ZeroDayCN's catalog is sourced from four primary channels: an in-house honeypot array spanning 14 ISPs across mainland China and three Southeast Asian PoPs; a private sandbox cluster running daily triage of suspicious samples submitted by enterprise subscribers; a responsible-disclosure intake that has coordinated 230+ vendor patches with Microsoft, Apple, Google, and Huawei security teams; and direct research output from the team's 11 senior vulnerability researchers — alumni of Qihoo 360, NSFocus, and Pangu Lab with 140+ years of combined experience.
Each candidate CVE passes a four-stage validation pipeline before publication. First, a static and dynamic analysis pass against the in-house sandbox to confirm exploitability and reproducibility. Second, a vendor-notification handshake — we hold publication until the vendor has confirmed or 72 hours have elapsed, whichever comes first. Third, a peer review by at least two senior researchers outside the original discoverer. Fourth, a confidence rating from 1 to 5 with the rationale recorded in the advisory metadata. We cite our false-positive rate at 4.7% across the 1,840+ cataloged entries in 2024 — not zero, because zero is a lie your SOC team would catch inside a week.
The cross-reference layer between CVEs and the 312 tracked Chinese-nexus APT and gray-market exploit vendors is built and maintained by a separate team of 6 threat intelligence analysts, with attribution confidence scores reviewed quarterly. We do not assert state affiliation beyond what open-source reporting already supports, and we do not publish exploit binaries, weaponized proof-of-concept code, or hacking-as-a-service offerings. What we publish is validated intelligence — the kind that survives a SOC2 audit and a procurement review.
SIGNED
ZeroDayCN Research Desk
Shanghai · Updated quarterly
4.7%
cited false-positive rate