Skip to content
feed: live
>_0dayNews
$ whoami

Who we are.

0dayNews is an independent newsroom covering vulnerabilities, exploits, and the breach news that follows from them. We launched in 2026 to fill a specific gap: fast, sourced, jargon-aware reporting on CVEs and active exploitation, written for security practitioners and the technically curious — without the costume-first, credibility-second tone that plagues a lot of infosec media.

~/about/masthead.conf
Publisher
0dayNews Desk
Byline
"0day News Desk" (legacy) & named editors
Jurisdiction
United States
Ownership
Independent — no parent company, no investors, no government funding

Mission & coverage priorities

Vulnerability disclosure moves fast, and the gap between "a CVE exists" and "people are already exploiting it" can be hours, not days. Vendor advisories are accurate but slow and scattered across dozens of separate portals. Security Twitter is fast but noisy. We sit in the gap: fast, sourced, skeptical, and focused only on what's verifiable and what it means for defenders. In order:

  1. 01
    CISA KEV catalog additions
    Every new entry in the Known Exploited Vulnerabilities catalog, tracked within 24 hours of publication.
  2. 02
    Actively exploited zero-days
    Vulnerabilities exploited in the wild before a patch exists, regardless of KEV status.
  3. 03
    High-impact CVEs
    Critical and high-severity flaws in widely deployed enterprise software, edge devices, and infrastructure.
  4. 04
    Breach news
    Confirmed incidents tied to specific vulnerabilities, with sourcing back to the affected organization or a named outlet.
  5. 05
    Patch Tuesday & advisory roundups
    What shipped, what's critical, what to prioritize.

How we report on vulnerabilities

SOURCE-FIRST

Every claim links to a primary source — CISA, NVD, the affected vendor's advisory, or named security researchers/firms who disclosed the issue.

NO EXPLOIT CODE

We describe vulnerabilities, their mechanism at a conceptual level, and their real-world impact. We never publish proof-of-concept exploit code, weaponized payloads, or step-by-step attack instructions.

RESPONSIBLE DISCLOSURE

When covering a vulnerability not yet publicly disclosed or patched, we hold publication until the vendor has had a reasonable opportunity to respond. Full policy on the disclosure page

CORRECTED, NOT SILENCED

When we get something wrong — a CVSS score, a patch date, a vendor name — we say so at the top of the article, dated and signed. See the corrections log

~/about/how-we-work.md

How the newsroom works

0dayNews is a small newsroom under direct editorial review. Our editorial process uses a range of research tools — including AI-powered software — to scan public advisories (CISA, NVD, vendor security bulletins), extract key technical details, and draft initial copy. Every published article is reviewed and fact-checked by the editor before it appears on the site, and every factual claim must trace to a primary source the reader can verify — a CISA KEV entry, an NVD record, or the affected vendor's own advisory.

We disclose our tools because our readers deserve transparency. Software assists research and drafting; it is not a replacement for sourcing, judgment, or accountability. If a published article ever contains a factual error, that is the editor's responsibility.

How we're funded

0dayNews is independently owned. At launch, our only revenue source isdisplay advertising. Ads are programmatic; no editor selects, sells, or negotiates ad placements. We run no affiliate program, no sponsored posts, and no paid placements of any kind.

No editorial decision has ever been or will ever be influenced by any commercial relationship. We do not run gambling, crypto-token-promotion, or partisan-political advertising, and we do not accept payment for coverage, ever.

Ownership & structure

0dayNews is independently owned and operated under United States jurisdiction. We have no parent company, no investors, no political donors, and no government funding of any kind.

~/about/contact

General inquiries and news tips, responsible-disclosure coordination, and takedown requests — full contact options on the contact page. We do not sell user data, period.