/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google's Threat Analysis Group breaks down three recent malware campaigns, likely state-backed, and notes a large uptick of in-the-wild 0-day attacks this year

Zero-day vulnerabilities are unknown software flaws.  Until they're identified and fixed, they can be exploited by attackers.

The Keyword Maddie Stone

Context & Ripple Effects

Google’s warning followed a TAG-discovered actively exploited Chrome flaw in 2020, extending the group’s public reporting from individual browser vulnerabilities to campaign-level activity assessed as likely state-backed.

The alert also foreshadowed a sustained rise in detected exploitation: Project Zero later recorded 58 in-the-wild zero days in 2021, while subsequent Google research identified espionage actors as a major source of abuse.

First-order effects

  • Google’s Threat Analysis Group publicly identifies three malware campaigns as likely state-backed, giving defenders concrete campaign activity to prioritize alongside vulnerability patching.
  • The reported uptick elevates in-the-wild zero days from isolated software defects to an active threat-intelligence concern for Google’s security operations.

Second-order effects

  • Google’s later data showing espionage actors used 48 of 97 observed 2023 zero days reinforces that state-linked operators, rather than financially motivated groups alone, must be central to zero-day defense planning.
  • The growing volume of observed exploitation increases the value of rapid discovery and disclosure work: Project Zero attributed its 2021 record in part to improved industry detection.

Third-order effects

  • The pattern points to zero-day exploitation becoming a durable feature of state-aligned and commercial surveillance operations, even as annual totals fluctuate; Google later tracked 90 exploited zero days in 2025.
  • Security competition increasingly hinges on the ability to detect live exploitation and turn those observations into patches and public intelligence, not solely on preventing vulnerabilities from existing.

The trend: Zero-day defense is shifting toward continuous exploitation tracking as state-linked and commercial spyware actors sustain demand for previously unknown flaws.

Discussion

  • @b_fung Brian Fung on x
    Google's @ShaneHuntley tells me the suspected Russian hackers who exploited the Apple WebKit zero-day outlined here https://blog.google/... was more specifically the same group behind the USAID impersonation phishing campaign — e.g., Russian foreign intelligence. More from Shane:…
  • @shanehuntley Shane Huntley on x
    Post by @_clem1 & @maddiestone on 4 0days TAG found this year (with IOCs!). We tie three to a commercial surveillance vendor arming govt backed attackers and one to likely Russian APT. Also thoughts on why we are seeing so many 0day in 2021. https://blog.google/... https://twitte…
  • @maddiestone Maddie Stone on x
    More details about the 4 in-the-wild 0-day exploits that Google's Threat Analysis Group has discovered this year as well as our thoughts on the uptick in in-the-wild 0-days we're seeing this year. @_clem1 https://blog.google/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Google found that some LinkedIn messages sent to European government officials led to a zero-day exploit to steal their authentication cookies. Company believes hackers were “likely Russian government-backed.” https://www.vice.com/...
  • @shanehuntley Shane Huntley on x
    These are two different campaigns, but based on our visibility, we consider the actors behind the WebKit 0-day and the USAID campaign to be the same group of actors. https://arstechnica.com/...
  • @lukolejnik Lukasz Olejnik on x
    “exploit would turn off Same-Origin-Policy protections in order to collect authentication cookies from several popular websites, including Google, Microsoft, LinkedIn, Facebook and Yahoo and send them via WebSocket to an attacker-controlled IP” https://blog.google/... https://twi…
  • @campuscodi Catalin Cimpanu on x
    A fourth zero-day was used by a Russian cyber-espionage group (most likely APT29) to target western European government officials via LinkedIn Dedicated report here: https://twitter.com/...
  • @osxreverser @osxreverser on x
    Apple should just outbid everyone else and buy all the exploits. 😂😂😂😂 😂 https://twitter.com/...
  • @dangoodin001 Dan Goodin on x
    iOS zero-day let SolarWinds hackers compromise fully updated iPhones https://arstechnica.com/...
  • @shhnjk Jun Kokatsu on x
    Attackers taking advantage of missing Site Isolation in WebKit. That makes sense for them because all browsers on iOS uses WebKit 🙄Clearly, Apple is behind in the game of Site Isolation and it's impacting users even outside Safari. https://blog.google/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    UPDATE: Google Threat Analysis Group director @ShaneHuntley says they don't know how many people were successfully hacked in this campaign. But he says Google normally sends around 4,000 warnings to users targeted by government hackers. https://www.vice.com/... https://twitter.co…
  • @malwarere Ramin on x
    Additional information/context from TAG regarding the WebKit vulnerability (CVE-2021-1879) leveraged by #NOBELIUM during their email-based attacks (https://www.microsoft.com/...): https://blog.google/... https://twitter.com/...
  • @carolafrediani Carola Frediani on x
    “Russian government hackers targeted European government officials with LinkedIn messages that contained malicious links designed to exploit unknown vulnerabilities in Windows and iOS, according to Google's report” https://www.vice.com/... https://blog.google/... https://twitter.…
  • @maddiestone Maddie Stone on x
    We're also publishing root cause analyses for the four 0-days: Chrome CVE-2021-21166: https://googleprojectzero.github.io/ ... Chrome CVE-2021-30551: https://googleprojectzero.github.io/ ... Internet Explorer CVE-2021-33742: https://googleprojectzero.github.io/ ... Safari CVE-202…
  • @maddiestone Maddie Stone on x
    For the past few months, I've had the honor to work within both Google TAG and Project Zero on the 0-days in-the-wild program. I'm excited to share with y'all the good stuff we've done and will continue to do on the TAG side 🤗