Malware
Zero-day
Also called 0-day.
Zero-day is an attack on a vulnerability that the vendor has no fix for, often because it was unknown to them. Defenders have had zero days to prepare.
How it is measured
You rarely see a zero-day in advance. You find it after: an exploit in the wild against software with no matching advisory, a vendor notice saying 'exploited before patch', or an incident whose entry path no known CVE explains. Entries in the CISA catalog sometimes begin as zero-days.
Response metrics are time to mitigation and time to patch after release. Mitigations are things you can do before a patch exists: disabling a feature, blocking a path, restricting access, or tightening monitoring.
Worked example
A vendor of a file-transfer appliance posts an advisory on a Friday: exploitation observed, no patch, disable the web admin interface. An agency using it blocks the interface at the firewall the same hour. On Monday it checks logs and finds a request to a path from the prior Wednesday that dropped a 3 KB file.
The patch arrives eight days after the advisory. Between the advisory and the patch the only protection was the firewall rule and log review; the earlier compromise needed a rebuild, not just the update.
How it differs
An n-day has a fix available, so the gap is how fast you apply it. A zero-day has no fix, so the defence is reducing exposure and detecting abuse. Most compromises on small sites come from n-days, which is why patch speed matters more than worry about the rare zero-day.
Common errors
Treating every breach as a zero-day. Waiting for a patch when a mitigation exists. Assuming small sites are never hit. Forgetting to check logs back to before the advisory date. Counting a patched system as clean without searching for dropped files.
In practice
Know which internet-facing software you run and how to turn off its risky features quickly. Subscribe to vendor and CISA notices for those products. When a zero-day lands, mitigate first, hunt in logs from earlier dates, then patch.