Our standard

We publish to help defenders make better decisions. That means our test for a story is not “is this interesting?” but “does this change what someone should do?” Plenty of security news is interesting and changes nothing. We try to leave that to others.

Sourcing and verification

  • Primary sources first. Vendor advisories, CVE records, government alerts and original research take precedence over aggregated reporting.
  • Everything is linked. Each article carries the sources it drew from, so you can check our work rather than take it on trust.
  • Claims are labelled as claims. Statements from extortion groups, unverified breach listings and vendor-supplied statistics are attributed and flagged as unconfirmed where they are.
  • Commercial interest is disclosed. Where a statistic comes from a company that sells a product addressing that problem, we say so.
  • Right of reply. Where we report on a named organisation's security failure, we seek comment before publication and include their response.

Anonymous sources

We prefer named sources. We use anonymous ones where the information is in the public interest and naming the source would expose them to retaliation. Anonymous claims are corroborated before publication wherever possible, and we describe the source's position closely enough for readers to judge credibility without identifying them.

We do not disclose sources. Not to advertisers, not to the subjects of stories, and not in response to informal requests.

Vulnerability and exploit content

We report on vulnerabilities to help people defend against them. Our practice:

  • We describe impact, affected versions and mitigation. We do not publish working exploit code.
  • We follow coordinated disclosure timelines for research shared with us before public release.
  • We lead with detection and mitigation guidance rather than technical detail that is useful only to an attacker.
  • Where exploitation is already widespread, we publish promptly — withholding information from defenders does not withhold it from attackers.

Corrections

We get things wrong. When we do:

  • Factual errors are corrected as soon as we confirm them, with a note on the article stating what changed and when.
  • Developing stories carry an updated timestamp when new information is added.
  • Significant errors — anything that could have led a reader to a wrong decision — get a prominent correction notice, not a quiet edit.
  • We do not delete articles to hide mistakes.

Report an error to info@0daysecure.com. Include what is wrong and, where you can, a source for the correct information.

Editorial independence

Advertising and sponsorship pay for this publication. They do not buy coverage. Concretely:

  • Advertisers have no input into editorial decisions, timing or framing.
  • Advertisers receive no advance notice of stories and no pre-publication review.
  • We report on advertisers' security failures on exactly the same terms as anyone else's.
  • Commercial staff do not attend editorial planning, and editorial staff have no revenue targets.

Sponsored content

Where we publish sponsored content it is labelled clearly at the top of the page and in every listing it appears in, it is visually distinct from editorial, it is never written by newsroom staff, and it is excluded from the newsletter's editorial section.

Conflicts of interest

Contributors disclose financial interests, employment history and personal relationships relevant to what they cover. Where a conflict cannot be managed, the story is reassigned. Contributors do not trade securities in companies they cover.

Use of AI tools

We are a publication about technology risk, so we will be direct about this. AI tools may be used for research assistance, transcription and copy editing. They are not used to generate published articles. Every article is written, verified and signed off by a named human who is accountable for its accuracy.

Reader contact

Tips, corrections and complaints: info@0daysecure.com, or via the contact page. We read everything.