HomeSecurityGoogle: Half of 2025's zero-days targeted businesses

Google: Half of 2025's zero-days targeted businesses

Google just revealed that in 2025, half of the 90 zero-day vulnerabilities exploited were targeted at businesses. These zero-day vulnerabilities, which are unknown to software vendors and therefore unpatched, pose a serious threat to the security of information systems. Although fewer than half of these zero-day vulnerabilities have been attributed to specific malicious actors, spyware vendors and China appear to lead the list of perpetrators.

See also: APT28 linked to MSHTML zero-day ahead of February Patch Tuesday

Google zero-day

Zero-day vulnerabilities are especially dangerous because they allow attackers to exploit systems without leaving room for immediate response by security personnel. Companies, especially large multinationals, are attractive targets due to the vast amount of data they handle and the potential financial gains for attackers.

The Google report highlights that spyware software vendors, who often collaborate with governments, are responsible for developing and selling tools that exploit these vulnerabilities. These tools are used for surveillance and espionage, often without the victims' knowledge.

See also: US sanctions Russian zero-day broker for stolen exploits

Google: Half of 2025's zero-days targeted businesses

Furthermore, China has been cited as one of the main players in the realm of zero‑day attacks. The country has invested significantly in developing cyber‑warfare capabilities, and zero‑day vulnerabilities constitute a critical tool in its arsenal. Attacks from China often target industrial sectors and government infrastructures, aiming to gain strategic advantages.

Google, through its Project Zero team, works continuously to discover and fix zero‑day vulnerabilities. This team’s mission is to identify and report vulnerabilities before they are exploited by malicious actors. Collaboration with other technology companies and government agencies is also critical to address this threat.

Protection against zero-day vulnerabilities requires a multi-layered approach to security. Companies must invest in advanced detection and response systems, train their staff to recognize suspicious activities, and keep their systems updated with the latest security patches.

See also: Hackers exploit Ivanti EPMM zero-days to take control of MDM servers

Google: Half of 2025's zero-days targeted businesses

In conclusion, zero-day vulnerabilities will continue to be one of the biggest challenges for cybersecurity in the coming years. Cooperation between the private and public sectors, as well as continuous vigilance, is essential to address this threat.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS