed of it. At that moment, that there's no workaround, so perpetrators can quickly compromise the flaw, realizing that no safeguards are in place. This makes zero-day bugs a serious security problem.

When adversaries have discovered a zero-day flaw, they need a delivery mechanism to access the compromised device. In certain instances, the distribution method is a socially constructed email—an email that is allegedly from an established or reputable correspondent, but is really from an intruder. The email is intended to persuade a person to take an act such as opening a file or accessing a compromised website, unintentionally triggering the exploit.

When a patch is posted and then used, the flaw is no longer called a zero-day exploit. These bugs are normally found immediately. In fact, it often takes years, for a developer to know the loophole that led to the intrusion.

For further details reach out to us at contact@nexixsecuritylabs.com

Your Security | Our Concern

All research

Cookie preferences

Choose what this site may store on your device. Your choice is remembered for six months and you can change it any time from the footer. Nothing in the optional categories is stored until you turn it on.

Always active

Needed for the site to work and to remember this choice. It is a single first-party cookie recording which categories you allowed. It carries no identifier and is never sent to anyone else.

Google Analytics and PostHog, so we can see which pages are read and where people give up. This is what lets us recognise one visit across several pages instead of counting every page as a new person. Records are anonymous — we never attach your name or email, and form fields are masked before anything is recorded.

Lets Google measure whether an ad we paid for led to an enquiry, and build audiences for future campaigns. Turning this off does not change what you see on this site.