Threat

Zero-Day

A zero-day is a security vulnerability that is exploited before the manufacturer provides a patch.

A zero-day vulnerability is a security flaw exploited by attackers before the manufacturer provides a patch. The name comes from defenders having zero days of advance warning.

How it works

Attackers discover a vulnerability themselves or buy it. They use it selectively, often against a few high-value targets. Once the flaw becomes public, the manufacturer issues a warning and later a patch. From this point, the number of attacks usually increases sharply. This is because many groups are now aware of the vulnerability. In recent years, many zero-days affected perimeter systems like VPN appliances, firewalls, and file transfer solutions.

A practical example: a manufacturer reports an actively exploited flaw in its VPN appliance on Thursday. There is no patch yet, only a temporary mitigation. The SOC checks which customers use the device. It then searches logs for known traces of compromise. For one customer, it finds a suspicious login from the previous week.

What to look out for

  • Maintain an up-to-date inventory of your systems, especially internet-facing ones.
  • Implement temporary mitigations immediately, even without a patch.
  • Search retrospectively for traces of compromise. The attack may have occurred before public disclosure.
  • Reduce the attack surface. Anything not reachable from the internet cannot be attacked from it.

Why it matters

No patch can protect against an unknown vulnerability. What helps is detecting the behaviour that follows an attack. This includes new accounts, unusual processes, or outbound connections. Behavioural detection is therefore crucial for zero-days.

Switzerland and regulation

The National Cyber Security Centre (NCSC) issues warnings for critical vulnerabilities. It sometimes informs affected operators directly. If a zero-day is exploited at a critical infrastructure operator, the reporting obligation under the Information Security Act (ISG) has applied since 1 April 2025. If the attack meets the criteria, it must be reported to the NCSC within 24 hours of discovery.

Typical mistakes

Often, organisations only patch after disclosure without searching for past compromise. An attacker who has already gained access will then remain undetected.

How we implement it

For critical zero-days, our SOC actively hunts for signs of exploitation. You receive findings and recommendations directly from us.

How ANOMAL implements this