Skip to main content

Just released: TrendAI™ Research reveals AI risks moving at machine speed

About TrendAI™ Zero Day Initiative™ (ZDI)

Bug

Celebrating 20 years strong

For two decades, TrendAI™ ZDI has empowered researchers, protected users, and shaped the future of cybersecurity through world-leading vulnerability discovery and responsible disclosure.

Our mission

TrendAI™ ZDI was created in 2005 to encourage the private reporting of 0-day vulnerabilities to affected vendors by financially rewarding researchers. At the time, some in the information security industry perceived those who discovered vulnerabilities as malicious hackers with harmful intentions. Some still do. While skilled malicious attackers do exist, they represent only a small minority of those who discover new software vulnerabilities.

Shield

Incorporating the global community of independent researchers also augments our internal research organizations with additional zero-day research and exploit intelligence. This approach coalesced with the formation of TrendAI™ ZDI. The main goals of TrendAI™ ZDI are to:

Two people looking at the tablet
Amplify team efficacy by creating a virtual community of skilled researchers
Laptop
Encourage responsible reporting of zero-day vulnerabilities through financial incentives
Protect TrendAI™ customers from harm until the affected vendor is able to deploy a patch
Protect TrendAI™ customers from harm until the affected vendor is able to deploy a patch

How it works

Today, TrendAI™ ZDI is the world's largest vendor-agnostic bug bounty program. Unlike other programs, we acquire vulnerabilities through a unique approach. No technical details about reported vulnerabilities are released publicly until the vendor mitigates the issue. This enables TrendAI™ to extend its internal research capabilities by leveraging the methodologies, expertise, and time of external researchers while protecting customers as vendors work on a patch.

Independent researchers from around the world provide us with exclusive information about unpatched vulnerabilities. Our internal researchers and analysts validate each submission in our security labs and make a monetary offer to the researcher. If the offer is accepted, payment is issued promptly. Submitting through TrendAI™ ZDI eliminates the need for researchers to coordinate directly with vendors. Instead, we work closely with vendors to ensure they understand the technical details and severity of each reported vulnerability, allowing researchers to focus on discovering new ones.

“You have these threat researchers that I can't hire that are finding things so that I can sleep better at night - they also make the world a better place.”

Jason Cradit - CIO, CTO Summit Carbon

Responsible
disclosure in action

Our disclosure policy ensures that vulnerability details are made public if a vendor takes too long to address the issue. This allows defenders to protect their environments even when a patch isn't yet available. No acquired vulnerability is ever kept quiet simply because a vendor chooses not to address it. TrendAI™ products provide protections regardless of the vendor's response. In 2025, those protections were delivered to TrendAI™ customers an average of 115 days before vendor patches were released. This policy assures researchers that their discoveries will never be swept under the rug while providing vendors with a consistent, professional framework for responsible disclosure.

Once the affected vendor has a patch ready, TrendAI™ ZDI works collaboratively with the vendor to publicly disclose the vulnerability through a joint advisory. Unless the researcher chooses to remain anonymous, they receive full credit for the discovery. This collaborative approach helps protect a customer base far beyond our own.

World Laptop

Strengthening cybersecurity worldwide

Without TrendAI™ ZDI, many vulnerabilities would remain undisclosed or be sold on underground marketplaces for malicious purposes. TrendAI™ ZDI's long-standing relationships with software vendors and the security research community have helped elevate the importance of security throughout the product development lifecycle, resulting in more secure products and better protection for customers.

Over the past 20 years, TrendAI™ ZDI has disclosed more than 15,000 vulnerabilities while providing unique threat intelligence to TrendAI Vision One™ platform and helping strengthen the security of software and services used around the world.

General Inquiries

zdi@trendmicro.com

Find us on X

thezdi

Sensitive email communications

PGP key