
Trend Micro's Zero Day Initiative marks two decades of impact
The ZDI claims the position as the world's largest vendor-agnostic bug bounty programme, having helped to identify and disclose thousands of software security flaws since its founding in 2005. According to data referenced by the company, the ZDI contributed to the responsible disclosure of 73 per cent of all reported vulnerabilities in 2024, exceeding the total from all other participating vendors combined.
The bug bounty programme incentivises security researchers globally to uncover zero-day vulnerabilities in widely used products and to submit them in exchange for financial rewards. By working with vendors ahead of public disclosure, the ZDI aims to close security gaps before malicious actors can exploit them.
One of the notable features for Trend customers is early access to virtual patches for zero-day threats. These interim security fixes are distributed, on average, over two months in advance of the release of official vendor updates. This provides an extended window of protection as vendors work to develop and test their formal patches. "Our top priority is empowering our customers to take a proactive approach to cybersecurity. The Zero Day Initiative is one of the best tools we have to stay ahead of cybercriminals, and it's one of a kind. Nobody else in the industry can protect their customers as far in advance as we do."
This was stated by Mick McCluney, ANZ Field CTO at Trend Micro, who emphasised the significance of proactive approaches enabled by the ZDI's work.
The initiative's history began in 2005 when it was established by TippingPoint, then a division of 3Com. Initially, it focussed on bringing together the security research community, providing a framework for researchers to report zero-day bugs responsibly by offering financial incentives. Two years later, the Pwn2Own competition was launched, challenging teams of researchers to discover vulnerabilities in specific software and operating system categories against the clock.
Trend Micro took over the ZDI in 2016 following its acquisition of TippingPoint. Today, the programme comprises more than 450 dedicated researchers across 14 global threat centres, supported by a broader community of over 19,000 vulnerability researchers.
The ZDI has played a role in several major security events over the past two decades. For example, its researchers uncovered issues with a patch intended to fix a LNK file vulnerability exploited by the Stuxnet worm, prompting Microsoft to develop a subsequent patch. Similarly, collaborative research with Microsoft led to the award of USD $125,000 to original ZDI researchers for identifying a method to bypass Internet Explorer's defences; this sum was subsequently donated to charity, and the technique went on to earn a patent.
Other notable research successes include the identification of two zero-day vulnerabilities in Apple's QuickTime for Windows product, which resulted in Apple discontinuing support for the software and ZDI advising users to uninstall it. The ZDI's investigative output has also contributed to disrupting covert operation campaigns such as Black Energy APT, which has targeted Ukraine on multiple occasions. In 2023, a researcher associated with the ZDI was recognised with a Pwnie award for "most under-hyped research" after discovering a previously unreported exploit technique called activation context cache poisoning.
The ZDI's operations not only benefit Trend Micro's client base but also contribute to improved security outcomes more broadly, by ensuring that vulnerabilities in widely used products are fixed before hostile actors can take advantage. The bug bounty scheme is credited with encouraging vendors to implement more robust security practices and to address security flaws ahead of public exploitation.
As one of the larger vendor-neutral vulnerability research communities, ZDI continues to rely on its global network of researchers, ethical hacking competitions such as Pwn2Own, and partnerships with vendors, to fulfil its remit of identifying and coordinating the remediation of critical security flaws.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Scoop
a day ago
- Scoop
From Trade Gains To AI Dividends: APEC's Next Growth Play
Cooling Growth, Lingering Risks APEC's growth slowed to 3.5 percent in the first quarter of 2025, down from 3.8 percent a year earlier, reflecting weaker demand and heightened global uncertainty. Early trade gains, driven by businesses rushing to ship goods before new trade restrictions take effect, gave the economy a short-term boost. However, sustained momentum requires consistent reforms and renewed investment in productivity. Regional growth is now projected at 3.0 percent in 2025 and 2.9 percent in 2026, slightly above the May 2025 APEC Regional Trends Analysis forecasts, but trailing behind the rest of the world, which is expected to grow by 3.4 percent in 2026. Despite the emergence of new technologies and the relative resiliency of greenfield investments in productivity-enhancing projects, downside risks are expected to dominate, marked by policy uncertainty, geopolitical tensions, and elevated debt levels as legacy from the pandemic. Central Banks Balance Support and Stability Inflation averaged 2.5 percent across APEC in the second quarter of 2025, lower than a year ago and easing pressure on households and businesses. In response to downside risks, the majority of central banks have trimmed policy rates to help spur economic activity. Other APEC economies have kept their policy rates unchanged, maintaining a cautious stance amid potential price pressures and external shocks. In recent months, oil prices edged higher as energy markets responded to shifting supply dynamics amid geopolitical instability. In contrast, food prices remained broadly stable, reflecting mixed movements across key commodity groups. Trade Gains Reflect Precautionary Activity Merchandise trade in APEC posted solid growth in the first quarter of 2025 as businesses moved shipments forward, hedging against possible new trade restrictions. Export and import values rose by 5.0 percent and 7.7 percent, respectively, while volumes climbed even faster, by 7.0 percent and 7.9 percent. This expansion suggests that early-year trade gains were driven by risk-mitigation strategies rather than a sustained rebound in demand, and may taper off as temporary factors fade. Trade momentum remains highly sensitive to policy developments. Services trade told a different story. Export growth slowed to 6 percent in the first quarter of 2025 from 11 percent a year earlier. Travel services exports contributed to the decline as it decelerated sharply to 9 percent from 30 percent over the same period even as transport and other commercial services increased. Trade policy uncertainty, although easing from earlier peaks as negotiations gain traction and trade deals begin to take shape, has remained well above historical norms. In fact, financial markets reflect amplified investor concerns, with gold prices near record highs and demand for safe-haven assets is strong. Emerging Opportunities: Resilient Greenfield Investments and AI Potential Although FDI inflows have moderated, falling from USD 1,157 billion in 2021 to USD 956 billion in 2024, greenfield investment remains a bright spot. Announced greenfield projects in APEC reached USD 595 billion in 2024, up 56 percent compared to the level in 2021, underscoring investor confidence in new capacity and innovation. Sustained investments in innovation and digitalization signal an ongoing shift toward productivity-enhancing sectors, which bodes well for APEC's growth trajectory. Digital technologies, particularly artificial intelligence (AI), are poised to amplify these gains. Modelling estimates suggest that, when treated as a productivity shock, AI adoption could raise GDP by 1.3 to 3.9 percent. On average, APEC economies already score above global averages on AI readiness, highlighting strong potential to capture digital dividends. Still, digital capacity remains uneven across the region, with persistent gaps in digital skills limiting broader adoption. Closing these gaps will be key to unlocking AI's full economic potential and ensuring that its benefits reach all people, across communities, sectors and economies. Policy Priorities: Strengthening Confidence, Harnessing Digital Gains With growth moderating and uncertainty still elevated, APEC economies must walk a fine line, preserving near-term macroeconomic stability while advancing structural transformation. Tackling current headwinds and fostering innovation to lay the foundation for sustained growth that benefits the entire population will require coordinated policy action across three key areas: Inclusive Structural Reform: Advance labor market reforms and scale up digital skills development to strengthen human capital and ensure that the benefits of AI-driven productivity are widely shared. Adaptive Economic Policy: Maintain flexible macroeconomic frameworks, rebuild fiscal space, and channel investment toward sectors that boost productivity to support adjustment and resilience. Coordinated Regional Cooperation: Use APEC's platform to align responses to shifting global environment, reinforce regional economic stability, and deepen integration through sustained dialogue. As APEC economies navigate persistent global uncertainty, it is important to strike a careful balance between policy responses that yield short-term gains and structural reforms that drive enduring momentum and productivity growth. Regional cooperation is indispensable in today's uncertain environment. APEC as a regional platform must continue to foster open dialogue, align policies, and coordinate responses to shared challenges. Clear direction and consistent collaboration are vital to managing risks and supporting durable, innovation-driven growth.


Techday NZ
a day ago
- Techday NZ
Certes launch quantum-safe technology to nullify stolen data
Certes has announced the availability of a quantum-safe data protection approach that aims to render stolen data useless to attackers. With cybercrime costs predicted to exceed USD $10.5 trillion by the end of 2025, the cybersecurity sector faces growing challenges, especially as quantum computing rapidly evolves. Certes has stated that its solution is designed to address this escalating threat by making intercepted data indecipherable even to powerful quantum-enabled adversaries. The company's analysis compares modern cyberattacks to advanced bank heists, where criminals focus on stealing sensitive data, especially while it is in transit. Traditional security measures, according to Certes, typically aim to keep threat actors out via perimeter defences. However, the firm's new focus is on neutralising the value of any data that is intercepted, protecting it throughout its lifecycle. "You don't stop a heist by just locking the doors; you make sure the robbers leave with nothing they can use. That's exactly what we're doing. Even if attackers gain access, the data is quantum-protected, scrambled, and completely useless to them," said Simon Pamplin, CTO at Certes. Certes reports that more than 80% of data breaches occur during the transmission of data, and 82% take advantage of weaknesses in either perimeter or internal systems. This vulnerability, combined with the increasing sophistication of cybercriminal tactics, means that conventional security postures may become obsolete as quantum computing capabilities advance. The company's patented Data Protection and Risk Mitigation (DPRM) solution is built on quantum-safe algorithms and provides end-to-end data security. This includes data in use, at rest, and in transit. Certes distinguishes its solution from existing tools by focusing on making the data itself secure, rather than relying on the strength of the surrounding network perimeter. Simon Pamplin said, "We're preparing clients for the next era of cybersecurity; one where perimeter defences won't cut it. Quantum resilience is critical, but so is the shift in mindset: it's not just about keeping data safe, but making sure that if cybercriminals ever access it, it's useless to them." Certes extends the analogy of dye packs used by banks to thwart robbers. Just as dye packs make stolen banknotes unusable, Certes aims to ensure that attackers cannot benefit from intercepted data, as it remains encrypted and undecipherable. The firm describes its approach as providing a digital equivalent of a dye pack, neutralising the value of the data even if it is physically stolen. Organisations across several sectors, including finance, healthcare, defence, and government, are currently being advised by Certes on post-quantum data strategies. These measures are intended to protect against both current and future threats as quantum capabilities become more widely available. Certes' expertise is being leveraged to help these institutions safeguard essential assets and remain compliant with evolving security regulations. The company highlights that its technology is in use by over 1,000 clients in nearly 100 countries. Certification standards such as FIPS 140-2 and Common Criteria EAL4+ are in place for its security products, according to company background materials. Certes concludes that though data breaches are becoming more common, organisations now have the means to ensure that any information stolen is effectively rendered valueless, reducing the overall impact and risk associated with inevitable breaches.


Techday NZ
2 days ago
- Techday NZ
Trend Micro unveils Agentic SIEM to automate & streamline security
Trend Micro has launched Agentic SIEM, an artificial intelligence-powered security solution designed to address the longstanding challenges faced by traditional Security Information and Event Management (SIEM) systems. SIEM challenges Security Information and Event Management systems are relied upon by organisations to detect and respond to cyber threats. However, users of traditional SIEM solutions regularly cite challenges around high costs, operational complexity, alert overload, and passive data storage. Manual setup and static parsing also reportedly hinder effective management of the increasing variety and volume of contemporary data sources. The newly-announced Agentic SIEM deploys agentic AI to automate and improve key tasks, acting independently to reduce the number of alerts and streamline the workload of security teams. The platform is designed from the outset to utilise AI-driven capabilities in detecting, learning from, and responding to threats with minimal human intervention. Integration and scale Agentic SIEM supports over 900 data sources from launch, with integration options not only for Trend's proprietary XDR security sensors but also for third-party telemetry. This aims to provide a more comprehensive view of the security environment. The solution also offers three-day onboarding for new log types, with an aim to reduce this further to three hours by 2026. Data retention features include up to seven years of archival storage and two years of analytics retention, supporting both compliance and threat hunting requirements. Agentic SIEM is built to complement Trend's digital twin technology, enabling proactive risk mitigation across sectors such as healthcare, supply chains, predictive maintenance, and smart infrastructure. Industry perspective "As the cybersecurity stack increasingly becomes AI driven, the security data layer must evolve to support data-hungry agentic capabilities, including infusing agentic AI into core SIEM functions. Trend Vision One Agentic SIEM enters the SIEM market at a pivotal time, leveraging Agentic AI from the ground up to drive speed, performance, and a new level of risk-driven, contextual insights to rapidly mitigate cyber threat activity." This observation from Dave Gruber, Principal Cybersecurity Analyst at ESG, reflects current industry expectations for greater automation and intelligence in responding to security challenges. Workload automation The system employs agentic AI to map and optimise data flows swiftly, automating tasks that previously took security teams weeks to configure and manage. Trend Micro states that this immediate reduction in manual effort allows security professionals to concentrate on strategic and analytical work instead of routine monitoring and response. "Agentic SIEM is a major stepping stone to our long-term vision for full, AI-driven SecOps. It's a future in which security teams will have more time to work on strategic tasks, safe in the knowledge that our agentic AI has their backs. With this launch, Trend is once again laying down a marker for cybersecurity innovation and global market leadership." This was the statement from Mick McCluney, ANZ Field CTO at Trend. Use cases According to Trend Micro, Agentic SIEM can facilitate a range of use cases including automated threat detection and response, streamlined compliance support, and enhanced incident investigation. By performing autonomous data analysis, correlating information from multiple sources, and retaining extensive historical data, the system aims to reduce investigation timeframes and improve accuracy. The combination of Agentic SIEM with digital twin technology is intended to bolster cyber resilience and compliance further. Trend Micro points to prospective benefits in environments where virtual models and real-time data integration can inform risk mitigation, such as in healthcare operations, supply chain security, smart building management and predictive maintenance scenarios.