Google Threat Intelligence Group (GTIG) reported tracking 90 zero-day vulnerabilities exploited in the wild during 2025, up from 78 in 2024 (and below the 2023 peak of 100). GTIG said it could directly attribute exploitation for 42 of the 90, including 18 assessed as definitively or likely used by commercial surveillance vendors (CSVs), while state-sponsored espionage groups (including PRC-, Russia-, and UAE-linked activity) continued to exploit zero-days—often prioritizing edge devices and security appliances (e.g., routers, firewalls, VPN and other perimeter technologies) to gain organizational access. The report also highlighted vendor and platform targeting patterns, with Microsoft products most frequently affected, followed by Google and Apple, and noted shifts in target categories such as fluctuating mobile-device zero-days and a decline in browser zero-days.
Google’s accompanying analysis emphasized that, for the first time in its tracking, attributed CSV exploitation exceeded traditional state-sponsored cyber-espionage attribution, reflecting a broader trend of commercial exploit capabilities being productized and used by a wider set of customers. Separate commentary on exploitation timelines argued that the window between disclosure and exploitation has rapidly compressed—citing a “Zero Day Clock” dataset built from thousands of CVE-to-exploit observations and additional findings (e.g., a material share of known-exploited vulnerabilities being weaponized on or before CVE publication)—reinforcing that defenders should assume faster weaponization and reduced patching lead time for high-value targets, especially perimeter and mobile/browser attack surfaces.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On March 5, 2026, Google Cloud and GTIG published their annual review of 2025 zero-day exploitation, detailing 90 in-the-wild cases, the rise of enterprise targeting, and the growing role of commercial surveillance vendors. The report also warned that AI could further accelerate exploit discovery and development in 2026.
In late 2025, attackers used a SonicWall SMA 1000 exploit chain combining an authentication bypass, a deserialization RCE, and local privilege escalation zero-day CVE-2025-40602. The chain allowed compromise of the appliance up to root level.
Google described suspicious 2025 exploitation of Samsung's Quram image library flaw CVE-2025-21042 using DNG images delivered through a WhatsApp-to-MediaStore path. The report said weak sandboxing in com.samsung.ipservice could enable powerful surveillance outcomes from a single memory-corruption bug.
Google highlighted a 2025 campaign linked to Clop/FIN11 that exploited Oracle E-Business Suite vulnerabilities and stole HR data from dozens of organizations, including Harvard University, Envoy, and The Washington Post. The activity illustrated financially motivated zero-day exploitation at scale.
GTIG attributed nine zero-days in 2025 to financially motivated actors, showing increased criminal use of high-end exploits. The report cited activity linked to CL0P/FIN11 and Russian-linked clusters, including overlap on CVE-2025-8088.
Google assessed PRC-linked espionage groups as the most prolific state users of zero-days in 2025, with at least 10 attributed cases. Their activity focused heavily on edge devices, security appliances, and networking infrastructure for persistent access.
For the first time in Google's tracking, commercial surveillance vendors were attributed more zero-day exploitation in 2025 than traditional state-sponsored espionage groups. The finding marked a notable shift in how governments and customers obtain offensive cyber capabilities.
GTIG reported that 90 zero-day vulnerabilities were actively exploited in the wild in 2025. Nearly half affected enterprise technologies, with Microsoft products the most targeted and operating systems a major category.
Google Threat Intelligence Group recorded 78 zero-day vulnerabilities exploited in the wild during 2024, establishing the baseline for later year-over-year comparisons in its 2025 review.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcecloud.google.com
Open sourcetechcrunch.com
Open sourcebleepingcomputer.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.