Point out such a source of malware.
I believe there is no such thing. What is zero-day from the user's point of view? Something that hit him the first time?
Consider, for example, APP.ANY.RUN. They have a great deal of files from users. How do you investigate whether they are zero-day? For some sample will be zero-day, for other vendors not.
You won't get a malware test base of many thousands in one month. Even paid malware services don't have such databases. I know, because I checked. I asked. I did the reconnaissance to even pay for it. They don't have such databases.
From our point of view, it is not the base that is important, but the REAL URLs that live a few minutes, a few hours max, and the malware is 404.
Another difficulty is that not every unknown file is malware. This is where Vendors may have the most doubt, as you have investigated it, show and proof that it is harmful!