/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google tracked 75 zero days exploited in the wild in 2024, down from 98 in 2023 but up from 63 in 2022; state-sponsored threat groups led in zero-day exploits

Google Threat Intelligence  —  Visibility and context on the threats that matter most.  —  Executive Summary

Google Cloud Blog

Context & Ripple Effects

Google’s 2024 count follows a sharp rise in the prior year, when researchers recorded 97 exploited zero days in 2023, and a longer record of improved visibility into in-the-wild flaws, including 58 detections shared in 2021. The decline is meaningful, but the 2024 level remains above 2022, while the attribution mix makes the activity a national-security as well as a product-security concern.

First-order effects

  • Google Threat Intelligence’s finding puts defenders on notice that state-sponsored groups were the principal users of observed zero days in 2024, concentrating immediate attention on patching and threat hunting for actively exploited vulnerabilities.
  • The lower annual total versus 2023 offers a narrower incident burden for vendors and customers, but does not remove the need to treat exploited flaws as urgent because the count remains elevated relative to 2022.

Second-order effects

  • Software and device makers face added pressure to shorten the path from detection to remediation, while enterprise security teams will prioritize intelligence tied to suspected state-linked activity over raw vulnerability volume.
  • A state-led exploitation profile increases the value of cross-company threat sharing and of capabilities that connect vulnerability research with actor attribution, an example of earlier public sharing of detected zero days.

Third-order effects

  • If exploitation continues to be led by state-backed actors, zero-day defense is likely to become more tightly integrated with geopolitical risk management rather than handled solely as routine vulnerability management.
  • Year-to-year counts should be read as a measure of both attacker activity and detection coverage; the durable shift is toward treating observed exploitation trends as intelligence signals, not a complete census of zero days.

The trend: Zero-day security is evolving from a vulnerability-counting exercise into an intelligence-driven contest shaped increasingly by state-linked operators and defenders’ detection reach.