/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google's TIG documented 90 zero-day vulnerabilities exploited in 2025, up from 78 in 2024; commercial spyware vendors and China-linked groups led the abuse

The Register Jessica Lyons

Context & Ripple Effects

Google's tracking has shown exploited zero-days fluctuating at a high level: 55 cases documented for 2022 were followed by 97 observed in 2023. The new tally places 2025 back near that earlier peak rather than indicating a sustained decline.

The attribution matters because Google's prior reporting also described targeted spyware campaigns using zero-days across Android, iOS, and Chrome. This report identifies commercial spyware vendors and China-linked groups as leading sources of abuse in the latest period.

First-order effects

  • Google, software vendors, and their users face a larger set of known real-world exploited flaws to patch and mitigate, with exploitation concentrated among spyware suppliers and China-linked actors.
  • The findings give defenders a clearer basis to prioritize detection and response around targeted intrusion activity rather than treating zero-days primarily as opportunistic cybercrime.

Second-order effects

  • Platform vendors and enterprise security teams will face added pressure to shorten remediation and monitoring cycles for high-risk products, particularly where targeted surveillance operations are a concern.
  • Commercial spyware vendors face greater scrutiny as their role in zero-day abuse becomes more visible, while government-linked operators retain an incentive to seek or develop scarce exploit capabilities.

Third-order effects

  • If elevated zero-day exploitation persists, the market for high-end exploits is likely to remain tied to espionage and surveillance demand, making defensive patching and threat intelligence a more central competitive requirement for major platforms.
  • The repeated concentration of exploitation among state-linked and commercial surveillance actors strengthens the case for policy attention to the cross-border trade and use of offensive cyber capabilities, though the report alone does not establish which intervention would be effective.

The trend: Zero-day exploitation is becoming a durable feature of state-aligned and commercial surveillance operations, sustaining demand for both offensive capabilities and faster platform defenses.

Discussion

  • @cooperq.com @cooperq.com on bluesky
    The cyber-mercenary industry is now bigger than state sponsored hacking.  —  “For the first time since we began tracking zero-day exploitation, we attributed more zero-days to [commercial surveillance vendors] than to traditional state-sponsored cyber espionage groups.”  —  cloud…