THREAT LIBRARY
Attack #12: Zero-Day Exploits
When the vulnerability is still unknown
Threat snapshot – Zero-Day Exploits
| Category | Summary |
|---|---|
| What it is | Attacks that exploit software vulnerabilities before a security patch or official mitigation becomes available. |
| Most common targets | Enterprise applications, operating systems, browsers, cloud platforms, VPN appliances, and internet-facing services. |
| What it relies on | Previously unknown vulnerabilities, delayed detection, exposed services, and lack of behavioral visibility. |
| How it’s detected | Behavioral anomalies, unusual process execution, endpoint telemetry, threat intelligence, and SOC investigation. |
| Primary impact | Initial compromise, privilege escalation, data theft, ransomware deployment, or persistent access. |
| What realistically helps | Continuous monitoring, layered security, rapid detection and response, threat hunting, and resilience planning. |
How the attack works
Zero-day attacks exploit a vulnerability before defenders know it exists.
Unlike attacks that rely on already known weaknesses, zero-day exploits target software flaws that have not yet been publicly disclosed or patched.
This means organizations cannot rely on patching alone.
Attackers often combine zero-day exploits with phishing, credential abuse, or social engineering to gain initial access, execute malicious code, or bypass security controls.
The vulnerability may be unknown.
The attack rarely is.
Real-World Cases
Zero-day attacks exploit vulnerabilities for which no patch is available at the time of initial exploitation, or which defenders do not yet know are being actively abused. This significantly reduces the time available for response.
Ivanti Connect Secure (2024)
Sector: Enterprise Remote Access and Network Security
How did the incident begin?
Attackers chained two vulnerabilities affecting Ivanti Connect Secure and Ivanti Policy Secure: CVE-2023-46805 for authentication bypass and CVE-2024-21887 for command injection. When the vulnerabilities were publicly disclosed, they were already being actively exploited before complete patches were available.
What was compromised?
- internet-facing VPN (Virtual Private Network) gateways;
- administrative control of affected appliances;
- internal networks and user credentials in some compromised environments.
How did the attack develop?
The vulnerability chain allowed an unauthenticated attacker to bypass authentication and execute commands on an affected gateway. Ivanti initially issued temporary mitigations and later released patches in stages for the affected product versions.
What could have reduced the impact?
- accurate inventories of all internet-facing appliances;
- immediate application of vendor mitigations and patches;
- monitoring for configuration changes and unusual administrative sessions;
- rebuilding compromised appliances when their integrity cannot be confirmed.
Palo Alto Networks PAN-OS (2024)
Sector: Network Security and Firewalls
How did the incident begin?
CVE-2024-3400 affected specific PAN-OS versions and configurations using the GlobalProtect feature. The vulnerability allowed an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Palo Alto Networks began investigating after receiving information about a suspicious data-exfiltration attempt in a customer environment.
What was compromised?
- affected PAN-OS firewalls;
- configuration files and sensitive information stored on the devices;
- internal systems reachable from the compromised firewall.
How did the attack develop?
The activity, tracked as MidnightEclipse, used the vulnerability for initial access, persistence, and further movement into internal environments. The vendor released patches and guidance for identifying signs of compromise on affected devices.
What could have reduced the impact?
- priority patching of internet-facing security appliances;
- restricting administrative access to trusted networks;
- monitoring for unusual files, processes, and outbound connections;
- network segmentation to prevent unrestricted access from a compromised firewall.
What do these incidents show?
In the Ivanti case, attackers chained two vulnerabilities to bypass authentication and take control of remote-access gateways. In the Palo Alto Networks case, a single critical vulnerability enabled code execution with the highest privileges on the firewall.
Both incidents show that zero-day risk is particularly high for internet-facing infrastructure. When no patch is available, organizations must rely on temporary mitigations, enhanced monitoring, and rapid investigation for signs of an existing compromise.
Who they most often target
Zero-day attacks typically focus on high-value environments where a single exploit can provide significant access.
Roles
- IT administrators
- security teams
- infrastructure engineers
- cloud operations teams
Sectors
- government
- financial services
- healthcare
- technology providers
- critical infrastructure
- telecommunications
Organization types
- organizations operating internet-facing services
- enterprises with complex infrastructure
- cloud-native organizations
- businesses running critical applications
The greater the value of uninterrupted operations, the more attractive the target.
What the attack relies on
Zero-day exploitation succeeds when unknown vulnerabilities meet insufficient visibility.
Human factors
- delayed reporting
- lack of security awareness
- slow incident escalation
Technical gaps
- exposed internet services
- insufficient endpoint visibility
- weak application monitoring
- inadequate network segmentation
Process weaknesses
- reactive security operations
- reliance on signatures alone
- lack of threat hunting
- slow vulnerability management processes
Zero-day attacks exploit uncertainty more than technology.
How it is detected
Detection rarely starts with identifying the vulnerability.
It starts with identifying abnormal behavior.
What users may notice
- unexpected application crashes
- unusual device behavior
- abnormal application responses
What IT teams observe
- unexplained system processes
- unexpected outbound connections
- unauthorized privilege changes
- suspicious application activity
What SOC teams detect
- behavioral anomalies
- suspicious process chains
- exploitation indicators
- threat intelligence correlations
Behavior often exposes the attack before the vulnerability is understood.
How impact is contained
Containment focuses on limiting attacker movement while investigation continues.
Immediate priorities include:
- isolating affected systems
- blocking malicious communication
- restricting compromised accounts
- collecting forensic evidence
- deploying temporary mitigations
- increasing monitoring across similar assets
What does not help:
- waiting for a vendor patch before acting
- assuming only one system is affected
- relying solely on antivirus signatures
Rapid response reduces exposure while permanent fixes become available.
What realistically helps
Organizations cannot prevent every zero-day attack.
They can significantly reduce the consequences.
People
- trained incident response teams
- clear escalation paths
- continuous security awareness
Processes
- vulnerability management
- threat hunting
- incident response playbooks
- asset visibility
Technology
- EDR/XDR
- behavioral detection
- threat intelligence
- network segmentation
- continuous SOC monitoring
Cyber resilience is built on the ability to detect and respond, not only to prevent.
Common myths
“Zero-day attacks are common.”
“Only governments are targeted.”
“Nothing can be done until a patch is released.”
“Traditional antivirus is enough.”
In reality, zero-day exploits are relatively rare compared to phishing or credential abuse, but they often have a disproportionate impact because defenders have little time to react.
Continue Exploring the Threat Library
This concludes the core Threat Library series.
Follow the series to understand how modern cyber attacks work, how they evolve, and what helps organizations reduce risk.
Attack #1: Phishing & Social Engineering
Attack #2: Credential Abuse & Account Takeover
Attack #3: Business Email Compromise (BEC)
Attack #5: Supply Chain Attack
Attack #7: Malware & Infostealers
Attack #9: Privilege Escalation & Lateral Movement
Attack #10: Cloud Misconfiguration Abuse
Attack #11: DDoS & Service Disruption
Attack #12 – Zero-Day Exploits
Next, we’ll expand into emerging threats shaping the future of cybersecurity:
- AI-Assisted Cyber Attacks
- Physical Infrastructure Attacks
- Deepfake & Identity Manipulation






