The document describes an empirical study that identifies zero-day attacks from data on 11 million real-world hosts. The study finds 18 vulnerabilities exploited before public disclosure, with 11 being previously unknown zero-day attacks. On average, a zero-day attack lasts 312 days and affects few hosts, though some high-profile attacks like Stuxnet spread more widely. After disclosure, the number of malware variants and attacks increase by up to 5 orders of magnitude as cyber criminals start exploiting the now public vulnerabilities on a larger scale before patching occurs.