Skip to content

company

Zero Day Initiative

Trend Micro's bug bounty program that buys vulnerability research and coordinates disclosure of flaws with affected vendors.

Known aliases

  • TrendAI Zero Day Initiative
  • Trend Micro Zero Day Initiative
  • ZDI

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Windows DNS Server's 9.8 bug takes one unauthenticated packet to port 53

Microsoft patched CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role reachable with one unauthenticated packet to port 53. In most Active Directory shops that role runs on the domain controller, so the box answering on port 53 also holds the identity database.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence40
security4 publishers

Detections on VulnCheck's canaries climb from 50 to 360 amid Langflow, Rails exploitation

The probes read Langflow's secret key file and grep the process environment for OpenAI and AWS credentials, which puts an AI orchestration tool on the same scanning clock as the Rails file-read bug of the same week.

Perspective Coverage

4 publishers
Builder
Builder 30%
Operator
Operator 60%
Investor
Investor 10%

Reality

Evidence62
Adoption40
Hype gap+15
Incentives65
Confidence60
security3 publishers

Guest admin is enough to break out of VMware Workstation onto the host

Broadcom's VMSA-2026-0007 fixes an integer overflow in the VMXNET3 adapter and a stack overflow in HGFS, both reachable by a local administrator inside the VM, and the only remedy on offer is version 26H1u1.

Perspective Coverage

3 publishers
Builder
Builder 28%
Operator
Operator 58%
Investor
Investor 14%

Reality

Evidence80
Adoption30
Hype gap+8
Incentives60
Confidence72