← Glossary

Zero Day Attacks

Attacks exploiting a vulnerability the vendor has not yet patched. Signatures fail by definition; most zero-days arrive by email.

Updated

Key facts

  • Zero-day refers to the defender's knowledge, not the attack's sophistication; the exploit may be old in attacker circles before discovery.
  • Delivery is mundane even when the exploit is exotic: a crafted attachment or link, sent by phishing or spear phishing.
  • Defense that works pre-patch is behavioral: anomalous senders, anomalous files, anomalous intent.

The zero-day lifecycle

A vulnerability exists unnoticed; someone finds it (researcher or attacker); an exploit is built and used or sold; eventually the vendor learns, patches, and the window closes. The dangerous interval is between exploitation and patch, and organizations extend it themselves by patching slowly. During that window, the only detection surface is behavior: the exploit is unknown, but the phishing email carrying it, the strange sender, the odd attachment type from an unexpected relationship, is not. See also spear phishing and AI-native security.

How to defend

Rapid patching shrinks the window after disclosure. Before disclosure: reduce attack surface, isolate and sandbox risky content, apply least privilege so one exploited client does not open the network, and put behavioral detection on the delivery channel, because stopping the carrier email stops the exploit unexamined.

How Sentaro helps

Sentaro is AI-native: verdicts come from models evaluating sender infrastructure, relationship history, content intent and attachment anomalies, not from signature lists. A zero-day payload has no signature, but its delivery email almost always deviates somewhere, and that deviation is detectable. This is precisely the attack class where rule-based gateways have nothing to match against.

Questions we get asked.

What does zero-day mean?

The vendor has had zero days to fix the flaw: it is exploited before a patch exists. Detection cannot rely on known signatures.

How do zero-day attacks reach victims?

Most commonly through email: a crafted attachment or link delivered by phishing, often personalized. The exploit is advanced; the delivery is ordinary.

Can zero-day attacks be prevented?

The vulnerability cannot be pre-patched, but the attack chain can be broken: behavioral email security on delivery, sandboxing, least privilege and fast patching once fixes ship.

What is the difference between a zero-day vulnerability and a zero-day attack?

The vulnerability is the unknown flaw; the attack (or exploit) is its active use against systems before a patch is available.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.