"Half-Day": 0-Day in the Age of AI

aaronsdevera1 pts0 comments

Introducing the Half-Day: 0-Day in the Age of AI — Margin Research

Introducing the Half-Day: 0-Day in the Age of AI

Introducing the Half-Day: 0-Day in the Age of AI

by Claudia d'Antoine

Aug 19, 2026

You are entering a world somewhere between 0 and 1. It is a world that feels unsettling, strange, and new. There are often hallucinations. Bugs are flying everywhere. Are you in the twilight zone? No. You are working in offensive cybersecurity in 2026.<br>The future of the offensive cybersecurity marketplace in the age of AI remains one of the most hotly debated topics today. Everywhere you look, there are prominent stories about a glut of AI-generated vulnerabilities, rogue models escaping their tethers to hack prominent targets, and the general expectation that our industry will quickly be overrun by frontier models. Conversely, many hackers are using this as an opportunity to churn out the best research of their lives at a pace that far outstrips what they could have done previously.<br>In our new world, despite this great research, 0-days become n-days much more quickly.<br>In fact — they should.<br>Many of the best offensive researchers in the industry now work for the likes of Anthropic and OpenAI and are training aggregate cyber models on their brains which previously functioned in silos. Naturally, the most popular software and hardware targets will be the best targets to train against. After all, these titans of hacking are expert in them and the targets underpin much of the Western world’s most critical work. Form follows function.<br>A question: What happens when a market that places a high value on exclusive access to hyper-specialized products and talent is now dealing with autonomous competition that learns continuously from some of the greatest minds in that industry?<br>To begin to answer this question, we must acknowledge a new kind of product in our midst. If an exploit is technically 0-day but it is currently located in a surface where AI-enabled vulnerability discovery is now the norm, then I argue it is not pure 0-day. Welcome, to the world of the half-day.<br>Half-Day Defined<br>A half-day still has value in the offensive marketplace; after all, it is technically an 0-day. The manufacturer does not know about it and cannot, as a result, patch it. But the half-day exploit is in a surface that is so heavily scrutinized by frontier models that its lifespan must be assumed to be shorter and contaminated by association with these models. Before an offensive researcher is even able to find a vulnerability or exploit it, it is already “halfway to n.”<br>Since the dawn of cyber warfare, a 0-day exploit has been considered valuable because the assumption is made that only the supplier and the customer know about its existence. The utility of the vulnerability relies on a customer’s need for access to whatever that exploit provides and their level of confidence that whoever or whatever is being exploited is unaware of their risk.<br>The traditional transition of 0-day to n-day provides us with some insight into how half-days introduce new risk to the marketplace. As soon as a CVE implicating the 0-day exploit is reported, the offensive customer naturally contemplates some hypothetical future scenarios. It is possible that the manufacturer never patches the vulnerability in the software or firmware version of interest. It is also possible that the manufacturer foregoes patching altogether. In those hypothetical futures, the customer could still use the now n-day to continue gaining access to the target. We could look upon this population of vulnerabilities as “historic half-days” since they are publicly disclosed but functionally do not differ from the 0-day from which they sprang. They still offer value. All that changes here is the risk profile for those running an offensive operation.<br>Thus, the “modern half-day” forces offensive customers to have risk tradeoff conversations much earlier in the lifecycle of an exploit (Figure 1). In order to begin making decisions faster and with greater confidence, those running cyber operations must have a firm understanding of exploits as not only a technical product, but also as a weapon with an indeterminate expiration date.<br>Figure 1: Proposed model for lifecycle of vulnerability research from initial analysis to exploit patching. The timepoints in the model are denoted T_X. Product names directly stem from certain portions of the lifecycle. (Source: Margin Research)Product Assumptions<br>The basic technical product assumptions of an exploit can be summarized with the classic “bring me a rock” business analogy. The rock here is an exploit.<br>The current lifecycle of research begins when a customer says, “bring me a rock.” Customers generally do not specify what rocks they want and cannot inspect the rocks without first purchasing them. The longer they wait to purchase, the less likely the rock will be of use to them. In turn, suppliers hunt for, find, and polish an awesome rock and then...

half exploit offensive research world models

Related Articles