Skip to content

The Chinese threat landscape, in English at last

ZeroDayCN was founded by a team of 11 veteran analysts from the Chinese security industry who saw a structural gap: critical vulnerability and threat-actor activity disclosed first in Chinese-language channels — vendor notices, researcher blogs, code repositories — reached Western security teams days late, if ever. We built the English-accessible feed that closes that gap: dedicated coverage of zero-day activity inside the Chinese threat landscape, translated, analyzed, and triage-ready.

Since 2017 we have cataloged 1,840+ CVEs with a 96% vendor-confirmation rate, tracked 312 named threat actor groups, and delivered advisories to subscribers an average of 19 hours before the same intelligence reached mainstream feeds.

What subscribers get

  • The daily feed: newly disclosed vulnerabilities in Chinese-origin software, hardware, and supply chains — with exploitability scoring in English.
  • APT group tracking: infrastructure changes, tooling shifts, and attribution updates, sourced and dated.
  • Triage-ready advisories formatted for SOC workflows — affected versions, mitigations, and detection guidance.

Trusted daily by 2,100+ enterprise SOC teams across 58 countries, our readers are security engineers, SOC analysts, and vulnerability researchers who need the intelligence early and the sourcing intact. Every advisory lists its original source and translation status, because trust in intelligence is built on traceability.

Our editorial line

We report on threats, not narratives: attribution claims are labeled as claims, and we publish when evidence contradicts our earlier analysis. ZeroDayCN is the front line of English-language zero-day intelligence on the Chinese threat landscape — earlier, sourced, and readable by the teams defending against it.