A zero-day vulnerability is a bug in a piece of software. Of course, all complicated software has bugs, so why should a zero-day be given a special name? A zero-day bug is one that has been discovered by cybercriminals but the authors and users of the software don’t yet know about it. And, crucially, a zero-day is a bug that gives rise to an exploitable vulnerability.
Google is announcing its sponsorship of the Secure Open Source (SOS) pilot program, run by the Linux Foundation, which financially rewards developers for enhancing the security of critical open source projects.