I wonder if this whole article was written by an LLM. I've never heard anyone worth listening to use the term 1day. I've always just called them vulnerability. I've actually just recently taken to calling them bugs in normal conversations.
but while I'm ranting, I'm gonna rant about the widening of 0day. it's not synonymous with vulnerability it's when shell code or other POC payload is 'released' as the disclosure. Usually when it's release is immediately following an update. Especially when that update is 'Patch Tuesday.' It also should be scary, "you can make the app exit/crash" doesn't really count, but I'm not usually that pedantic. Meaning, if you disclose something to a vendor, give them 90 days, then publish the CVE but not shellcode, the best you have in a "90day" but even then, no POC exploit, no anything-day.