Better, but it’s still glossing over the critical bit, which is “previously unrevealed to who?” Specifically, “zero day” implies both that:
The vendor or maintainers had no idea of the vulnerability’s existence.
A diligent defender would have zero days to prepare, hence the name.
Meanwhile, it’s entirely possible that the attacker has known for months or years.
Words like “unknown”, “unreleased”, etc., are all imprecise about this asymmetry. For example, if Microsoft knows about a vulnerability in Windows but hasn’t shared that information with the public, that’s “unrevealed” to the public. But most people would not consider it a zero day.
“Zero day” is an established term that is widely understood by practitioners and the relevant professionals. It might not be an ideal choice of terminology when writing a newspaper article for a non-technical audience.
How about, “previously unrevealed”?
Better, but it’s still glossing over the critical bit, which is “previously unrevealed to who?” Specifically, “zero day” implies both that:
The vendor or maintainers had no idea of the vulnerability’s existence.
A diligent defender would have zero days to prepare, hence the name.
Meanwhile, it’s entirely possible that the attacker has known for months or years.
Words like “unknown”, “unreleased”, etc., are all imprecise about this asymmetry. For example, if Microsoft knows about a vulnerability in Windows but hasn’t shared that information with the public, that’s “unrevealed” to the public. But most people would not consider it a zero day.
“Zero day” is an established term that is widely understood by practitioners and the relevant professionals. It might not be an ideal choice of terminology when writing a newspaper article for a non-technical audience.