Skip to content
// 01 — LIVE INTEL FEED

China's front line for zero-day intelligence — vulnerabilities disclosed, weaponized, and defended against in real time.

ZeroDayCN catalogs 1,840+ CVEs, tracks 312 named APT and exploit-vendor groups, and ships triage-ready advisories to enterprise SOCs an average of 19 hours before NVD. Built by an 11-person research team out of Shanghai since 2017.

  • SOURCEZeroDayCN Research Co., Ltd. — Shanghai
  • UPDATED14:32 CST · auto-refresh 60s
  • FEED STATUSOPERATIONAL
// CATALOGED CVEs 1,840+ since 2017 · 96% vendor-confirmed
// TRACKED APTS 312 named groups + exploit vendors
// LEAD VS NVD 19h avg. 2024 disclosure lead time
// SUBSCRIBERS 2,100+ enterprise SOCs · 58 countries
// 02 — PIPELINE

Latest advisories moving through the pipeline right now.

A live cross-section of the four most recent disclosures staged for subscriber release. Tickers cycle automatically; full advisory body lives behind the Threat Brief paywall.

CVECVE-2025-0193Huawei HarmonyOS NEXT sandbox escape — in-the-wild, APT-31 cluster14:28 CST ADVZDCN-ADV-04217Chrome V8 type-confusion — POC public, PoC reproducibility 0.9413:51 CST APTZDCN-APT-108Volt Typhoon subnet pivot toolkit — 4 new IoCs linked to gray-market vendor12:14 CST PATCHZDCN-PAT-00886iOS 18.2.1 kernel UAF — coordinated disclosure closed with Apple PSRT11:02 CST
// 03 — APT INDEX

312 named APT and exploit vendors under continuous observation.

The industry's only continuously updated database of Chinese-nexus APT and gray-market exploit vendors. Four entries below are pulled live from the index; the full 312-group roster ships with every Threat Brief subscription.

  • ZDCN-APT-004 Volt Typhoon aka BRONZE SILHOUETTE · HATTER-002 Critical infra · OT · US/EU/CA ACTIVE · 14 IoCs/30d DOSSIER →
  • ZDCN-APT-027 APT31 aka ZIRCONIUM · Judgment Panda Gov · aerospace · maritime ELEVATED · 9 IoCs/30d DOSSIER →
  • ZDCN-APT-061 Mustang Panda aka BRONZE PRESIDENT · RedDelta Diplomatic · NGOs · ASEAN MONITORING · 6 IoCs/30d DOSSIER →
  • ZDCN-VEN-009 Shanghai XXX Exploit Brokerage aka Gray-VEN-009 · iOS broker Gray-market · mobile RCE · $ TRACKED · 3 listings/30d DOSSIER →
// FULL INDEX 312 groups · 47 exploit frameworks · last refreshed 14:30 CST QUERY THE FULL DATABASE →
// 02 / DIFFERENTIATORS

Why enterprise SOC teams renew year after year.

CVE / ADVISORY

19 hours ahead of NVD, on average.

In 2024, ZeroDayCN advisories reached enterprise subscribers a median 19 hours before the corresponding CVE landed in the National Vulnerability Database — long enough for patch staging, IOC ingestion, and SIEM rule rollout before the public storm.

LEAD TIME 19h
APT / CONFIRMATION

96% vendor-confirmed, never claimed at zero.

Every ZeroDayCN disclosure carries a vendor-confirmation stamp or an explicit "in-the-wild, unverified" caveat. We cite our false-positive rate at 4.7% and let the audit trail prove the rest — no marketing-driven "zero false positives" theater.

CONFIRMATION 96.0%
PATCH / DISCLOSURE

230+ coordinated patches since 2017.

Our private disclosure pipeline has responsibly coordinated 230+ vendor fixes with the Microsoft, Apple, Google, and Huawei security teams. We publish a patch advisory for every disclosure we help close — the receipts are in the archive.

PATCHES 230+
// 03 / CATALOG

Seven years of cataloged zero-day activity, by the numbers.

// CATALOGED CVEs
1,840+
Zero-day and exploited-in-the-wild vulnerabilities since 2017.
// TRACKED APTS
312
Named Chinese-nexus APT groups and gray-market exploit vendors, continuously updated.
// LEAD VS NVD
19h
Average 2024 lead time over NVD publication for enterprise subscribers.
// SUBSCRIBERS
2,100+
Enterprise SOC teams across 58 countries reading the feed daily.
// 04 / TEAM

Eleven senior researchers. 140+ years of vuln-research experience. One feed.

01
FOUNDED 2017

Ex-Qihoo 360 and Pangu Lab pedigree.

ZeroDayCN was founded in Shanghai by researchers who previously shipped offensive tooling and vulnerability research for Qihoo 360 and the Pangu Lab jailbreak team — the same lineage that produced some of the most-cited Chinese-language exploit analyses of the last decade.

BASE SHANGHAI, CN
02
RESEARCH STAFF

11 senior researchers, 6 intel analysts.

The desk includes former NSFocus red team leads and three Pangu Lab alumni, with combined 140+ years of vulnerability-research experience. Every CVE in the catalog carries a named analyst and a chain-of-custody timestamp.

HEADCOUNT 17
03
RESPONSE

24/7 on-call hotline, 12-minute median.

Enterprise subscribers get a 24/7 on-call research hotline with a 12-minute median response time — escalation paths straight to the analyst who wrote the advisory, not a tier-one support queue.

RESPONSE ~12 MIN