Google researchers observed 97 zero-day exploits in the wild in 2023, up 50% from 62 in 2022; 48 were used by espionage actors and 10 were financially-motivated
Cybersecurity experts are warning that zero-day exploits, which can be used to compromise devices before anyone is aware they're vulnerable …
Context & Ripple Effects
Google's tracking had already identified 58 in-the-wild zero-days in 2021, a record that Project Zero partly attributed to stronger discovery and sharing practices. The 2023 count therefore extends a multi-year picture of both persistent exploitation and improving visibility into it.
The mix matters as much as the total: espionage-linked activity accounts for nearly half of the cases observed, placing this reporting in the same state-backed threat arc as Google's earlier warning on likely state-backed malware campaigns. Later tracking remained elevated, with 75 exploited zero-days recorded in 2024.
First-order effects
- Security teams and software vendors face a larger confirmed pool of actively exploited flaws to investigate, patch, and use in threat-hunting priorities.
- The concentration in espionage use makes government, diplomatic, and other high-interest targets especially relevant to defenders' immediate risk assessments.
Second-order effects
- Platform vendors and enterprise security providers are pushed toward faster vulnerability triage and more coordinated disclosure, because a flaw exploited before public awareness leaves little margin for routine patch cycles.
- The high espionage share raises the value of intelligence-sharing across vendors and targeted organizations, while financially motivated actors demonstrate that zero-days are not solely a state-security problem.
Third-order effects
- If elevated in-the-wild exploitation persists, zero-day response becomes a standing ecosystem-defense function rather than an exceptional incident process, spanning discovery, disclosure, patching, and detection.
- Counts should not be read only as attacker capacity: the earlier record number detected in 2021 was also tied to improved finding and sharing, so trends reflect both adversary activity and defensive visibility.
The trend: Zero-day exploitation is becoming a sustained cyber-defense challenge shaped by both state-linked operations and the industry's growing ability to detect previously hidden attacks.