Wei Zhang
Director of Research
Eleven named researchers — not a faceless “threat intel team”. ZeroDayCN is staffed by operators who reverse-engineered the CobaltStrike-Beacon-CN fork, coordinated 230+ vendor patches, and built the only continuously updated database of 312 Chinese-nexus APT groups and exploit vendors.
ZeroDayCN was founded in 2017 in Shanghai by a small group of vulnerability researchers from Qihoo 360 and Pangu Lab who had grown tired of watching high-quality Chinese-origin exploit intelligence disappear into Mandarin-only forums, vendor-secured Slack channels, and WeChat groups that English-speaking enterprise defenders could not access.
For years, an entire ecosystem of kernel exploits, mobile-browser RCE chains, ICS/SCADA bugs, and gray-market exploit vendors operated in a parallel information space. Mainstream feeds learned about these vulnerabilities days or weeks after researchers, vendors, and APT operators already did. A SOC engineer in Frankfurt, Austin, or Tel Aviv could not read the original advisory, verify the PoC, or corroborate the patch timeline — even when their own infrastructure was on the line.
We built ZeroDayCN to close that gap. Everything published here is sourced, validated, and triaged by named researchers who have spent careers on the originating side of these bugs. The editorial discipline is strict: a published 4.7% false-positive rate (cited, never claimed as zero), a 96% vendor-confirmation rate, and a hard refusal to publish exploit code without an accompanying disclosure timeline or vendor patch status.
This is the team that did the work, with their names, their lineage, and an open door to anyone who has a zero-day to disclose.
Eleven senior vulnerability researchers and six threat intelligence analysts. Below: a cross-section of the core team — each with a prior Chinese-security-firm affiliation and a named specialty. The full roster is published in our transparency report.
Director of Research
Principal Researcher · Mobile
Lead ICS Researcher
Head of Threat Intelligence
// ADDITIONAL RESEARCHERS
Six more senior vulnerability researchers (browser exploitation, smart-contract audits, Linux kernel, supply-chain, network protocols, embedded RTOS) plus six threat-intelligence analysts form the full team. The complete roster — including bios, published CVEs, and conference talks — is available in our annual transparency report.
Request the roster PDF →If you have a zero-day, an in-the-wild exploit sample, or a vendor patch timeline to coordinate, our disclosure pipeline is open 24/7 — staffed by senior researchers, not first-tier triage contractors. Submissions are read within twelve minutes (median) and acknowledged in writing within four hours.
We operate a private disclosure pipeline that has responsibly coordinated 230+ patches with security teams at Microsoft, Apple, Google, and Huawei. Every submission is PGP-encrypted at rest, handled by a named researcher who becomes your point of contact, and tracked in a shared disclosure registry until either a patch ships or a coordinated public disclosure date is reached.
We do not buy, sell, or broker exploit code. We do coordinate timelines, verify PoCs under controlled conditions, and credit researchers by their preferred handle in every public advisory.
Researchers and vendor coordinators have asked these four questions hundreds of times. We have answered them the same way hundreds of times — here are those answers.
Email [email protected] from the address you want credited. Encrypt the message to the PGP fingerprint above (do not rely on TLS alone — we need the payload encrypted at rest). Include a one-paragraph description, the affected vendor and version, a reproducer or PoC, and your preferred coordination timeline.
First reply from a named researcher: within 4 hours. Median response across 2024: 12 minutes during enterprise hotline hours.
We default to 90-day coordinated disclosure, in line with industry norm. We negotiate from there based on vendor patch complexity, active exploitation, and your preference. Public release is never unilateral — we hold the embargo until the vendor confirms a patch, a 90-day window elapses, or you request release. We will not publish exploit code before an accompanying timeline and patch status.
We credit you by whatever handle you prefer — real name, Twitter/X handle, Mastodon, GitHub, or a generic “independent researcher”. The choice is yours at submission. ZeroDayCN never reveals identity beyond the credited handle. If a vendor request requires more, we come back to you first.
Three categories: (1) vulnerabilities in software developed by vendors headquartered in Greater China — Huawei, Alibaba, Tencent, ByteDance, Xiaomi, etc.; (2) vulnerabilities actively exploited by groups on our tracked APT index; (3) vulnerabilities in the global supply chain (Microsoft, Apple, Google, Linux) where a Chinese-nexus researcher or vendor is a credible attribution. Reports outside these categories are forwarded to a partner feed — we will tell you where they went.
Have a zero-day, a PoC, or a vendor patch timeline to coordinate? Encrypt to the key above and send.