Although catchy as a phrase, "zero day" means no more than that the bad folks found an exploitable vulnerability before the good folks did. Given the prevalence of exploitable vulnerabilities, they're nothing special - indeed they're inevitable. Exploiting them before they're recognised and fixed is also inevitable, given that the first finder has an advantage. Our problem as defenders is the increasing scale of the vulnerability space, making it ever harder to investigate the problem. And I expect that the bad folks have rather more (and possibly better organised) resources for finding the vulnerabilities, as there's potential for serious monetary returns for them.

