we_are_coded.by CODE · The world, decoded
БГ
Concept

Zero-day

The BasicsUpdated on 16 August 2026we are coded

A hole the vendor itself doesn't even know about yet - which is exactly why it's the most dangerous kind. Zero days means no one has had time to close it.

Checked on16 August 2026
In short: a zero-day is a hole in a program or system that the vendor doesn't know about yet - or knows about but has no patch ready. Zero days is how much time has passed between the hole coming to light and the moment it's closed. The whole time, anyone who knows about it can walk in unopposed. That's why it's the most dangerous kind of breach there is.

Every program has bugs in its code. Most are harmless - a button that doesn't line up, a screen that flickers. But some bugs open a door: they let a stranger run their own code on someone else's computer, steal data, or take control remotely. A bug like that is called a vulnerability. Once the vendor finds it, it ships a patch - an update that closes it. A zero-day is a vulnerability for which there's no patch yet.

In practice it looks like this: a researcher or a hacker finds a hole in a browser, a phone, an accounting program. They write a small piece of code - an exploit - that uses exactly that hole to get in. If they sell it or use it quietly instead of reporting it to the vendor, the hole stays open for every victim until someone else notices and raises the alarm. Between discovery and patch, days can pass, months, sometimes years.

It exists because no software is perfect. Millions of lines of code, written by thousands of people, under enormous pressure to ship fast - a mistake is bound to slip through. The question is never whether there are holes, but who finds them first: a researcher who reports it responsibly, or someone who sells it to whoever pays more.

That's why there's a whole market around this. State intelligence agencies pay serious sums for undisclosed holes in phones and operating systems - for spying, not for defense. There's a flip side too: companies pay a bounty to researchers who find a hole and report it quietly instead of selling it. The difference between the two is the difference between a locked door and a door left deliberately open for whoever pays more.

A zero-day isn't a bug you're waiting to get fixed. A bug is a known risk. A zero-day is a hole that, at the very moment you're reading this, someone may already be walking through - and you don't even know it exists.

Here's what bugs me

A lock with no locksmith - that's a zero-day. You have a door, you have a lock, it looks secure. But the locksmith who's supposed to fix it doesn't even know it's broken. And until he finds out, the door stays open for whoever tried it first.

I work with systems that talk to the internet all day - agents, automations, tools wired to each other. Every one of them is a potential lock with no locksmith until you pay attention to it. That doesn't scare me - what scares me is the confidence that everything's fine just because nothing's blown up yet. A zero-day is exactly that silence before the problem, not the problem itself.

The visual is generated code art. No third-party images.
Official primary sources
→NIST CSRC glossary: zero-day attack