Vulnerabilities

Google: Half of 2025’s 90 Exploited Zero-Days Aimed at Enterprises

Less than half of the total zero-days have been attributed to a threat actor, but spyware vendors and China are in the lead. 

Zero-day

Google’s Threat Intelligence Group (GTIG) reported on Thursday that 90 zero-day vulnerabilities were exploited in the wild in 2025, and an increasing percentage were aimed at enterprises.  

In comparison, the company tracked 78 zero-days in 2024 and 100 in the previous year. 

The number of zero-days seen by Google every year

In 2025, Microsoft accounted for 25 of the zero-days, followed by Google (11), Apple (8), and Cisco (4).

Operating systems (both mobile and desktop) were the most targeted, increasing from 40% of the total in 2024 to 44% in 2025. 

Mobile device zero-days also increased, from 9 vulnerabilities in 2024 to 15 in 2025. However, in the case of mobile exploits, Google noted that in many cases three or more flaws were chained to achieve a single goal.  

The number of browser zero-days continues to drop. While this can be an indicator of stronger browser security, it can also suggest that attacks are more sophisticated and harder to spot. 

Zero-day attribution in 2025

The exploitation of 42 of the 2025 zero-days has been attributed to a threat actor, with commercial surveillance vendors (CSV) taking the lead for the first time. These spyware makers exploited 15 of the vulnerabilities and three other flaws have been marked as ‘likely CSV’.

State-sponsored cyberespionage groups account for 12 of the zero-days and three additional vulnerabilities are also believed to be in this category. A significant percentage of these flaws has been linked to China. 

Advertisement. Scroll to continue reading.

“Consistent with the trend we have observed for nearly a decade, in comparison to other state sponsors, PRC-nexus groups remained the most prolific users of zero-day vulnerabilities in 2025. These groups, such as UNC5221 and UNC3886, continued to focus heavily on security appliances and edge devices to maintain persistent access to strategic targets,” Google said in its report.

Enterprises increasingly targeted

Google highlighted that 43 of the zero-days, representing nearly half of the total, affected enterprise technologies, which is an all-time high. 

Many attacks were aimed at networking and cybersecurity appliances with the goal of gaining initial access.

“Increased exploitation of security and networking devices highlights the critical risk that can be posed by trusted edge infrastructure, while targeting of enterprise software exhibits the value of highly interconnected platforms that provide privileged access across networks and data assets,” Google explained.

Google believes AI will be increasingly used in 2026. While threat actors will leverage AI to accelerate vulnerability discovery and exploit development, defenders can use it to enhance security operations, including proactively discovering unknown vulnerabilities and neutralizing them before they are weaponized. 

Additional information and insights can be found in Google’s full report.

Related: Nation-State iOS Exploit Kit ‘Coruna’ Found Powering Global Attacks

Related: Cisco Warns of More Catalyst SD-WAN Flaws Exploited in the Wild

Related: Android Update Patches Exploited Qualcomm Zero-Day

Related Content

Vulnerabilities

Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.

Vulnerabilities

An improper authentication bug allows attackers to escalate their privileges and escape containers.

Vulnerabilities

The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.

Vulnerabilities

Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.

Mobile & Wireless

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.

Mobile & Wireless

Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.

Endpoint Security

A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device.

Vulnerabilities

The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version