Comment by fred_is_fred

6 hours ago

Is the word zero-day here superfluous? If they were previously unknown doesn't that make them zero-day by definition?

I think it's a fairly common trope in communication to explain in simple terms any language that the wider part of an audience doesn't understand.

It's a term of art. In print media, the connotation is "vulnerabilities embedded into shipping software", as opposed to things like misconfigurations.

I though zero-day meant actively being exploited in the wild before a patch is available?

  • Zero day means that there is zero days between a patch being available and the vulnerability being disclosed (as opposed to the patch being available before disclosure).