/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google's TIG documented 90 zero-day vulnerabilities exploited in 2025, up from 78 in 2024; commercial spyware vendors and China-linked groups led the abuse

Of the 90 zero-days GTIG tracked in 2025, 43 hit enterprise tech  —  Zero-day exploitation targeting enterprise tech products reached …

The Register Jessica Lyons

Context & Ripple Effects

Google’s tracking has shown a volatile but elevated zero-day environment: 97 exploits observed in 2023 were followed by 75 tracked in 2024. The 2025 count rises again, while remaining below the 2023 peak.

The notable shift in this report is concentration, not only volume: 43 of the documented exploits affected enterprise technology, and commercial spyware vendors and China-linked groups were identified as leading sources of abuse.

First-order effects

  • Enterprise technology vendors and their customers face a more immediate patching and exposure-management burden, since nearly half of the tracked exploits affected enterprise products.
  • The report puts added scrutiny on commercial spyware providers and China-linked operators as leading users of the 2025 exploits.

Second-order effects

  • Security teams are likely to prioritize internet-facing enterprise systems and faster vulnerability remediation, increasing pressure on vendors to shorten the time between disclosure and fixes.
  • The concentration of exploitation among spyware vendors and state-linked groups makes zero-day intelligence and attribution more consequential for enterprise security buyers and defenders.

Third-order effects

  • If enterprise-targeted exploitation remains this concentrated, zero-day defense will increasingly be treated as a core operational resilience requirement rather than a specialized threat-intelligence function.
  • Repeated high annual totals—from the 2022 overview of exploited zero-days through the latest tracking—suggest a durable contest between exploit developers and defenders, even though year-to-year counts remain uneven.

The trend: Zero-day exploitation is becoming a sustained enterprise-security risk shaped by specialized commercial tooling and state-linked operators, rather than an episodic outlier.

Discussion

  • @cooperq.com @cooperq.com on bluesky
    The cyber-mercenary industry is now bigger than state sponsored hacking.  —  “For the first time since we began tracking zero-day exploitation, we attributed more zero-days to [commercial surveillance vendors] than to traditional state-sponsored cyber espionage groups.”  —  cloud…