Skip to content
// SECTION 01 — SUBSCRIPTION
THREAT BRIEF // ESTABLISHED 2017

First to know.
Not last to patch.

ZeroDayCN is the only English-accessible feed dedicated to zero-day activity inside the Chinese threat landscape — cataloging 1,840+ CVEs since 2017, tracking 312 named APT groups, and delivering triage-ready advisories an average of 19 hours before they hit mainstream feeds.

// CATALOGED CVEs
1,840+
since 2017 · 96% vendor-confirmed
// TRACKED APTs NOW
312
named groups & exploit vendors
// LEAD VS NVD (2024)
19h
median ahead of public NVD
// SUBSCRIBERS
2,100+
SOC teams · 58 countries
// LIVE TICKER
[14:22 UTC] CVE-2024-49113 — Windows LDAP RCE · in-the-wild exploit confirmed · PoC circulating on Chinese forums [13:58 UTC] APT-Q-218 (MirrorFace) attributed cluster targeting JP semiconductor sector · Huawei PSIRT notified [13:11 UTC] Advisory TB-0988 published — Confluence Data Center auth bypass · patch coordinated w/ Atlassian [12:44 UTC] CVE-2024-38063 — IPv6 IPv6PacketDeserialization · weaponized sample detected in customer telemetry
// SECTION 02 — SAMPLE
// WHAT YOU GET EVERY WEDNESDAY

A weekly briefing engineered for the first hour of an incident — not the 49th.

Every Threat Brief is a triage-ready advisory: vendor attribution, exploit-chain context, IOC bundles, and a defensive playbook you can hand straight to a Tier-1 analyst. No fluff, no filler — the same format our researchers use internally.

CVE TB-0988 · CONFIRMED CRITICAL

Confluence Data Center — Authentication Bypass via Setup Endpoint

CVE-2024-XXXX-YYYY CVSS 9.8 2024-10-23

Summary. Atlassian Confluence Data Center and Server fail to validate setup-token rotation in the /setup endpoint, allowing unauthenticated attackers to forge an admin session and execute arbitrary setup actions, including SMTP reconfiguration and user-import.

Exploit chain. Endpoint enumeration → token-state inspection via timing oracle → admin session forge → persistent SMTP relay for credential phishing.

In-the-wild signal. Two customer SIEMs logged probe traffic from AS4134 backbone ranges 36h before public disclosure.

// INDICATOR (STIX 2.1)
indicator-pattern: [file:hashes.'SHA-256' = 'a31f...c902']
malware-classification: trojan.linux.confluence-bypass
first-seen: 2024-10-21T03:14:00Z
// PATCH: Atlassian 8.5.6 / 8.7.2 / 8.8.1 // COORDINATED: 14 days, 3 vendor calls
// SECTION 03 — BY THE NUMBERS
// 2024 OPERATIONAL METRICS · AUDITABLE

The lead time, the patch rate, the response time — all of it is measurable.

19h
// LEAD VS NVD PUBLICATION
median across 612 advisories published in 2024
96%
// VENDOR-CONFIRMED CVEs
1,840+ catalogued since founding; 4.7% false-positive rate cited
230+
// COORDINATED PATCHES
disclosure pipeline w/ Microsoft, Apple, Google, Huawei, Atlassian
312
// NAMED APT & EXPLOIT VENDORS
only continuously updated DB of Chinese-nexus groups in the industry
9/10
// DOMESTIC SIEM INTEGRATIONS
read-only feed integrated with top 9 of 10 PRC SIEM platforms
12min
// ON-CALL RESPONSE
median time-to-acknowledgement for enterprise hotline tickets
// SECTION 04 — TIERS
// PRICING · USD · BILLED ANNUALLY

Three tiers. No seat-count gotchas. Enterprise quotes ship with a procurement-ready MSA.

All plans include the full archive (1,840+ CVEs since 2017), the weekly Threat Brief, the APT database, and STIX 2.1 export. The difference is delivery surface, on-call depth, and redistribution rights.

TIER 01

Individual

$1,490/yr

For independent researchers, journalists, and senior analysts who need the raw feed without team seats.

  • Weekly Threat Brief (PDF + JSON)
  • Full CVE & APT database access
  • STIX 2.1 & MISP export
  • Email support, 48h response
  • 1 named user, single IP binding
  • Archive access: 2017 → present
Start individual →
TIER 03

Enterprise

Quote/yr

For organizations running their own MSSP, CTI product, or red team — volume redistribution, on-premise mirror, and a direct line to research.

  • Everything in Team
  • Unlimited seats, multi-region
  • On-premise feed mirror (Air-gap option)
  • Redistribution rights inside your org
  • 24/7 on-call hotline · 12-min median
  • Named researcher · quarterly briefing
  • Custom SLAs, MSA, DPA, security review
Talk to research →
// FEATURE MATRIX
FEATURE PARITY AT A GLANCE
CAPABILITY INDIVIDUAL TEAM ENTERPRISE
Weekly Threat Brief (PDF + JSON)
Full CVE archive since 2017
APT & exploit-vendor database
STIX 2.1 / MISP export
TAXII 2.1 / REST API
SIEM native apps
Named seats1up to 25Unlimited
24/7 hotline · 12-min median
On-premise feed mirror
Redistribution rights
Named researcher + briefing
Inside ZeroDayCN's Shanghai research operations
// RESEARCH OPS · PUDONG, SHANGHAI SUITE 1804, TOWER B · LUJIAZUI RING RD
// SECTION 05 — ENTERPRISE
// VOLUME LICENSING · ON-PREMISE · CUSTOM SLA

If a checkout button won't satisfy your procurement team, start a conversation here.

Enterprise buyers — MSSPs, governments, Tier-1 telcos, CTI vendors — typically need volume licensing, on-premise feed delivery, air-gapped mirror, or a custom response SLA. Tell us roughly what you need; a senior researcher replies within one business day.

  • // 2,100+ SOC teams58 countries
  • // Read-only feed integrated into9 of top 10 domestic SIEMs
  • // On-call hotline12-min median response
  • // Coordinated disclosure withMicrosoft, Apple, Google, Huawei

// We reply within 1 business day. By submitting you accept our research-disclosure terms.

// SECTION 06 — FAQ
// WHAT BUYERS ASK BEFORE SIGNING

The four sharp questions a SOC lead or CISO will ask first — answered in writing.

01

Where does the data actually come from?

A combination of in-house vulnerability research from our team of 11 senior researchers, a private disclosure pipeline coordinated with Microsoft, Apple, Google, Huawei and Atlassian security teams (230+ patches coordinated to date), customer telemetry from 2,100+ enterprise SOC integrations, and dark-web / gray-market monitoring within Chinese-language forums and reseller channels. Every advisory is graded by source confidence and attribution confidence. We do not republish NVD entries — our lead time over NVD is part of the product.

02

What's your false-positive rate, and how is it measured?

We cite a 4.7% false-positive rate across all catalogued CVEs since 2017 (1,840+ entries, 96% vendor-confirmed). False positive is defined as: a CVE we flagged as "in-the-wild exploit" that was never corroborated by independent vendor telemetry, customer sensor, or sample submission within 90 days. We do not claim zero false positives — that claim would not survive a procurement security review. Every advisory carries an explicit confidence tier (Confirmed / High / Medium / Low) so your team can route by tier.

03

How is the feed delivered — and what export formats are supported?

Individual tier: weekly PDF + JSON via authenticated download. Team tier adds TAXII 2.1 collection, REST API with webhook push, and native apps for Splunk, Elastic, QRadar, and the top 9 Chinese SIEM platforms. Enterprise tier adds an on-premise mirror (HTTPS or air-gapped) plus STIX 2.1, MISP-compatible JSON, and CSV. Every advisory ships as a discrete object with provenance metadata — your SOAR can route by CVE, APT, sector, or confidence tier without manual parsing.

04

Can we cancel, and what are the disclosure-ethics boundaries?

Annual subscriptions can be cancelled at the end of the term with 30 days' notice; mid-term refunds are pro-rated after the first 60 days. We do not sell exploit binaries, 0day, or hacking-as-a-service — the Threat Brief is a defensive intelligence product. All disclosures follow a 90-day coordinated-disclosure default (configurable per vendor), and we have never publicly disclosed a vendor-confirmed vulnerability before patch availability. Enterprise buyers can request our full responsible-disclosure charter, MSA template, and security-review packet before signing.

// STILL EVALUATING

Read the free weekly Threat Brief first — 74,000+ security professionals already do.

No paywall, no email gate. Sample the editorial depth and decide whether the format fits your team.

Read the free brief →