Skip to content
// 01 / RESEARCHERS

The people behind the catalog.

Eleven named researchers — not a faceless “threat intel team”. ZeroDayCN is staffed by operators who reverse-engineered the CobaltStrike-Beacon-CN fork, coordinated 230+ vendor patches, and built the only continuously updated database of 312 Chinese-nexus APT groups and exploit vendors.

FOUNDED2017 · Shanghai LINEAGEQihoo 360 · NSFocus · Pangu Lab RESEARCHERS11 senior · 6 analysts
// CATALOGED CVEs 1,840+ updated continuously since 2017
// TRACKED APTs 312 named groups + exploit vendors
// COMBINED YEARS 140+ vuln-research experience
// LEAD VS NVD 19h avg ahead of NVD publication
// 02 / ORIGIN

An editorial bridge, not a marketing play.

ZeroDayCN was founded in 2017 in Shanghai by a small group of vulnerability researchers from Qihoo 360 and Pangu Lab who had grown tired of watching high-quality Chinese-origin exploit intelligence disappear into Mandarin-only forums, vendor-secured Slack channels, and WeChat groups that English-speaking enterprise defenders could not access.

For years, an entire ecosystem of kernel exploits, mobile-browser RCE chains, ICS/SCADA bugs, and gray-market exploit vendors operated in a parallel information space. Mainstream feeds learned about these vulnerabilities days or weeks after researchers, vendors, and APT operators already did. A SOC engineer in Frankfurt, Austin, or Tel Aviv could not read the original advisory, verify the PoC, or corroborate the patch timeline — even when their own infrastructure was on the line.

We built ZeroDayCN to close that gap. Everything published here is sourced, validated, and triaged by named researchers who have spent careers on the originating side of these bugs. The editorial discipline is strict: a published 4.7% false-positive rate (cited, never claimed as zero), a 96% vendor-confirmation rate, and a hard refusal to publish exploit code without an accompanying disclosure timeline or vendor patch status.

This is the team that did the work, with their names, their lineage, and an open door to anyone who has a zero-day to disclose.

— ZeroDayCN Research Co., Ltd. Suite 1804, Tower B, 1000 Lujiazui Ring Road, Pudong New District, Shanghai
// 03 / THE ROSTER

Named, accountable, verifiable.

Eleven senior vulnerability researchers and six threat intelligence analysts. Below: a cross-section of the core team — each with a prior Chinese-security-firm affiliation and a named specialty. The full roster is published in our transparency report.

R-01 REVERSE ENGINEERING

Wei Zhang

Director of Research

  • PRIORQihoo 360 · Vulcan Team
  • FOCUSWindows kernel · EDR bypass
  • CVESMicrosoft, Adobe, VMware
R-02 MOBILE / iOS

Lin Yufeng

Principal Researcher · Mobile

  • PRIORPangu Lab
  • FOCUSiOS sandbox escape · WebKit
  • CVESApple, Google, Huawei
R-03 ICS / SCADA

Chen Huibo

Lead ICS Researcher

  • PRIORNSFocus · Knownsec
  • FOCUSSiemens · Schneider · GE
  • CVESCISA-credited finds
R-04 APT ATTRIBUTION

Han Mengyu

Head of Threat Intelligence

  • PRIORQihoo 360 · SkyEye
  • FOCUSToolchain fingerprinting · C2 pivots
  • TRACKING47 named APT clusters

// ADDITIONAL RESEARCHERS

Six more senior vulnerability researchers (browser exploitation, smart-contract audits, Linux kernel, supply-chain, network protocols, embedded RTOS) plus six threat-intelligence analysts form the full team. The complete roster — including bios, published CVEs, and conference talks — is available in our annual transparency report.

Request the roster PDF
// 04 / TRACK RECORD
140+ COMBINED YEARS
VULN RESEARCH
230+ COORDINATED VENDOR
PATCHES TO DATE
12min MEDIAN ON-CALL
RESPONSE TIME
96% VENDOR-CONFIRMATION
RATE ON ADVISORIES
// 05 / DISCLOSURE PIPELINE

A structured, encrypted, fast intake.

If you have a zero-day, an in-the-wild exploit sample, or a vendor patch timeline to coordinate, our disclosure pipeline is open 24/7 — staffed by senior researchers, not first-tier triage contractors. Submissions are read within twelve minutes (median) and acknowledged in writing within four hours.

We operate a private disclosure pipeline that has responsibly coordinated 230+ patches with security teams at Microsoft, Apple, Google, and Huawei. Every submission is PGP-encrypted at rest, handled by a named researcher who becomes your point of contact, and tracked in a shared disclosure registry until either a patch ships or a coordinated public disclosure date is reached.

We do not buy, sell, or broker exploit code. We do coordinate timelines, verify PoCs under controlled conditions, and credit researchers by their preferred handle in every public advisory.

  • 24/7 intake. Senior researcher on rotation, never a ticket queue.
  • PGP everywhere. Fingerprint published below; submissions encrypted at rest.
  • 12-minute SLA. Median acknowledgement time on enterprise hotline.
  • Named coordination partners. Microsoft, Apple, Google, Huawei security teams.
// 06 / BEFORE YOU WRITE TO US

The predictable questions, answered plainly.

Researchers and vendor coordinators have asked these four questions hundreds of times. We have answered them the same way hundreds of times — here are those answers.

Q.01 How do I submit a vulnerability or PoC sample?

Email [email protected] from the address you want credited. Encrypt the message to the PGP fingerprint above (do not rely on TLS alone — we need the payload encrypted at rest). Include a one-paragraph description, the affected vendor and version, a reproducer or PoC, and your preferred coordination timeline.

First reply from a named researcher: within 4 hours. Median response across 2024: 12 minutes during enterprise hotline hours.

Q.02 What is your embargo and coordinated disclosure policy?

We default to 90-day coordinated disclosure, in line with industry norm. We negotiate from there based on vendor patch complexity, active exploitation, and your preference. Public release is never unilateral — we hold the embargo until the vendor confirms a patch, a 90-day window elapses, or you request release. We will not publish exploit code before an accompanying timeline and patch status.

Q.03 How am I credited, and can I stay anonymous?

We credit you by whatever handle you prefer — real name, Twitter/X handle, Mastodon, GitHub, or a generic “independent researcher”. The choice is yours at submission. ZeroDayCN never reveals identity beyond the credited handle. If a vendor request requires more, we come back to you first.

Q.04 What counts as a “Chinese-nexus” disclosure for your scope?

Three categories: (1) vulnerabilities in software developed by vendors headquartered in Greater China — Huawei, Alibaba, Tencent, ByteDance, Xiaomi, etc.; (2) vulnerabilities actively exploited by groups on our tracked APT index; (3) vulnerabilities in the global supply chain (Microsoft, Apple, Google, Linux) where a Chinese-nexus researcher or vendor is a credible attribution. Reports outside these categories are forwarded to a partner feed — we will tell you where they went.

// READY TO SUBMIT

Have a zero-day, a PoC, or a vendor patch timeline to coordinate? Encrypt to the key above and send.

Contact Research