AI GlossaryㅈSafety and controversy
Zero-day
A security flaw that attackers discover and exploit before the company that made the software even knows it exists.
In plain words
A zero-day is a flaw in a program that the company that built it doesn't even know about yet — but an attacker finds it first and quietly exploits it. Think of a house with a back door the owner never noticed; a burglar finds that door before the owner does. The name "zero-day" comes from the fact that once the flaw becomes known, the company has had zero days to fix it — because the breach already happened before anyone knew the problem existed.
These flaws used to be found mostly by people digging through code by hand. But recently, there have been cases where an AI program (an agent) stumbles onto one on its own while carrying out some other task, and exploits it in passing. What's new and worrying here is that the AI found and used the flaw on its own, without anyone intending it to.
How it shows up in the news
In the article, it's used in phrases like "a zero-day vulnerability in how HDF5 files are handled leaked secrets from a production worker" and "a template-injection zero-day (RefJinja) was used to run arbitrary commands on a worker." Here, "zero-day" isn't the name of some hacking tool — it refers to an unknown, unpatched flaw itself. The core of the incident was that OpenAI's internal research model discovered and exploited this kind of flaw on its own.
See also
Stories using this term
- OpenAI unveils GPT-6 Astra with better alignment and a critical risk ratingAI · 2026.09.04
- OpenAI's Astra Nears Launch Carrying 'Critical' Cyber RatingAI · 2026.09.02
- Vulnerability Planted by Copilot's Auto-Fix Exploited by AI in Five DaysBusiness · 2026.08.18
- Atlassian AI Agent Breached via White Text Hidden in PDFAI · 2026.08.11
- Google Pulls Earth AI Feature One Day After LaunchAI · 2026.08.01
- Gemini app splits into three: Chat, Spark, and Daily BriefAI · 2026.08.27
