75 zero-day exploitations spotted by Google, governments increasingly responsible for attacks
- Google observed 75 zero-day bugs last year
- Most were used by state-sponsored actors
- Countries like China and North Korea were specifically mentioned
In 2024, Google’s Threat Intelligence Group (GTIG) discovered 75 zero-day vulnerabilities, and argued that the majority were used in state-sponsored hacking campaigns. The company made these claims in “Hello zero-day my old friend, a 2024 exploitation analysis” paper published recently.
In the report, Google says that the number of zero-day flaws dropped compared to 2023 (from 98 to 75). However, the four-year trend is that the rate of zero-day exploitation “continues to grow at a slow but steady pace.”
While consumer devices continue to be the most attacked targets, there is an increase in adversaries exploiting enterprise-specific technologies. In 2023, roughly a third (37%) of zero-days targeted enterprise products, jumping to 44% last year. This, Google says, is primarily fueled by the increased exploitation of security and networking software and appliances.
Governments at it again
In fact, zero-day vulnerabilities in security software and appliances were a high-value target in 2024. Google says it identified 20 security and networking flaws, which was over 60% of all zero-day exploitation of enterprise technologies. Since the exploitation of these products results in a more efficient and extensive system and network compromise, Google expects threat actors’ focus on these technologies to continue growing.
The biggest abusers of zero-day vulnerabilities are the governments, Google says. “Between government-backed groups and customers of commercial surveillance vendors, actors conducting cyber espionage operations accounted for over 50% of the vulnerabilities we could attribute in 2024,” the report says.
Google singled out China as a major player in this regard, but also mentioned North Korea, whose operatives mixed espionage with financially motivated operations.
The number of Windows exploits rose to 22 (from 16 the year before), while on Safari and iOS it fell (from 11 and 9 to 3 and 2). Android retained its “lucky number” 7, as did Chrome. Firefox was up from zero in 2023 to one in 2024.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via Ars Technica
You might also like
Google observed 75 zero-day bugs last year Most were used by state-sponsored actors Countries like China and North Korea were specifically mentioned In 2024, Google’s Threat Intelligence Group (GTIG) discovered 75 zero-day vulnerabilities, and argued that the majority were used in state-sponsored hacking campaigns. The company made these claims in…
Recent Posts
- Amazon’s new Proteus warehouse robot is fully autonomous
- Let us filter AI slop, you cowards
- AI leaders call for tougher protections against AI-aided bioweapons
- 5 Best Smart Speakers (2026): Alexa, Google Assistant, Siri
- I’m an outdoors expert — here are 9 easy-pitch tents I’d recommend for a fuss-free camping trip
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023