/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

An overview of 55 zero-day vulnerabilities exploited in 2022, mostly in products from Apple, Microsoft, and Google; Chinese groups exploited more than others

- Mandiant tracked 55 zero-day vulnerabilities that we judge were exploited in 2022.  Although this count is lower …

Mandiant

Context & Ripple Effects

This assessment follows Project Zero’s 2021 tally of 58 in-the-wild zero-days, showing that widely used consumer and enterprise platforms had already become a concentrated target set. Mandiant’s 2022 view adds an actor dimension: Chinese groups accounted for more exploitation than other tracked actors.

Later reporting recorded a sharp rise in observed 2023 zero-day exploitation, while subsequent Google tracking still found activity above the 2022 baseline. The differing totals also underline that zero-day counts reflect each research team’s visibility and methodology, not a single complete census.

First-order effects

  • Apple, Microsoft, and Google face immediate pressure to identify affected product components, issue fixes, and prioritize mitigations for exploit classes being used in the wild.
  • Defenders using those vendors’ products have a clearer basis to prioritize patching and threat hunting around actively exploited flaws, particularly where China-linked activity is relevant to their risk profile.

Second-order effects

  • Security teams and managed-service providers are pushed toward faster emergency-patching processes because exploitation can precede public disclosure and routine update cycles.
  • The concentration in a few platform vendors raises the value of their vulnerability research, telemetry, and mitigation programs, while making customers more dependent on the speed and quality of vendor response.

Third-order effects

  • If exploitation remains concentrated in dominant platforms and state-linked operations, platform security will increasingly be judged on exploit resistance and response capacity rather than vulnerability counts alone.
  • Persistent differences between researchers’ annual tallies may make cross-industry measurement less straightforward, increasing the importance of shared indicators on exploitation, attribution confidence, and remediation.

The trend: This is an early data point in the continuing industrialization of zero-day exploitation against dominant software platforms, with state-linked actors and commercial capabilities driving sustained defensive investment.

Discussion

  • @johnhultquist John Hultquist on x
    Mandiant took a look at zeroday usage by adversaries in 2022. Chinese state actors were in a comfortable lead, followed by those from commercial vendors then Russia and DPRK. For more check out the blog: https://www.mandiant.com/... https://twitter.com/...
  • @shashj Shashank Joshi on x
    Very interesting from Mandiant. “The increased focus on disrupting Russian cyber operations since Russia's invasion of Ukraine may have discouraged Russian operators from widely using valuable zero-day exploits for access they expected to lose quickly.” https://www.mandiant.com/.…