Skip to content
Sedat Özdemir

Posts on zero-day

13 posts on zero-day. Notes from public sources and my own test lab.

Not the Backdoor, but the Front Door: Metabase and the 'Secure' Internal Tools Fallacy

A deep dive into the Metabase zero-day and why the 'internal network is safe' mindset is a dangerous myth in modern DevSecOps environments.

August 10, 2026·4 dk readdevsecopsmetabasesizmatesti

Trojan in the Mailbox: Zimbra and the Invisible Leak

A deep dive into why enterprise mail platforms like Zimbra remain a goldmine for attackers and how DevSecOps can mitigate zero-day risks.

July 27, 2026·4 dk readaptdevsecopssiberguvenlik

Saatli Bombayı Duymak: Zero-Day Gerçeği ve Savunmanın Görünmez Cephesi

Yazılım dünyasının en büyük kabusu: Sıfırıncı gün. Peki, daha kimsenin bilmediği bir açığa karşı nasıl savunma yapılır? Gelin, bilinmeyenin peşine düşelim.

July 10, 2026·4 dk readexploit-developmentred-teamsavunma

Jumping to Address 0x41414141: What Do You Do When the Patch Isn't Out Yet?

Seeing 0x41414141 in the EIP register means you're already past the 'get well soon' phase. Let's dive into the anatomy of zero-days and how to survive the gap before a patch is released.

July 1, 2026·4 dk readdefensive-securityexploitred-team

Ticking Time Bomb: The Zero-Day Chase and the False Security Illusion of Automated Tools

Relying on 'Enterprise' scanners to sleep soundly? We need to talk. Here's why automated tools fail against Zero-days and why logic errors are the real silent killers.

June 25, 2026·4 dk readexploitredteamsavunmastratejileri

The Ticking Bomb You Can’t Hear: A Survival Guide for Zero-Day Chaos

In the world of cybersecurity, some threats are invisible until they strike. Let's talk about the 'dark matter' of our industry: Zero-Day vulnerabilities, and how to survive when the clock hits zero.

June 23, 2026·4 dk readcybersecurityexploitred-team

Not a Time Bomb, but a Ghostly Shadow: The Reality of Zero-Days and the Night We Wait for the Patch

A deep dive into the reality of Zero-Day vulnerabilities from a Red Teamer's perspective—why waiting for a patch is no longer a luxury and how we handle those hidden tunnels in our systems.

June 19, 2026·4 dk readdefensive-securityexploit-devred-team

When the Clock Stops: A Zero-Day Survival Guide

What happens when you face a vulnerability that doesn't even have a name yet? I'm sharing the story of a 3:00 AM wake-up call and how we handle 'ghost' threats from a Red Team perspective.

June 2, 2026·4 dk readcyber-securityincident-responsered-team

Chasing the Unknown: Zero-Day Chaos and the Vulnerabilities That Won't Wait for a Patch

A deep dive into the world of Zero-Day exploits from a Red Teamer's perspective. Learn the anatomy of an attack that bypasses traditional defenses and how we deal with invisible threats.

May 30, 2026·4 dk readexploitred-teamsiber-savunma

Fighting an Invisible Enemy: The Zero-Day Paradox and the Art of Defense

A deep dive into the world of Zero-Day vulnerabilities, why patching isn't always enough, and how we can defend against what we can't see.

May 23, 2026·5 dk readcyber-securitydefense-in-depthexploit-development

An Invisible Bullet: Zero-Days and That Fatal Gap in Memory

Zero-Days aren't just Hollywood magic; they are the result of unnoticed logic flaws or memory management slips. Let's dive into the 'Window of Exposure' and how these vulnerabilities actually work under the hood.

April 25, 2026·3 dk readcybersecuritydefense-in-depthexploit

The Shadow of the Ghost: Is Anyone Truly Safe in a Zero-Day World?

Dive into the world of Zero-Day vulnerabilities from a Red Team perspective. We explore how these invisible threats are born and why understanding the 'logic of the break-in' is the best defense.

March 28, 2026·4 dk readexploitredteamsiberguvenlik