Computers sometimes have secret holes. 

Computers sometimes have secret holes. 
Even the makers of the computer do not know about them. These holes are called zero-days.
Bad people can find these holes. They use them to get into systems. They may try to steal data. 
When a maker finds a hole, they make a fix. This fix is called a patch. A patch helps keep things safe.
It can take a long time to make a fix. Some people even buy and sell these secret holes. We must use patches to stay safe.
Computers are made of software and hardware. Most products have small mistakes called bugs. If a bug creates a security risk, it is a vulnerability. 
A zero-day is a special kind of vulnerability. It is a secret hole in a system. The makers of the software do not know it exists. This means they have had zero days to fix it.
Bad actors can use these holes. They use a zero-day exploit to get inside a system. An exploit is a way to use the hole. They may use it to steal data or break things. 
When a maker finds a hole, they make a patch. A patch is a fix that closes the hole. It can take weeks or months to make a patch. Some people buy and sell these secret holes. Governments are big buyers of zero-days. They may use them for their own work. Other people sell them to make money. To stay safe, users must install their patches quickly.
{
"text": "A zero-day vulnerability is a secret hole in a computer system. Most software has small mistakes called bugs. If a bug creates a security risk, it is called a vulnerability. A zero-day is a special kind of vulnerability that the makers do not know about yet. This means the creators have had zero days to fix the problem. Because the makers are unaware, they cannot protect their users from it. 



A zero-day vulnerability is a security hole in a computer system that is unknown to its developers. Because the creators are unaware of the flaw, they have had zero days to create a fix. This makes these vulnerabilities a severe threat to digital security. Most software and hardware contain bugs, which are mistakes in the code. When a bug creates a risk that someone can use to enter a system, it is called a vulnerability. 
An exploit is the specific method or tool used to take advantage of a vulnerability. Attackers use exploits to penetrate a target's system for several purposes. They might disrupt operations, install malware, or exfiltrate data, which means stealing information. Some vulnerabilities only cause a denial of service, making a device stop working. The most dangerous exploits allow an attacker to inject and run their own code. This can happen without the user ever knowing the system has been compromised.
Researchers classify vulnerabilities into different stages based on their status. A vulnerability is considered "alive" if there is no public knowledge of it. It is considered "dead" once it has been disclosed but remains unpatched. If the software is no longer being maintained, these are called "immortal" vulnerabilities. There are also "zombie" vulnerabilities, which exist in older software versions but have been patched in newer ones. 
Finding and fixing these flaws follows a specific timeline. The process begins at "Day 0" when a researcher identifies the vulnerability. Next, the researcher reports the finding to the vendor to start remediation. The vendor then undergoes patch development, which is the creation of a code fix. This stage can take weeks or even months depending on the complexity. Finally, the vendor reaches public disclosure by releasing the patch to users. 
There is a massive global market for these exploits, divided into three main categories. The "white market" involves vendors or third parties like the Zero Day Initiative. Sellers in this market often receive a bug bounty, which is a reward for finding flaws. The "gray market" is the largest and most lucrative, consisting of government or intelligence agencies. The United States is a major buyer, alongside the "Five Eyes" nations: the United Kingdom, Canada, Australia, and New Zealand. Finally, the "black market" is used by organized crime for illegal activities. 
Economics play a major role in how these vulnerabilities are used. In 2015, the government and crime markets were estimated to be ten times larger than the white market. Zero-day exploits can fetch millions of dollars, especially remote "zero-click" exploits. Research from the RAND Corporation shows that zero-day exploits remain usable for an average of 6.9 years. However, exploits purchased from third parties only remain usable for 1.4 years on average. 
History shows how these tools can impact the real world. A famous example is the Stuxnet worm, which used four zero-day vulnerabilities in 2010. This worm was used to damage a nuclear program in Iran. This event showed the world the power of zero-day exploits and expanded the global market. Since then, many companies like Google have created programs to find these flaws early. By finding them first, they can prevent criminals from stealing passwords or bank details.
Because writing perfectly secure software is impossible, experts use various defense strategies. Many organizations use "defense-in-depth" tactics to protect their data. This means an attacker must breach multiple levels of security to succeed. Other methods include multi-factor authentication and air-gapping, which means disconnecting a computer from the internet. While detecting zero-day exploits is an active area of research, these layers help reduce the overall risk.
🖼️ Images & Media (2)
More to explore
✨ What else?
Related topics you might enjoy
🔬 Go deeper
More advanced topics to explore
🪜 Step back
Simpler topics to build understanding
What is Nepedia?
A free, ad-free encyclopedia for children. Every article is written at five reading levels, so the same page works for a five-year-old and a fifteen-year-old — use the level switcher above to see this one change. No account needed to read.