About Trend Zero Day Initiative™ (ZDI)

Our Mission

Trend ZDI was created in 2005 to encourage the reporting of 0-day vulnerabilities privately to  affected vendors by financially rewarding researchers. At the time, some in the information security industry perceived those who discovered vulnerabilities as malicious hackers with harmful intentions. Some still feel that way. While skilled, malicious attackers do exist, they remain a small minority of the total number of people who discover new software flaws.

Our mission

Incorporating the global community of independent researchers also augments our internal research organizations with  additional zero-day research and exploit intelligence. This approach coalesced with the formation of  Trend ZDI. The main goals of  Trend ZDI are to:

icon

Amplify team efficacy by creating a virtual community of skilled researchers.

icon

Encourage  responsible reporting of zero-day vulnerabilities through financial incentives.

icon

Protect Trend Micro customers from harm until the affected vendor is able to deploy a patch.

Today, Trend ZDI represents the world’s largest vendor-agnostic bug bounty program. Our approach to the acquisition of vulnerability information is different than other programs. No technical details concerning the bugs are released publicly until the vendor mitigates the issue. It enables Trend to extend its internal research teams by leveraging the methodologies, expertise and time of external researchers while protecting customers as affected vendors work on a patch.

Independent researchers from around the globe provide us with exclusive information about unpatched vulnerabilities. Our internal researchers and analysts validate the issue in our security labs and make a monetary offer to the researcher. If they accept the offer, a payment will be promptly made. Submitting through the Trend ZDI eliminates the need for researchers to track bugs with vendors. We make every effort to work with vendors to ensure they understand the technical details and severity of a reported security flaw, which leaves researchers free to find other bugs.

You have these threat researchers that I can't hire that are finding things so that I can sleep better at night - they also make the world a better place.

Jason Cradit

CIO, CTO Summit Carbon

Our disclosure policy ensures certain details will be made public should the vendor take too long to address the vulnerability. This allows defenders to take action to protect their resources even if no patch is available. In no cases will an acquired vulnerability be "kept quiet" because a product vendor does not wish to address it. Protections are made available through Trend products regardless of vendor response. In 2024, these protections were released to Trend customers an average of 90+ days prior to the vendor patch. This policy further reassures researchers that in no case will any of their discoveries be "swept under the rug". It also reassures product vendors that there is a professional and standard set of guidelines they can expect to be utilized throughout the disclosure process.

Once a patch is ready from the affected vendor, Trend ZDI works collaboratively with the vendor to notify the public of the vulnerability through a joint advisory that provides full credit to the originating researcher unless the researcher chooses to remain anonymous. This practice allows us to facilitate the protection of a customer base larger than our own.

Trend ZDI event

Without Trend ZDI, many vulnerabilities would continue to remain behind closed doors or be sold to an underground marketplace and used for nefarious purposes. Trend ZDI’s long-standing relationships with software vendors and the research community help influence the importance of security in the product development life cycle, leading to more secure products and more secure customers.

Over the last 20 years, Trend ZDI disclosed more than 15,000 vulnerabilities while providing unique threat intelligence to the Trend platform while also bolstering the attack surface for software and services that impact everyone.

Get in touch

General Inquiries

zdi@trendmicro.com

Find us on X

@thezdi

Find us on Mastodon

Mastodon

Sensitive Email Communications

PGP Key